Repository navigation
fix(dashboard): correct the four guard-flag descriptions to the audited semantics - #15617
Merged
diegosouzapw merged 1 commit intoOct 6, 2026
Conversation
…ed semantics The feature-flag cards render the raw English description from featureFlagDefinitions.ts; all four still carried the pre-correction claims. They now match docs/reference/FEATURE_FLAGS.md as corrected in PR diegosouzapw#15616: the legacy alias reads its dashboard toggle before the environment, the private flag turns the host checks off (metadata block included) while the proxy-fallback test and webhook targets consult only it, the local flag is the local-first default with the full metadata block, and the rerank card no longer claims metadata hosts are never routed to. Pinned by four unit tests.
diegosouzapw
merged commit Oct 6, 2026
d6b7f72
into
diegosouzapw:release/v3.8.52
42 of 51 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Follow-up to #15616. The feature-flag cards on the dashboard render the raw English
descriptionfromsrc/shared/constants/featureFlagDefinitions.ts(thedescriptionI18nKeyvalues have noen.jsonmessage — verified, zero grep matches), and four of them still carried the pre-correction guard semantics that #15616 fixed in the docs:OUTBOUND_SSRF_GUARD_ENABLEDsaid "Block outbound requests to private/internal IP ranges" — implying local/private URLs are blocked by default. It is a legacy alias whose dashboard toggle (a DB override) is read before the environment (fix(providers): read the SSRF Guard toggle from the dashboard, not only env #14172);false/0/no/offin either turns the host checks off like the private flag.OMNIROUTE_ALLOW_PRIVATE_PROVIDER_URLSsaid "Allow provider URLs pointing to private/internal networks" — it turns the host checks off (cloud-metadata block included) on the guard-mode paths and allows private webhook targets; the proxy-fallback test and webhook targets consult only this flag, so local/LAN hosts stay blocked there while it is off.OMNIROUTE_ALLOW_LOCAL_PROVIDER_URLSstill said local models "need" this flag — it is the local-first default (on), and the metadata block covers all of 169.254.0.0/16 plus the known metadata hostnames.RERANK_REMOTE_PROVIDER_NODESended with "(cloud-metadata hosts are never routed to)" — overstated: under guard modenone(private opt-in) the node check does not block metadata. The clause is dropped, matching the correctedFEATURE_FLAGS.mdrow.No keys, defaults, or types change;
descriptiontext only.Tests Added Or Updated
tests/unit/feature-flag-descriptions-claims.test.ts— four tests pinning the corrected claims (legacy-alias semantics, metadata block scope, local-first default, no "never routed to" claim), so the dashboard text cannot drift back. All pass; the existingfeature-flags-settings.test.ts(63 tests) stays green.Validation
node --import tsx/esm --test tests/unit/feature-flag-descriptions-claims.test.ts— 4/4.node --import tsx/esm --test tests/unit/feature-flags-settings.test.ts— 63/63 (the suite that assertsdescriptionI18nKeywiring).npm run lint— 0 errors..envchanges → no docs gates in scope.Reviewer Notes