a2aproject / a2aproject/a2a-js

[Feat]: Integrated SSRF and DNS Rebinding Protection across all Transports

オープン
#350 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
TypeScript
スター
613
フォーク
169
平均マージ
1日 6時間
マージ済み PR(30日)
21

説明

### Is your feature request related to a problem? Please describe.

The Gemini CLI team is integrating the A2A SDK to support remote agents. To meet production security standards, it is critical that the CLI is protected against Server-Side Request Forgery (SSRF) and DNS Rebinding attacks.

We believe these security guardrails should be a native part of the SDK to ensure all consumers are "secure by default."

### Describe the solution you'd like

Requested Features:
1. **Transport-Agnostic Connection Filtering:** A unified mechanism (e.g., a connectionInterceptor or lookup hook) in the ClientFactory that applies to all transports (REST, JSONRpc, and gRPC) to block access to private/internal IP ranges.
1. **DNS Rebinding Protection (IP Pinning):** Support for "pinning" a connection to the specific IP address resolved during the initial Agent Card discovery phase. This is necessary to prevent Time-of-Check/Time-of-Use (TOCTOU) attacks where an attacker swaps a hostname's DNS record between discovery and tool execution.
1. **Secure Card Validation:** Built-in validation in the DefaultAgentCardResolver to automatically reject agent cards if the card URL or any nested interface URLs point to restricted IP ranges.

### Describe alternatives you've considered

We attempted to implement these protections at the application layer, but found it impossible to achieve full coverage without "hacking" SDK internals—especially for gRPC, which does not respect the same connection-level hooks as HTTP-based transports.

### Additional context

_No response_

### Code of Conduct

- [x] I agree to follow this project's Code of Conduct

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Look at the ClientFactory and the transport implementations (REST, JSONRpc, gRPC) to understand how connections are made. The DefaultAgentCardResolver needs validation logic. Check for existing hooks or interceptors. The goal is to add IP filtering and DNS pinning across all transports, ensuring secure-by-default behavior.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
nodejs, typescript
領域
backend-api-design, networking, security
issue の種類
機能追加
難易度
4/5
見積もり時間
3〜5日
活発さ
静か
明瞭さ
おおむね明確
初心者へのやさしさ
45/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。