Skip to content

fix(docs): keep operator-internal security writeups out of public /docs - #13136

Merged
diegosouzapw merged 4 commits into
diegosouzapw:release/v3.8.51from
HouMinXi:fix/docs-sensitive-catalog
Sep 11, 2026
Merged

diegosouzapw merged 4 commits into
diegosouzapw:release/v3.8.51from
HouMinXi:fix/docs-sensitive-catalog

Conversation

@HouMinXi

@HouMinXi HouMinXi commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Summary

/docs compiled four operator-internal security writeups into the public fumadocs tree:

  • docs/security/STEALTH_GUIDE.md (TLS impersonation profiles)
  • docs/security/SOCKET_DEV_FINDINGS.md (supply-chain attestation of flagged call sites)
  • docs/security/MITM-TPROXY-DECRYPT.md (TPROXY decrypt recipe)
  • docs/security/PUBLIC_CREDS.md (XOR-mask recipe for public OAuth identifiers)

A reverse-proxy Basic gate on the whole /docs path was a deploy bandage. It also blocked LAN operators hitting https://<lan>:20128/docs.

This PR drops those four files from the fumadocs glob and from the Docker image. They stay in git. Public pages that pointed at them now cite the repo path instead of a /docs URL. Operator-facing security pages (Guardrails, error sanitization, route-guard tiers, and the rest of that index) stay public.

The catalog test's .dockerignore matcher now walks rules in file order (last match wins) and anchors the last literal of a * glob, so *.md does not match STEALTH_GUIDE.md.bak.

Test plan

  • node --import tsx/esm --test tests/unit/docs-public-catalog-sensitive-pages.test.ts — 7/7
  • node --import tsx/esm --test tests/unit/dockerignore-docs-coverage.test.ts — 2/2
  • node scripts/check/check-docs-frontmatter.mjs — 123 compiled docs
  • node scripts/check/check-doc-links.mjs — 948 links, 0 broken
  • Injection: remove the four !./security/… globs → catalog test fails; restore → pass

After merge, a production rebuild is required before /docs/security/stealth-guide 404s. The reverse-proxy /docs Basic gate can then stay limited to WAN Hosts; the catalog exclusion is what stops the leak.

Notes

Contributor PR. Please do not merge from this account.

HouMinXi added a commit to HouMinXi/OmniRoute that referenced this pull request Sep 9, 2026
HouMinXi added a commit to HouMinXi/OmniRoute that referenced this pull request Sep 10, 2026
@HouMinXi
HouMinXi force-pushed the fix/docs-sensitive-catalog branch from 4d98ae8 to f7d5614 Compare September 10, 2026 11:19
HouMinXi added a commit to HouMinXi/OmniRoute that referenced this pull request Sep 10, 2026
@HouMinXi
HouMinXi force-pushed the fix/docs-sensitive-catalog branch from f7d5614 to 02a2203 Compare September 10, 2026 12:57
Public fumadocs compiled STEALTH_GUIDE, SOCKET_DEV_FINDINGS,
MITM-TPROXY-DECRYPT, and PUBLIC_CREDS into /docs. A Caddy Basic gate
on the whole path was a deploy bandage and also blocked LAN.

Exclude those four files from the catalog glob and Docker image. They
stay in git. Public security pages that still pointed at them now
cite the repo path instead of a /docs URL.

Signed-off-by: Minxi Hou <houminxi@gmail.com>
The catalog guard copied a dockerignore matcher that applied every
exclude then every include. Docker last-match-wins: a later exact
exclude must beat an earlier include. *.md also matched
STEALTH_GUIDE.md.bak because the last literal was not anchored.

Keep files in git. The matcher now walks rules in file order and
anchors the last glob chunk.

Signed-off-by: Minxi Hou <houminxi@gmail.com>
Signed-off-by: Minxi Hou <houminxi@gmail.com>
@HouMinXi
HouMinXi force-pushed the fix/docs-sensitive-catalog branch from 02a2203 to 83b3dc7 Compare September 11, 2026 08:21
@HouMinXi

Copy link
Copy Markdown
Contributor Author

CI red on this PR matches current release/v3.8.51, not the unique files in the diff.

Measured on tip af49d4972 (#12925) against the HouMinXi open set:

  • Docs Gates: live provider modules 358 vs docs/SVG still saying 356; cli-tunnel skill dry-run out of date.
  • Fast Quality: open-sse/services/autoCombo/__tests__/autoCombo.test.ts TS2739 vs frozen baseline 0; pack-policy follows that.
  • ESLint: tests/unit/volcengine-plan-binding-upsert.test.ts @typescript-eslint/no-explicit-any (file is on tip).
  • Unit shards: chat-rate-limit-body-lock, antigravity-missing-project-chat, chat-rejects-image-only-model, stream-handler-public-error-boundary (and the glm GLM_STREAM_BUFFER_BYTES assert, which fix(stream): accept the buffer size glm.ts has been passing since #12179 #12925 already landed on tip).

Unique diff does not touch those files. Contributor-only; not merging.

