mirror of
https://github.com/THU-MAIC/OpenMAIC.git
synced 2026-10-02 01:15:18 +08:00
* fix(pdf): pin verify-pdf-provider probes to the strict provider transport The MinerU Cloud and self-hosted connectivity probes validated a caller-supplied base URL once and then issued a plain fetch that resolved DNS again, so a rebinding hostname could pass validation and connect to a loopback or private address. The response also echoed the target's status, its 401/403 body, and per-errno connection errors. Both probes now go through providerFetch with reject-redirects and the operator address policy (the same ALLOW_LOCAL_NETWORKS policy the route already validates against), so the connect address is pinned to the vetted DNS answers. A 3xx still maps to REDIRECT_NOT_ALLOWED. Authentication failures return a fixed message, every other connection failure returns a single generic message, and the success payload no longer includes the target status. Details are logged server-side only. Tests drive the real route, guard and pinned transport against loopback servers, covering rebinding, auth body suppression, identical refused/not-found/timeout answers, redirect refusal and the managed path. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(pdf): pin self-hosted MinerU parsing to the strict provider transport Self-hosted MinerU parsing validated a caller-supplied base URL once and then posted the document with a plain fetch that re-resolved DNS and followed redirects, so a public host could hand the upload (and API key) to a loopback or private address. The /file_parse request now goes through providerFetch under the operator address policy with redirects refused. Transport failures, policy blocks and redirects collapse into one fixed message; an unknown error status is reported without its body (the missing-dependency classification stays), a non-JSON body no longer surfaces the parser's input snippet, and the empty-result error no longer lists response keys. MinerU Cloud control plane, upload and ZIP errors likewise stop quoting raw response bodies. Tests drive the real parse route and pinned transport against loopback servers: rebinding, redirect refusal, body suppression, the multipart upload shape and the managed path. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(tts): pin the Azure voice list request to the strict provider transport The voice list request validated the caller-supplied base URL once and then fetched it with a plain fetch that resolved DNS again. It also mirrored the target's HTTP status as the route's own status and returned the full error body, plus any JSON the target answered on success. The request now goes through providerFetch under the operator address policy with redirects refused and a 20s deadline. Non-2xx answers return a fixed 502 (authentication failures get their own fixed message), only a JSON array is returned as the voice list, and transport failures share one fixed 500 message. Details are logged server-side only. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(providers): pin model-list probing to the strict provider transport Model discovery validated the caller-supplied base URL and models URL once and then issued a plain fetch per candidate, which resolved DNS again. Non-2xx answers carried up to 512 bytes of the provider's body into the route response, and a non-JSON success body surfaced the parser's input snippet. fetchModels now defaults to providerFetch under the operator address policy with redirects refused (a refused hop keeps the REDIRECT_NOT_ALLOWED contract), and accepts an injected transport for tests. Error bodies are never read; the route keeps its 401/404/403 contracts, reports other HTTP failures by status class only, answers a non-JSON list and every transport failure with fixed messages, and returns 400 for a malformed request body. The rejected-redirect detector is shared from the transport module instead of being copied per caller. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(media): run image/video provider requests on the strict provider transport The image and video routes validated a caller-supplied provider base URL once, then every adapter issued plain fetch calls that resolved DNS again. Adapter errors carried full non-2xx bodies into the route responses, the auth-only probes returned the 401/403 body, and connectivity failures echoed the transport error text. Adapters now take a `fetchImpl` from their config and use it for every provider request (submit, poll, download and connectivity probe). The adapters are also imported by the settings UI, so they cannot import the server transport; every server caller (the four routes, classroom media generation and the agent runtime tools) injects mediaProviderFetch, which is providerFetch under the operator address policy with redirects refused. Connectivity results are fixed text: authentication failures, redirects, other HTTP statuses and transport failures each have one message, and no provider body is read. The generation routes log the adapter error and answer a fixed message, keeping the content-safety classification. A malformed Kling key is still reported before any request. The rejected-redirect detector moves to a dependency-free module so the browser-bundled probe helper can share it with the server transport. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(llm): pin LLM calls to a client-supplied base URL resolveModel validated a client-supplied base URL once and then handed the AI SDK a redirect-validating fetch whose only dispatcher was the timeout-only agent, so connect-time DNS was resolved again without the guard. verify-model also echoed the provider's error message (which can carry its response body) and distinguished errno classes. A client-supplied base URL now gets providerFetch under the operator address policy with redirects refused. The pinned dispatcher accepts headers/body timeouts, and this path uses the same 15-minute budget as the default LLM dispatcher; the transport's body normalization and streaming are unchanged. Operator-configured endpoints keep the existing redirect-validating transport. verify-model now classifies failures by the provider's HTTP status only (401/403, 404, 429, other status class) and answers every transport or parse failure with one fixed message. Tests stream a real SSE chat completion through the pinned path and check that deltas arrive before the server finishes, plus rebinding, redirect refusal and the managed path. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(pdf): accept only official AliDocMind endpoints from clients AliDocMind requests go through the vendor SDK, which builds its own HTTPS agent and resolves the endpoint itself, so a client-supplied endpoint that passed the URL guard could not be pinned to the validated address. The credential check also returned the SDK's error code and message, which told a refused port from a TLS failure or a timeout. When the provider is not server-managed, verify-pdf-provider, parse-pdf and extract-document (document and media paths) now accept a client endpoint only when it is an official docmind-api.<region>.aliyuncs.com host over https with no port, path or credentials, and answer INVALID_URL before any SDK call otherwise. The accepted endpoint is passed on as the normalized host. Server-managed endpoints are unchanged. Credential verification failures now return fixed messages and log the SDK detail. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(agent-runtime): download provider result URLs under the strict public policy The agent-runtime image and video tools downloaded the URL a provider returned with a plain fetch, validating each redirect hop with the operator policy but connecting without pinning, and accepting http. A data: URL from an adapter that inlines its result (the OpenRouter video adapter) was rejected instead of decoded. The classroom download helper's policy is extracted into fetchProviderResultUrl: data: URLs are decoded locally, anything else must be https and pass the strict public policy (allowLocalNetworks false, regardless of ALLOW_LOCAL_NETWORKS), and the request goes through providerFetch, which re-validates redirect hops under the same policy and pins connect-time DNS. The agent-runtime tools and the classroom helper share it; the existing bounded reads and content-type checks are unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(changelog): note pinned provider transports and body-free provider errors Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(providers): keep vendor endpoint rules out of provider-neutral modules The provider-neutrality guard keeps vendor knowledge out of the capability routes and model resolution. The AliDocMind endpoint rule now sits behind provider-neutral helpers (checkClientDocumentExtractorBaseUrl and checkClientMediaExtractorBaseUrl), which apply the official-endpoint rule to extractors whose SDK cannot be pinned and the URL guard to the rest. The pinned LLM transport policy moves out of resolve-model into its own module. Behavior is unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(providers): hold IP-literal request hosts to the transport address policy The pinned dispatcher judges hostnames in its connect-time lookup, but Node never runs that lookup for an IP-literal host, so a request to a loopback or private IP reached it without the local-network opt-in. The provider transport now checks an IP-literal origin against the same policy before connecting, so it enforces the policy on its own rather than relying on every caller to validate the URL first. Tests that reached loopback IP literals without the opt-in now set it, as a self-hosted deployment would; cloud metadata stays refused under every policy. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(providers): let operator-configured local providers connect without the opt-in Image/video providers and self-hosted MinerU moved to the pinned transport under the operator address policy for every base URL, so a server-managed endpoint on a local network (for example a local Lemonade image server or a MinerU container) stopped working unless ALLOW_LOCAL_NETWORKS was set. A server-managed base URL is operator configuration: it now runs with local networks allowed, still pinned and still refusing redirects, while cloud metadata and reserved ranges stay refused. Caller-supplied base URLs keep the operator policy. Media routes pick the transport by the provider's managed flag; server-internal media generation uses the managed transport; document extraction carries a `managed` flag to the MinerU parsers and the PDF verification probe. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(llm): pin every caller-chosen endpoint and keep transport detail out of errors An unmanaged provider picked by the caller without a base URL fell back to its catalog default (for example a localhost Ollama or Lemonade endpoint) on the operator transport, which neither validated nor pinned the origin. The pinned client transport is now chosen whenever the caller picked the model or sent a base URL, and the effective endpoint (client URL or catalog default) is validated under the operator policy first. A model the operator selected through MODEL_ROUTES or DEFAULT_MODEL keeps the operator transport. Routes relay LLM error messages, and the AI SDK builds them from the fetch failure cause and from the provider's error body. On the caller-chosen transport a failed request now surfaces a fixed reason ("connection failed", "request timed out" or "redirects are not allowed") with the system error logged server-side, and an HTTP error response reaches the SDK with an empty body and the standard reason phrase, keeping its status and headers for retry and status classification. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(pdf): keep MinerU Cloud envelope text out of errors and refuse query/fragment base URLs MinerU Cloud errors quoted the endpoint's envelope `msg`, a failed row's `err_msg` and the batch id, and the parse routes relay error messages. They now report the context with the HTTP status or, for a rejected request, the numeric code only; the endpoint text is logged server-side. Provider paths are appended to a base URL as text, so a client base URL ending in `?` or `#` (or carrying a query) absorbs the fixed path and leaves the request target to the caller. Client-supplied provider base URLs are now refused when they contain a query string or fragment, across the LLM, media, document extraction, PDF verification, model probe and Azure voice routes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(media): bound provider data: URL results before decoding them `fetchProviderResultUrl` decoded a provider-returned `data:` URL in full and left the size check to the caller's body reader, so an oversized payload was materialized first. Callers now pass their byte limit, and the payload size is estimated from the encoded length (base64: 3/4 less padding; percent-encoded: at least one byte per three characters) and refused over the limit before any buffer is built, then checked exactly after decoding. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(changelog): describe provider transport behavior changes accurately Note which base URLs refuse redirects (MinerU Cloud API roots still follow validated, pinned hops), the query/fragment base URL refusal, IP-literal hosts under the address policy, validation of an unmanaged LLM provider's built-in default, server-configured local providers working without the opt-in, HTTPS for agent-runtime video and poster downloads, pinned requests bypassing the environment proxy, and the fixed LLM and MinerU Cloud error text. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(llm): bound the logged error body and map out-of-range statuses to 502 An error response from a caller-chosen LLM endpoint was read in full only to log 500 characters, and a status of 600-999 (passed through by the transport) made the replacement Response constructor throw. Read at most 1 KB (or 1 s) of the body before cancelling it, and report statuses above 599 as 502. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(pdf): hold MinerU Cloud redirect hops to the operator policy for a managed root A server-managed MinerU Cloud API root runs with local networks allowed, and the same policy applied to every redirect it answered with, so a hop to a private address was followed without ALLOW_LOCAL_NETWORKS. The provider transport now takes a separate address policy for redirect hops (`redirectAllowLocalNetworks`): each hop is validated and pinned on a dispatcher for that policy. A managed MinerU Cloud root keeps local access for itself while its hops use the operator policy. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(providers): match server-configured providers by own keys only Provider ids come from requests and were looked up on plain config objects, so an id such as `constructor` or `toString` read an inherited property and counted as server-configured (and its key, base URL and models resolved from that property). All per-provider config lookups now go through one helper that accepts only the section's own keys. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(audio): let server-configured TTS/ASR endpoints reach local networks Server-configured image/video, MinerU and LLM providers on a local network work without ALLOW_LOCAL_NETWORKS, but a server-configured TTS/ASR or voice-registration endpoint given as a loopback or private IP literal (for example a VoxCPM server at 127.0.0.1:8000) was refused unless the opt-in was set. The routes and the server-side narration, classroom TTS and voice-clone paths now mark server-configured providers as `managed`; their endpoint requests run with local networks allowed, still pinned, with cloud metadata and reserved ranges refused, and redirect hops held to the operator policy. Client-supplied endpoints keep the strict public policy, and an unmanaged provider's catalog default keeps the operator policy. Provider-returned result URLs are unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(changelog): server-configured TTS/ASR local endpoints and config id lookups Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>