Repository navigation
fix(docs): keep operator-internal security writeups out of public /docs - #13136
Merged
diegosouzapw merged 4 commits intoSep 11, 2026
Merged
diegosouzapw merged 4 commits into
diegosouzapw merged 4 commits into
Conversation
HouMinXi
added a commit
to HouMinXi/OmniRoute
that referenced
this pull request
Sep 9, 2026
…3136 Signed-off-by: Minxi Hou <houminxi@gmail.com>
HouMinXi
added a commit
to HouMinXi/OmniRoute
that referenced
this pull request
Sep 10, 2026
…3136 Signed-off-by: Minxi Hou <houminxi@gmail.com>
HouMinXi
force-pushed
the
fix/docs-sensitive-catalog
branch
from
September 10, 2026 11:19
4d98ae8 to
f7d5614
Compare
HouMinXi
added a commit
to HouMinXi/OmniRoute
that referenced
this pull request
Sep 10, 2026
…3136 Signed-off-by: Minxi Hou <houminxi@gmail.com>
HouMinXi
force-pushed
the
fix/docs-sensitive-catalog
branch
from
September 10, 2026 12:57
f7d5614 to
02a2203
Compare
Public fumadocs compiled STEALTH_GUIDE, SOCKET_DEV_FINDINGS, MITM-TPROXY-DECRYPT, and PUBLIC_CREDS into /docs. A Caddy Basic gate on the whole path was a deploy bandage and also blocked LAN. Exclude those four files from the catalog glob and Docker image. They stay in git. Public security pages that still pointed at them now cite the repo path instead of a /docs URL. Signed-off-by: Minxi Hou <houminxi@gmail.com>
The catalog guard copied a dockerignore matcher that applied every exclude then every include. Docker last-match-wins: a later exact exclude must beat an earlier include. *.md also matched STEALTH_GUIDE.md.bak because the last literal was not anchored. Keep files in git. The matcher now walks rules in file order and anchors the last glob chunk. Signed-off-by: Minxi Hou <houminxi@gmail.com>
Signed-off-by: Minxi Hou <houminxi@gmail.com>
…3136 Signed-off-by: Minxi Hou <houminxi@gmail.com>
HouMinXi
force-pushed
the
fix/docs-sensitive-catalog
branch
from
September 11, 2026 08:21
02a2203 to
83b3dc7
Compare
Contributor
Author
|
CI red on this PR matches current Measured on tip
Unique diff does not touch those files. Contributor-only; not merging. |
diegosouzapw
merged commit Sep 11, 2026
aedc506
into
diegosouzapw:release/v3.8.51
8 of 16 checks passed
Githab-capibara
added a commit
to Githab-capibara/OmniRoute
that referenced
this pull request
Sep 17, 2026
…cs (diegosouzapw#13136) Security-relevant and the right fix. A Basic gate on the whole `/docs` path was a deploy bandage that also locked LAN operators out of `https://<lan>:20128/docs`; dropping the four operator-internal writeups from the fumadocs glob and the Docker image removes the reason for the gate instead of papering over it. Keeping them in git and citing repo paths from the public pages is the right trade. The `.dockerignore` matcher walking rules in file order with last-match-wins is a genuine correctness fix in the test's own matcher. --- Validated in one consolidated worktree cut from `release/v3.8.51`, boarded with the other 19 PRs of this batch. Two in-batch conflicts, both additive and resolved by keeping each side: the `ENVIRONMENT.md` table (diegosouzapw#13035 + diegosouzapw#13011) and the `chatHelpers.ts` import block (diegosouzapw#12975 on the tip + diegosouzapw#13017). - `typecheck:core` clean; `check:dashboard-typecheck` OK (206 pre-existing, within baseline); `check:changelog-integrity` OK; `check:docs-counts` migrations ✓ - complexity 2816 / baseline 3218 and cognitive-complexity 1271 / baseline 1437 — both under baseline - 531 of 532 focused assertions green across the batch's 46 test files - `check-file-size` rebaselined for the batch's real growth (annotation `_rebaseline_2026_09_11_mergebatch_v3851_houminxi`, landed on diegosouzapw#13038), attributed per PR The single red is **not this batch**: `tests/unit/combo/quota-weighted-strategy.test.ts` → "A/B isolation: 7 hard-empty + 2 at 0.5% + 1 at 40%, floor=1" asserts an order between two connections of identical weight and flakes on the pure tip too — 2 failures in 4 runs at `origin/release/v3.8.51` with nothing from this batch applied.⚠️ base-red inherited: diegosouzapw#12732 — `Docs Gates`, `Merge integrity`, `No new ESLint warnings`, `Unit Tests fast-path` and `Fast Quality Gates` reproduce on the pure tip (provider count 356 vs the 358 the modules define, SKILL.md drift, and `open-sse/utils/stream.ts` at 3115 > frozen 3098, untouched here). Thanks @HouMinXi — the live evidence on these (X500 logs, `storage.sqlite` state, real `/v1/models` probes, the 36-minute outage write-up) is what let a 20-PR batch be reviewed as a unit.
