Skip to content

fix(api): constrain workflow response headers - #8341

Merged
waleedlatif1 merged 2 commits into
stagingfrom
codex/workflow-response-header-safety
Sep 26, 2026
Merged

waleedlatif1 merged 2 commits into
stagingfrom
codex/workflow-response-header-safety

Conversation

@waleedlatif1

Copy link
Copy Markdown
Collaborator

Summary

  • Keep Response block HTTP replies as JSON regardless of custom header casing.
  • Reserve cookie, browser-policy, redirect, and transport headers for the server while preserving response data, status codes, and ordinary custom headers.
  • Document the header restrictions and cover the HTTP response boundary with regression tests.

Type of Change

  • Bug fix

Testing

  • 127 tests passed across response security, workflow utilities, and v1/v2 workflow execution routes.
  • All five security regression cases failed before the fix; removing each of the four guards also failed the regression suite.
  • App type-check, lint, all 51 repository audits, block-registry check, and docs-manifest check passed.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Sep 26, 2026 9:31pm UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 3 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/workflows/utils.ts
@greptile-apps

greptile-apps Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Critical risk] Constrains which HTTP headers workflow responses can set.

The PR appears safe to merge; the previously reported browser-policy header gap is fixed.

Summary

The PR constrains Response block HTTP headers while preserving JSON responses, status codes, and ordinary custom headers.

  • Reserves additional browser-policy and legacy security headers.
  • Extends boundary tests and documents the restriction.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Response block output] --> B[Normalize and filter headers]
  B --> C[Set JSON content type and nosniff]
  C --> D[Public HTTP response]
Loading

Reviews (2) · Last reviewed commit: "fix(api): reserve additional browser pol..."

Comment thread apps/sim/lib/workflows/utils.ts
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 3 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit ec0f474 into staging Sep 26, 2026
23 checks passed
@waleedlatif1
waleedlatif1 deleted the codex/workflow-response-header-safety branch September 26, 2026 21:37

This branch was previously deployed

1 inactive deployment
Preview — ba5cde1d Deployed Sep 26, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant