mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-08-20 06:02:14 +03:00
* chore(release): open v3.8.39 development cycle * docs(changelog): backfill 5 v3.8.38 bullets merged after release finalize These PRs squash-merged into release/v3.8.38 between the CHANGELOG finalize (ff57be32f) and the merge-to-main (ae6e2342d), so they shipped in the v3.8.38 tag but had no bullet: - feat(compression): Ionizer engine (lossy JSON-array sampling + CCR) (#5148) - fix(sse): preserve non-stream reasoning fields (#5155, @rdself) - fix(i18n): add missing English UI labels (#5153, @rdself) - test(combo): gated live smoke (#5151) + release-expectations refresh (#5150, @KooshaPari) (#5129 exact-host Anthropic baseUrl is already covered by the #5130 bullet — same CodeQL #674.) Synced 41 i18n CHANGELOG mirrors. * feat(compression): TOON best-of-N candidate encoder + encoder A/B table (#5163) Integrated into release/v3.8.39. TOON best-of-N candidate encoder (GCF default, fail-open). 17/17 unit tests pass on merge result; CI reds were base-stale + Quality Ratchet DRIFT. * fix(zenmux): normalize vendor-prefixed GLM system roles (#5158) Integrated into release/v3.8.39. ZenMux vendor-prefixed GLM system-role normalization; 12/12 role-normalizer tests pass on merge result. CI reds base-stale. * [codex] fix xAI OAuth test and reasoning effort (#5157) Integrated into release/v3.8.39. xAI reasoning-effort normalization (max/xhigh→high) + OAuth test config; 46/46 xai-translator tests pass on merge result. CI reds base-stale. * docs(i18n): add Traditional Chinese (zh-TW) README and update zh-CN to latest (#5162) Integrated into release/v3.8.39. Traditional Chinese (zh-TW) README + zh-CN refresh; docs-only. * test(security): guard PII redaction stays opt-in (default off) + Hard Rule #20 (#5159) Integrated into release/v3.8.39. PII opt-in regression guard + Hard Rule #20; rebased to strip base-drift (+81/-1). 5/5 guard tests pass; flip-proof verified. * test(combo): deterministic context-relay universal-handoff coverage (closes phase-2 TODO) (#5168) Integrated into release/v3.8.39. Deterministic context-relay universal-handoff coverage (3 tests); 3/3 pass on merge result. * docs(i18n): full sync zh-TW and zh-CN README with canonical English v3.8.39 (#5171) Integrated into release/v3.8.39. Full zh-TW docs tree + zh-CN sync with canonical English v3.8.39; docs-only. * fix(serve): honour HOSTNAME from .env instead of hardcoding 0.0.0.0 (#5134) (#5170) Integrated into release/v3.8.39. HOSTNAME env override in serve (#5134) + regression test (4/4, TDD flip-proof verified). * fix(sse): resolve nameless deepseek-web tool blocks via parameter-schema match (#5154) (#5173) Integrated into release/v3.8.39. Schema-based nameless deepseek-web tool-block resolution (#5154); 6/6 tests pass on merge result (incl. ambiguous/no-match negatives + named-tag no-regression). * fix(sse): normalize array user content for Command Code to avoid upstream 400 (#5166) (#5174) Integrated into release/v3.8.39. Normalize array user content for Command Code (#5166, user-array/400 symptom); 4/4 tests pass on merge result. * fix(sse): defer </think> close so it never leaks before tool_calls (#5123) (#5175) Integrated into release/v3.8.39. Defer </think> close so it never leaks before tool_calls (#5123); 4/4 tests pass (incl. #4633 no-regression). CHANGELOG synced to keep all 3 v3.8.39 fixes. * fix(dashboard): use amber for home update-step warning icon (#5176) Integrated into release/v3.8.39. Amber for home update-step warning icon; 1/1 UI test. * fix(api): LAN/Tailscale dashboard — host-aware CSP + GET-exempt version route + combo field errors (#5083) (#5177) Integrated into release/v3.8.39. Host-aware CSP (ReDoS/injection-safe host validation) + GET-exempt /api/system/version (POST/spawn stays LOCAL_ONLY, exact-match safe-methods-only) + COMBO_002 firstField. 44/44 tests + route-guard membership gate green. CHANGELOG synced to keep all 4 v3.8.39 fixes. * fix(api): replace #5083 global middleware CSP with declarative ws: scheme (#5083) Follow-up to PR #5177 (merged): that version implemented the LAN-CSP fix (Bug 1) with a new global `src/middleware.ts` + `src/server/csp.ts`, which contradicts the project's documented architecture — 'No global Next.js middleware — interception is route-specific' (CLAUDE.md / AGENTS.md) — and was merged unverified (middleware vs next.config header precedence was never confirmed in a real build). This replaces that approach with the minimal, declarative equivalent: • next.config.mjs: connect-src now permits the bare `ws:` scheme (symmetric with the bare `wss:` already allowed) so the dashboard can reach its own Live WS server from a LAN/Tailscale host. No middleware. • Removes src/middleware.ts, src/server/csp.ts, and tests/unit/csp-host-aware.test.ts. • Adds tests/unit/csp-lan-ws-5083.test.ts (incl. a guard asserting src/middleware.ts does NOT exist, so the global-middleware approach cannot silently return). Bugs 2 (GET-exempt /api/system/version) and 3 (COMBO_002 field surfacing) from #5177 are unaffected and remain in place. Co-authored-by: KooshaPari <KooshaPari@users.noreply.github.com> * test(combo): end-to-end quota-share DRR routing-decision coverage (matrix parity) (#5179) Integrated into release/v3.8.39. Quota-share DRR routing-decision coverage (matrix parity); 2/2 pass on merge result. * feat(agent-bridge): graceful cert-install fallback with manual guide for containers (#4546) (#5178) Integrated into release/v3.8.39. Agent-bridge graceful cert-install fallback + manual guide (#4546); 6/6 tests pass on merge result. * fix(antigravity): family-scoped quota lockout (gemini/claude buckets) (#5180) Integrated into release/v3.8.39 — family-scoped antigravity quota lockout. Rebased from v3.8.37 + validated (vitest 5/5, typecheck clean, full combo-matrix green, model-lockout 99/0). Same-model cross-account retry (chat.ts) deferred pending live antigravity VPS validation. * fix(cli): force NODE_ENV to match dev/start run mode in custom Next server (#5189) Integrated into release/v3.8.39. Force NODE_ENV to match dev/start run mode in custom Next server; 2/2 source-scan+ordering tests pass on merge result. * feat(compression): CCR ranged/grep/stats retrieval (ReDoS-safe, backward-compat) (#5187) Integrated into release/v3.8.39. CCR ranged/grep/stats retrieval (safe-regex ReDoS guard + length/match caps); 17/17 tests pass on merge result. * docs(combo): sync all combo/routing-strategy docs to current state + document test coverage (#5185) Integrated into release/v3.8.39. Combo/routing-strategy docs sync; docs-only. * fix(mcp): return 404 (not 400) for unknown Streamable HTTP session id (#5169) (#5191) * fix(api): respect blocked Auto (Zero-Config) provider in /v1/models catalog (#5192) (#5194) * test(combo): deterministic context-relay codex quota-handoff coverage (closes last gap) (#5195) * test(ci): wire antigravity-quota-family under test:vitest (fix test-discovery orphan) (#5196) * fix(oauth): antigravity login no longer hangs — fire-and-forget onboarding + bounded post-exchange (#5193) Antigravity OAuth hang fix (no-PKCE/no-openid + bounded post-exchange + exchange-500 fix). Includes #5200 (Koosha) revert + owner rebaseline to keep documented comments. Integrated into release/v3.8.39. * feat(oauth): remote Antigravity login via local helper + paste-credentials (#5203) Remote Antigravity login: local helper (omniroute login antigravity) + paste-credentials. Integrated into release/v3.8.39. * fix(translator): accept Claude Messages shape in non-stream malformed-200 guard (#5156) Integrated into release/v3.8.39 * fix(cli): default dev bundler to Turbopack (16.2.x panic no longer reproduces) (#5206) Integrated into release/v3.8.39 * fix(cli): auto-calibrate server V8 heap from physical RAM (#5172) (#5213) The server was spawned with a fixed --max-old-space-size=512 (omniroute serve) or no heap flag at all (Electron), so RAM-rich boxes still OOM-crashed under load (Ineffective mark-compacts near heap limit ~500MB) with many providers/ accounts and large model catalogs. New calibrateHeapFallbackMb(os.totalmem()) defaults the heap to ~35% of RAM clamped [512,4096], wired into serve.mjs and electron/main.js. Explicit OMNIROUTE_MEMORY_MB still wins (#2939 unchanged). Also addresses #5160 (same OOM root); #5152 (docker) benefits via the same knob. Closes #5172 * fix(proxy): coalesce fast-fail health probes (#5208) Integrated into release/v3.8.39 * fix(proxy): close dispatchers when clearing cache (#5202) Integrated into release/v3.8.39 * fix(cli): raise dev server Node heap limit to 8GB to prevent OOM (#5198) Integrated into release/v3.8.39 * fix(auth): allow synthetic no-auth fallback for mimocode (#5205) Integrated into release/v3.8.39 * fix(oauth): preserve Antigravity refresh_token on empty/omitted upstream response (#3850) (#5214) Google's OAuth refresh tokens are non-rotating: the refresh response usually omits refresh_token and occasionally returns it as an empty string. The Antigravity executor used `typeof tokens.refresh_token === "string" ? ... ` which accepts "" (typeof "" === "string") and overwrote the stored token with empty, nulling it on first refresh. Now treats non-string OR empty as absent and preserves credentials.refreshToken, matching refreshGoogleToken semantics. Closes #3850 * fix(responses): normalize non-array input (#5204) Integrated into release/v3.8.39 * fix(stream): normalize safety finish reasons via shared helper (#5197) Integrated into release/v3.8.39 * fix(request-logger): never render negative '(-100%)' compression badge (#5201) Integrated into release/v3.8.39 * fix(combo): reject empty responses api output (#5207) Integrated into release/v3.8.39 — combo failover now rejects empty Responses API output (validateQuality). Baseline rebaseline dropped (main-measured drift; maintainer rebaselines at release). * fix(pwa): prefer cached navigation before offline page (#5209) Integrated into release/v3.8.39 — PWA service worker prefers cached navigation before offline page (#5165). * chore(release): v3.8.39 — 2026-06-28 * chore(release): rebaseline openapi+i18n coverage ratchet drift for v3.8.39 --------- Co-authored-by: Arthur Bodera <abodera@gmail.com> Co-authored-by: Nguyen Minh <lop123thcs@gmail.com> Co-authored-by: lunkerchen <labanchen@gmail.com> Co-authored-by: Ankit <177378174+anki1kr@users.noreply.github.com> Co-authored-by: KooshaPari <KooshaPari@users.noreply.github.com> Co-authored-by: Ardem2025 <ardemb22@gmail.com> Co-authored-by: backryun <bakryun0718@proton.me> Co-authored-by: Anton <39598727+NomenAK@users.noreply.github.com> Co-authored-by: KooshaPari <42529354+KooshaPari@users.noreply.github.com> Co-authored-by: Wilson <pedbookmed@gmail.com> Co-authored-by: Randi <55005611+rdself@users.noreply.github.com>
249 lines
12 KiB
TypeScript
249 lines
12 KiB
TypeScript
/**
|
|
* 3-tier route guard constants and helpers.
