Skip to content

fix(core,transports): validate passthrough paths and provider header (#7855) - #7879

Merged
akshaydeo merged 1 commit into
mainfrom
backport/passthrough-routing
Oct 3, 2026
Merged

akshaydeo merged 1 commit into
mainfrom
backport/passthrough-routing

Conversation

@akshaydeo

Copy link
Copy Markdown
Contributor

Summary

Briefly explain the purpose of this PR and the problem it solves.

Changes

  • What was changed and why
  • Any notable design decisions or trade-offs

Type of change

  • Bug fix
  • Feature
  • Refactor
  • Documentation
  • Chore/CI

Affected areas

  • Core (Go)
  • Transports (HTTP)
  • Providers/Integrations
  • Plugins
  • UI (React)
  • Docs

How to test

Describe the steps to validate this change. Include commands and expected outcomes.

# Core/Transports
go version
go test ./...

# UI
cd ui
pnpm i || npm i
pnpm test || npm test
pnpm build || npm run build

If adding new configs or environment variables, document them here.

Screenshots/Recordings

If UI changes, add before/after screenshots or short clips.

Breaking changes

  • Yes
  • No

If yes, describe impact and migration instructions.

Related issues

Link related issues and discussions. Example: Closes #123

Security considerations

Note any security implications (auth, secrets, PII, sandboxing, etc.).

Checklist

  • I read docs/contributing/README.md and followed the guidelines
  • I added/updated tests where appropriate
  • I updated documentation where needed
  • I verified builds succeed (Go and UI)
  • I verified the CI pipeline passes locally if applicable

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Important

Review skipped

We couldn't safely recover the incremental review. No full review was started, and the last reviewed checkpoint was preserved. Retry later, or explicitly request a full review by commenting @coderabbitai full review.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: maximhq/bifrost/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Team
  • Run ID: 1f06a8ad-bf79-4b08-91af-86fa235ef6c1
📥 Commits

Reviewing files that changed from the base of the PR and between 6379405 and 7db2d24.

📒 Files selected for processing (15)
  • core/providers/anthropic/anthropic.go
  • core/providers/azure/azure.go
  • core/providers/gemini/gemini.go
  • core/providers/openai/openai.go
  • core/providers/openai/passthrough_test.go
  • core/providers/runware/passthrough_usage_test.go
  • core/providers/runware/runware.go
  • core/providers/utils/utils.go
  • core/providers/utils/utils_test.go
  • core/providers/vertex/vertex.go
  • tests/e2e/api/collections/provider-harness.json
  • transports/bifrost-http/integrations/passthrough.go
  • transports/bifrost-http/integrations/router.go
  • transports/bifrost-http/integrations/router_test.go
  • transports/bifrost-http/integrations/utils.go

Limit details: You’ve used all 8 included reviews currently available.


📝 Summary

Summary by CodeRabbit

  • Bug Fixes
    • Passthrough requests now handle paths and query strings more consistently across supported providers, including paths that resemble version prefixes.
    • Invalid or unsafe passthrough paths and malformed upstream URLs are rejected before a request is sent.
    • Passthrough routing now matches configured prefixes at segment boundaries, returns clear errors for invalid paths or unrecognized providers, and uses the default provider when no provider is specified.

Walkthrough

Passthrough routing now validates path prefixes, decoded paths, and provider selection. Provider adapters use a shared URL builder that validates upstream URLs and reports construction errors before sending requests.

