Skip to content

fix(executors): DuckDuckGo AI Chat uses duckduckgo.com (fixes 400) (#4037) - #4333

Merged
diegosouzapw merged 2 commits into
release/v3.8.30from
fix/4037-duckduckgo-domain
Jun 20, 2026
Merged

diegosouzapw merged 2 commits into
release/v3.8.30from
fix/4037-duckduckgo-domain

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Refs #4037 (the DuckDuckGo half — Chipotle is tracked separately, see below)

Problem

DuckDuckGo AI Chat returns HTTP 400. The executor hardcoded DUCKAI_BASE = "https://duck.ai" for the status/chat fetches, Origin, and Referer, while sending Sec-Fetch-Site: same-origin — an inconsistent same-origin triplet (the live backend is served from duckduckgo.com), which the backend rejects with 400. Secondary: FE_VERSION_PATTERN required a 40-hex tail but the real served x-fe-version token has a 20-hex tail, so the scrape never matched and silently fell back to a hardcoded future-dated default.

Fix

  • Repoint STATUS_URL, CHAT_URL, AUTH_TOKEN_URL, COUNTRY_URL, Origin, Referer, and the homepage warm-fetch onto the already-present DUCKDUCKGO_BASE = "https://duckduckgo.com" (consistent same-origin triplet; Sec-Fetch-Site: same-origin kept).
  • Relax FE_VERSION_PATTERN tail [0-9a-f]{40} → [0-9a-f]{20,40} (bounded, ReDoS-safe) to match the real 20-hex token.
  • Minimal export on STATUS_URL/CHAT_URL/FAKE_HEADERS/FE_VERSION_PATTERN for testability. Out-of-scope duck.ai refs (challenge-stub fingerprint, comment, opt-in Playwright path) intentionally untouched.

Validation (Hard Rule #18)

tests/unit/duckduckgo-domain-4037.test.ts (8 assertions): all HTTP-path URLs + Origin/Referer use duckduckgo.com; FE_VERSION_PATTERN matches a real 20-hex token and still a 40-hex one. RED 1/8 → GREEN 8/8; existing duckduckgo-web-executor + web-cookie sweep green (23/23 on my re-run). Lint 0-err, typecheck:core clean, file-size baseline bumped 917 → 925.

⚠️ Live-validation caveat: confirming the live 400 → 200 needs a VPS/live run — there's no stable CI DDG endpoint and DDG also gates on TLS fingerprint + anti-abuse. The builder-shape fix (URLs, header triplet, regex) is unit-TDD-covered; live validation is recommended before relying on it in production.

Chipotle (the other half of #4037) is not fixed here: our Chipotle code matches the current best public reference exactly, so its 502 is an upstream WS-contract change that needs a live capture — tracked separately in the issue.

The DuckDuckGo AI Chat executor fetched status/chat and set Origin/Referer
against https://duck.ai while sending Sec-Fetch-Site: same-origin, making the
same-origin triplet (host + Origin + Referer) inconsistent so the backend
rejected the request with HTTP 400. Repoint the executor's status URL, chat
URL, Origin, Referer, and warm fetch to https://duckduckgo.com (matching the
provider registry baseUrl and current DDG reverse-engineering references); the
same-origin header is now coherent.

Also relax FE_VERSION_PATTERN from a 40-hex tail to a bounded {20,40} tail so it
matches the real served x-fe-version token (20-hex, e.g.
serp_20250401_100419_ET-19d438eb199b2bf7c300) instead of silently falling back
to the hardcoded default. The bound keeps the pattern ReDoS-safe.

This is the DuckDuckGo half of the report; the separate Chipotle upstream
breakage is tracked independently.

TDD: tests/unit/duckduckgo-domain-4037.test.ts (8 assertions, RED before the
fix, GREEN after). Baseline bump 917->925 for the added comments.

Refs #4037
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@diegosouzapw
diegosouzapw merged commit 24cee53 into release/v3.8.30 Jun 20, 2026
3 checks passed
@diegosouzapw
diegosouzapw deleted the fix/4037-duckduckgo-domain branch June 20, 2026 04:21
tkgo11 pushed a commit to tkgo11/OmniRoute that referenced this pull request Sep 23, 2026
…iegosouzapw#4037) (diegosouzapw#4333)

The DuckDuckGo AI Chat executor fetched status/chat and set Origin/Referer
against https://duck.ai while sending Sec-Fetch-Site: same-origin, making the
same-origin triplet (host + Origin + Referer) inconsistent so the backend
rejected the request with HTTP 400. Repoint the executor's status URL, chat
URL, Origin, Referer, and warm fetch to https://duckduckgo.com (matching the
provider registry baseUrl and current DDG reverse-engineering references); the
same-origin header is now coherent.

Also relax FE_VERSION_PATTERN from a 40-hex tail to a bounded {20,40} tail so it
matches the real served x-fe-version token (20-hex, e.g.
serp_20250401_100419_ET-19d438eb199b2bf7c300) instead of silently falling back
to the hardcoded default. The bound keeps the pattern ReDoS-safe.

This is the DuckDuckGo half of the report; the separate Chipotle upstream
breakage is tracked independently.

TDD: tests/unit/duckduckgo-domain-4037.test.ts (8 assertions, RED before the
fix, GREEN after). Baseline bump 917->925 for the added comments.

Refs diegosouzapw#4037
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant