From 83814b30f2028aabcc878bf04e3a794455f9ef7f Mon Sep 17 00:00:00 2001 From: liqiang-fit2cloud Date: Fri, 7 Nov 2025 11:02:17 +0800 Subject: [PATCH] refactor: ban host.docker.internal access by default. --- installer/Dockerfile-base | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/installer/Dockerfile-base b/installer/Dockerfile-base index ebf6c00ce..030d341a0 100644 --- a/installer/Dockerfile-base +++ b/installer/Dockerfile-base @@ -47,7 +47,7 @@ ENV PATH=/opt/py3/bin:$PATH \ MAXKB_SANDBOX=1 \ MAXKB_SANDBOX_PYTHON_PACKAGE_PATHS="/opt/py3/lib/python3.11/site-packages,/opt/maxkb-app/sandbox/python-packages,/opt/maxkb/python-packages" \ MAXKB_SANDBOX_PYTHON_BANNED_KEYWORDS="subprocess.,system(,exec(,execve(,pty.,eval(,compile(,shutil.,input(,__import__" \ - MAXKB_SANDBOX_PYTHON_BANNED_HOSTS="127.0.0.1,localhost,maxkb,pgsql,redis" \ + MAXKB_SANDBOX_PYTHON_BANNED_HOSTS="127.0.0.1,localhost,host.docker.internal,maxkb,pgsql,redis" \ MAXKB_ADMIN_PATH=/admin EXPOSE 6379 \ No newline at end of file