You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix(ci): cap Figma REST bodies and refuse Host overrides
Absorb the #1032 security extras: allow only X-Figma-Token, cap
whoami/file bodies, cite CWE-22 and plan tokens, and keep a live
unauthenticated /v1/me accuracy check. Prefer this head over #1032.
Co-authored-by: Seongho Bae <[email protected]>
Copy file name to clipboardExpand all lines: CHANGELOG.md
+1Lines changed: 1 addition & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -40,6 +40,7 @@ Semantic Versioning where the repository publishes a release.
40
40
41
41
### Security
42
42
43
+
- Pin Figma REST calls to `http.client.HTTPSConnection("api.figma.com")`, allow only the `X-Figma-Token` header, allowlist file keys and node ids, and cap whoami/file bodies so `file://`, `Host` retargeting, and unbounded reads cannot leave the helper.
43
44
- Reject `.github/` and `scripts/ci/` from review-thread-derived autofix path authority so an untrusted inline reviewer cannot authorize the write-capable repair agent to modify workflows, CODEOWNERS, actions, scheduler code, or CI helpers that govern its own control plane.
44
45
- Require the model-write snapshot and exact-path allowlist to remain outside the pull-request worktree, checking both absolute and resolved locations so repository-local controls and outside-looking symlinks resolving into the repository fail closed before they can authorize or verify model changes.
45
46
- Snapshot the complete pre-model worktree for ordinary and conflict repair and reject every model-caused created, deleted, modified, mode-changed, retargeted, ignored, dangling, directory-backed, external-link, metadata-race, or out-of-scope path before staging or push.
| Cursor Cloud Agent | Figma personal access token in `FIGMA_ACCESS_TOKEN`| REST only: `python3 scripts/ci/figma_rest_auth.py` then `python3 scripts/ci/figma_rest_file.py <file-key-or-url>` (`X-Figma-Token`on pinned `https://api.figma.com/v1/me` and `/v1/files/{key}`) |
43
+
| Cursor Cloud Agent | Figma personal or plan access token in `FIGMA_ACCESS_TOKEN`| REST only: `python3 scripts/ci/figma_rest_auth.py` then `python3 scripts/ci/figma_rest_file.py <file-key-or-url>` (`X-Figma-Token`only, pinned `https://api.figma.com/v1/me` and `/v1/files/{key}`) |
44
44
45
-
A personal access token does **not** unlock Figma MCP on Cloud Agents. It only
46
-
authorizes the REST API. Do not commit the token. Do not put it in
45
+
A personal or plan access token does **not** unlock Figma MCP on Cloud Agents.
46
+
It only authorizes the REST API. Do not commit the token. Do not put it in
47
47
`environment.json`, workflow YAML, or chat output.
48
48
49
+
Prefer a **plan access token** for organization Cloud Agent fleets
50
+
(admin-managed, expiry up to one year; Figma, 2026a). Use a personal access
51
+
token only when the operator is acting on their own account (maximum 90 days).
52
+
Both kinds are stored in the same secret name. Whoami and file bodies are
53
+
capped (64 KiB / 8 MiB). The opener refuses every header except
54
+
`X-Figma-Token` so a `Host` override cannot retarget TLS (CWE-22; MITRE, 2026).
55
+
49
56
## Operator procedure
50
57
51
58
1.**Desktop / CLI MCP (preferred for design-to-code).** In Cursor Desktop,
@@ -123,6 +130,13 @@ authorization framework* (Internet-Draft draft-ietf-oauth-v2-1). Internet
123
130
Engineering Task Force. Retrieved August 16, 2026, from
0 commit comments