Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

AI Bridge Proxy: authenticate tunneled traffic

オープン
#1,352 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

この issue はまだ評価されていません。

説明

must-do

Problem

AI Bridge Proxy does not perform any authentication on tunneled traffic. This applies to:

  • Non-allowlisted HTTPS CONNECT requests: tunneled via tunneledMiddleware without any credential check
  • Plain HTTP proxy requests: forwarded without any credential check (related to bug https://github.com/coder/internal/issues/1351)

For allowlisted domains (AI providers), the proxy extracts the Coder session token from Proxy-Authorization and forwards it to AI Bridge, which validates it. However, for tunneled traffic there is no AI Bridge in the path, so no authentication happens at all.

This means anyone who can reach the proxy can tunnel traffic through it to any non-allowlisted destination without credentials. This is a known limitation documented in Security Considerations.

Proposal

Validate authentication for all tunneled traffic before forwarding. The proxy should check the Proxy-Authorization header on both non-allowlisted CONNECT requests and plain HTTP proxy requests.

Open Questions

The proxy currently does not validate tokens itself, for allowlisted domains, it passes the token to AI Bridge which validates it against Coder. For tunneled traffic there is no AI Bridge in the path, so the proxy would need to validate the token directly.

Options:
  • Check header exists only: verify that Proxy-Authorization is present but don't validate the token. Simple but weak, any string would pass.
  • Validate against Coder API: make a request to Coder to verify the token. Correct but expensive, every tunneled request would hit the Coder API.
  • Validate with caching: validate the token against Coder API on first use and cache the result for a period. Balances correctness with performance.
主要言語
言語のデータがありません
スター
3
フォーク
0
PR マージ指標
30日以内にマージされた PR はありません

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

coder/internal のほかの issue

coder/internal の issue をすべて見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。