Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion static/schemas/Builder.schema.json
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@
"instance_id": {
"description": "Instance ID from `xmpMM:InstanceID` in XMP metadata.",
"type": "string",
"default": "xmp.iid:95caab0d-9a0d-4246-b26c-88f7b939562b"
"default": "xmp.iid:eda53aaf-f7c0-4d91-8320-13fa82c0037f"
},
"thumbnail": {
"description": "An optional ResourceRef to a thumbnail image that represents the asset that was signed.\nMust be available when the manifest is signed.",
Expand Down
2 changes: 1 addition & 1 deletion static/schemas/ManifestDefinition.schema.json
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@
"instance_id": {
"description": "Instance ID from `xmpMM:InstanceID` in XMP metadata.",
"type": "string",
"default": "xmp.iid:cc18752d-10a4-4b45-ac18-73586cb35418"
"default": "xmp.iid:32903aee-412b-4e46-adb1-58605efded26"
},
"thumbnail": {
"description": "An optional ResourceRef to a thumbnail image that represents the asset that was signed.\nMust be available when the manifest is signed.",
Expand Down
2 changes: 1 addition & 1 deletion static/schemas/Reader.schema.json
Original file line number Diff line number Diff line change
Expand Up @@ -108,7 +108,7 @@
"instance_id": {
"description": "Instance ID from `xmpMM:InstanceID` in XMP metadata.",
"type": "string",
"default": "xmp.iid:e589348a-be9b-4191-9e5c-1f6359510aaf"
"default": "xmp.iid:05575196-8d0c-420e-9ec0-38f43cd96623"
},
"thumbnail": {
"anyOf": [
Expand Down
4 changes: 2 additions & 2 deletions static/schemas/Settings.schema.json
Original file line number Diff line number Diff line change
Expand Up @@ -254,7 +254,7 @@
"default": true
},
"allowed_network_hosts": {
"description": "<div class=\"warning\">\nThe CAWG identity assertion does not currently respect this setting.\nSee [Issue #1645](https://github.com/contentauth/c2pa-rs/issues/1645).\n</div>\n\nList of host patterns that are allowed for network requests.\n\nEach pattern may include:\n- A scheme (e.g. `https://` or `http://`)\n- A hostname or IP address (e.g. `contentauthenticity.org` or `192.0.2.1`)\n - The hostname may contain a single leading wildcard (e.g. `*.contentauthenticity.org`)\n- An optional port (e.g. `contentauthenticity.org:443` or `192.0.2.1:8080`)\n\nMatching is case-insensitive. A wildcard pattern such as `*.contentauthenticity.org` matches\n`sub.contentauthenticity.org`, but does not match `contentauthenticity.org` or `fakecontentauthenticity.org`.\nIf a scheme is present in the pattern, only URIs using the same scheme are considered a match. If the scheme\nis omitted, any scheme is allowed as long as the host matches.\n\nThe behavior is as follows:\n- `None` (default): no host allow-list is applied. Redirect handling is governed\n independently by [`allow_redirects`] (which rejects redirects to internal addresses).\n- `Some(vec)` where `vec` is empty, all traffic is blocked.\n- `Some(vec)` with at least one pattern, filtering enabled for only those patterns.\n\nWhen an allow-list is set it is enforced on every request, including each redirect hop the\nSDK follows, so a redirect to a host outside the allow-list is rejected.\n\n[`allow_redirects`]: Core::allow_redirects\n\n# Examples\n\nPattern: `*.contentauthenticity.org`\n- Does match:\n - `https://sub.contentauthenticity.org`\n - `http://api.contentauthenticity.org`\n- Does **not** match:\n - `https://contentauthenticity.org` (no subdomain)\n - `https://sub.fakecontentauthenticity.org` (different host)\n\nPattern: `http://192.0.2.1:8080`\n- Does match:\n - `http://192.0.2.1:8080`\n- Does **not** match:\n - `https://192.0.2.1:8080` (scheme mismatch)\n - `http://192.0.2.1` (port omitted)\n - `http://192.0.2.2:8080` (different IP address)\n\nThese settings are applied by the SDK's HTTP resolvers to restrict network requests.\nWhen network requests occur depends on the operations being performed (reading manifests,\nvalidating credentials, timestamping, etc.).",
"description": "<div class=\"warning\">\nThe CAWG identity assertion does not currently respect this setting.\nSee [Issue #1645](https://github.com/contentauth/c2pa-rs/issues/1645).\n</div>\n\nList of host patterns that are allowed for network requests.\n\nEach pattern may include:\n- A scheme (e.g. `https://` or `http://`)\n- A hostname or IP address (e.g. `contentauthenticity.org` or `192.0.2.1`)\n - The hostname may contain a single leading wildcard (e.g. `*.contentauthenticity.org`)\n- An optional port (e.g. `contentauthenticity.org:443` or `192.0.2.1:8080`)\n\nMatching is case-insensitive. A wildcard pattern such as `*.contentauthenticity.org` matches\n`sub.contentauthenticity.org`, but does not match `contentauthenticity.org` or `fakecontentauthenticity.org`.\nIf a scheme is present in the pattern, only URIs using the same scheme are considered a match. If the scheme\nis omitted, any scheme is allowed as long as the host matches.\n\nThe behavior is as follows:\n- `None` (default): no host allow-list is applied. Redirect handling is governed\n independently by [`allow_redirects`] (which rejects redirects to internal addresses), and\n the initial request is still rejected if it directly names a link-local/cloud-metadata\n address (SSRF – <https://github.com/contentauth/c2pa-rs/issues/2430>); see [`allow_redirects`] for the full initial-request policy.\n- `Some(vec)` where `vec` is empty, all traffic is blocked.\n- `Some(vec)` with at least one pattern, filtering enabled for only those patterns. Setting\n this takes over the initial-request policy entirely, superseding the default\n link-local/cloud-metadata guard described above.\n\nWhen an allow-list is set it is enforced on every request, including each redirect hop the\nSDK follows, so a redirect to a host outside the allow-list is rejected.\n\n[`allow_redirects`]: Core::allow_redirects\n\n# Examples\n\nPattern: `*.contentauthenticity.org`\n- Does match:\n - `https://sub.contentauthenticity.org`\n - `http://api.contentauthenticity.org`\n- Does **not** match:\n - `https://contentauthenticity.org` (no subdomain)\n - `https://sub.fakecontentauthenticity.org` (different host)\n\nPattern: `http://192.0.2.1:8080`\n- Does match:\n - `http://192.0.2.1:8080`\n- Does **not** match:\n - `https://192.0.2.1:8080` (scheme mismatch)\n - `http://192.0.2.1` (port omitted)\n - `http://192.0.2.2:8080` (different IP address)\n\nThese settings are applied by the SDK's HTTP resolvers to restrict network requests.\nWhen network requests occur depends on the operations being performed (reading manifests,\nvalidating credentials, timestamping, etc.).",
"type": [
"array",
"null"
Expand All @@ -265,7 +265,7 @@
"default": null
},
"allow_redirects": {
"description": "Whether the SDK follows HTTP redirects for requests made while reading and validating\n(remote manifests, OCSP, timestamps, `did:web`).\n\nBecause some request URLs come from untrusted content, following redirects can be abused to\nreach internal or cloud-metadata endpoints (SSRF – CAI-12574). To prevent that while\nremaining compatible with legitimate redirects:\n\n- `true` (default): redirects are followed, **except** when a redirect target is a\n non-globally-routable address (loopback, private/RFC1918, link-local and cloud-metadata,\n IPv6 unique-local/link-local, CGNAT, etc.). Such a redirect is rejected with\n [`HttpResolverError::RedirectTargetDisallowed`]. Redirects to public hosts are followed\n normally.\n- `false`: redirects are not followed at all; a redirect response is surfaced as\n [`HttpResolverError::RedirectDisallowed`].\n\nThis applies to redirect *targets*, not the initial request: a URL that *directly* names an\ninternal host (for example an enterprise OCSP responder on a private address, or a\n`localhost` development server) is still fetched. Use [`allowed_network_hosts`] to restrict\nwhich hosts may be contacted at all.\n\n[`allowed_network_hosts`]: Core::allowed_network_hosts\n[`HttpResolverError::RedirectTargetDisallowed`]: crate::http::HttpResolverError::RedirectTargetDisallowed\n[`HttpResolverError::RedirectDisallowed`]: crate::http::HttpResolverError::RedirectDisallowed",
"description": "Whether the SDK follows HTTP redirects for requests made while reading and validating\n(remote manifests, OCSP, timestamps, `did:web`).\n\nBecause some request URLs come from untrusted content, following redirects can be abused to\nreach internal or cloud-metadata endpoints (SSRF – CAI-12574). To prevent that while\nremaining compatible with legitimate redirects:\n\n- `true` (default): redirects are followed, **except** when a redirect target is a\n non-globally-routable address (loopback, private/RFC1918, link-local and cloud-metadata,\n IPv6 unique-local/link-local, CGNAT, etc.). Such a redirect is rejected with\n [`HttpResolverError::RedirectTargetDisallowed`]. Redirects to public hosts are followed\n normally.\n- `false`: redirects are not followed at all; a redirect response is surfaced as\n [`HttpResolverError::RedirectDisallowed`].\n\nThis applies to redirect *targets*, not the initial request. Independently of this setting,\nthe initial request is rejected by default when it directly names a link-local or\ncloud-metadata address (e.g. `169.254.169.254`), reported as\n[`HttpResolverError::MetadataOrLinkLocalUriDisallowed`] (SSRF – <https://github.com/contentauth/c2pa-rs/issues/2430>). A URL that\ndirectly names a loopback or private (RFC 1918) host (for example an enterprise OCSP\nresponder on a private address, or a `localhost` development server) is not covered by that\nguard and is still fetched. Use [`allowed_network_hosts`] to restrict which hosts — including\nloopback/private ones — may be contacted at all.\n\n[`allowed_network_hosts`]: Core::allowed_network_hosts\n[`HttpResolverError::RedirectTargetDisallowed`]: crate::http::HttpResolverError::RedirectTargetDisallowed\n[`HttpResolverError::RedirectDisallowed`]: crate::http::HttpResolverError::RedirectDisallowed\n[`HttpResolverError::MetadataOrLinkLocalUriDisallowed`]: crate::http::HttpResolverError::MetadataOrLinkLocalUriDisallowed",
"type": "boolean",
"default": true
},
Expand Down