mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-09-20 05:42:19 +03:00
Merged as part of the 39-PR owner batch of 2026-09-11, validated as a unit. Boarded into one consolidated worktree cut from `release/v3.8.51` with the other 38 — zero conflicts between them. - ESLint over every changed file: no errors (the only finding was one suppression entry the batch emptied, pruned on #13243) - `typecheck:core` clean; `check:dashboard-typecheck` OK (206 pre-existing, within baseline); `check:changelog-integrity` OK - complexity 2821 / baseline 3218 and cognitive-complexity 1272 / baseline 1437 — both under baseline - 256 assertions green: 246 under node:test and 10 under vitest, which is where `tests/unit/**/*.test.tsx` actually runs - `check-file-size`: `chatCore.ts` rebaselined 6144 → 6146 for #13278 and #13276, annotated and landed on #13243 ⚠️ base-red inherited: #12732 — the provider count (356 in the docs vs the 358 the modules define) and `open-sse/utils/stream.ts` at 3115 > frozen 3098 both reproduce on the pure tip with zero contribution from this batch.
37 lines
1.7 KiB
TypeScript
37 lines
1.7 KiB
TypeScript
// Boot-time guard for issue #12568: docker-compose can be told to bind the
|
|
// dashboard/API/live-WS ports to a non-loopback interface (APP_BIND_HOST,
|
|
// API_HOST, LIVE_WS_HOST) while REQUIRE_API_KEY still defaults to `false`.
|
|
// That combination puts the anonymous /v1 LLM proxy on the LAN/WAN with no
|
|
// key required. This never hard-fails the boot (a reverse proxy in front of
|
|
// OmniRoute may already be doing its own auth) — it only logs a loud warning
|
|
// so the operator notices the exposure instead of discovering it from traffic.
|
|
|
|
const LOOPBACK_HOSTS = new Set(["127.0.0.1", "::1", "localhost", "::ffff:127.0.0.1"]);
|
|
|
|
function isLoopbackHost(host: string): boolean {
|
|
return LOOPBACK_HOSTS.has(host.trim().toLowerCase());
|
|
}
|
|
|
|
function isRequireApiKeyDisabled(): boolean {
|
|
const raw = (process.env.REQUIRE_API_KEY || "").trim().toLowerCase();
|
|
// Matches the feature-flag default: unset/empty falls back to "false".
|
|
return raw !== "true" && raw !== "1" && raw !== "yes";
|
|
}
|
|
|
|
/**
|
|
* Logs a warning when `host` resolves to a non-loopback interface while
|
|
* REQUIRE_API_KEY is disabled. Never throws and never blocks startup.
|
|
*/
|
|
export function warnIfNonLoopbackWithoutApiKey(serverLabel: string, host: string): void {
|
|
if (isLoopbackHost(host)) return;
|
|
if (!isRequireApiKeyDisabled()) return;
|
|
|
|
console.warn(
|
|
`[startup] ${serverLabel} is bound to non-loopback host "${host}" while ` +
|
|
"REQUIRE_API_KEY is disabled — this exposes the anonymous /v1 proxy to " +
|
|
"every reachable network interface. Set REQUIRE_API_KEY=true, or bind " +
|
|
"back to 127.0.0.1, unless a reverse proxy in front of this instance " +
|
|
"already enforces its own authentication."
|
|
);
|
|
}
|