Changes

Passthrough URL construction

Layer / File(s) Summary
Shared upstream URL construction
core/providers/utils/utils.go, core/providers/utils/utils_test.go
BuildPassthroughURL validates base URLs and paths, appends the raw query separately, and rejects changes to the base URL authority. Tests cover valid joining, encoded characters, user information, and invalid inputs.
HTTP passthrough path and provider validation
transports/bifrost-http/integrations/passthrough.go, transports/bifrost-http/integrations/utils.go, transports/bifrost-http/integrations/router.go, transports/bifrost-http/integrations/router_test.go
The router strips configured prefixes at segment boundaries, validates paths, and resolves the provider before creating the Bifrost context. Tests cover rejected paths and provider values, plus forwarding valid requests with query strings and the configured operator key.
Provider URL construction
core/providers/anthropic/anthropic.go, core/providers/azure/azure.go, core/providers/gemini/gemini.go, core/providers/openai/openai.go, core/providers/openai/passthrough_test.go, core/providers/runware/runware.go, core/providers/runware/passthrough_usage_test.go, core/providers/vertex/vertex.go
Provider passthrough methods use the shared URL builder. Anthropic, Gemini, OpenAI, Runware, and Vertex return bad-request errors when URL construction fails. Runware strips /v1 only when it is a complete path segment.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Provider as Provider passthrough
  participant Builder as BuildPassthroughURL
  participant Upstream as Upstream server
  Provider->>Builder: Build URL from base URL, path, and raw query
  Builder-->>Provider: Return validated URL or construction error
  Provider->>Upstream: Send request when URL construction succeeds
Loading

Suggested reviewers: tejasghatte, r-droid101

Merge Risk: ⚪ Minimal · up to 7db2d

No actionable risk introduced by this change is established. The passthrough validation changes appear mergeable after normal checks.

🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description contains only the unfilled template. It does not explain the purpose, changes, testing, or security considerations. Replace the template prompts with a concise summary of the passthrough validation changes, list the notable changes and affected areas, describe the tests run and their results, and state any security implications and whether the change is …
Docstring Coverage ⚠️ Warning Docstring coverage is 65.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 20 functions across 14 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the main change: validating passthrough paths and provider headers.
Linked Issues check ✅ Passed The only directly linked issue is #123, which is closed. It supplies historical context only. No active linked issue imposes coding requirements.
Out of Scope Changes check ✅ Passed The changes support the PR's passthrough validation purpose. They validate paths and provider headers, centralize upstream URL construction, and add focused tests for routing and URL safety. The strea…
Full details: Description check

Resolution

Replace the template prompts with a concise summary of the passthrough validation changes, list the notable changes and affected areas, describe the tests run and their results, and state any security implications and whether the change is breaking.

✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

coderabbitai[bot]
coderabbitai Bot previously approved these changes Oct 3, 2026
@akshaydeo
akshaydeo force-pushed the backport/passthrough-routing branch from 7db2d24 to f610644 Compare October 3, 2026 06:29
@akshaydeo
akshaydeo force-pushed the backport/auth-config-update branch from 6379405 to b5ea5d9 Compare October 3, 2026 06:29
@akshaydeo
akshaydeo force-pushed the backport/passthrough-routing branch from f610644 to e4e60a4 Compare October 3, 2026 07:10
@akshaydeo
akshaydeo force-pushed the backport/auth-config-update branch from b5ea5d9 to b32d261 Compare October 3, 2026 07:10
@akshaydeo
akshaydeo force-pushed the backport/passthrough-routing branch from e4e60a4 to 2076722 Compare October 3, 2026 08:01
@akshaydeo
akshaydeo force-pushed the backport/auth-config-update branch from b32d261 to 03aab9e Compare October 3, 2026 08:01

akshaydeo commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor Author

Merge activity

  • Oct 3, 8:43 AM UTC: A user started a stack merge that includes this pull request via Graphite.
  • Oct 3, 9:05 AM UTC: Graphite rebased this pull request as part of a merge.
  • Oct 3, 9:07 AM UTC: @akshaydeo merged this pull request with Graphite.

@akshaydeo
akshaydeo changed the base branch from backport/auth-config-update to graphite-base/7879 October 3, 2026 09:01
@akshaydeo
akshaydeo changed the base branch from graphite-base/7879 to main October 3, 2026 09:03
@akshaydeo
akshaydeo dismissed coderabbitai[bot]’s stale review October 3, 2026 09:03

The base branch was changed.

@mintlify

mintlify Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
bifrost 🟢 Ready View Preview Oct 3, 2026, 9:06 AM

💡 Tip: Enable Automations to automatically generate PRs for you.

@akshaydeo
akshaydeo merged commit d4f6c08 into main Oct 3, 2026
14 of 15 checks passed
@akshaydeo
akshaydeo deleted the backport/passthrough-routing branch October 3, 2026 09:07

This branch was successfully deployed

1 active deployment
staging - docs — 9d262434 Deployed Oct 3, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant