Skip to content

fix(ai): restrict Ollama egress to operator-approved origins - #367

Merged
arutsh merged 1 commit into
mainfrom
AI/fix/Issue-362/provider-ssrf-group1
Sep 30, 2026
Merged

arutsh merged 1 commit into
mainfrom
AI/fix/Issue-362/provider-ssrf-group1

Conversation

@arutsh

@arutsh arutsh commented Sep 30, 2026

Copy link
Copy Markdown
Owner

Summary

  • Tenant-supplied Ollama base_urls could reach internal services (SSRF). Egress is now limited to AI_PROVIDER_APPROVED_ORIGINS, enforced both when a key is saved (422) and when the model resolves (ai_egress_denied). Redirects are disabled.
  • Origins without allow_private connect through a transport pinned to the validated public IP (covers CGNAT, link-local, ULA and IPv4-mapped addresses, and DNS rebinding), while keeping Host/SNI. The frontend swaps the free-text URL field for a picker of approved endpoints.
  • Code-review fixes: a malformed approved-origin config now fails at startup instead of returning a 500 on every request, and the Ollama adapter reuses one pooled client per egress mode instead of leaking a client per request.

Also included: this branch carries group 2's implementation (tasks 2.1–2.3, #363), plus four unrelated OpenSpec proposals (site-assistant ×3, public-site-content).

Behaviour change: existing Ollama keys whose origin isn't on the approved list stop resolving. That is intended (fail closed). Set AI_PROVIDER_APPROVED_ORIGINS in each environment, prod included, before deploying.

Test plan

  • pytest services/ai passes (193 tests)
  • flake8 --max-line-length=100 passes on the changed AI files
  • Task 1.1: prod count of base_url origins, to decide what to approve before merging
  • Task 1.5: save an Ollama config and chat, in both dev.sh mode and Docker local mode
  • Frontend npm test / npm run lint

🤖 Generated with Claude Code

Closes #362

Tenant-supplied Ollama base_urls could reach internal services (SSRF).
Egress is now limited to AI_PROVIDER_APPROVED_ORIGINS; non-private
origins connect via a transport pinned to the validated public address,
with redirects disabled. Settings routes reject unapproved base_urls and
expose the approved list, which the frontend offers as an endpoint picker.

Malformed approved-origin config now fails at startup, and the Ollama
adapter reuses one pooled HTTP client per egress mode instead of leaking
a new client per request.

Also adds unrelated OpenSpec proposals (site assistant, public site content).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Sep 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
grant-flow Ready Ready Preview Sep 30, 2026 1:07pm UTC

@arutsh
arutsh merged commit 5fad140 into main Sep 30, 2026
27 of 29 checks passed

This branch was successfully deployed

1 active deployment
Preview — 928187d6 Deployed Sep 30, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

provider-ssrf: Approved-origin policy at save and use time (group 1)

1 participant