Skip to content

fix(search): enforce blockedProviders setting on search endpoint (#11100) - #11125

Merged
diegosouzapw merged 3 commits into
diegosouzapw:release/v3.8.50from
rqzbeh:fix/mcp-web-search-blocked-providers
Aug 22, 2026
Merged

diegosouzapw merged 3 commits into
diegosouzapw:release/v3.8.50from
rqzbeh:fix/mcp-web-search-blocked-providers

Conversation

@rqzbeh

@rqzbeh rqzbeh commented Aug 22, 2026

Copy link
Copy Markdown
Contributor

Fixes #11100.

Root Cause

getAllSearchProviders() in open-sse/config/searchRegistry.ts returned all search providers without filtering out those present in blockedProviders settings.

Fix

  • Updated getAllSearchProviders(blockedProviders: string[] = []) in open-sse/config/searchRegistry.ts to filter out disabled providers and any provider matching isProviderBlockedByIdOrAlias(p.id, blockedProviders).
  • Updated GET /v1/search in src/app/api/v1/search/route.ts to pass blockedProviders from settings to getAllSearchProviders(blockedProviders).

Test Coverage

Added unit test tests/unit/search-blocked-providers-11100.test.ts verifying getAllSearchProviders filters out blocked providers.

@diegosouzapw
diegosouzapw force-pushed the fix/mcp-web-search-blocked-providers branch from 753a914 to 5f57502 Compare August 22, 2026 19:12
@diegosouzapw
diegosouzapw merged commit 367ae2f into diegosouzapw:release/v3.8.50 Aug 22, 2026
5 of 7 checks passed
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…gosouzapw#11100) (diegosouzapw#11125)

Cherry-picked the three value commits onto the current tip, dropping the stale base-red sync commits. Focused tests: search-blocked-providers-11100 + search-registry/searxng-loopback/chat-guard/x-search suites 65/65. Fixes diegosouzapw#11100 (endpoint half) — GET /v1/search now honors blockedProviders via getAllSearchProviders. Thank you @rqzbeh!
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] MCP omniroute_web_search provider enum exposes all 16 registry providers while GET /v1/search lists only non-blocked ones

2 participants