Repository navigation
fix(ai-gateway): limit firewall forwarding headers - #6730
Conversation
Code Review SummaryStatus: No Issues Found | Recommendation: Merge Executive SummaryReviewed the incremental fallback that derives the firewall host from the request URL when the host header is absent, plus its regression test; the Files Reviewed (2 files)
Previous Review Summary (commit 712c8e8)Current summary above is authoritative. Previous snapshots are kept for context only. Previous review (commit 712c8e8)Status: No Issues Found | Recommendation: Merge Executive SummaryReviewed the header-allowlist change in the AI gateway firewall check and its regression tests; the allowlist, missing-host failure, and account-scoped key look correct and consistent with existing Files Reviewed (2 files)
Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0 Review guidance: REVIEW.md from base branch |
Summary
Context
Vercel support identified that
@vercel/firewallduplicates every original request header onto its internal rate-limit request. Requests with many headers can prevent the internal rate-limit identifier from being recognized, causing the SDK to reporterror: "not-found"even though thegateway-inferencerule is configured. This change applies their allowlist workaround only to the affected gateway check.Sentry: https://kilo-code.sentry.io/issues/7742540582/
Verification
pnpm --filter web test -- --runTestsByPath src/lib/ai-gateway/gateway-account-rate-limit.test.ts --runInBandpnpm --filter web typecheckpnpm --filter web lintpnpm exec oxfmt --list-different apps/web/src/lib/ai-gateway/gateway-account-rate-limit.ts apps/web/src/lib/ai-gateway/gateway-account-rate-limit.test.tsgit diff --check