{"record":{"id":"271bbe938b9dc4ea","repo":"affaan-m/ECC","slug":"download-requires-https-on-an-approved-fal-media-host","errorCode":null,"errorMessage":"download requires HTTPS on an approved fal.media host","messagePattern":"download requires HTTPS on an approved fal\\.media host","errorType":"exception","errorClass":"FalError","httpStatus":null,"severity":"error","filePath":"skills/taste-application/scripts/falapi.py","lineNumber":671,"sourceCode":"# ---------------------------------------------------------------------------\n# download\n# ---------------------------------------------------------------------------\n\n\nMAX_DOWNLOAD_BYTES = 2 * 1024 * 1024 * 1024  # bounded large video/GLB downloads\n\n\ndef _validate_download_url(url: str) -> None:\n    try:\n        parsed = urllib.parse.urlsplit(url)\n        host = parsed.hostname or \"\"\n        valid = (parsed.scheme == \"https\" and not parsed.username\n                 and not parsed.password and parsed.port in (None, 443)\n                 and (host == \"fal.media\" or host.endswith(\".fal.media\")))\n    except ValueError:\n        valid = False\n    if not valid:\n        raise FalError(\"download requires HTTPS on an approved fal.media host\")\n\n\nclass _SafeRedirect(urllib.request.HTTPRedirectHandler):\n    def redirect_request(self, req, fp, code, msg, headers, newurl):\n        _validate_download_url(newurl)\n        return super().redirect_request(req, fp, code, msg, headers, newurl)\n\n\ndef download(url: str, dest: str | Path) -> Path:\n    \"\"\"Bounded HTTPS download; failed transfers preserve existing destinations.\"\"\"\n    dest = Path(dest)\n    if is_dry_run():\n        dest.parent.mkdir(parents=True, exist_ok=True)\n        dest.write_bytes(b\"taste-forge dry-run placeholder\\n\")\n        log.info(\"[dry-run] would download from %s\", safe_url(url))\n        return dest\n\n    require_live()","sourceCodeStart":653,"sourceCodeEnd":689,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/skills/taste-application/scripts/falapi.py#L653-L689","documentation":"FalError raised by _validate_download_url() when a download target URL is not HTTPS on an approved fal.media host (exact host 'fal.media' or any '*.fal.media' subdomain), or carries embedded credentials or a non-443 port. This guard is enforced both for the initial download URL and on every redirect (via _SafeRedirect), preventing the library from fetching attacker-controlled URLs or leaking data to non-approved hosts.","triggerScenarios":"Passing an http:// URL, a non-fal.media host (CDN host other than fal.media), a URL with user:pass@, an explicit port like :8443, or a redirect chain that hops to a disallowed host.","commonSituations":"Provider responses that changed and now point at a different CDN domain; hand-editing URLs to http; older cached URLs pointing at a legacy host; a redirect from fal.media to a generic storage domain that the validator blocks by design.","solutions":["Use the exact URL returned by fal APIs unmodified — it should be https on fal.media","Downgrade http:// to https:// only if the host is fal.media or *.fal.media","Strip any embedded credentials or explicit port from the URL","If the provider now returns a different host, update the allowlist in _validate_download_url consciously (with a security review) rather than bypassing it"],"exampleFix":"// before\nurl = result[\"video\"][\"url\"].replace(\"https\", \"http\")\ndownload(url, dest)\n// after\nurl = result[\"video\"][\"url\"]  # https://...fal.media/...\ndownload(url, dest)","handlingStrategy":"validation","validationCode":"from urllib.parse import urlparse\ndef is_approved_fal_url(u: str) -> bool:\n    p = urlparse(u)\n    return (p.scheme == \"https\" and not p.username and not p.password\n            and p.port in (None, 443)\n            and (p.hostname == \"fal.media\" or (p.hostname or \"\").endswith(\".fal.media\")))","typeGuard":"def is_approved_fal_url(u: object) -> bool:\n    if not isinstance(u, str):\n        return False\n    try:\n        p = urlparse(u)\n    except ValueError:\n        return False\n    return p.scheme == \"https\" and p.hostname in (\"fal.media\",) or (p.hostname or \"\").endswith(\".fal.media\") and p.scheme == \"https\"","tryCatchPattern":"try:\n    download(url, dest)\nexcept FalError as e:\n    if \"approved fal.media host\" in str(e):\n        logging.error(\"refusing non-approved download URL: %r\", safe_url(url))\n    raise","preventionTips":["Only pass URLs returned directly by fal APIs","Never rewrite scheme, host, port, or credentials on provider URLs","Don't follow hand-built URLs from logs into download()","If the provider changes CDN hosts, review and update the allowlist deliberately"],"tags":["security","download","url-validation"],"backgroundTag":"invalid-url","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}