mirror of
https://github.com/DayuanJiang/next-ai-draw-io.git
synced 2026-10-10 19:49:52 +08:00
Chats: - New Chat right after an answer saves that chat once. Saves run one at a time and read the chat on screen when their turn comes; a save scheduled for a chat that is no longer on screen is dropped. A chat whose id was still on its way to the URL no longer comes back after New Chat (the next answer went into it). - Crossing the 768 px breakpoint keeps the chat panel: a streaming answer, unsaved messages and attachments stay. The panel gets the sizes of each side, and a panel collapsed on desktop opens on mobile. - The chat's export waits for its own reply: an edit's history export still on its way no longer answers it with the older diagram, and two file saves at once no longer swap results. - A second edit in one answer is previewed on the first edit's result. - Stop also ends a running screenshot check; a chat that cannot be saved (storage full) can be left with "Continue without saving". - Small diagrams with shapes count as diagrams; the tool card no longer crashes on malformed operations. Quota and providers: - Requests that reach the server's own endpoints count toward the quota: EdgeOne (always its own endpoint now), a private base URL whatever key header is sent, keyless Ollama without a URL. With the quota on, a redirect is followed only to a public address. The output cap applies to these requests too. - Stop records the tokens of the steps that finished; the screenshot check counts its tokens without counting a request. - EdgeOne configured only by AI_PROVIDER works, also in the admin Test, which forwards the access code. Azure set up only in the admin panel works in chat. The Test sends a Bedrock session token. - The admin panel's Test of an entry without a URL uses the server's URL as the server does (no private address check for it); the admin panel no longer writes an Ollama URL. MCP server: - Write tools and start_session run one at a time, so two at once never drop each other's change; a cancelled call waiting its turn is skipped. get_diagram and export_diagram keep the session they started with. - Export to .drawio first gets the user's latest edits from the browser. - History thumbnails: one that arrives after the next AI write is dropped; a sync reply keeps the image; a version that changed only page settings is its own entry. - A diagram over the 10 MB limit is saved without its image, or the user is told to download it (the server now answers 413 instead of cutting the connection). - Labels holding text like id='1' or parent='1' are no longer read as attributes (a layer or a parent was deleted). A broken bare <mxGraphModel> file is refused. - After a sync reply the tab no longer sends its autosave copy again. Desktop and files: - A newer switch of the same preset is not rolled back by an older one that failed. .env values with escaped quotes are read whole. - MCP saved files: a file that could not be read stays protected while a folder without permission hides it, and is saved again once deleted. - The desktop app reports "no chats" only when the count was read and no model settings are stored.
151 lines
5.9 KiB
TypeScript
151 lines
5.9 KiB
TypeScript
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest"
|
|
import { isPrivateUrl, redirectGuardedFetch } from "@/lib/ssrf-protection"
|
|
|
|
// Mock DNS so tests are deterministic and never hit the network.
|
|
const lookupMock = vi.hoisted(() => vi.fn())
|
|
vi.mock("node:dns/promises", () => ({
|
|
default: { lookup: lookupMock },
|
|
lookup: lookupMock,
|
|
}))
|
|
|
|
describe("isPrivateUrl", () => {
|
|
beforeEach(() => {
|
|
lookupMock.mockReset()
|
|
})
|
|
|
|
it("blocks private IPv6 URLs (string-only fast path, no DNS)", async () => {
|
|
expect(await isPrivateUrl("http://[::1]/")).toBe(true)
|
|
expect(await isPrivateUrl("http://[0:0:0:0:0:0:0:1]/")).toBe(true)
|
|
expect(await isPrivateUrl("http://[::]/")).toBe(true)
|
|
expect(await isPrivateUrl("http://[::ffff:127.0.0.1]/")).toBe(true)
|
|
expect(await isPrivateUrl("http://[fc00::1]/")).toBe(true)
|
|
expect(await isPrivateUrl("http://[fd12:3456:789a::1]/")).toBe(true)
|
|
expect(await isPrivateUrl("http://[fe80::1]/")).toBe(true)
|
|
expect(await isPrivateUrl("http://[fe9f::1]/")).toBe(true)
|
|
expect(await isPrivateUrl("http://[febf::1]/")).toBe(true)
|
|
expect(lookupMock).not.toHaveBeenCalled()
|
|
})
|
|
|
|
it("blocks literal private IPv4 without DNS", async () => {
|
|
expect(await isPrivateUrl("http://127.0.0.1/")).toBe(true)
|
|
expect(await isPrivateUrl("http://10.0.0.5/")).toBe(true)
|
|
expect(await isPrivateUrl("http://192.168.1.1/")).toBe(true)
|
|
expect(await isPrivateUrl("http://169.254.169.254/")).toBe(true)
|
|
expect(await isPrivateUrl("http://0.0.0.0/")).toBe(true)
|
|
// 100.64.0.0/10 CGNAT (RFC 6598), routable in some cloud internal nets
|
|
expect(await isPrivateUrl("http://100.64.0.1/")).toBe(true)
|
|
expect(await isPrivateUrl("http://100.127.255.255/")).toBe(true)
|
|
expect(lookupMock).not.toHaveBeenCalled()
|
|
})
|
|
|
|
it("treats CGNAT boundaries correctly", async () => {
|
|
// 100.63.x and 100.128.x are outside 100.64.0.0/10 → public
|
|
lookupMock.mockResolvedValue([{ address: "100.63.255.255", family: 4 }])
|
|
expect(await isPrivateUrl("http://just-below.example/")).toBe(false)
|
|
lookupMock.mockResolvedValue([{ address: "100.128.0.1", family: 4 }])
|
|
expect(await isPrivateUrl("http://just-above.example/")).toBe(false)
|
|
})
|
|
|
|
it("blocks a hostname that resolves to a private IPv6 address", async () => {
|
|
lookupMock.mockResolvedValue([{ address: "fd00::1", family: 6 }])
|
|
expect(await isPrivateUrl("http://v6.example.com/")).toBe(true)
|
|
})
|
|
|
|
it("allows public URLs that resolve to public IPs", async () => {
|
|
lookupMock.mockResolvedValue([{ address: "93.184.216.34", family: 4 }])
|
|
expect(await isPrivateUrl("https://example.com/article")).toBe(false)
|
|
})
|
|
|
|
it("blocks public-looking hostnames that resolve to a private IP (DNS-rebinding-style bypass)", async () => {
|
|
// e.g. 127-0-0-1.sslip.io resolves to 127.0.0.1
|
|
lookupMock.mockResolvedValue([{ address: "127.0.0.1", family: 4 }])
|
|
expect(await isPrivateUrl("http://127-0-0-1.sslip.io/")).toBe(true)
|
|
})
|
|
|
|
it("blocks when any resolved address is private", async () => {
|
|
lookupMock.mockResolvedValue([
|
|
{ address: "93.184.216.34", family: 4 },
|
|
{ address: "10.1.2.3", family: 4 },
|
|
])
|
|
expect(await isPrivateUrl("http://mixed.example.com/")).toBe(true)
|
|
})
|
|
|
|
it("blocks when DNS resolution fails", async () => {
|
|
lookupMock.mockRejectedValue(new Error("ENOTFOUND"))
|
|
expect(await isPrivateUrl("http://does-not-resolve.example/")).toBe(
|
|
true,
|
|
)
|
|
})
|
|
})
|
|
|
|
describe("redirectGuardedFetch with the quota on", () => {
|
|
const answers = (map: Record<string, Response>) =>
|
|
vi.fn(
|
|
async (url: string) =>
|
|
map[String(url)] ?? new Response("?", { status: 404 }),
|
|
)
|
|
|
|
beforeEach(() => {
|
|
lookupMock.mockReset()
|
|
// Hosts ending in .example are public
|
|
lookupMock.mockImplementation(async (host: string) =>
|
|
host.endsWith(".example")
|
|
? [{ address: "93.184.216.34", family: 4 }]
|
|
: [],
|
|
)
|
|
process.env.DYNAMODB_QUOTA_TABLE = "quota"
|
|
delete process.env.ALLOW_PRIVATE_URLS
|
|
})
|
|
|
|
afterEach(() => {
|
|
delete process.env.DYNAMODB_QUOTA_TABLE
|
|
vi.unstubAllGlobals()
|
|
})
|
|
|
|
it("follows a redirect to a public address", async () => {
|
|
// A user's own proxy that moves http to https
|
|
vi.stubGlobal(
|
|
"fetch",
|
|
answers({
|
|
"http://proxy.example/v1/chat": new Response(null, {
|
|
status: 308,
|
|
headers: { location: "https://proxy.example/v1/chat" },
|
|
}),
|
|
"https://proxy.example/v1/chat": new Response("ok"),
|
|
}),
|
|
)
|
|
const guarded = redirectGuardedFetch()
|
|
expect(guarded).toBeDefined()
|
|
const res = await guarded?.("http://proxy.example/v1/chat", {
|
|
method: "POST",
|
|
body: "{}",
|
|
})
|
|
expect(await res?.text()).toBe("ok")
|
|
})
|
|
|
|
it("refuses a redirect to the server's own network", async () => {
|
|
// It would be counted as a public endpoint while using the server's
|
|
vi.stubGlobal(
|
|
"fetch",
|
|
answers({
|
|
"https://public.example/api/chat": new Response(null, {
|
|
status: 307,
|
|
headers: { location: "http://127.0.0.1:11434/api/chat" },
|
|
}),
|
|
}),
|
|
)
|
|
await expect(
|
|
redirectGuardedFetch()?.("https://public.example/api/chat", {
|
|
method: "POST",
|
|
body: "{}",
|
|
}),
|
|
).rejects.toThrow(/private addresses/)
|
|
expect(fetch).toHaveBeenCalledTimes(1)
|
|
})
|
|
|
|
it("is not used without the quota", () => {
|
|
delete process.env.DYNAMODB_QUOTA_TABLE
|
|
expect(redirectGuardedFetch()).toBeUndefined()
|
|
})
|
|
})
|