Skip to content

fix(tracking): validate identifiers and keep server paths inside the storage directory - #948

Open
elijahbenizzy wants to merge 2 commits into
mainfrom
fix/tracking-identifier-validation
Open

elijahbenizzy wants to merge 2 commits into
mainfrom
fix/tracking-identifier-validation

Conversation

@elijahbenizzy

Copy link
Copy Markdown
Contributor

Carries forward #795 by @andreahlert with his commit intact, and shares the identifier rule with the tracking client (#946).

  • Project and app identifiers in tracking server requests are validated against the same allowlist the client uses; invalid ones return HTTP 400.
  • Paths the server builds are resolved and kept inside the configured storage directory.
  • python -m burr.tracking.server.run binds to 127.0.0.1 by default, overridable with BURR_SERVER_HOST, matching what the burr CLI already does. The CLI help and module docstring note that the server has no built-in authentication.

23 tests added. Merge before #944, which documents this behavior.

andreahlert and others added 2 commits October 4, 2026 13:21
…storage directory

Add an allowlist check for project and app identifiers in LocalBackend and a
join helper that resolves paths and verifies they stay inside the configured
storage directory. Bind the standalone server to 127.0.0.1 by default.
…e server endpoints

Move the project/app identifier rule and the path join helper into
burr.tracking.common.identifiers (shared with LocalTrackingClient), keep the
LocalBackend wrappers that report failures as HTTP 400, honour BURR_SERVER_HOST
for the standalone server, and extend the tests to the FastAPI endpoints,
symlinked directories and client-style identifiers.
@elijahbenizzy
elijahbenizzy requested a review from skrawcz October 4, 2026 20:38
@github-actions github-actions Bot added the area/tracking Telemetry, tracing, OpenTelemetry label Oct 4, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/tracking Telemetry, tracing, OpenTelemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants