Skip to content

PRDCT-547: harden the Ask Kai proxy (timeout, CORS allowlist, message cap) - #1099

Open
Iamfle4ka wants to merge 1 commit into
mainfrom
PRDCT-547-chat-proxy-hardening
Open

Iamfle4ka wants to merge 1 commit into
mainfrom
PRDCT-547-chat-proxy-hardening

Conversation

@Iamfle4ka

Copy link
Copy Markdown
Collaborator

Re-cut of #1011 (closed 2026-08-19 under the stale-draft mandate) onto current main — the gap it fixes is still live: api/chat.ts serves access-control-allow-origin: * on a proxy that runs a shared Storage token, so any page on the internet can script it and burn AI quota.

What changes:

  • CORS allowlist instead of * — the origin is echoed back only for help.keboola.com, *.vercel.app previews, and localhost; everything else gets no CORS header. vary: origin set accordingly.
  • 2,000-character message cap — oversized payloads get a 400 before anything reaches the AI service.
  • Real request timeout — the retry loop passes AbortSignal.timeout(remainingBudget) into the upstream fetch, so one hung connection can't blow past the 15s budget.
  • Generic client-facing errors — internals are logged server-side (console.error), the client sees a generic message instead of raw error text.

Single cherry-pick of the reviewed commit from the kept fix/chat-proxy-hardening branch; applied cleanly, tsc --noEmit passes. Per the connection-docs bot profile, api/chat.ts correctly escalates to a human reviewer.

🤖 Generated with Claude Code

- enforce the 15s budget on the in-flight fetch (AbortSignal.timeout per
  attempt) — a hung upstream connection no longer blocks past the budget
- CORS: echo only trusted origins (help.keboola.com, *.vercel.app previews,
  localhost) instead of wildcard — foreign pages can't script the proxy
- cap message length (2000 chars) to protect the shared AI quota
- return a generic error to the client; log the real one server-side

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Aug 26, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
connection-docs Ready Ready Preview Aug 26, 2026 4:12pm

Request Review

@linear-code

linear-code Bot commented Aug 26, 2026

Copy link
Copy Markdown

PRDCT-547

@Iamfle4ka Iamfle4ka added the site-tooling Touches build config, CI, scripts or runtime code — the reviewer bot always routes these to a human label Sep 23, 2026
@Iamfle4ka

Copy link
Copy Markdown
Collaborator Author

@keboola-pr-reviewer review

@keboola-pr-reviewer-bot keboola-pr-reviewer-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: needs_human (risk 4/5) · profile connection-docs

Escalating to a human because this PR modifies the Ask Kai chat proxy (api/chat.ts), which policy lists under "Always needs human — escalate no matter how small." Policy's "Always needs human"…

Suggested reviewers: @keboola/docs

This branch was successfully deployed

1 active deployment
Preview — ead653f4 Deployed Aug 26, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

agent-needs-human agent-profile:connection-docs site-tooling Touches build config, CI, scripts or runtime code — the reviewer bot always routes these to a human

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants