Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

AI Bridge Proxy: authenticate tunneled traffic

未关闭
#1,352 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

这个 Issue 还没有评估数据。

描述

must-do

Problem

AI Bridge Proxy does not perform any authentication on tunneled traffic. This applies to:

  • Non-allowlisted HTTPS CONNECT requests: tunneled via tunneledMiddleware without any credential check
  • Plain HTTP proxy requests: forwarded without any credential check (related to bug https://github.com/coder/internal/issues/1351)

For allowlisted domains (AI providers), the proxy extracts the Coder session token from Proxy-Authorization and forwards it to AI Bridge, which validates it. However, for tunneled traffic there is no AI Bridge in the path, so no authentication happens at all.

This means anyone who can reach the proxy can tunnel traffic through it to any non-allowlisted destination without credentials. This is a known limitation documented in Security Considerations.

Proposal

Validate authentication for all tunneled traffic before forwarding. The proxy should check the Proxy-Authorization header on both non-allowlisted CONNECT requests and plain HTTP proxy requests.

Open Questions

The proxy currently does not validate tokens itself, for allowlisted domains, it passes the token to AI Bridge which validates it against Coder. For tunneled traffic there is no AI Bridge in the path, so the proxy would need to validate the token directly.

Options:
  • Check header exists only: verify that Proxy-Authorization is present but don't validate the token. Simple but weak, any string would pass.
  • Validate against Coder API: make a request to Coder to verify the token. Correct but expensive, every tunneled request would hit the Coder API.
  • Validate with caching: validate the token against Coder API on first use and cache the result for a period. Balances correctness with performance.
主要语言
没有语言数据
星标
3
派生
0
PR 合并指标
30 天内没有已合并 PR

贡献指南

这个仓库没有索引到贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

coder/internal 的其他 Issue

查看 coder/internal 的全部 Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。