Skip to content

fix(ai-gateway): limit firewall forwarding headers - #6730

Merged
pandemicsyn merged 3 commits into
mainfrom
investigate/sentry-7742540582-header-forwarding
Sep 25, 2026
Merged

pandemicsyn merged 3 commits into
mainfrom
investigate/sentry-7742540582-header-forwarding

Conversation

@pandemicsyn

Copy link
Copy Markdown
Contributor

Summary

  • pass only the host and Vercel client IP headers to the gateway inference firewall check
  • preserve the existing account-scoped rate-limit key
  • fail explicitly when the host required by the firewall SDK is unavailable
  • add regression coverage proving unrelated request headers are not forwarded

Context

Vercel support identified that @vercel/firewall duplicates every original request header onto its internal rate-limit request. Requests with many headers can prevent the internal rate-limit identifier from being recognized, causing the SDK to report error: "not-found" even though the gateway-inference rule is configured. This change applies their allowlist workaround only to the affected gateway check.

Sentry: https://kilo-code.sentry.io/issues/7742540582/

Verification

  • pnpm --filter web test -- --runTestsByPath src/lib/ai-gateway/gateway-account-rate-limit.test.ts --runInBand
  • pnpm --filter web typecheck
  • pnpm --filter web lint
  • pnpm exec oxfmt --list-different apps/web/src/lib/ai-gateway/gateway-account-rate-limit.ts apps/web/src/lib/ai-gateway/gateway-account-rate-limit.test.ts
  • git diff --check

@kilo-code-bot

kilo-code-bot Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Executive Summary

Reviewed the incremental fallback that derives the firewall host from the request URL when the host header is absent, plus its regression test; the ?? new URL(request.url).host fallback is safe in a Next.js request context and the prior header-allowlist behavior is unchanged.

Files Reviewed (2 files)
  • apps/web/src/lib/ai-gateway/gateway-account-rate-limit.ts
  • apps/web/src/lib/ai-gateway/gateway-account-rate-limit.test.ts
Previous Review Summary (commit 712c8e8)

Current summary above is authoritative. Previous snapshots are kept for context only.

Previous review (commit 712c8e8)

Status: No Issues Found | Recommendation: Merge

Executive Summary

Reviewed the header-allowlist change in the AI gateway firewall check and its regression tests; the allowlist, missing-host failure, and account-scoped key look correct and consistent with existing @vercel/firewall usage in the repo.

Files Reviewed (2 files)
  • apps/web/src/lib/ai-gateway/gateway-account-rate-limit.ts
  • apps/web/src/lib/ai-gateway/gateway-account-rate-limit.test.ts

Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0

Review guidance: REVIEW.md from base branch main

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants