fix(auth): protect root /responses rewrite
Add /responses to PUBLIC_PREFIXES in dashboardGuard so pre-rewrite remote requests require API key validation as intended.
This commit is contained in:
@@ -34,7 +34,8 @@ const PUBLIC_API_PATHS = [
|
|||||||
];
|
];
|
||||||
|
|
||||||
// Public top-level prefixes (LLM API endpoints with their own API key auth).
|
// Public top-level prefixes (LLM API endpoints with their own API key auth).
|
||||||
const PUBLIC_PREFIXES = ["/v1", "/v1beta", "/api/v1", "/api/v1beta", "/codex"];
|
// Keep root-level rewrites here too: middleware runs before Next.js rewrites.
|
||||||
|
const PUBLIC_PREFIXES = ["/v1", "/v1beta", "/api/v1", "/api/v1beta", "/codex", "/responses"];
|
||||||
|
|
||||||
// Always require JWT token regardless of requireLogin setting
|
// Always require JWT token regardless of requireLogin setting
|
||||||
const ALWAYS_PROTECTED = [
|
const ALWAYS_PROTECTED = [
|
||||||
|
|||||||
@@ -125,6 +125,25 @@ describe("dashboard guard public LLM API access", () => {
|
|||||||
expect(response.body.error).toBe("API key required for remote API access");
|
expect(response.body.error).toBe("API key required for remote API access");
|
||||||
});
|
});
|
||||||
|
|
||||||
|
it("rejects remote /responses rewrite without API key", async () => {
|
||||||
|
const response = await proxy(request("/responses", { host: "router.example.com" }));
|
||||||
|
|
||||||
|
expect(response.status).toBe(401);
|
||||||
|
expect(response.body.error).toBe("API key required for remote API access");
|
||||||
|
});
|
||||||
|
|
||||||
|
it("allows remote /responses rewrite with a valid API key", async () => {
|
||||||
|
mocks.validateApiKey.mockResolvedValue(true);
|
||||||
|
|
||||||
|
const response = await proxy(request("/responses", {
|
||||||
|
host: "router.example.com",
|
||||||
|
authorization: "Bearer sk-valid",
|
||||||
|
}));
|
||||||
|
|
||||||
|
expect(response).toBe(mocks.nextResponse);
|
||||||
|
expect(mocks.validateApiKey).toHaveBeenCalledWith("sk-valid");
|
||||||
|
});
|
||||||
|
|
||||||
it("allows remote codex rewrite with valid API key", async () => {
|
it("allows remote codex rewrite with valid API key", async () => {
|
||||||
mocks.validateApiKey.mockResolvedValue(true);
|
mocks.validateApiKey.mockResolvedValue(true);
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user