Repository navigation
acl: support single-label wildcards in domain globs - #344
Merged
Merged
Conversation
Domain globs only allowed a leading "*.", so patterns like access-analyzer.*.amazonaws.com (#241) or api*.example.com had to be expanded by hand, and new regions or hosts silently fell outside the list. Globs may now also contain a single wildcard that is confined to one label: either a whole non-leftmost label or a suffix after a literal prefix. Such a wildcard never crosses a dot, must be followed by a registrable domain, and is rejected in the TLD, Punycode labels, IP-shaped patterns, and directly after a leading "*" since that is usually a typo for "*.". Outside the global deny list, a host only matches if its registrable domain per the public suffix list equals that of the glob's literal suffix. Without this, access-analyzer.*.amazonaws.com would allow access-analyzer.s3.amazonaws.com, an S3 bucket anyone can claim. The cost is that hosts the PSL splits off, like the us-east-1.amazonaws.com suffix, must be listed explicitly. The global deny list skips the check so a denied glob blocks every host it reads as. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Committed-By-Agent: claude
The matcher re-derived a label wildcard's structure on its own and only rejected some of the shapes that validation rejects, so an unvalidated glob such as 1*.0.0.1 still matched an IP address in the global deny list. Validation and matching now share one parser, and a glob only matches after passing the same checks as ValidateDomainGlob. The normalization and public suffix checks run only after the labels match, so a miss costs no more than before. The README now also notes that hosts that are public suffixes themselves, such as regional S3 endpoints, never match a wildcard, and that denying a label wildcard covers neither the bare prefix nor subdomains. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Committed-By-Agent: claude
Contributor
Author
A label wildcard that lands on a public suffix, such as sts.*.amazonaws.com against sts.us-east-1.amazonaws.com, is skipped in allow lists. Until now the resulting denial read like a missing entry, so the decision reason now names the skipped wildcard and the public suffix responsible. The hint is only computed on denied or reported requests, and Reason is not a metric tag. Some ACLs may prefer the broader match, so unsafe_allow_wildcards_across_public_suffixes turns the check off for every allow list in that ACL. It stays off by default, validation is unchanged, and HostMatchesGlob and the IP filter bypass list remain strict because they don't belong to an ACL. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Committed-By-Agent: claude
gauthamw-stripe
approved these changes
Oct 6, 2026
This was referenced Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Domain globs only supported a leading
*., so patterns likeaccess-analyzer.*.amazonaws.com(#241) had to be listed host by host. This PR allows one wildcard confined to a single label:access-analyzer.*.amazonaws.commatches exactly one label.api*.example.comandweb*-canary.example.commatch one or more characters within a label, never a..Validation rejects multiple wildcards, wildcards in the TLD, and wildcards directly under a public suffix (e.g.
foo*.github.io,login.*.com).A wildcard also can't match a host owned by someone else, according to the public suffix list. For example,
access-analyzer.*.amazonaws.comdoesn't matchaccess-analyzer.s3.amazonaws.com, an S3 bucket anyone can create. When that's the only reason a request is denied or reported, the deny message says so:An ACL can turn the check off with
unsafe_allow_wildcards_across_public_suffixes: true. The global deny list always skips it on purpose. There, matching too much only blocks extra hosts, while matching too little would let denied traffic through.Existing globs validate and match exactly as before. Error messages for globs with non-leading wildcards have changed.
Limitations
us-east-1.amazonaws.comands3.<region>.amazonaws.com. Without the opt-out, these never match and need explicit entries.decision_reasonvalues, so anything grouping logs by that field sees them.x/net.api*.example.comdoesn't matchapi.example.com.Testing
Run locally, not committed:
Decide.🤖 Generated with Claude Code