Repository navigation
Add AI provider security: SSRF, consent, MCP scope - #502
Conversation
…ope enforcement - SSRF validation for Ollama/LM Studio base URLs in provider factory with private IP blocking, DNS rebinding mitigation, and safe fetch (Fixes #420) - Cloud provider consent management with DB schema, API route, repository, and UI dialog integration in both chat views (Fixes #462) - MCP token drive scope enforcement across chat, messages, and tasks routes with proper 403 responses for out-of-scope requests (Fixes #417) - userId pseudonymization (Fixes #464): verified as false positive — experimental_context never leaves the Node.js process in AI SDK v5.0.54 172 tests passing across all security modules. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Warning Rate limit exceeded
⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ✨ Finishing touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
Both PRs generated migrations from the same parent snapshot (0077), creating a fork. Re-chain 0079 as child of 0078 and fix journal timestamp ordering. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Summary
Security hardening for AI provider infrastructure, addressing four security issues:
ai_provider_consents), API route (/api/ai/consent), repository layer, and UI dialog integrated into both AiChatView and GlobalAssistantView/api/ai/chat,/api/ai/chat/messages, and/api/tasksroutes with proper 403 responsesexperimental_contextnever leaves Node.js process in AI SDK v5.0.54 (documented in SWARM-TRACKER)Fixes #420, Fixes #462, Fixes #417, Fixes #464
Changes
SSRF Validation (
packages/lib/src/security/)url-validator.ts:validateLocalProviderURL(),validateExternalURL(),isBlockedIP(),safeFetch()with DNS rebinding protectionConsent Management
packages/db/src/schema/ai.ts:aiProviderConsentstable with unique constraint and cascade deleteapps/web/src/lib/repositories/ai-consent-repository.ts:hasConsent(),grantConsent(),revokeConsent(),getConsents()apps/web/src/app/api/ai/consent/route.ts: GET/POST/DELETE with CSRF and authapps/web/src/components/ai/consent/CloudProviderConsentDialog.tsx: AlertDialog with privacy linksapps/web/src/lib/ai/core/provider-factory.ts: Consent check before provider creation (exempt: pagespace, ollama, lmstudio)apps/web/src/lib/ai/core/ai-providers-config.ts:CONSENT_EXEMPT_PROVIDERS,requiresConsent()MCP Scope Enforcement
apps/web/src/app/api/ai/chat/messages/route.ts:checkMCPPageScope()guardapps/web/src/app/api/ai/chat/route.ts:checkMCPPageScope()guardapps/web/src/app/api/tasks/route.ts:checkMCPDriveScope()+filterDrivesByMCPScope()guardsTest plan
pnpm typecheck— all packages passpnpm build— production build succeedspnpm db:migrateto apply consent table migration🤖 Generated with Claude Code