@diegosouzapw
diegosouzapw merged commit aedc506 into diegosouzapw:release/v3.8.51 Sep 11, 2026
8 of 16 checks passed
@HouMinXi
HouMinXi deleted the fix/docs-sensitive-catalog branch September 16, 2026 12:43
Githab-capibara added a commit to Githab-capibara/OmniRoute that referenced this pull request Sep 17, 2026
…cs (diegosouzapw#13136)

Security-relevant and the right fix. A Basic gate on the whole `/docs` path was a deploy bandage that also locked LAN operators out of `https://<lan>:20128/docs`; dropping the four operator-internal writeups from the fumadocs glob and the Docker image removes the reason for the gate instead of papering over it. Keeping them in git and citing repo paths from the public pages is the right trade. The `.dockerignore` matcher walking rules in file order with last-match-wins is a genuine correctness fix in the test's own matcher.

---

Validated in one consolidated worktree cut from `release/v3.8.51`, boarded with the other 19 PRs of this batch. Two in-batch conflicts, both additive and resolved by keeping each side: the `ENVIRONMENT.md` table (diegosouzapw#13035 + diegosouzapw#13011) and the `chatHelpers.ts` import block (diegosouzapw#12975 on the tip + diegosouzapw#13017).

- `typecheck:core` clean; `check:dashboard-typecheck` OK (206 pre-existing, within baseline); `check:changelog-integrity` OK; `check:docs-counts` migrations ✓
- complexity 2816 / baseline 3218 and cognitive-complexity 1271 / baseline 1437 — both under baseline
- 531 of 532 focused assertions green across the batch's 46 test files
- `check-file-size` rebaselined for the batch's real growth (annotation `_rebaseline_2026_09_11_mergebatch_v3851_houminxi`, landed on diegosouzapw#13038), attributed per PR

The single red is **not this batch**: `tests/unit/combo/quota-weighted-strategy.test.ts` → "A/B isolation: 7 hard-empty + 2 at 0.5% + 1 at 40%, floor=1" asserts an order between two connections of identical weight and flakes on the pure tip too — 2 failures in 4 runs at `origin/release/v3.8.51` with nothing from this batch applied.

⚠️ base-red inherited: diegosouzapw#12732 — `Docs Gates`, `Merge integrity`, `No new ESLint warnings`, `Unit Tests fast-path` and `Fast Quality Gates` reproduce on the pure tip (provider count 356 vs the 358 the modules define, SKILL.md drift, and `open-sse/utils/stream.ts` at 3115 > frozen 3098, untouched here).

Thanks @HouMinXi — the live evidence on these (X500 logs, `storage.sqlite` state, real `/v1/models` probes, the 36-minute outage write-up) is what let a 20-PR batch be reviewed as a unit.
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…cs (diegosouzapw#13136)

Security-relevant and the right fix. A Basic gate on the whole `/docs` path was a deploy bandage that also locked LAN operators out of `https://<lan>:20128/docs`; dropping the four operator-internal writeups from the fumadocs glob and the Docker image removes the reason for the gate instead of papering over it. Keeping them in git and citing repo paths from the public pages is the right trade. The `.dockerignore` matcher walking rules in file order with last-match-wins is a genuine correctness fix in the test's own matcher.

---

Validated in one consolidated worktree cut from `release/v3.8.51`, boarded with the other 19 PRs of this batch. Two in-batch conflicts, both additive and resolved by keeping each side: the `ENVIRONMENT.md` table (diegosouzapw#13035 + diegosouzapw#13011) and the `chatHelpers.ts` import block (diegosouzapw#12975 on the tip + diegosouzapw#13017).

- `typecheck:core` clean; `check:dashboard-typecheck` OK (206 pre-existing, within baseline); `check:changelog-integrity` OK; `check:docs-counts` migrations ✓
- complexity 2816 / baseline 3218 and cognitive-complexity 1271 / baseline 1437 — both under baseline
- 531 of 532 focused assertions green across the batch's 46 test files
- `check-file-size` rebaselined for the batch's real growth (annotation `_rebaseline_2026_09_11_mergebatch_v3851_houminxi`, landed on diegosouzapw#13038), attributed per PR

The single red is **not this batch**: `tests/unit/combo/quota-weighted-strategy.test.ts` → "A/B isolation: 7 hard-empty + 2 at 0.5% + 1 at 40%, floor=1" asserts an order between two connections of identical weight and flakes on the pure tip too — 2 failures in 4 runs at `origin/release/v3.8.51` with nothing from this batch applied.

⚠️ base-red inherited: diegosouzapw#12732 — `Docs Gates`, `Merge integrity`, `No new ESLint warnings`, `Unit Tests fast-path` and `Fast Quality Gates` reproduce on the pure tip (provider count 356 vs the 358 the modules define, SKILL.md drift, and `open-sse/utils/stream.ts` at 3115 > frozen 3098, untouched here).

Thanks @HouMinXi — the live evidence on these (X500 logs, `storage.sqlite` state, real `/v1/models` probes, the 36-minute outage write-up) is what let a 20-PR batch be reviewed as a unit.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants