Skip to content

Add AI provider security: SSRF, consent, MCP scope - #502

Merged
2witstudios merged 1 commit into
masterfrom
security/ai-providers
Feb 8, 2026
Merged

2witstudios merged 1 commit into
masterfrom
security/ai-providers

Conversation

@2witstudios

Copy link
Copy Markdown
Owner

Summary

Security hardening for AI provider infrastructure, addressing four security issues:

Fixes #420, Fixes #462, Fixes #417, Fixes #464

Changes

SSRF Validation (packages/lib/src/security/)

  • url-validator.ts: validateLocalProviderURL(), validateExternalURL(), isBlockedIP(), safeFetch() with DNS rebinding protection
  • 57 unit tests covering IPv4/IPv6 private ranges, cloud metadata, bypass techniques

Consent Management

  • packages/db/src/schema/ai.ts: aiProviderConsents table with unique constraint and cascade delete
  • apps/web/src/lib/repositories/ai-consent-repository.ts: hasConsent(), grantConsent(), revokeConsent(), getConsents()
  • apps/web/src/app/api/ai/consent/route.ts: GET/POST/DELETE with CSRF and auth
  • apps/web/src/components/ai/consent/CloudProviderConsentDialog.tsx: AlertDialog with privacy links
  • apps/web/src/lib/ai/core/provider-factory.ts: Consent check before provider creation (exempt: pagespace, ollama, lmstudio)
  • apps/web/src/lib/ai/core/ai-providers-config.ts: CONSENT_EXEMPT_PROVIDERS, requiresConsent()

MCP Scope Enforcement

  • apps/web/src/app/api/ai/chat/messages/route.ts: checkMCPPageScope() guard
  • apps/web/src/app/api/ai/chat/route.ts: checkMCPPageScope() guard
  • apps/web/src/app/api/tasks/route.ts: checkMCPDriveScope() + filterDrivesByMCPScope() guards

Test plan

  • 172 tests passing across all modules
  • pnpm typecheck — all packages pass
  • pnpm build — production build succeeds
  • Run pnpm db:migrate to apply consent table migration
  • Verify consent dialog appears when selecting a cloud provider for the first time
  • Verify MCP-scoped tokens are rejected for out-of-scope pages/drives
  • Verify Ollama/LM Studio URLs are validated on settings save and provider creation

🤖 Generated with Claude Code

…ope enforcement

- SSRF validation for Ollama/LM Studio base URLs in provider factory
  with private IP blocking, DNS rebinding mitigation, and safe fetch (Fixes #420)
- Cloud provider consent management with DB schema, API route, repository,
  and UI dialog integration in both chat views (Fixes #462)
- MCP token drive scope enforcement across chat, messages, and tasks routes
  with proper 403 responses for out-of-scope requests (Fixes #417)
- userId pseudonymization (Fixes #464): verified as false positive —
  experimental_context never leaves the Node.js process in AI SDK v5.0.54

172 tests passing across all security modules.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Feb 8, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Rate limit exceeded

@2witstudios has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 21 minutes and 59 seconds before requesting another review.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch security/ai-providers

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@2witstudios

Copy link
Copy Markdown
Owner Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Feb 8, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Review triggered.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@2witstudios
2witstudios merged commit ce7edcb into master Feb 8, 2026
10 checks passed
@2witstudios
2witstudios deleted the security/ai-providers branch February 8, 2026 21:24
2witstudios added a commit that referenced this pull request Feb 8, 2026
Both PRs generated migrations from the same parent snapshot (0077),
creating a fork. Re-chain 0079 as child of 0078 and fix journal
timestamp ordering.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant