Repository navigation
Conversation
…ckfile #55 bumped package.json to 3.0.16 without updating package-lock.json; 3.x peer-depends on eslint ^9 while eslint is pinned to 8.57.1, so npm install fails with ERESOLVE and every CI run is red at Test.
The worker proxied every path to main--helix-website--adobe.aem.live, so its *.workers.dev hostnames served a full Adobe-branded copy of www.aem.live and were reported as phishing. Requests outside /tools/rum/ now get a 301 to the same path and query on https://www.aem.live; /tools/rum/* is unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The Cloudflare account Helix-Dev (
852dfa4ae1b0d579df29be65b986c101) has accepted phishing abuse reports (Netcraft and others) on:rum-proxy-ci.adobeaem.workers.dev/phishing_interstitialactive since 2026-10-03 09:58Zrum-proxy-prod.adobeaem.workers.dev/rum-explorer-og.adobeaem.workers.dev/The interstitial only covers the root URL.
/returns403 Suspected Phishing | Cloudflare, but/docs/and/tools/rum/explorer.htmlstill return 200 with full aem.live content.Root cause
handleRequesthandles/tools/rum/_ogimage*and/tools/rum/_cors*itself. It proxies every other path tomain--helix-website--adobe.aem.live, and only adds the RUM Explorerog:*meta on/tools/rum/explorer.html. Sohttps://rum-proxy-*.adobeaem.workers.dev/,/docs/, etc. serve a full Adobe-branded copy of www.aem.live on aworkers.devhost. That is the pattern phishing scanners flag.Change
fix(security): requests whose path does not start with/tools/rum/now get301 Location: https://www.aem.live<path><query>with an empty body. The aem.live origin is never contacted for those paths. Everything under/tools/rum/behaves exactly as before: the explorerog:*rewrite,_ogimage,_cors, and the other/tools/rum/assets are still proxied.Routing finding (why a redirect is safe, not a loop)
A 301 to www.aem.live would loop if www.aem.live's CDN sent non-
/tools/rum/paths to this Worker. I checked read-only, on 2026-10-05, using response headers that only the Worker path produces on www.aem.live (Worker responses carry the Cloudflarenel/report-toheaders and a singlevia: 1.1 varnish; origin responses carryvia: 1.1 varnish, 1.1 varnish):/,/docs/,/developer/tutorial,/scripts/scripts.js,/favicon.ico,/robots.txtnel/tools/,/tools/rum,/tools/rum-,/tools/rumx,/tools/rumexplorer.html,/tools/oversight/explorer.htmlnel/TOOLS/rum/_cors/tools/rum/,/tools/rum/explorer.html,/tools/rum/elements/list-facet.js,/tools/rum/nonexistentnel/tools/rum/_cors400,x-error: invalid url(origin direct: 404)/tools/rum/_ogimage400,x-error: missing domain or view(origin direct: 404)So the CDN in front of www.aem.live (Fastly/varnish) sends exactly the case-sensitive prefix
/tools/rum/to the Worker. That is the same prefix the new guard keeps. A redirected request therefore always lands on a path that www.aem.live serves from the origin, so it cannot come back to the Worker. Dot-segment paths such as/tools/rum/%2e%2e/docs/are forwarded to the Worker but normalised by WHATWG URL parsing to/tools/docs/, and they redirect to that origin-served path. A code search forrum-proxy-prodacrossorg:adobefinds only this repo, so the CDN config is not in a public adobe repo. The finding above rests on the response headers alone.A plain 404 would also be safe. I chose the redirect so that any old links to the workers.dev hostnames still reach the real site.
Pre-existing CI failure (separate commit)
chore(deps): main has been red since chore(deps): update dependency @adobe/eslint-config-helix to v3 #55 (2026-01-20). That PR bumped@adobe/eslint-config-helixto3.0.16inpackage.jsonbut not inpackage-lock.json, which still has2.0.9. 3.x peer-depends oneslint ^9, whileeslintis pinned to8.57.1, sonpm installfails withERESOLVEand every run fails at Test. The main-run log has expired, but the identical failure is in current Renovate runs, e.g. job 111597208900. This PR pins the package back to2.0.9, matching the lockfile. There is no lockfile change and no other dependency change. Moving to eslint 9 / flat config is left to Renovate.Testing
test/index.test.js: replaced the placeholder with 19 unit tests that stubfetch:/tools/rum/paths (/,/docs/,/developer/tutorial,/tools/rum,/tools/rumx,/tools/,/TOOLS/rum/explorer.html) get a 301 to www.aem.live and make no origin fetch;/tools/rum/explorer.htmlstill proxies tomain--helix-website--adobe.aem.liveand adds escapedog:*tags, and non-ok origin responses pass through;/tools/rum/assets are proxied unchanged;_corsreturns 400 / 403 / 200 with CORS headers;_ogimagereturns 400, the stored image, or the pending 302./tools/: 3 tests fail;Location: 1 test fails.The guard was restored after each.
test/post-deploy.test.js(ci host only, skipped for production):/docs/?x=1must return a 301 tohttps://www.aem.live/docs/?x=1with no HTML body;/must return 301 or 403 (Cloudflare's interstitial answers/before the Worker runs) and must not contain the aem.live page;/tools/rum/_corsmust still return the Worker's 400invalid url.CI blocker: Test Deploy (not caused by this PR)
Test Deploy fails at "Branch Deployment", before the post-deploy tests run. Wrangler gets
Authentication error [code: 10000]from/accounts/852dfa4ae1b0d579df29be65b986c101/workers/services/rum-proxy-ci, so theCLOUDFLARE_API_TOKENrepo secret is invalid or lacks Workers deploy permission. A re-run failed identically. The last successful workflow run in this repo was on main on 2025-09-15, and the January 2026 branch Test Deploy runs also failed (their logs have expired). Thereleasejob deploys through the same token (.releaserc.cjs:deploy:ci,test-postdeploy,deploy:production), so after a merge, the release would also fail until the token is replaced. Someone with Helix-Dev Cloudflare and repo-admin rights needs to issue a new token and update the secret, then re-run this PR's workflow. The post-deploy tests have therefore not been run yet.Follow-ups (not done here)
rum-proxy-ciandrum-proxy-prod.rum-explorer-og.adobeaem.workers.devis a dashboard-only Worker (deployed by maxed@adobe.com, 2024-06) and not part of this repo. It should be deleted; that is Max Edell's call.CLOUDFLARE_API_TOKEN(see above).