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…cs (diegosouzapw#13136) Security-relevant and the right fix. A Basic gate on the whole `/docs` path was a deploy bandage that also locked LAN operators out of `https://<lan>:20128/docs`; dropping the four operator-internal writeups from the fumadocs glob and the Docker image removes the reason for the gate instead of papering over it. Keeping them in git and citing repo paths from the public pages is the right trade. The `.dockerignore` matcher walking rules in file order with last-match-wins is a genuine correctness fix in the test's own matcher. --- Validated in one consolidated worktree cut from `release/v3.8.51`, boarded with the other 19 PRs of this batch. Two in-batch conflicts, both additive and resolved by keeping each side: the `ENVIRONMENT.md` table (diegosouzapw#13035 + diegosouzapw#13011) and the `chatHelpers.ts` import block (diegosouzapw#12975 on the tip + diegosouzapw#13017). - `typecheck:core` clean; `check:dashboard-typecheck` OK (206 pre-existing, within baseline); `check:changelog-integrity` OK; `check:docs-counts` migrations ✓ - complexity 2816 / baseline 3218 and cognitive-complexity 1271 / baseline 1437 — both under baseline - 531 of 532 focused assertions green across the batch's 46 test files - `check-file-size` rebaselined for the batch's real growth (annotation `_rebaseline_2026_09_11_mergebatch_v3851_houminxi`, landed on diegosouzapw#13038), attributed per PR The single red is **not this batch**: `tests/unit/combo/quota-weighted-strategy.test.ts` → "A/B isolation: 7 hard-empty + 2 at 0.5% + 1 at 40%, floor=1" asserts an order between two connections of identical weight and flakes on the pure tip too — 2 failures in 4 runs at `origin/release/v3.8.51` with nothing from this batch applied.⚠️ base-red inherited: diegosouzapw#12732 — `Docs Gates`, `Merge integrity`, `No new ESLint warnings`, `Unit Tests fast-path` and `Fast Quality Gates` reproduce on the pure tip (provider count 356 vs the 358 the modules define, SKILL.md drift, and `open-sse/utils/stream.ts` at 3115 > frozen 3098, untouched here). Thanks @HouMinXi — the live evidence on these (X500 logs, `storage.sqlite` state, real `/v1/models` probes, the 36-minute outage write-up) is what let a 20-PR batch be reviewed as a unit.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
/docscompiled four operator-internal security writeups into the public fumadocs tree:docs/security/STEALTH_GUIDE.md(TLS impersonation profiles)docs/security/SOCKET_DEV_FINDINGS.md(supply-chain attestation of flagged call sites)docs/security/MITM-TPROXY-DECRYPT.md(TPROXY decrypt recipe)docs/security/PUBLIC_CREDS.md(XOR-mask recipe for public OAuth identifiers)A reverse-proxy Basic gate on the whole
/docspath was a deploy bandage. It also blocked LAN operators hittinghttps://<lan>:20128/docs.This PR drops those four files from the fumadocs glob and from the Docker image. They stay in git. Public pages that pointed at them now cite the repo path instead of a
/docsURL. Operator-facing security pages (Guardrails, error sanitization, route-guard tiers, and the rest of that index) stay public.The catalog test's
.dockerignorematcher now walks rules in file order (last match wins) and anchors the last literal of a*glob, so*.mddoes not matchSTEALTH_GUIDE.md.bak.Test plan
node --import tsx/esm --test tests/unit/docs-public-catalog-sensitive-pages.test.ts— 7/7node --import tsx/esm --test tests/unit/dockerignore-docs-coverage.test.ts— 2/2node scripts/check/check-docs-frontmatter.mjs— 123 compiled docsnode scripts/check/check-doc-links.mjs— 948 links, 0 broken!./security/…globs → catalog test fails; restore → passAfter merge, a production rebuild is required before
/docs/security/stealth-guide404s. The reverse-proxy/docsBasic gate can then stay limited to WAN Hosts; the catalog exclusion is what stops the leak.Notes
Contributor PR. Please do not merge from this account.