mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-07-31 04:12:10 +03:00
#243 (js/request-forgery, high) — providers/bulk/route.ts - Replace `fetch(\${origin}/api/providers/validate)` (where origin came from spoofable `new URL(request.url).origin`) with a direct in-process call to validateProviderApiKey. Eliminates the SSRF vector and the HTTP round-trip through the same app. - Resolve proxy once outside the loop and reuse via runWithProxyContext. - Drop now-unused passthroughAuthHeaders helper. #244 (js/resource-exhaustion, warn) — copilot-web.ts::solveHashcash - Clamp upstream-supplied `difficulty` to [1, 8] before `"0".repeat(difficulty)` so a malicious/buggy server can't force a huge prefix allocation or push the 10M-iteration loop into effectively unbounded work. #245 (js/insufficient-password-hash, warn) — copilot-web.ts::getSession - Dedupe the inline `createHash("sha256").update(accessToken)` call by reusing the existing sessionPoolKey helper. - Rename its parameter from `accessToken` to `token` and document that the input is a high-entropy OAuth bearer used only as an in-memory Map key — bcrypt/scrypt/argon2 would be incorrect here, and SHA-256:16 is an appropriate fingerprint per docs/security/PUBLIC_CREDS.md. Tests - Export solveHashcash and add unit tests asserting it returns null for out-of-range / non-integer difficulty and produces a numeric nonce for the common difficulty=1 case. - All 26 tests in copilot-web-executor.test.ts and providers-bulk-route.test.ts continue to pass; sessionPoolKey contract (SHA-256:16) preserved.