vendure-data-hub-plugin

Security Policy

Supported Versions

Version Supported
0.1.x Yes

Reporting a Vulnerability

Do not open a public issue for a suspected security vulnerability. Email office@oronts.com with:

We aim to acknowledge a report within 48 hours and provide an initial assessment within seven days.

Security Boundaries

Outbound HTTP and SSRF

Outbound HTTP features call the plugin’s URL validator before the initial request. The validator accepts only HTTP and HTTPS URLs, rejects known local and metadata hostnames, resolves DNS, and rejects private or reserved IP addresses by default.

Built-in HTTP requests revalidate redirects and socket DNS lookups. Native RabbitMQ AMQP, Redis Streams, FTP, SFTP, SMTP, custom S3/SQS endpoints, PostgreSQL, and MySQL bind connections to an address approved by the same policy; SFTP also supports required production host-key fingerprints. Database connection strings accept only documented single-host TCP URI schemes, reject endpoint-changing parameters and local sockets, and enable MySQL TLS certificate identity verification. These controls are defense in depth, not a replacement for an outbound proxy or firewall allowlist. Custom adapters must apply equivalent redirect and connection-time validation, and SSRF protection must remain enabled for untrusted pipeline configuration.

RabbitMQ adapters require explicit username and password values. Saved connections resolve the password through passwordSecretCode; direct adapter use must provide the resolved password. No built-in RabbitMQ adapter supplies default guest credentials.

Redis Streams resolves the configured host through the same policy and connects to an approved IP while preserving the original TLS server name. Custom SQS endpoint and non-AWS queueUrl hosts use a bounded Smithy transport with a pinned DNS lookup. SQS URLs containing credentials are rejected; use Secret Codes or the AWS credential-provider chain.

allowedHostnames is an explicit bypass of the normal hostname and IP checks. Only use it for hosts that are trusted even if they resolve to a private address.

Expressions and Scripts

Expression operators use a whitelist validator and a Node VM timeout. Script operators also validate source text, limit execution time, restrict the globals supplied by the plugin, and copy record data into the VM context.

Node’s VM is not a strong isolation boundary for hostile code. Treat users who can create, edit, review, or publish script-bearing pipelines as trusted administrators. Disable script operators when that trust model is inappropriate:

DataHubPlugin.init({
    security: {
        script: { enabled: false },
    },
});

SQL

The plugin provides identifier validation and escaping utilities, and supported database handlers use parameter binding for values. Custom adapters and custom queries remain responsible for parameterizing values, validating identifiers, using a least-privilege database account, and applying any required channel or tenant scope.

Permissions

The plugin registers two Vendure CRUD permission groups and 19 task-specific permissions. Assign the smallest applicable set to each role. In particular, separate pipeline read/edit permissions from run, review, and publish permissions where operational separation is required.

Secret Handling

Plugin Security Configuration

The security options belong under security in DataHubPlugin.init():

DataHubPlugin.init({
    security: {
        ssrf: {
            allowedHostnames: ['api.trusted-partner.example'],
            additionalBlockedHostnames: ['legacy.internal.example'],
            additionalBlockedRanges: ['198.51.100.0/24'],
            allowPrivateIPs: false,
        },
        script: {
            enabled: true,
            defaultTimeoutMs: 5_000,
            validation: {
                maxCodeLength: 10_000,
                maxConditionLength: 2_000,
            },
        },
    },
});

disableSsrfProtection and allowPrivateIPs materially reduce protection. Keep their default false values unless the deployment is isolated and the risk is explicitly accepted.

Deployment Checklist

Contact

Security reports: office@oronts.com

General support: https://oronts.com