fix(core,transports): validate passthrough paths and provider header (#7855) - #7879
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Important Review skippedWe couldn't safely recover the incremental review. No full review was started, and the last reviewed checkpoint was preserved. Retry later, or explicitly request a full review by commenting You can disable this status message by setting the Use the checkbox below for a quick retry:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (15)
Limit details: You’ve used all 8 included reviews currently available. 📝 SummarySummary by CodeRabbit
WalkthroughPassthrough routing now validates path prefixes, decoded paths, and provider selection. Provider adapters use a shared URL builder that validates upstream URLs and reports construction errors before sending requests. ChangesPassthrough URL construction
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~25 minutes Sequence Diagram(s)sequenceDiagram
participant Provider as Provider passthrough
participant Builder as BuildPassthroughURL
participant Upstream as Upstream server
Provider->>Builder: Build URL from base URL, path, and raw query
Builder-->>Provider: Return validated URL or construction error
Provider->>Upstream: Send request when URL construction succeeds
Suggested reviewers: Merge Risk: ⚪ Minimal · up to No actionable risk introduced by this change is established. The passthrough validation changes appear mergeable after normal checks. 🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (3 passed)
Full details: Description checkResolution Replace the template prompts with a concise summary of the passthrough validation changes, list the notable changes and affected areas, describe the tests run and their results, and state any security implications and whether the change is breaking. ✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
7db2d24 to
f610644
Compare
6379405 to
b5ea5d9
Compare
f610644 to
e4e60a4
Compare
b5ea5d9 to
b32d261
Compare
e4e60a4 to
2076722
Compare
b32d261 to
03aab9e
Compare
Merge activity
|
The base branch was changed.
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
2076722 to
9d26243
Compare

Summary
Briefly explain the purpose of this PR and the problem it solves.
Changes
Type of change
Affected areas
How to test
Describe the steps to validate this change. Include commands and expected outcomes.
If adding new configs or environment variables, document them here.
Screenshots/Recordings
If UI changes, add before/after screenshots or short clips.
Breaking changes
If yes, describe impact and migration instructions.
Related issues
Link related issues and discussions. Example: Closes #123
Security considerations
Note any security implications (auth, secrets, PII, sandboxing, etc.).
Checklist
docs/contributing/README.mdand followed the guidelines