Skip to content

STAC and OAProc fixes#2320

Open
tomkralidis wants to merge 3 commits intomasterfrom
stac-proc-fixes
Open

STAC and OAProc fixes#2320
tomkralidis wants to merge 3 commits intomasterfrom
stac-proc-fixes

Conversation

@tomkralidis
Copy link
Copy Markdown
Member

Overview

This PR fixes the following issues:

  • STAC: further secures path traversal handling
  • OAProc: prevent internal URL requests on process execution with subscribe objects defined, also introducing a configurable allow_internal_requests boolean for those wishing to explicitly allow internal request workflow

Note that this PR should be merged as 2 separate commits (and not squash merged).

Related Issue / discussion

TBD

Additional information

None

Dependency policy (RFC2)

  • I have ensured that this PR meets RFC2 requirements

Updates to public demo

Contributions and licensing

(as per https://github.com/geopython/pygeoapi/blob/master/CONTRIBUTING.md#contributions-and-licensing)

  • I'd like to contribute [feature X|bugfix Y|docs|something else] to pygeoapi. I confirm that my contributions to pygeoapi will be compatible with the pygeoapi license guidelines at the time of contribution
  • I have already previously agreed to the pygeoapi Contributions and Licensing Guidelines

@tomkralidis tomkralidis added this to the 0.24.0 milestone Apr 21, 2026
@tomkralidis tomkralidis added bug Something isn't working STAC SpatioTemporal Asset Catalog OGC API - Processes OGC API - Processes labels Apr 21, 2026
Comment thread docs/source/configuration.rst Outdated
@tomkralidis tomkralidis requested a review from webb-ben April 21, 2026 17:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working OGC API - Processes OGC API - Processes STAC SpatioTemporal Asset Catalog

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants