Skip to content

fix(security): fail closed on chatgpt-web-codex CDP proxy without token (#14486) - #15825

Merged
diegosouzapw merged 1 commit into
release/v3.8.52from
fix/14486-cdp-proxy-fail-closed
Oct 10, 2026
Merged

diegosouzapw merged 1 commit into
release/v3.8.52from
fix/14486-cdp-proxy-fail-closed

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Closes #14486

Finding 1 (/api/cli/connect + CHANGEME) was already fixed by #14491/#15043 and is untouched. This PR is Finding 2.

Root cause

docker/chatgpt-web-codex-browser/cdp-proxy.mjs hasValidToken() returned true when CDP_PROXY_TOKEN was empty (the compose default), so anyone reaching port 9223 got unauthenticated CDP (full control of the logged-in browser session). Unlike the sibling cdp-bridge.py, it failed open.

Fix (all three parts together)

  • (a) cdp-proxy.mjs now fails CLOSED with no token (constant-time compare, warning text updated, token never logged).
  • (b) Provisioning in docker-compose.yml and docker-compose.prod.yml: with CDP_PROXY_TOKEN empty, the browser container auto-generates a secret into CDP_PROXY_TOKEN_FILE on a named volume shared read-only with the app container (prod also gets the same wiring). No internal: true network (would cut egress). .env.example documented.
  • (c) New open-sse/vendor/codex-chatgpt-web/cdp-auth.ts; all connectOverCDP call sites in browser-login.ts and browser-worker.ts now pass X-Omni-Cdp-Token (from CDP_PROXY_TOKEN or the shared file), so the executor keeps working.
  • CDP_PROXY_LISTEN_PORT / CDP_PROXY_UPSTREAM_PORT env overrides (defaults unchanged) so the new test does not collide with the security(defaults): 16 verified insecure defaults from the insecure-defaults pipeline (cloud-sync HMAC fail-open, CLI token salt, keyless listeners, compose/podman defaults) #13679 test ports.

Tests

  • tests/unit/cdp-proxy-fail-closed-no-token-14486.test.ts: RED on unfixed proxy (2 fail: forwarded upstream with no token; token-file case), GREEN after (2 pass).
  • tests/unit/chatgpt-web-codex-cdp-token-header-14486.test.ts: header options from env / token file / none (3 pass).
  • Existing cdp-proxy-auth-gate-13679 (2) and chatgpt-web-codex (41) pass.

Gates

file-size, complexity, cognitive-complexity, typecheck:core, check:open-sse-typecheck, eslint (with suppressions), prettier, husky pre-commit.

Note: browser-worker.ts is frozen for size; one blank line removed to keep it line-neutral.

⚠️ base-red inherited: #15306 — unit/integration/package-artifact gates timing out, vitest open-sse/mcp-server/tests/audit.test.ts, check:ai-attribution range error

…en and provision it end to end (#14486)

cdp-proxy.mjs returned true from hasValidToken() when CDP_PROXY_TOKEN was
empty, forwarding unauthenticated CDP (full browser control) on the default
deploy. It now rejects everything without a token. To keep the executor
working, the browser container auto-generates a secret into a volume shared
read-only with the app in both compose files (or uses CDP_PROXY_TOKEN), and
the vendored connectOverCDP calls send X-Omni-Cdp-Token. The token is never
logged.
@diegosouzapw diegosouzapw added the hold-vps PR verde, merge aguardando validação live (release-drain) label Oct 8, 2026
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

CI Coverage Report

  • Coverage job: skipped
  • PR test policy: success

Coverage artifact was not available for this run.

@diegosouzapw
diegosouzapw merged commit 478e683 into release/v3.8.52 Oct 10, 2026
36 of 56 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hold-vps PR verde, merge aguardando validação live (release-drain)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(auth): /api/cli/connect accepts CHANGEME with no loopback gate (admin token); chatgpt-web-codex cdp-proxy is fail-open without CDP_PROXY_TOKEN

1 participant