Skip to content

fix(dashboard): correct the four guard-flag descriptions to the audited semantics - #15617

Merged
diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.52from
woodsonl:fix/flag-descriptions-setup-claims
Oct 6, 2026
Merged

diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.52from
woodsonl:fix/flag-descriptions-setup-claims

Conversation

@woodsonl

@woodsonl woodsonl commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Summary

Follow-up to #15616. The feature-flag cards on the dashboard render the raw English description from src/shared/constants/featureFlagDefinitions.ts (the descriptionI18nKey values have no en.json message — verified, zero grep matches), and four of them still carried the pre-correction guard semantics that #15616 fixed in the docs:

  • OUTBOUND_SSRF_GUARD_ENABLED said "Block outbound requests to private/internal IP ranges" — implying local/private URLs are blocked by default. It is a legacy alias whose dashboard toggle (a DB override) is read before the environment (fix(providers): read the SSRF Guard toggle from the dashboard, not only env #14172); false/0/no/off in either turns the host checks off like the private flag.
  • OMNIROUTE_ALLOW_PRIVATE_PROVIDER_URLS said "Allow provider URLs pointing to private/internal networks" — it turns the host checks off (cloud-metadata block included) on the guard-mode paths and allows private webhook targets; the proxy-fallback test and webhook targets consult only this flag, so local/LAN hosts stay blocked there while it is off.
  • OMNIROUTE_ALLOW_LOCAL_PROVIDER_URLS still said local models "need" this flag — it is the local-first default (on), and the metadata block covers all of 169.254.0.0/16 plus the known metadata hostnames.
  • RERANK_REMOTE_PROVIDER_NODES ended with "(cloud-metadata hosts are never routed to)" — overstated: under guard mode none (private opt-in) the node check does not block metadata. The clause is dropped, matching the corrected FEATURE_FLAGS.md row.

No keys, defaults, or types change; description text only.

Tests Added Or Updated

tests/unit/feature-flag-descriptions-claims.test.ts — four tests pinning the corrected claims (legacy-alias semantics, metadata block scope, local-first default, no "never routed to" claim), so the dashboard text cannot drift back. All pass; the existing feature-flags-settings.test.ts (63 tests) stays green.

Validation

  • node --import tsx/esm --test tests/unit/feature-flag-descriptions-claims.test.ts — 4/4.
  • node --import tsx/esm --test tests/unit/feature-flags-settings.test.ts — 63/63 (the suite that asserts descriptionI18nKey wiring).
  • npm run lint — 0 errors.
  • No docs or .env changes → no docs gates in scope.

Reviewer Notes

⚠️ base-red inherited: #15306 (unit/integration/package-artifact ceiling hangs, vitest MCP-audit failure, ai-attribution lint error) — none traces to this diff. Depends on the corrected doc semantics from #15616 only for wording alignment; merges independently of it.

…ed semantics

The feature-flag cards render the raw English description from
featureFlagDefinitions.ts; all four still carried the pre-correction
claims. They now match docs/reference/FEATURE_FLAGS.md as corrected in
PR diegosouzapw#15616: the legacy alias reads its dashboard toggle before the
environment, the private flag turns the host checks off (metadata block
included) while the proxy-fallback test and webhook targets consult only
it, the local flag is the local-first default with the full metadata
block, and the rerank card no longer claims metadata hosts are never
routed to. Pinned by four unit tests.
@woodsonl
woodsonl requested a review from diegosouzapw as a code owner October 6, 2026 04:14
@diegosouzapw
diegosouzapw merged commit d6b7f72 into diegosouzapw:release/v3.8.52 Oct 6, 2026
42 of 51 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants