Scalingo / go-utils

Small libraries and helpers concerning errors, logging, nsq
6 stars 2 forks source link

[NCP-555][storage] Add an allow list of domain names for uploading files to storage #804

Open ipfaze opened 7 months ago

ipfaze commented 7 months ago

NCP-555

To enforce security, we would like to add an allow list to make sure we upload our files to a trusted object storage.

https://www.notion.so/scalingooriginal/Is-the-URL-schema-port-and-destination-enforced-with-a-positive-allow-list-b5748b867b52451e9d6f70081c8d82ae

SCedricThomas commented 7 months ago

Here is the meeting we had with infosec that specify the requirements of this fix: https://www.notion.so/scalingooriginal/SCAR-Upload-deployments-logs-to-OOS-bf134f86588c46f7ac28ab349f360240

ipfaze commented 4 months ago

STORY-428

yanjost commented 3 months ago

Proposal: