fix: reject malformed API inputs - #41
Conversation
There was a problem hiding this comment.
🟡 Changes recommended
The current Content-Length oversize path delays the 413 until request end, enabling slow/huge uploads to tie up capacity and conflicting with the intended behavior of promptly returning a 413.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
This PR tightens OpenWire’s HTTP API validation to fail closed on malformed inputs (messages/content parts/tool calls/response_format), adds stricter image input validation, and improves request-body limit handling so oversized uploads return consistent JSON errors.
Changes:
- Enforce stricter request-shape validation for chat messages, content parts, tool calls, and
response_format. - Add image data URI validation (MIME required, canonical base64, signature match, decoded size cap).
- Add tests for malformed inputs and oversized request bodies; clamp numeric config values and document bounds.
File summaries
| File | Description |
|---|---|
| src/test/gateway.test.ts | Adds coverage for JSON 413 responses and slow chunked oversized uploads, plus malformed message cases. |
| src/server/gateway.ts | Adjusts 413 error handling and request-body reading logic to support safer oversized upload handling. |
| src/server/config.ts | Introduces bounded integer normalization for numeric config values. |
| src/server/config.test.ts | Adds tests verifying numeric config clamping behavior. |
| src/routes/json-mode.ts | Tightens response_format parsing by requiring an explicit type when provided. |
| src/routes/json-mode.test.ts | Adds test ensuring missing response_format.type is rejected. |
| src/routes/content.ts | Strengthens content/message validation and enforces strict image data URI validation (type/base64/signature/size). |
| src/routes/content.test.ts | Updates/extends tests for stricter content/message/tool-call and image validation behavior. |
| README.md | Updates documentation to reflect stricter validation rules, limits, and image validation guarantees. |
| package.json | Updates VS Code settings schema to bounded integer types and min/max constraints. |
Review details
- Files reviewed: 10/10 changed files
- Comments generated: 2
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Addressed both review findings in e4bda29:
Added regressions for normal oversized bodies, incomplete declared 100 MiB uploads, and unterminated chunked uploads. All 239 tests pass. |
Pre-merge checks · ✅ 2 · ⚠ 0 · ❌ 0 · ⏭ 1
|
Pre-merge checks · ✅ 2 · ⚠ 0 · ❌ 0 · ⏭ 1
|
WalkthroughThis PR tightens input validation across the API gateway. Malformed messages, content parts, image payloads and response formats now return 400 errors instead of being silently normalised. Image data URIs are validated for MIME type, canonical base64, magic-byte signatures and decoded size. Oversized request bodies produce reliable JSON 413 responses with safe connection teardown, and integer configuration values are bounded and clamped. Changes
🎯 Effort: 3 (Moderate) · ⏱ ~30 minutes Generated by Sebastion Code Security · docs |
There was a problem hiding this comment.
🔒 Sebastion Code Security review
1 finding on this PR.
Sources: 1 LLM
Inline comments are posted on changed lines below.
Other findings (in scanned files but outside this diff)
- HIGH
hardcoded-secret· CWE-798 —package.json:95— The default API key is a well-known static string "change-me-openwire-key". Users who do not change it are exposed to unauthenticated access from any local process. An attacker on the same machine can use this predictable token to invoke any language model the user has access to.
Fix: Remove the default value or generate a random key on first activation and store it in VS Code's SecretStorage. At minimum, refuse to start the server when the key is still the default placeholder.
Findings also visible in Security tab.
Audited by Sebastion Code Security · docs · install on more repos
Prompt for all review comments with AI agents
In package.json:
- Line 95: In
package.jsonat line95, the default API key is a well-known static string "change-me-openwire-key". Users who do not change it are exposed to unauthenticated access from any local process. An attacker on the same machine can use this predictable token to invoke any language model the user has access to. Fix: Remove the default value or generate a random key on first activation and store it in VS Code's SecretStorage. At minimum, refuse to start the server when the key is still the default placeholder. Context: rulehardcoded-secretand CWECWE-798.
🔧 Autofix (action required)
Sebastion Code Security couldn't open a draft autofix PR because the installed GitHub App is missing Contents: Read and write. A repository owner must approve the pending permission at https://github.com/settings/installations, then push another commit to retry. This permission only lets Sebastion create fix branches and draft PRs; Sebastion cannot approve or merge them.
There was a problem hiding this comment.
🔒 Sebastion Code Security review
1 finding on this PR.
Sources: 1 LLM
Inline comments are posted on changed lines below.
Other findings (in scanned files but outside this diff)
- HIGH
hardcoded-secret· CWE-798 —package.json:95— The default API key is a well-known static string "change-me-openwire-key". Users who do not change this value are exposed to unauthorized access from any local process. An attacker on the same machine can call the API with this predictable token.
Fix: Remove the default value or generate a random key on first activation and store it in VS Code's SecretStorage. At minimum, refuse to start with the default key and force the user to set one.
Findings also visible in Security tab.
Audited by Sebastion Code Security · docs · install on more repos
Prompt for all review comments with AI agents
In package.json:
- Line 95: In
package.jsonat line95, the default API key is a well-known static string "change-me-openwire-key". Users who do not change this value are exposed to unauthorized access from any local process. An attacker on the same machine can call the API with this predictable token. Fix: Remove the default value or generate a random key on first activation and store it in VS Code's SecretStorage. At minimum, refuse to start with the default key and force the user to set one. Context: rulehardcoded-secretand CWECWE-798.
🔧 Autofix (action required)
Sebastion Code Security couldn't open a draft autofix PR because the installed GitHub App is missing Contents: Read and write. A repository owner must approve the pending permission at https://github.com/settings/installations, then push another commit to retry. This permission only lets Sebastion create fix branches and draft PRs; Sebastion cannot approve or merge them.
Summary
Verification
npm run test— 238 passednpm run lintnpm run buildnpm run packagenpm audit --omit=dev— 0 vulnerabilities