Files
OmniRoute/tests/unit/base-executor-ssrf-guard.test.ts
Praveen K Palaniswamy 65e81158ab fix(ollama): route models by advertised capability (#11088)
Landed with the design call resolved per the owner's pick — **option 1**: the synced store is now endpoint-agnostic (persistDiscoveredModels and managedModelImport no longer drop non-chat models at write time), and chat selectability moved to read time (auto-pool expansion in autoStrategy applies filterChatSelectableModels; the models-route projection already had its chatOnly filter). Your discovery test now passes end-to-end (3/3): /api/show capabilities persist per connection and image/embedding requests route through the advertising host.

Reconciliation notes: conflicted areas merged onto the current tip (adobe discovery import, requestedModel preflight signature, resolvedProvider fast-path coexists with the synced-route override — explicit resolution wins); carried base-red drains (#10055 memoization, #11071 test variants) dropped as already-landed; the managed-model-import exclusion test was propagated to the new contract (image/video models persist; the read filter still hides them from chat pickers — pinned by a new assertion). Full battery: 205/206 focused (the one red is a confirmed periodic-timer timing flake on the loaded devbox — 20/20 isolated), autoCombo vitest 30/30, combo suites 46/46, gates + typecheck clean.

Thank you @yourspraveen — the capability probe + routing design was right; it just needed the store contract opened up. Fixes #11087.
2026-08-23 11:45:01 -03:00

39 lines
1.8 KiB
TypeScript

import test from "node:test";
import assert from "node:assert/strict";
import { DefaultExecutor } from "../../open-sse/executors/default.ts";
// GHSA-4f49-hj64-448x — a persisted, caller-supplied providerSpecificData.baseUrl
// reaches fetch() on the runtime dispatch path with no SSRF guard. BaseExecutor
// now mirrors the provider VALIDATION guard before every upstream fetch. In the
// shipped default (block-metadata) mode the cloud-metadata IMDS pivot is blocked
// for non-local providers, public upstreams pass, and local / self-hosted
// providers (vLLM, LM Studio, Ollama, …) stay exempt so loopback/LAN keeps working.
function guardOf(provider: string) {
const exec = new DefaultExecutor(provider) as unknown as {
assertOutboundUrlAllowed(url: string): void;
};
return (url: string) => exec.assertOutboundUrlAllowed(url);
}
test("BaseExecutor blocks cloud-metadata for a non-local provider (GHSA-4f49-hj64-448x)", () => {
const guard = guardOf("openai");
assert.throws(() => guard("http://169.254.169.254/latest/meta-data/iam/security-credentials/"));
// IPv4-mapped IPv6 spelling of the same address (folded out by #10843).
assert.throws(() => guard("http://[::ffff:169.254.169.254]/latest/meta-data/"));
});
test("BaseExecutor allows a public upstream URL for a non-local provider", () => {
const guard = guardOf("openai");
assert.doesNotThrow(() => guard("https://api.openai.com/v1/chat/completions"));
});
test("BaseExecutor exempts local / self-hosted providers from the outbound guard", () => {
assert.doesNotThrow(() => guardOf("ollama-local")("http://127.0.0.1:11434/v1/chat/completions"));
assert.doesNotThrow(() => guardOf("lm-studio")("http://192.168.1.50:1234/v1/chat/completions"));
});
test("BaseExecutor guard is a no-op for an empty URL", () => {
assert.doesNotThrow(() => guardOf("openai")(""));
});