988a3cca9a
Multi-user authorization hardening from a full security evaluation (EVALUATION.md):
- P0: /api/settings/{export,import}-db are now admin-only. Previously any signed-in user could download the whole instance DB (all bcrypt hashes + plaintext AI keys) or replace it wholesale. Per-user CSV export/import stays open.
- AI custom-URL providers (Ollama, OpenAI-compatible) are now admin-only, and every server fetch to a user-supplied URL passes through assertSafeProviderUrl (blocks link-local/cloud-metadata; private LAN allowed by design). Fixed-URL cloud providers stay per-user. Removed the dead legacy /api/ai/config route.
- Dev: fixed broken quick-start (added npm run create-admin; rewrote README; dropped dead CLAUDE_API_KEY) and the export-db 0-byte path resolution (resolveDatabasePath now matches Prisma).
ExVer bumped to 1.1.0:8 (no schema/data migration). Tests 197 pass, build green, tsc clean.
2.4 KiB
2.4 KiB
paths
| paths | ||
|---|---|---|
|
AI subsystem
Scoped guidance for the AI generation subsystem (proof-of-work/lib/ai/** and the
generate/generations route handlers). Whole-repo rules live in AGENTS.md.
Architecture
generate/route.tskicks off a detached background runner (generationRunner.ts) and returns an id; the client attaches via SSE (generations/[id]/stream) and can also poll the row. Navigating away does NOT cancel generation.- System prompt =
systemPromptBase.ts(output contract: JSON-only, libraryexerciseIds only, suggested weights) + the template's coaching prompt +PROGRAM_OUTPUT_SHAPE+ library + optional history block (historyContext.ts). - Multi-config:
AIConfigProfilerows per user;UserPreferences.activeAIConfigIdpoints at the active one and is mirrored into the legacyai*columns for back-compat.
Provider abstraction
- Each provider yields an async iterable of
GenerateChunk(text/usage/done/error); add new ones underlib/ai/providers/and register inindex.ts.openai.tsexports bothopenaiandopenai-compatible, so the four provider files register 5 providers (claude,openai,openai-compatible,gemini,ollama). - Streaming AI uses SSE; partial JSON is recovered with
lib/ai/lenientJson.ts. - Pricing/model menus live in
lib/ai/pricing.ts(PRICES,MODEL_MENU) — keep them paired so every menu model has a price entry (there's a test enforcing this).
SSRF / provider-URL safety
- Any
fetchto a user-supplied provider base URL MUST go throughassertSafeProviderUrl(lib/ai/safeUrl.ts) first — it enforces http(s) and blocks link-local/cloud-metadata (169.254/16, fe80::/10) + unspecified. Private-LAN + loopback are allowed on purpose (reachingollama.startos/LAN gateways is the feature). Currently wired intoproviders/ollama.ts, theopenai-compatiblepath inproviders/openai.ts(NOT the fixedapi.openai.compath), and theai/ollama/modelsprobe. Add the guard to any new user-URL fetch path. - Custom-URL providers (those with
requiresBaseUrl: ollama, openai-compatible) are admin-only —isCustomUrlProvidergatesai/configsPOST +[id]PATCH +ai/test, andai/ollama/modelsis fully admin-only. The Settings UI hides them from non-admins. This is a second defense layer on top of the IP block; keep both when adding routes.