Repository navigation
fix(ai): restrict Ollama egress to operator-approved origins - #367
Merged
Merged
Conversation
Tenant-supplied Ollama base_urls could reach internal services (SSRF). Egress is now limited to AI_PROVIDER_APPROVED_ORIGINS; non-private origins connect via a transport pinned to the validated public address, with redirects disabled. Settings routes reject unapproved base_urls and expose the approved list, which the frontend offers as an endpoint picker. Malformed approved-origin config now fails at startup, and the Ollama adapter reuses one pooled HTTP client per egress mode instead of leaking a new client per request. Also adds unrelated OpenSpec proposals (site assistant, public site content). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
base_urls could reach internal services (SSRF). Egress is now limited toAI_PROVIDER_APPROVED_ORIGINS, enforced both when a key is saved (422) and when the model resolves (ai_egress_denied). Redirects are disabled.allow_privateconnect through a transport pinned to the validated public IP (covers CGNAT, link-local, ULA and IPv4-mapped addresses, and DNS rebinding), while keeping Host/SNI. The frontend swaps the free-text URL field for a picker of approved endpoints.Also included: this branch carries group 2's implementation (tasks 2.1–2.3, #363), plus four unrelated OpenSpec proposals (site-assistant ×3, public-site-content).
Behaviour change: existing Ollama keys whose origin isn't on the approved list stop resolving. That is intended (fail closed). Set
AI_PROVIDER_APPROVED_ORIGINSin each environment, prod included, before deploying.Test plan
pytest services/aipasses (193 tests)flake8 --max-line-length=100passes on the changed AI filesbase_urlorigins, to decide what to approve before mergingdev.shmode and Docker local modenpm test/npm run lint🤖 Generated with Claude Code
Closes #362