mirror of
https://github.com/THU-MAIC/OpenMAIC.git
synced 2026-10-03 09:48:24 +08:00
Audio provider requests (TTS, ASR, voice registration and voice cloning) validated a client-supplied base URL once and then issued a plain fetch with default redirect-follow and no pinned dispatcher. A base URL that resolved to a public address but answered with a redirect to an internal one was followed, and a DNS answer that changed between the guard's lookup and the connect reached an internal host — both readable in-band. - Route every lib/audio provider request through a new lib/server/audio-provider-fetch.ts that combines per-hop redirect re-validation with a pinned undici dispatcher, so the socket can only reach an address the guard validated, on every hop. - Select the public-vs-local policy server-side from isServerConfiguredProvider; a client-supplied base URL is always strict public and can never reach a private, loopback or cloud-metadata address, even with ALLOW_LOCAL_NETWORKS set. - Pin the result-audio download hop as well, keeping its host allowlist and redirect:'error'. - Add a coverage-matrix test that fails if any lib/audio module regains a raw provider fetch. Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>