Conversation
- decolua#1962: mask API keys in usage stats and history responses - decolua#1961: validate proxy URL scheme before writing to env vars - decolua#1963: use atomic O_EXCL lock file to prevent TOCTOU race in startServer - decolua#1965: set mitmIsRestarting guard synchronously before any await - decolua#1972: escape HTML in OAuth callback result page to prevent XSS
21 tests covering: - AUDIT-002: API key masking in usage stats and history - AUDIT-003: Proxy URL scheme validation and shell metacharacter rejection - AUDIT-004: Atomic O_EXCL lock file for MITM startup - AUDIT-001: Synchronous restart guard before any await - AUDIT-018: HTML escaping in OAuth callback page
hamsa0x7
force-pushed
the
fix/security-audit-001-018
branch
from
June 23, 2026 04:41
6809eb7 to
8deded7
Compare
ozkancan-apk
added a commit
to ozkancan-apk/9routerFullFree
that referenced
this pull request
Jun 24, 2026
…it), decolua#2020 (cascade delete + token limits), decolua#2018 (dynamic model fetch) PR decolua#2046: SSE non-JSON satir + duplicate [DONE] fix. Stream kararlilik. PR decolua#2007: 5 guvenlik yamasi (API key leak, proxy URL validation, XSS, MITM race, lock file). PR decolua#2020: Provider silinince model alias cascade delete + custom model token limit. PR decolua#2018: Custom provider'dan model listesi dinamik cekme. + onceki: betterSqliteAdapter transaction fix (createProviderConnection undefined hatasi).
Owner
|
Thanks @hamsa0x7! Reviewed all 5 security fixes — API key masking, proxy URL validation, OAuth XSS escaping, and the two MITM race/lock fixes. Verified no impact on existing UI or user data. Merged into master. Appreciate the thorough audit + tests. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security Audit Fixes
This PR patches 5 vulnerabilities identified during a comprehensive security audit of the 9router codebase.
Fixes
#1962 - API key leak in usage stats (AUDIT-002)
#1961 - Command injection via proxy URL (AUDIT-003)
#1963 - TOCTOU race in MITM server startup (AUDIT-004)
#1965 - Race condition in retry tracking (AUDIT-001)
#1972 - XSS in OAuth callback page (AUDIT-018)
Test Results
All 21 tests pass (vitest):
\
Tests 21 passed (21)
Duration 277ms
\\
Test plan