Server-side URL fetching for assets #14

Open
opened 2026-08-26 04:49:56 +00:00 by jlxq0 · 0 comments
Owner

Migrated from Plan.md's "Deferred (do not drift into these)" section when that file was retired; open work belongs in issues, not in a file with no state. Nothing here is scheduled and no decision has been taken. Do not start it without an explicit go.

Assets are supplied by the caller and validated in a metadata-only preflight before any bytes are read. Nothing in the request causes the server to make an outbound HTTP request.

Adding URL fetching makes the render path an SSRF surface reachable by any authenticated tenant, pointed at the cluster's internal network. That is a security decision, and it has not been taken.

Migrated from `Plan.md`'s "Deferred (do not drift into these)" section when that file was retired; open work belongs in issues, not in a file with no state. **Nothing here is scheduled and no decision has been taken.** Do not start it without an explicit go. Assets are supplied by the caller and validated in a metadata-only preflight before any bytes are read. Nothing in the request causes the server to make an outbound HTTP request. Adding URL fetching makes the render path an SSRF surface reachable by any authenticated tenant, pointed at the cluster's internal network. **That is a security decision**, and it has not been taken.
Sign in to join this conversation.
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
jlxq0/typst-mcp#14
No description provided.