Skip to content

fix(token-saver): secure management routes and honor PXPIPE opt-out - #3485

Open
KunN-21 wants to merge 2 commits into
decolua:masterfrom
KunN-21:fix/token-saver-safety
Open

KunN-21 wants to merge 2 commits into
decolua:masterfrom
KunN-21:fix/token-saver-safety

Conversation

@KunN-21

@KunN-21 KunN-21 commented Aug 23, 2026

Copy link
Copy Markdown
Contributor

Summary

  • restrict PXPIPE and spawn-capable Headroom management routes to the existing local-only trust boundary
  • make X-9Router-Token-Saver: off disable PXPIPE as well as RTK, Headroom, Caveman, and Ponytail
  • replace the previous false-positive PXPIPE bypass coverage with a real Claude-format, above-threshold negative/positive control

Security context

When dashboard login is disabled, generic /api/* routes are intentionally available remotely. Child-process/package-manager routes remain local-only. This PR extends that existing boundary to:

  • /api/pxpipe/*
  • /api/headroom/extras
  • /api/headroom/restart

PXPIPE installs a hardcoded pxpipe-proxy@latest package; this is a package-manager execution boundary, not attacker-controlled package selection. Headroom extras are also constrained to a closed code/ml whitelist.

This PR supersedes #3078 by including its /api/pxpipe guard plus Headroom coverage and focused tests. It does not close #3078 automatically.

Behavior

  • remote requests to these management prefixes receive 403, even when requireLogin=false
  • loopback authenticated/login-disabled access and valid CLI-token access remain allowed
  • X-9Router-Token-Saver: off or OFF returns PXPIPE skip telemetry (applied:false, reason:"disabled") and leaves the request body unchanged
  • no header keeps current PXPIPE behavior

Test plan

  • unit/dashboard-guard.test.js
  • unit/headroom-chat-core.test.js
  • unit/pxpipe.test.js
  • 46 tests passed, 0 failed
  • no-regression baseline: 0 new failures
  • provider, alias, and OAuth snapshots unchanged

Scope

Exactly four files. No dependency, version, changelog, Headroom pipeline, or system-injection changes.

Copilot AI lite review requested due to automatic review settings August 23, 2026 13:40

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@KunN-21

KunN-21 commented Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

Bảo trì: đã merge upstream eb712ca và push thường tip 8400a34. Diff còn 4 file, giữ local-only guards và PXPIPE opt-out. Review độc lập không thấy blocker; 39/39 scoped tests pass. Cohort liên quan có 1 lỗi headroom-detect Windows path, đã tái hiện trên upstream cùng SHA; không sửa lỗi ngoài phạm vi trong PR này. git diff --check pass. Chưa chạy full suite hoặc live provider.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants