Skip to content

fix(server): keep provider credentials on the configured origin - #331

Open
tahodev wants to merge 1 commit into
wordbricks:mainfrom
tahodev:fix/provider-http-origin-boundary
Open

tahodev wants to merge 1 commit into
wordbricks:mainfrom
tahodev:fix/provider-http-origin-boundary

Conversation

@tahodev

@tahodev tahodev commented Sep 25, 2026

Copy link
Copy Markdown

What

Require every provider HTTP endpoint to resolve to the configured API origin before adding credentials or calling fetch. Reject absolute and protocol-relative cross-origin endpoints while preserving same-origin absolute URL support. Add regression tests that assert no fetch occurs for rejected endpoints.

Why

ProviderHttpClient attaches a stored bearer, basic or raw token to every request, yet previously accepted any absolute https:// endpoint or //-relative path. A misconfigured endpoint or untrusted URL could send the provider credential to a different origin. This guard applies to the shared HTTP client rather than relying on each caller to make the same safety check.

Validation

  • bunx vitest run packages/server/src/services/provider-http-client.test.ts packages/server/src/source-api/adapters/github.test.ts (12 passed)
  • bunx turbo typecheck --filter=@onequery/server --json (passed)
  • bunx oxfmt packages/server/src/services/provider-http-client.ts packages/server/src/services/provider-http-client.test.ts and git diff --check (passed)

Local oxlint panicked in its Rust allocator; CI should verify lint.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant