Python: Adjust request validation#14114
Merged
SergeyMenshykh merged 2 commits intoJun 23, 2026
Merged
Conversation
Refine request validation behavior and update related tests. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Contributor
Python Test Coverage Report •
Python Unit Test Overview
|
||||||||||||||||||||||||||||||
Contributor
There was a problem hiding this comment.
Pull request overview
This PR tightens HttpPlugin request validation by adding port-based allow-listing, aiming to harden outbound HTTP requests (SSRF mitigation) and updates unit tests to reflect the new behavior.
Changes:
- Added
allowed_portsconfiguration toHttpPluginwith default behavior allowing only ports 80 and 443 unless overridden. - Implemented port parsing/enforcement as part of
_is_uri_allowedvalidation logic. - Updated and expanded unit tests to cover default port restrictions, custom port allow-lists, and malformed ports.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 3 comments.
| File | Description |
|---|---|
| python/semantic_kernel/core_plugins/http_plugin.py | Adds allowed_ports and enforces default-deny for non-standard ports during URL allow checks. |
| python/tests/unit/core_plugins/test_http_plugin.py | Updates/extends tests to assert the new port validation behavior and configuration options. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Mark class constants as ClassVar, validate port syntax regardless of allow_all_domains, and clarify docstrings. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
eavanvalkenburg
approved these changes
Jun 23, 2026
TaoChenOSU
approved these changes
Jun 23, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates request validation behavior and related tests.