Files
OmniRoute/src/server/authz/classify.ts
Diego Rodrigues de Sa e Souza 78f09c8d9f Release v3.8.41 (#5327)
Release v3.8.41 — 52 commits since v3.8.40 (19 CHANGELOG bullets, 11 contributors).

All gating CI green: Unit×8, Coverage×8, Vitest, Package Artifact, Quality Ratchet, CodeQL, Lint, Docs Sync (Strict), Node 24/26 compat, E2E×9, Integration, Electron smoke.

Advisory checks overridden (main unprotected): PR Test Policy = test-masking heuristic on the cumulative 52-commit assert delta (legitimate dead-code-sweep removals + consolidations, reviewed per-PR); SonarCloud/SonarQube = new-code maintainability/coverage quality gate (CodeQL/Semgrep/Security/npm-audit/Dependabot all clean — not a security finding).
2026-06-29 16:51:03 -03:00

142 lines
4.3 KiB
TypeScript

import {
PUBLIC_API_ROUTE_PREFIXES,
PUBLIC_READONLY_API_ROUTE_PREFIXES,
PUBLIC_READONLY_METHODS,
} from "../../shared/constants/publicApiRoutes";
import type { ClassificationReason, RouteClassification } from "./types";
const CLIENT_API_ALIAS_PREFIXES: ReadonlyArray<{ alias: string; canonical: string }> = [
{ alias: "/chat/completions", canonical: "/api/v1/chat/completions" },
{ alias: "/responses", canonical: "/api/v1/responses" },
{ alias: "/models", canonical: "/api/v1/models" },
];
function normalizePathname(rawPath: string): { path: string; reason?: ClassificationReason } {
let path = rawPath || "/";
if (!path.startsWith("/")) path = "/" + path;
if (path.length > 1 && path.endsWith("/")) path = path.slice(0, -1);
if (path === "/codex" || path.startsWith("/codex/")) {
return { path: "/api/v1/responses", reason: "client_api_codex_alias" };
}
if (path === "/v1/v1" || path.startsWith("/v1/v1/")) {
const tail = path.slice("/v1/v1".length) || "";
return { path: "/api/v1" + tail, reason: "client_api_double_prefix" };
}
if (path === "/v1beta" || path.startsWith("/v1beta/")) {
const tail = path.slice("/v1beta".length) || "";
return { path: "/api/v1beta" + tail, reason: "client_api_alias" };
}
if (path === "/v1" || path.startsWith("/v1/")) {
const tail = path.slice("/v1".length) || "";
return { path: "/api/v1" + tail, reason: "client_api_alias" };
}
for (const { alias, canonical } of CLIENT_API_ALIAS_PREFIXES) {
if (path === alias) {
return { path: canonical, reason: "client_api_alias" };
}
if (path.startsWith(alias + "/")) {
return { path: canonical + path.slice(alias.length), reason: "client_api_alias" };
}
}
return { path };
}
export function classifyRoute(rawPath: string, method: string = "GET"): RouteClassification {
const { path: normalizedPath, reason: aliasReason } = normalizePathname(rawPath);
if (normalizedPath === "/" || normalizedPath === "") {
return {
routeClass: "MANAGEMENT",
reason: "root_redirect",
normalizedPath: "/",
};
}
if (normalizedPath === "/dashboard/onboarding") {
return {
routeClass: "PUBLIC",
reason: "setup_wizard",
normalizedPath,
};
}
// Public, ticket-gated device-flow connect pages (e.g. /connect/codex/{token}).
// Anyone with the shared link completes the provider login in their own browser.
if (normalizedPath === "/connect" || normalizedPath.startsWith("/connect/")) {
return {
routeClass: "PUBLIC",
reason: "public_connect_page",
normalizedPath,
};
}
if (normalizedPath.startsWith("/dashboard")) {
return {
routeClass: "MANAGEMENT",
reason: "dashboard_prefix",
normalizedPath,
};
}
if (normalizedPath === "/api/v1" || normalizedPath.startsWith("/api/v1/")) {
return {
routeClass: "CLIENT_API",
reason: aliasReason ?? "client_api_v1",
normalizedPath,
};
}
if (normalizedPath === "/api/v1beta" || normalizedPath.startsWith("/api/v1beta/")) {
return {
routeClass: "CLIENT_API",
reason: aliasReason ?? "client_api_v1",
normalizedPath,
};
}
if (normalizedPath.startsWith("/api/")) {
if (isClassifiedAsPublic(normalizedPath, method)) {
return {
routeClass: "PUBLIC",
reason: matchesReadonlyPublic(normalizedPath, method)
? "public_readonly_prefix"
: "public_prefix",
normalizedPath,
};
}
return {
routeClass: "MANAGEMENT",
reason: "management_api",
normalizedPath,
};
}
return {
routeClass: "MANAGEMENT",
reason: "fallback_management",
normalizedPath,
};
}
function matchesReadonlyPublic(path: string, method: string): boolean {
if (!PUBLIC_READONLY_METHODS.has(String(method).toUpperCase())) return false;
return PUBLIC_READONLY_API_ROUTE_PREFIXES.some((p) => path.startsWith(p));
}
function isClassifiedAsPublic(path: string, method: string): boolean {
const isV1ApiPrefix = (p: string) =>
p === "/api/v1" || p === "/api/v1/" || p.startsWith("/api/v1/");
const filtered = PUBLIC_API_ROUTE_PREFIXES.filter((p) => p !== "/api/v1/");
if (filtered.some((prefix) => path.startsWith(prefix)) && !isV1ApiPrefix(path)) {
return true;
}
return matchesReadonlyPublic(path, method);
}