Files
OmniRoute/docs
Markus Hartung 0f4a92718c fix(security): harden codex app-server transport (#11205 post-merge review)
Two findings from the automated push security review on #11205:

1. HIGH (Agent/Subprocess Permission Bypass): approvalPolicy "never" +
   sandbox "danger-full-access" defaults, plus blanket auto-APPROVE of every
   server->client approval prompt, meant codex-decided host commands ran with
   no gate at all. Now: sandbox defaults to "workspace-write" (override via
   providerSpecificData.codexAppServerSandbox / OMNIROUTE_CODEX_APPSERVER_SANDBOX),
   and approval prompts — which gate codex's OWN command/file/permission
   execution, NOT the harness tool passthrough (item/tool/call) — are
   auto-DENIED unless the operator opts in via
   providerSpecificData.codexAppServerAutoApprove /
   OMNIROUTE_CODEX_APPSERVER_AUTO_APPROVE.

2. MEDIUM (SSRF / credential exfiltration): the /readyz health probe sent the
   bearer token to whatever URL a connection's providerSpecificData supplied
   and followed redirects. Now: env-sourced tokens only pair with env-sourced
   URLs or operator-local hosts (loopback/RFC1918/link-local/ULA/localhost/
   single-label LAN names/*.local/*.ts.net/*.internal — literal match, no DNS),
   enforced inside resolveAppServerConfig so executor, gating and health probe
   all inherit it; and the probe uses redirect:"manual".

TDD: 4 failing-then-passing tests (deny-by-default, workspace-write default,
env-token→remote-psd-URL refusal incl. no-network assertion, redirect pinning)
plus 6 new passing cases (local-host matrix, psd-token pairing, env/env
pairing, opt-in approve). 30/30 in tests/unit/codex-app-server.test.ts.
Also rebaselines two file-size entries that drifted on the release tip during
the 2026-08-23 merge wave (annotated; verified pristine-tip).
2026-08-23 16:02:31 -03:00
..
2026-06-29 08:40:06 -03:00

title, version, lastUpdated
title version lastUpdated
OmniRoute Documentation 3.8.40 2026-06-28

OmniRoute Documentation

Navigable index of the OmniRoute documentation set. Topics are grouped by intent so you can find what you need quickly.

Looking for the project overview, install steps, or release notes? See the root README.md, ROADMAP.md, CHANGELOG.md, and CONTRIBUTING.md.


For Non-Tech Users

Simple guides for using OmniRoute — no technical background needed.

getting-started/

guides/


For Tech Users

Technical documentation for developers and contributors.

architecture/

How the system is put together — read these to understand the runtime, code layout, and resilience model.

reference/

Lookup material — API surface, environment variables, CLI flags, provider catalog.

frameworks/

Pluggable subsystems exposed to clients, agents, and operators.

routing/

Combo routing, scoring, and replay.

security/

Guardrails, compliance, stealth, and the mandatory patterns for handling public credentials and error messages.

compression/

Prompt compression engines, rules, and language packs.

providers/

Provider-specific integration guides.

comparison/

ops/

Release, deployment, proxies, tunnels, coverage, database, monitoring.

diagrams/

Mermaid sources and exported SVG/PNG diagrams referenced from the docs above. See diagrams/README.md.

i18n/

Translated mirrors of the documentation in 43 locales. See i18n/README.md for the supported language list.

screenshots/

Static screenshots used by the dashboard and the README. Not part of the doc body.


Auto-generated artifacts

  • reference/PROVIDER_REFERENCE.md is generated by scripts/docs/gen-provider-reference.ts from src/shared/constants/providers.ts. Do not edit by hand.
  • The /docs UI is backed by Fumadocs MDX source generation from the subfolders above.