Files
OmniRoute/docs
diegosouzapw cfd1007f0d fix(docker): require a per-session token on the VNC browser CDP bridge (#12571)
docker/vnc-browser/chromium/cdp-bridge.py republished Chromium's loopback
CDP port (127.0.0.1:9222) onto 0.0.0.0:9223 with zero auth, and the
container joined Docker's default bridge network — any sibling container
could connect to 9223 and issue arbitrary CDP commands (Runtime.evaluate,
cookie theft) against a live, credential-bearing browser-login session.

- cdp-bridge.py now requires a shared secret (CDP_BRIDGE_TOKEN) presented
  as an X-Omni-Cdp-Token header on the first bytes of a connection before
  forwarding anything upstream; a missing/invalid token gets the socket
  closed silently.
- src/lib/vncSession/service.ts generates a random per-session token,
  injects it into the container via -e CDP_BRIDGE_TOKEN, and joins the
  container to a dedicated Docker network (not the default bridge) as
  defense-in-depth.
- src/lib/vncSession/harvest.ts forwards the token on every CDP HTTP/WS
  call so the harvester keeps working end-to-end.
2026-09-10 13:53:01 -03:00
..
2026-06-29 08:40:06 -03:00

title, version, lastUpdated
title version lastUpdated
OmniRoute Documentation 3.8.40 2026-06-28

OmniRoute Documentation

Navigable index of the OmniRoute documentation set. Topics are grouped by intent so you can find what you need quickly.

Looking for the project overview, install steps, or release notes? See the root README.md, ROADMAP.md, CHANGELOG.md, and CONTRIBUTING.md.


For Non-Tech Users

Simple guides for using OmniRoute — no technical background needed.

getting-started/

guides/


For Tech Users

Technical documentation for developers and contributors.

architecture/

How the system is put together — read these to understand the runtime, code layout, and resilience model.

reference/

Lookup material — API surface, environment variables, CLI flags, provider catalog.

frameworks/

Pluggable subsystems exposed to clients, agents, and operators.

routing/

Combo routing, scoring, and replay.

security/

Guardrails, compliance, stealth, and the mandatory patterns for handling public credentials and error messages.

compression/

Prompt compression engines, rules, and language packs.

providers/

Provider-specific integration guides.

comparison/

ops/

Release, deployment, proxies, tunnels, coverage, database, monitoring.

diagrams/

Mermaid sources and exported SVG/PNG diagrams referenced from the docs above. See diagrams/README.md.

i18n/

Translated mirrors of the documentation in 50 locales (plus the English originals — 51 languages in total). See i18n/README.md for the supported language list.

screenshots/

Static screenshots used by the dashboard and the README. Not part of the doc body.


Auto-generated artifacts

  • reference/PROVIDER_REFERENCE.md is generated by scripts/docs/gen-provider-reference.ts from src/shared/constants/providers.ts. Do not edit by hand.
  • The /docs UI is backed by Fumadocs MDX source generation from the subfolders above.