Files
wyucandClaude Opus 5.5 cd7d6a1a59 fix(providers): pin caller-chosen provider requests and keep upstream detail out of errors (#1704)
* fix(pdf): pin verify-pdf-provider probes to the strict provider transport

The MinerU Cloud and self-hosted connectivity probes validated a
caller-supplied base URL once and then issued a plain fetch that resolved
DNS again, so a rebinding hostname could pass validation and connect to a
loopback or private address. The response also echoed the target's status,
its 401/403 body, and per-errno connection errors.

Both probes now go through providerFetch with reject-redirects and the
operator address policy (the same ALLOW_LOCAL_NETWORKS policy the route
already validates against), so the connect address is pinned to the vetted
DNS answers. A 3xx still maps to REDIRECT_NOT_ALLOWED. Authentication
failures return a fixed message, every other connection failure returns a
single generic message, and the success payload no longer includes the
target status. Details are logged server-side only.

Tests drive the real route, guard and pinned transport against loopback
servers, covering rebinding, auth body suppression, identical
refused/not-found/timeout answers, redirect refusal and the managed path.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(pdf): pin self-hosted MinerU parsing to the strict provider transport

Self-hosted MinerU parsing validated a caller-supplied base URL once and
then posted the document with a plain fetch that re-resolved DNS and
followed redirects, so a public host could hand the upload (and API key)
to a loopback or private address.

The /file_parse request now goes through providerFetch under the operator
address policy with redirects refused. Transport failures, policy blocks
and redirects collapse into one fixed message; an unknown error status is
reported without its body (the missing-dependency classification stays),
a non-JSON body no longer surfaces the parser's input snippet, and the
empty-result error no longer lists response keys. MinerU Cloud control
plane, upload and ZIP errors likewise stop quoting raw response bodies.

Tests drive the real parse route and pinned transport against loopback
servers: rebinding, redirect refusal, body suppression, the multipart
upload shape and the managed path.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(tts): pin the Azure voice list request to the strict provider transport

The voice list request validated the caller-supplied base URL once and then
fetched it with a plain fetch that resolved DNS again. It also mirrored the
target's HTTP status as the route's own status and returned the full error
body, plus any JSON the target answered on success.

The request now goes through providerFetch under the operator address
policy with redirects refused and a 20s deadline. Non-2xx answers return a
fixed 502 (authentication failures get their own fixed message), only a
JSON array is returned as the voice list, and transport failures share one
fixed 500 message. Details are logged server-side only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(providers): pin model-list probing to the strict provider transport

Model discovery validated the caller-supplied base URL and models URL once
and then issued a plain fetch per candidate, which resolved DNS again. Non-2xx
answers carried up to 512 bytes of the provider's body into the route
response, and a non-JSON success body surfaced the parser's input snippet.

fetchModels now defaults to providerFetch under the operator address policy
with redirects refused (a refused hop keeps the REDIRECT_NOT_ALLOWED
contract), and accepts an injected transport for tests. Error bodies are
never read; the route keeps its 401/404/403 contracts, reports other HTTP
failures by status class only, answers a non-JSON list and every transport
failure with fixed messages, and returns 400 for a malformed request body.

The rejected-redirect detector is shared from the transport module instead
of being copied per caller.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(media): run image/video provider requests on the strict provider transport

The image and video routes validated a caller-supplied provider base URL
once, then every adapter issued plain fetch calls that resolved DNS again.
Adapter errors carried full non-2xx bodies into the route responses, the
auth-only probes returned the 401/403 body, and connectivity failures
echoed the transport error text.

Adapters now take a `fetchImpl` from their config and use it for every
provider request (submit, poll, download and connectivity probe). The
adapters are also imported by the settings UI, so they cannot import the
server transport; every server caller (the four routes, classroom media
generation and the agent runtime tools) injects mediaProviderFetch, which
is providerFetch under the operator address policy with redirects refused.

Connectivity results are fixed text: authentication failures, redirects,
other HTTP statuses and transport failures each have one message, and no
provider body is read. The generation routes log the adapter error and
answer a fixed message, keeping the content-safety classification. A
malformed Kling key is still reported before any request.

The rejected-redirect detector moves to a dependency-free module so the
browser-bundled probe helper can share it with the server transport.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(llm): pin LLM calls to a client-supplied base URL

resolveModel validated a client-supplied base URL once and then handed the
AI SDK a redirect-validating fetch whose only dispatcher was the
timeout-only agent, so connect-time DNS was resolved again without the
guard. verify-model also echoed the provider's error message (which can
carry its response body) and distinguished errno classes.

A client-supplied base URL now gets providerFetch under the operator
address policy with redirects refused. The pinned dispatcher accepts
headers/body timeouts, and this path uses the same 15-minute budget as the
default LLM dispatcher; the transport's body normalization and streaming
are unchanged. Operator-configured endpoints keep the existing
redirect-validating transport.

verify-model now classifies failures by the provider's HTTP status only
(401/403, 404, 429, other status class) and answers every transport or
parse failure with one fixed message.

Tests stream a real SSE chat completion through the pinned path and check
that deltas arrive before the server finishes, plus rebinding, redirect
refusal and the managed path.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(pdf): accept only official AliDocMind endpoints from clients

AliDocMind requests go through the vendor SDK, which builds its own HTTPS
agent and resolves the endpoint itself, so a client-supplied endpoint that
passed the URL guard could not be pinned to the validated address. The
credential check also returned the SDK's error code and message, which
told a refused port from a TLS failure or a timeout.

When the provider is not server-managed, verify-pdf-provider, parse-pdf and
extract-document (document and media paths) now accept a client endpoint
only when it is an official docmind-api.<region>.aliyuncs.com host over
https with no port, path or credentials, and answer INVALID_URL before any
SDK call otherwise. The accepted endpoint is passed on as the normalized
host. Server-managed endpoints are unchanged. Credential verification
failures now return fixed messages and log the SDK detail.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(agent-runtime): download provider result URLs under the strict public policy

The agent-runtime image and video tools downloaded the URL a provider
returned with a plain fetch, validating each redirect hop with the operator
policy but connecting without pinning, and accepting http. A data: URL
from an adapter that inlines its result (the OpenRouter video adapter) was
rejected instead of decoded.

The classroom download helper's policy is extracted into
fetchProviderResultUrl: data: URLs are decoded locally, anything else must
be https and pass the strict public policy (allowLocalNetworks false,
regardless of ALLOW_LOCAL_NETWORKS), and the request goes through
providerFetch, which re-validates redirect hops under the same policy and
pins connect-time DNS. The agent-runtime tools and the classroom helper
share it; the existing bounded reads and content-type checks are unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(changelog): note pinned provider transports and body-free provider errors

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(providers): keep vendor endpoint rules out of provider-neutral modules

The provider-neutrality guard keeps vendor knowledge out of the capability
routes and model resolution. The AliDocMind endpoint rule now sits behind
provider-neutral helpers (checkClientDocumentExtractorBaseUrl and
checkClientMediaExtractorBaseUrl), which apply the official-endpoint rule
to extractors whose SDK cannot be pinned and the URL guard to the rest.
The pinned LLM transport policy moves out of resolve-model into its own
module. Behavior is unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(providers): hold IP-literal request hosts to the transport address policy

The pinned dispatcher judges hostnames in its connect-time lookup, but Node
never runs that lookup for an IP-literal host, so a request to a loopback or
private IP reached it without the local-network opt-in. The provider transport
now checks an IP-literal origin against the same policy before connecting,
so it enforces the policy on its own rather than relying on every caller to
validate the URL first.

Tests that reached loopback IP literals without the opt-in now set it, as a
self-hosted deployment would; cloud metadata stays refused under every policy.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(providers): let operator-configured local providers connect without the opt-in

Image/video providers and self-hosted MinerU moved to the pinned transport
under the operator address policy for every base URL, so a server-managed
endpoint on a local network (for example a local Lemonade image server or a
MinerU container) stopped working unless ALLOW_LOCAL_NETWORKS was set.

A server-managed base URL is operator configuration: it now runs with local
networks allowed, still pinned and still refusing redirects, while cloud
metadata and reserved ranges stay refused. Caller-supplied base URLs keep the
operator policy. Media routes pick the transport by the provider's managed
flag; server-internal media generation uses the managed transport; document
extraction carries a `managed` flag to the MinerU parsers and the PDF
verification probe.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(llm): pin every caller-chosen endpoint and keep transport detail out of errors

An unmanaged provider picked by the caller without a base URL fell back to its
catalog default (for example a localhost Ollama or Lemonade endpoint) on the
operator transport, which neither validated nor pinned the origin. The pinned
client transport is now chosen whenever the caller picked the model or sent a
base URL, and the effective endpoint (client URL or catalog default) is
validated under the operator policy first. A model the operator selected
through MODEL_ROUTES or DEFAULT_MODEL keeps the operator transport.

Routes relay LLM error messages, and the AI SDK builds them from the fetch
failure cause and from the provider's error body. On the caller-chosen
transport a failed request now surfaces a fixed reason ("connection failed",
"request timed out" or "redirects are not allowed") with the system error
logged server-side, and an HTTP error response reaches the SDK with an empty
body and the standard reason phrase, keeping its status and headers for retry
and status classification.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(pdf): keep MinerU Cloud envelope text out of errors and refuse query/fragment base URLs

MinerU Cloud errors quoted the endpoint's envelope `msg`, a failed row's
`err_msg` and the batch id, and the parse routes relay error messages. They now
report the context with the HTTP status or, for a rejected request, the numeric
code only; the endpoint text is logged server-side.

Provider paths are appended to a base URL as text, so a client base URL
ending in `?` or `#` (or carrying a query) absorbs the fixed path and leaves
the request target to the caller. Client-supplied provider base URLs are now
refused when they contain a query string or fragment, across the LLM, media,
document extraction, PDF verification, model probe and Azure voice routes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(media): bound provider data: URL results before decoding them

`fetchProviderResultUrl` decoded a provider-returned `data:` URL in full and
left the size check to the caller's body reader, so an oversized payload was
materialized first. Callers now pass their byte limit, and the payload size is
estimated from the encoded length (base64: 3/4 less padding; percent-encoded:
at least one byte per three characters) and refused over the limit before any
buffer is built, then checked exactly after decoding.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(changelog): describe provider transport behavior changes accurately

Note which base URLs refuse redirects (MinerU Cloud API roots still follow
validated, pinned hops), the query/fragment base URL refusal, IP-literal hosts
under the address policy, validation of an unmanaged LLM provider's built-in
default, server-configured local providers working without the opt-in, HTTPS
for agent-runtime video and poster downloads, pinned requests bypassing the
environment proxy, and the fixed LLM and MinerU Cloud error text.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(llm): bound the logged error body and map out-of-range statuses to 502

An error response from a caller-chosen LLM endpoint was read in full only
to log 500 characters, and a status of 600-999 (passed through by the
transport) made the replacement Response constructor throw. Read at most
1 KB (or 1 s) of the body before cancelling it, and report statuses above
599 as 502.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(pdf): hold MinerU Cloud redirect hops to the operator policy for a managed root

A server-managed MinerU Cloud API root runs with local networks allowed,
and the same policy applied to every redirect it answered with, so a hop
to a private address was followed without ALLOW_LOCAL_NETWORKS.

The provider transport now takes a separate address policy for redirect
hops (`redirectAllowLocalNetworks`): each hop is validated and pinned on
a dispatcher for that policy. A managed MinerU Cloud root keeps local
access for itself while its hops use the operator policy.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(providers): match server-configured providers by own keys only

Provider ids come from requests and were looked up on plain config
objects, so an id such as `constructor` or `toString` read an inherited
property and counted as server-configured (and its key, base URL and
models resolved from that property). All per-provider config lookups now
go through one helper that accepts only the section's own keys.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(audio): let server-configured TTS/ASR endpoints reach local networks

Server-configured image/video, MinerU and LLM providers on a local
network work without ALLOW_LOCAL_NETWORKS, but a server-configured
TTS/ASR or voice-registration endpoint given as a loopback or private IP
literal (for example a VoxCPM server at 127.0.0.1:8000) was refused
unless the opt-in was set.

The routes and the server-side narration, classroom TTS and voice-clone
paths now mark server-configured providers as `managed`; their endpoint
requests run with local networks allowed, still pinned, with cloud
metadata and reserved ranges refused, and redirect hops held to the
operator policy. Client-supplied endpoints keep the strict public
policy, and an unmanaged provider's catalog default keeps the operator
policy. Provider-returned result URLs are unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs(changelog): server-configured TTS/ASR local endpoints and config id lookups

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 18:01:22 +08:00
..