Skip to content

fix(cli): secure configuration previews and atomic writes - #14381

Merged
diegosouzapw merged 4 commits into
release/v3.8.51from
fix/relay-config-security-20260921
Sep 24, 2026
Merged

diegosouzapw merged 4 commits into
release/v3.8.51from
fix/relay-config-security-20260921

Conversation

@diegosouzapw

@diegosouzapw diegosouzapw commented Sep 21, 2026 •

Copy link
Copy Markdown
Owner

Status: INCOMPLETE / INFRA — CI validation requested, not merge-ready

This is the configuration-security slice of the approved Relay CLI completion plan. It preserves the container write guard and does not merge or deploy anything.

Changes

  • Redact credentials (including existing JSONC/TOML/YAML profile fields) from non-cacheable configuration previews.
  • Require x-omniroute-config-api-key for GET /api/cli-tools/config; reject credentials in query strings, malformed JSON and unknown request fields.
  • Use private, atomic configuration and backup writes; refuse final destination symlinks and non-regular files. Codex/OpenCode reads refuse final symlinks.
  • Preserve original configuration values on disk; preview content is deliberately not an import/apply payload.
  • Align OpenAPI, canonical CLI guidance and generated agent-skill examples with header-based previews and original-input application. The apply example uses dryRun:true.
  • Remove only two obsolete unused-variable suppressions from the generator index.

Consumer audit

A bounded literal/constructed-path audit of src, bin, electron, open-sse, packages and scripts found no executable first-party caller of the generic config/apply endpoints. Dashboard cards use per-tool settings APIs; manual-copy configuration is built locally. CLI configure delegates to local setup recipes. Generated agent-skill documentation was a real consumer and is updated here.

External clients using the old apiKey query must migrate to the documented header. Clients must send original toolId/baseUrl/apiKey/model inputs to apply, not replay redacted response content.

Validation

  • PASS: 24 focused configuration/API/filesystem tests plus 2 generated-consumer/authentication-contract tests.
  • PASS: auth-hardening RED → GREEN (1 failed / 2 before, 5 passed / 5 after). Three added endpoint tests verify GET config, POST config and POST apply preserve 401/403, no-store, sanitized errors and reject before reading input. Production auth behavior is unchanged.
  • PASS: normal pre-commit gates, staged ESLint/Prettier, file-size and test discovery.
  • PASS: strict TypeScript for configPreview/privateConfigFile helpers; scoped complexity checks for new helpers.
  • PASS: regenerate omni-cli-tools, then scoped dry-run reports Generated 0 / Unchanged 1 / Errors 0.
  • PASS: docs-sync; focused documentation checks were exercised during implementation.
  • INCOMPLETE: a rendered Claude manual-config regression was added, but both single-worker Vitest threads and forks failed to start before test collection (worker timeout); no UI pass is claimed.
  • INTERRUPTED / INFRA: global typecheck:core was terminated after more than 20 minutes without a result on the saturated shared host. typecheck:noimplicit:core did not run.
  • BLOCKED: docs-counts could not execute its code-facts subprocess (readCodeFacts unavailable / tsx-spawnSync failure).
  • CI evidence at e5d60db: Fast Quality Gates (including core typecheck), API route typecheck, docs, MCP Vitest, generated-artifact integrity and unit shards 1/2/3 passed. Unit shard 4 found one stale structural-auth assertion; ce18146 fixes it with the behavioral proof above.
  • PENDING: authoritative CI completion on the new final head ce18146. MCP Vitest is not the rendered UI suite; local UI startup remains INFRA.

Open release-health issue: #13866 (reported docs/env hard failure and release ratchet drift). This candidate does not claim that the release base or this candidate is globally green.

No real credentials or temporary hook changes are committed. Final-parent-directory adversary protection is not claimed. Owner review and merge remain required.

@diegosouzapw
diegosouzapw marked this pull request as ready for review September 21, 2026 22:09
@diegosouzapw
diegosouzapw merged commit 4df9cea into release/v3.8.51 Sep 24, 2026
21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant