Skip to content

🔑 fix: Require Colon in API-Key Header Detection - #16803

Merged
danny-avila merged 1 commit into
devfrom
fix/api-key-header-detection
Oct 6, 2026
Merged

danny-avila merged 1 commit into
devfrom
fix/api-key-header-detection

Conversation

@dustinhealy

Copy link
Copy Markdown
Collaborator

Pull Request

Summary

The built-in api_key_header detector currently treats the colon after api-key as optional. This makes ordinary prose such as “contains an api-key header” match as though it contained a credential and can cause LibreChat's own content-filter error text to be rejected on a subsequent inspection.

This change requires the literal header delimiter, so api-key: secret remains detected while descriptive prose without a colon is allowed.

How it works

Focused diff:

-pattern: /\b(api-key:?\s+)[^\s"']+/i,
+pattern: /\b(api-key:\s+)[^\s"']+/i,

Type of change

  • Bug fix
  • Tests / tooling / CI

Testing

Added a regression test using the exact false-positive text: Submitted content contains an api-key header. Remove it and try again.

The existing starter-pattern tests continue to confirm that an actual api-key: header is detected.

Tested environments/configuration:

  • Source-aware message filtering
  • api_key_header starter pattern

Automated tests:

  • CI=true npm test --workspace=@librechat/api -- --runInBand --coverage=false src/protection/runtime.spec.ts
  • 48 tests passed
  • node scripts/sort-imports.mts <changed files>
  • node scripts/sort-imports.mts --check <changed files>
  • npx prettier --check <changed files>
  • npx eslint <changed files> --pass-on-unpruned-suppressions

Screenshots / recordings

No visual UI change; this is backend pattern-matching behavior.

Risk / compatibility

The detector now follows HTTP-style header syntax by requiring a colon. Existing api-key: <value> detection remains unchanged.

Checklist

  • I reviewed my own changes
  • Relevant tests have been added or updated
  • Existing relevant tests pass
  • The change does not introduce new warnings or errors
  • User-facing or complex behavior is documented where necessary
  • Required dependency changes have been merged/published
  • Required documentation PR: N/A

Copilot AI balanced review requested due to automatic review settings October 6, 2026 02:23
@dustinhealy

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-06T02:25:13.813373Z c78022a Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused regex correction preserves valid detection and includes appropriate regression coverage.

Review effort: Balanced
Findings: None

What changed in this PR

Requires a colon in api-key header detection, preventing prose from being misclassified as credentials.

Changes:

  • Tightens the api_key_header regex.
  • Adds regression coverage for the reported false positive.
File Description
packages/​api/​src/​protection/​detectors/​pattern.ts Requires the header colon.
packages/​api/​src/​protection/​runtime.spec.ts Tests descriptive prose remains allowed.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Nice work!

Reviewed commit: c78022afca

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@dustinhealy
dustinhealy marked this pull request as ready for review October 6, 2026 02:26
@danny-avila
danny-avila merged commit e1dfc10 into dev Oct 6, 2026
38 checks passed
@danny-avila
danny-avila deleted the fix/api-key-header-detection branch October 6, 2026 11:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants