.NET: Validate HTTP header delimiters - #8847
Conversation
Reject control delimiters at identity binding and transport boundaries.`n`nShare the validation with declarative workflow headers to keep enforcement consistent.
There was a problem hiding this comment.
MAF Automated Review — Iteration 1
Result: Findings reported
Scope: full PR (1 commit(s)): 7d82b2f94daa
Model: gpt-5.6-sol-fast
Overview
The PR centralizes NUL/CR/LF validation in an opt-in shared source and applies it at both metadata binding and final transport boundaries, with synchronous, asynchronous, streaming, and restored-state coverage. Validation-before-mutation ordering and transport assertions provide strong guardrails. One restored-state edge case remains: delimiter-only identities are classified as whitespace before the new transport validator runs, allowing the request to continue without its delegated identity.
Reviewed the supplied pull-request change set across correctness, security/reliability, architecture, and failure behavior.
1 verified finding remained after source verification (1 medium) across 1 file. Details are attached to the affected lines below.
Affected areas: dotnet/src/Microsoft.Agents.AI.Foundry/UserIdentityPolicy.cs
Validate restored non-null identities before whitespace handling so delimiter-only values cannot bypass transport checks.
Code Coverage OverviewLanguages: C# C# / code-coverage/dotnetThe overall line coverage in commit 32dcc03 in the Show a line coverage summary of the most covered files.
Updated |
There was a problem hiding this comment.
MAF Automated Review — Iteration 2
Result: No findings
Scope: 2 net-new commit(s): aadb0233d6e3, 32dcc0373f94
Model: gpt-5.6-sol-fast
Overview
The incremental change fixes the previously reported delimiter-only identity bypass by validating every non-null restored identity before preserving the existing whitespace-as-absent behavior. The strongest guardrails are the shared final-boundary validation, common sync/async stamping path, and direct plus end-to-end coverage asserting that invalid identities never reach transport. No residual Critical, High, or Medium issue is supported by the reviewed diff.
Reviewed the supplied incremental change set across correctness, security/reliability, architecture, and failure behavior.
No publishable findings remained after source verification for this scope.

Motivation & Context
Request metadata can reach HTTP transport APIs from more than one package and lifecycle path. These values need consistent delimiter validation before they are stored or written as headers so invalid metadata fails predictably without changing valid requests.
Description & Review Guide
Related Issue
N/A. This hardening change is tracked outside GitHub.
Contribution Checklist
breaking changelabel (or add "[BREAKING]" to the title prefix, before or after any language prefix) — a workflow keeps the label and the title prefix in sync automatically.