You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix(provider-utils): scope download credentials and pin per-URL, not per-config
Two trust-boundary gaps in the SSRF guard, both reachable:
1. The first request sent caller headers (which may carry the provider
API key) to whatever public host the response body named; cross-origin
clearing only ran after a redirect. Now credentials are sent only when
the target is on the configured base_url's origin or a same-scheme
sibling under its parent domain (api.us1.bfl.ai for api.bfl.ai), gated
before the first request and derived from config, never the response.
2. proxy_in_use() was a global boolean, so a request that a proxy would
actually send DIRECT (NO_PROXY match, or HTTP-only proxy for an HTTPS
URL) skipped DNS pinning and reopened the rebinding hole. The pinned
client now applies the proxy config and lets reqwest decide per URL:
proxied requests are resolved by that trusted transport, direct ones
stay pinned to the validated addresses.
Also allow clippy 1.98's chunks_exact_to_as_chunks in hash.rs and
openai/embedding.rs, and result_large_err in ws.rs (suggested APIs
exceed the 1.85 MSRV / boxing an immediately-consumed internal error).
0 commit comments