Repository navigation
cherry-pick(pr-10362): feat(routing): add exclusive managed session connection leases - #6
Merged
Conversation
…ive routing, and status inventory Inspired-by: diegosouzapw#10148
Merge #3 (cherry-pick pr-10148) into update/v3.8.50
…plication in the UX Inspired-by: diegosouzapw#10354
Merge #4 (cherry-pick pr-10354) into update/v3.8.50
Merge #5 (cherry-pick pr-10109) into update/v3.8.50
…onnection leases Inspired-by: diegosouzapw#10362
thinh0704hcm
pushed a commit
that referenced
this pull request
Sep 21, 2026
…e leak (diegosouzapw#13679) (diegosouzapw#13911) PR E of the diegosouzapw#13679 insecure-defaults umbrella (items #6, #7; item #8 analyzed as by-design, no change). The published Docker image and fly.toml shipped without REQUIRE_API_KEY set, so a bare `docker run` (README/QUICK-START one-liners, no --env-file) or a `fly deploy` combined "keyless" with "world-reachable" for the anonymous /v1 LLM proxy. docker-compose.yml already mitigates this via loopback-only binding (diegosouzapw#12568) and correctly keeps following the operator's own .env, so it is untouched. The npm/CLI local-first REQUIRE_API_KEY=false default in featureFlagDefinitions.ts is also untouched per the owner's decision. /api/free-tier/summary ships an unconditional Access-Control-Allow-Origin: "*" and always included the operator's own local usedThisMonth/remaining usage regardless of auth — a low-severity info leak to any reachable origin. Both fields are now withheld from unauthenticated callers while the intentionally public catalog data stays served to everyone. The gemini-SSE (openai-to-gemini-sse.ts) sub-finding needed no code change: /v1beta/models/*:streamGenerateContent is already classified CLIENT_API and fronted by clientApiPolicy through src/proxy.ts before the translator ever runs, and its CORS-header echo was already hardened fail-closed by diegosouzapw#12573. REQUIRE_API_KEY=true (this PR's container/Fly default) closes the dependency that finding cited. Added a locking regression test confirming this chain. Regression tests: - tests/unit/issue-13679-container-posture-require-api-key.test.ts - tests/unit/issue-13679-free-tier-summary-usage-leak.test.ts - tests/unit/issue-13679-gemini-sse-requires-api-key.test.ts (confirmation) Refs diegosouzapw#13679
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Port of diegosouzapw#10362 — diegosouzapw#10362
Exclusive managed session leases (58 files excl docs/i18n drift): 120s TTL, owner-hash+gen fencing, 429 WAITING_FOR_CAPACITY, localDb kept ensurePool from diegosouzapw#10148. Migration 154 retained (head is 153).
Gates: typecheck:core ✅, eslint ✅, focused lease tests 32/32 ✅