|
|
*
|
|
* Tier 1 — LOCAL_ONLY: accessible only from loopback. These routes spawn
|
|
* child processes; exposing them to non-local traffic is a known CVE class
|
|
* (GHSA-fhh6-4qxv-rpqj). Blocked unconditionally regardless of auth state.
|
|
*
|
|
* Carve-out: paths matching the live manage-scope bypass list (DB-stored,
|
|
* read via `getAuthzBypassSnapshot()`) MAY also be accessed from
|
|
* non-loopback if and only if the request carries an API key with the
|
|
* `manage` scope (or an authenticated dashboard session — see
|
|
* `policies/management.ts`). The bypass is opt-in per prefix and can be
|
|
* killed globally via the `localOnlyManageScopeBypassEnabled` setting.
|
|
* Unauthenticated requests to bypassable paths are still rejected with
|
|
* 403 LOCAL_ONLY.
|
|
*
|
|
* Tier 2 — ALWAYS_PROTECTED: auth is always required, even when
|
|
* requireLogin=false. Covers destructive / irreversible operations.
|
|
*
|
|
* Tier 3 — MANAGEMENT (default): auth required, but bypassed when
|
|
* requireLogin=false (existing behaviour).
|
|
*/
|
|
|
|
import { getAuthzBypassSnapshot } from "@/lib/config/runtimeSettings";
|
|
|
|
const LOOPBACK_HOSTS = new Set(["localhost", "127.0.0.1", "::1"]);
|
|
|
|
export const LOCAL_ONLY_API_PREFIXES: ReadonlyArray<string> = [
|
|
"/api/mcp/",
|
|
"/api/cli-tools/runtime/",
|
|
"/api/services/", // T-10: embedded service lifecycle (spawn child processes)
|
|
"/dashboard/providers/services/", // T-07: reverse proxy to embedded service UIs
|
|
"/api/copilot/", // unauthenticated LLM driver — CLI-only by default; admins can opt-in to remote access via manage-scope bypass
|
|
"/api/tools/agent-bridge/", // AgentBridge: spawns MITM server + DNS edits (Hard Rules #15 + #17)
|
|
"/api/tools/traffic-inspector/", // Traffic Inspector: http-proxy listener + system proxy (Hard Rules #15 + #17)
|
|
"/api/plugins/", // plugins: load/execute via worker_threads + child_process (Hard Rules #15 + #17)
|
|
"/api/plugins", // bare path: GET list + POST install also trigger plugin loading
|
|
"/api/system/version", // auto-update: spawns git checkout + npm install — RCE-via-tunnel surface (Hard Rules #15 + #17, found by 6A.8 route-guard gate)
|
|
"/api/db-backups/exportAll", // spawns tar for export archive (Hard Rules #15 + #17, found by 6A.8 route-guard gate)
|
|
"/api/local/", // T-12: 1-click local service launchers (Redis today; spawns podman/docker) — loopback-enforced by isLocalRequestAllowed() in src/lib/security/localEndpoints.ts (Hard Rules #15 + #17)
|
|
"/api/headroom/start", // Headroom token-saver proxy lifecycle: spawns headroom-ai python CLI (Hard Rules #15 + #17)
|
|
"/api/headroom/stop", // Headroom token-saver proxy lifecycle: sends SIGTERM/SIGKILL to managed PID (Hard Rules #15 + #17)
|
|
"/api/oauth/cursor/auto-import", // spawns `execFile("which", ["cursor"])` to verify a local Cursor install before importing creds — RCE-via-tunnel surface (Hard Rules #15 + #17, found by 6A.8 route-guard gate). Specific path only: the rest of /api/oauth/ (browser redirect/callback flows) must stay remote-reachable.
|
|
];
|
|
|
|
/**
|
|
* LOCAL_ONLY routes whose spawn-capable segment sits AFTER a dynamic path
|
|
* parameter, so a flat prefix in `LOCAL_ONLY_API_PREFIXES` cannot target them
|
|
* without over-broadening (e.g. locking the entire `/api/providers/` subtree,
|
|
* which remote dashboards legitimately use for provider CRUD). These are matched
|
|
* by regex instead.
|
|
*
|
|
* - `POST /api/providers/{id}/login` launches a headful Playwright Chromium
|
|
* (a child process) to drive a web-cookie login. Loopback enforcement must
|
|
* happen unconditionally before any auth check (Hard Rules #15 + #17), so a
|
|
* leaked JWT via tunnel cannot trigger a browser spawn.
|
|
*/
|
|
export const LOCAL_ONLY_API_PATTERNS: ReadonlyArray<RegExp> = [
|
|
/^\/api\/providers\/[^/]+\/login\/?$/,
|
|
];
|
|
|
|
/**
|
|
* Compile-time deny-list: route prefixes that can spawn arbitrary local
|
|
* subprocesses on behalf of the caller. These MUST NEVER appear in the
|
|
* manage-scope bypass list — regardless of DB state — because reaching them
|
|
* from non-loopback would re-introduce the GHSA-fhh6-4qxv-rpqj surface that
|
|
* the LOCAL_ONLY tier exists to close.
|
|
*
|
|
* Enforced at two layers:
|
|
* 1. zod schema (`settingsSchemas.ts`): rejects `PATCH /api/settings` with
|
|
* error code `BYPASS_PREFIX_NOT_ALLOWED` if any entry in
|
|
* `localOnlyManageScopeBypassPrefixes` falls inside this set.
|
|
* 2. runtime (`isLocalOnlyBypassableByManageScope` below): even if a
|
|
* malformed DB row somehow claims a spawn-capable path is bypassable,
|
|
* the policy still refuses to honour it.
|
|
*/
|
|
export const SPAWN_CAPABLE_PREFIXES: ReadonlyArray<string> = [
|
|
"/api/cli-tools/runtime/",
|
|
"/api/services/", // T-10: can run npm install + spawn node processes
|
|
"/api/tools/agent-bridge/", // start/stop MITM server + DNS edits (Hard Rules #15 + #17)
|
|
"/api/tools/traffic-inspector/", // http-proxy listener + system proxy (Hard Rules #15 + #17)
|
|
"/api/plugins/", // plugins: load/execute via worker_threads + child_process (Hard Rules #15 + #17)
|
|
"/api/local/", // T-12: 1-click local service launchers (Redis today) — must never be whitelistable via manage-scope bypass (Hard Rules #15 + #17)
|
|
"/api/headroom/start", // spawns headroom-ai python CLI — must never be bypassable (Hard Rules #15 + #17)
|
|
"/api/headroom/stop", // kills tracked PID — must never be bypassable (Hard Rules #15 + #17)
|
|
];
|
|
|
|
/**
|
|
* Compile-time default of the manage-scope bypass list. Kept as an exported
|
|
* constant so the Settings inventory page (and audit code) can render the
|
|
* "available bypassable prefixes" choices independent of current DB state.
|
|
*
|
|
* The RUNTIME decision in `isLocalOnlyBypassableByManageScope` does NOT
|
|
* consult this constant — it reads `getAuthzBypassSnapshot().prefixes`,
|
|
* which is hot-reloaded on every settings PATCH.
|
|
*/
|
|
export const LOCAL_ONLY_MANAGE_SCOPE_BYPASS_PREFIXES: ReadonlyArray<string> = ["/api/mcp/"];
|
|
|
|
export const ALWAYS_PROTECTED_API_PATHS: ReadonlyArray<string> = [
|
|
"/api/shutdown",
|
|
"/api/providers/health-autopilot/actions",
|
|
"/api/settings/database",
|
|
];
|
|
|
|
export function isLoopbackHost(hostHeader: string | null): boolean {
|
|
if (!hostHeader) return false;
|
|
let host = hostHeader.trim();
|
|
if (host.startsWith("[")) {
|
|
// IPv6 literal: [::1] or [::1]:port
|
|
const bracketEnd = host.indexOf("]");
|
|
host = bracketEnd >= 0 ? host.slice(1, bracketEnd) : host.slice(1);
|
|
} else if ((host.match(/:/g) || []).length === 1) {
|
|
// IPv4 / hostname with a single :port — strip it. A bare IPv6 address
|
|
// ("::1", "::ffff:127.0.0.1") has multiple colons and must stay intact
|
|
// (splitting on ":" would mangle it to "" and miss the loopback match).
|
|
host = host.split(":")[0];
|
|
}
|
|
host = host.replace(/^::ffff:/i, "");
|
|
return LOOPBACK_HOSTS.has(host.toLowerCase());
|
|
}
|
|
|
|
/**
|
|
* Classify a resolved peer IP into the locality tiers the authz layer cares
|
|
* about. `null`/unknown → "remote" (fail closed). Used by the pipeline to stamp
|
|
* a trusted locality marker that route handlers read without re-deriving it
|
|
* from the spoofable Host header.
|
|
*/
|
|
export function classifyHostLocality(ip: string | null): "loopback" | "lan" | "remote" {
|
|
if (!ip) return "remote";
|
|
if (isLoopbackHost(ip)) return "loopback";
|
|
if (isPrivateLanHost(ip)) return "lan";
|
|
return "remote";
|
|
}
|
|
|
|
/**
|
|
* Private-LAN ranges (RFC 1918 IPv4 + IPv6 ULA/link-local). Matched against the
|
|
* real socket peer address (NOT the spoofable Host header), so a public-internet
|
|
* client — which presents a public source IP — never matches.
|
|
*/
|
|
const PRIVATE_LAN_PATTERNS: ReadonlyArray<RegExp> = [
|
|
/^10\.\d{1,3}\.\d{1,3}\.\d{1,3}$/,
|
|
/^192\.168\.\d{1,3}\.\d{1,3}$/,
|
|
/^172\.(1[6-9]|2\d|3[01])\.\d{1,3}\.\d{1,3}$/,
|
|
/^f[cd][0-9a-f]{2}:/i, // IPv6 ULA fc00::/7
|
|
/^fe80:/i, // IPv6 link-local
|
|
];
|
|
|
|
/**
|
|
* True when the peer address is a private-LAN address. Used to widen the
|
|
* LOCAL_ONLY tier to a trusted private network (owner-authorized 2026-05-30 for
|
|
* a LAN-deployed instance). Loopback-only surfaces that do NOT use this (e.g.
|
|
* the CLI-token path) remain strictly loopback.
|
|
*/
|
|
export function isPrivateLanHost(hostHeader: string | null): boolean {
|
|
if (!hostHeader) return false;
|
|
let host = hostHeader.trim();
|
|
if (host.startsWith("[")) {
|
|
const bracketEnd = host.indexOf("]");
|
|
host = bracketEnd >= 0 ? host.slice(1, bracketEnd) : host.slice(1);
|
|
}
|
|
host = host.replace(/^::ffff:/i, "");
|
|
// Strip :port only for IPv4 / hostname (a lone colon); leave IPv6 intact.
|
|
if ((host.match(/:/g) || []).length === 1) host = host.split(":")[0];
|
|
host = host.toLowerCase();
|
|
return PRIVATE_LAN_PATTERNS.some((re) => re.test(host));
|
|
}
|
|
|
|
/**
|
|
* Paths that are LOCAL_ONLY for all write methods but may be accessed from
|
|
* non-loopback clients when the request method is GET, HEAD, or OPTIONS.
|
|
*
|
|
* Rule: a path belongs here only when the read methods perform NO child-process
|
|
* spawn and expose NO privileged mutation — only the write methods do.
|
|
*
|
|
* Current exemptions:
|
|
* /api/system/version — GET reads package.json + npm registry; only POST
|
|
* triggers the auto-update flow (spawns git checkout + npm install + pm2).
|
|
* Hard Rules #15/#17 still apply to POST.
|
|
*/
|
|
export const LOCAL_ONLY_API_GET_EXEMPTIONS: ReadonlySet<string> = new Set([
|
|
"/api/system/version",
|
|
]);
|
|
|
|
/** Safe HTTP methods that can be exempted for read-only paths. */
|
|
const SAFE_METHODS = new Set(["GET", "HEAD", "OPTIONS"]);
|
|
|
|
/**
|
|
* Returns true when `path` is a local-only route that must be blocked from
|
|
* non-loopback / non-LAN callers.
|
|
*
|
|
* @param path Normalized request path (e.g. "/api/mcp/sse").
|
|
* @param method Optional HTTP method. When provided and the method is a safe
|
|
* read-only method (GET/HEAD/OPTIONS) AND the path exactly
|
|
* matches an entry in `LOCAL_ONLY_API_GET_EXEMPTIONS`, this
|
|
* function returns false — i.e. the path is NOT local-only for
|
|
* that specific safe method. With no method argument (e.g.
|
|
* from security-scan scripts that test paths without a method),
|
|
* the function returns true (safe default) to preserve the
|
|
* conservative classification used by `check-route-guard-membership`.
|
|
*/
|
|
export function isLocalOnlyPath(path: string, method?: string): boolean {
|
|
// Method-aware GET exemption: only exact-match paths in the exemption set
|
|
// are eligible; prefix/wildcard matching is intentionally NOT used to avoid
|
|
// accidentally opening sub-paths of a spawn-capable route.
|
|
if (method && SAFE_METHODS.has(method.toUpperCase()) && LOCAL_ONLY_API_GET_EXEMPTIONS.has(path)) {
|
|
return false;
|
|
}
|
|
return (
|
|
LOCAL_ONLY_API_PREFIXES.some((p) => path === p || path.startsWith(p)) ||
|
|
LOCAL_ONLY_API_PATTERNS.some((re) => re.test(path))
|
|
);
|
|
}
|
|
|
|
/**
|
|
* Runtime predicate consulted by the management policy on every non-loopback
|
|
* request to a LOCAL_ONLY path. Reads the live snapshot:
|
|
* - returns false if the global kill-switch is off
|
|
* (`localOnlyManageScopeBypassEnabled === false`),
|
|
* - returns true iff `path` matches one of the live bypass prefixes AND
|
|
* that prefix is not in `SPAWN_CAPABLE_PREFIXES` (defence-in-depth: the
|
|
* zod schema already rejects spawn-capable entries, but a malformed DB
|
|
* row should not be able to grant a bypass).
|
|
*
|
|
* O(1) (no I/O, no async). Hot-reload SLA: <50 ms — satisfied structurally.
|
|
*/
|
|
export function isLocalOnlyBypassableByManageScope(path: string): boolean {
|
|
const snapshot = getAuthzBypassSnapshot();
|
|
if (!snapshot.enabled) return false;
|
|
return snapshot.prefixes.some((p) => {
|
|
// Defence-in-depth: reject a bypass prefix that is the same as, child of,
|
|
// OR PARENT of any spawn-capable prefix. The parent case catches e.g.
|
|
// `/api/cli-tools/` (parent of `/api/cli-tools/runtime/`) — a request to
|
|
// `/api/cli-tools/runtime/foo` would otherwise satisfy `path.startsWith(p)`
|
|
// and reach the spawn-capable surface without a loopback check.
|
|
if (
|
|
SPAWN_CAPABLE_PREFIXES.some(
|
|
(spawn) => p === spawn || p.startsWith(spawn) || spawn.startsWith(p)
|
|
)
|
|
) {
|
|
return false;
|
|
}
|
|
return path === p || path.startsWith(p);
|
|
});
|
|
}
|
|
|
|
export function isAlwaysProtectedPath(path: string): boolean {
|
|
return ALWAYS_PROTECTED_API_PATHS.some((p) => path === p || path.startsWith(p));
|
|
}
|