$ the-wire · showcase
Goose patches MCP redirect SSRF, Claude Code adds gateway IAM
By RepoJournal · Filed · About Agentic Coding · Composed from the cited sources · methodology
A day of things operators can actually use: a security fix for Goose's MCP HTTP client, a lean ACP-only binary, Claude Code gateway roles and Bedrock guardrails, Codex sandbox credential repair on Windows, and Goose v1.52.0 with voice and new providers.
fix: guard MCP streamable-HTTP client redirects against SSRF (loopback/link-local/metadata) aaif-goose/goose
Goose's MCP streamable-HTTP client used to follow server redirects to any host, up to reqwest's default 10 hops and cross-origin, so a remote or compromised MCP server returning 301/302/307/308 with a loopback, link-local, or 169.254.169.254 Location could steer the client inward. Redirects into loopback, link-local, and metadata ranges are now blocked.
v2.1.281 anthropics/claude-code
Claude Code v2.1.281 adds Claude apps gateway support for newer Claude Desktop keys in desktop policy blocks, including blockReadsOutsideWorkingDirectories and disableBypassPermissionsMode, plus assume_role on Bedrock upstreams so the gateway calls Bedrock as an STS-assumed IAM role in another AWS account. Bedrock upstreams also take a guardrail: {id, version} block.
feat: a lean ACP-only Goose binary aaif-goose/goose
Goose gains a size-optimized lean Cargo profile and a minimal goose-acp stdio ACP server binary, with bundled MCP servers, scheduler, optional platform extensions, and the ACP HTTP transport now feature-gated while the default build is unchanged. The ACP-only native-TLS build lands at roughly 15 MiB, down from the original.
Repair rejected Windows sandbox credentials during provisioning openai/codex
Windows sandbox provisioning used to report setup complete when Windows had rejected the stored account passwords, because checking account flags alone missed the failure before runtime logon. Provisioning now checks stored credentials for offline and online accounts before reusing completed setup, and classifies logon failure, expired-password, and password-change-required errors.
v1.52.0 aaif-goose/goose
by github-actions[bot]
Goose v1.52.0 ships live voice conversations in the desktop app, a Decisions provider crate with OpenRouter and Jev implementations, and a Z.AI Coding Plan provider with streaming tool calls. Recipe parameters are now capped at 32 params, 200 select options, and 128 KiB.
fix(opencode): redact credentials in debug config anomalyco/opencode
Also worth knowing: opencode debug config now redacts credential-named values, all configured HTTP header values, and credential-bearing URLs with full *** masks and no unmasking flag, and gemini-cli v0.61.0 fixes the loading indicator that stayed stuck on "Thinking..." during 429 and 503 retries under ui.errorVerbosity = "full".
Action items