Feat/attachment malware scanning - #1310
Open
jjavieralv wants to merge 2 commits into
Open
Conversation
/files/confirm now scans every confirmed upload after the magic-byte gate and before the file is queued: a flagged file has its blob deleted and its slot released, so it never reaches the session queue, the Linear ticket or the support team, and the widget shows "Malicious code detected". Scanning goes through a new IMalwareScanner seam over the file-malware-scanner Cloudflare worker (VirusTotal + Claude, /v1/scan). Each engine has its own policy — off (ignored), optional (only a positive detection blocks) or mandatory (a missing verdict blocks too, as a retriable scan_unavailable) — defaulting to Claude mandatory and VirusTotal optional, since VirusTotal's free tier rate-limits at 4 req/min and knows no hash for freshly created files. The feature is behind a master switch (off in production until validated on dev/preview) and every setting has an ASSISTANT_MALWARE_SCAN_* env override.
The three findings are the public contract address 0x0bA45A8b... used as a test fixture in variables named `token`; gitleaks reads it as a generic API key. Same finding already baselined for permissionsList.test.tsx under its pre-monorepo path — re-fingerprinted after the move to apps/app. Blocks every new branch push until baselined.
|
E2E results (preview) Smoke
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Please include a summary of the changes and the related issue. Please also include relevant motivation and context. List
any dependencies that are required for this change.
Type of Change
Developer Checklist:
Review Checklist: