A security release. Server-side requests to provider URLs that a caller can choose now connect only to the addresses that passed validation and refuse redirects, and error responses no longer carry provider response bodies or connection details. Read Behavior Changes before upgrading.
Security
- Provider connections: when a provider is not configured on the server, the settings UI can supply its own base URL, endpoint or model. Several routes validated such a URL once and then connected with a transport that resolved DNS again or followed redirects: PDF parsing and connectivity checks, the Azure voice list, model listing, image and video providers, and LLM calls. Some of these routes also echoed provider response bodies or connection errors back to the caller. This allowed requests to internal addresses and probing of internal services. These requests now go through the strict provider transport, which pins every connection to validated addresses and refuses redirects. IP-literal hosts and the built-in default URLs of unmanaged providers are held to the same policy. Caller-facing errors are fixed text. Client-supplied AliDocMind endpoints must be official hosts. GHSA-g87c-cm4q-cw5x #1704
- Classroom media generation downloads provider-returned image and video URLs through the strict provider transport: HTTPS public addresses only,
data:URLs decoded locally, and size bounded while streaming #1692 (by @Yi-111-a). Agent-runtime image and video tools now do the same #1704.
Behavior Changes
- A caller-supplied LLM, image/video, model-list, PDF-check or self-hosted MinerU base URL that answers with a redirect is refused instead of followed. Configure the final URL.
- A caller-supplied provider base URL containing a query string or fragment is refused.
- A caller-chosen loopback or private address, including an IP literal or an unmanaged provider's built-in
localhostdefault (Ollama, Lemonade, VoxCPM), needsALLOW_LOCAL_NETWORKS. Configure the provider on the server to keep it operator-managed. - Server-configured providers (LLM, image/video, TTS/ASR, MinerU, MinerU Cloud) may use local network addresses without
ALLOW_LOCAL_NETWORKS. Cloud metadata and reserved ranges stay blocked, and redirects from them followALLOW_LOCAL_NETWORKS. - A client-supplied AliDocMind endpoint must be an official
docmind-api.<region>.aliyuncs.comhost over HTTPS; other endpoints answer403 INVALID_URL. Server-configured endpoints are unchanged. - Provider check and generation errors are fixed messages without the provider's response text or connection errors:
/api/verify-pdf-providersuccess no longer includesstatus;/api/azure-voicesanswers provider failures with502;/api/provider/probe-modelsreports other HTTP failures as502with the status class only;- LLM errors for a client-selected endpoint read
Cannot connect to API: connection failed(orrequest timed out,redirects are not allowed) or the HTTP reason phrase; - MinerU Cloud errors report the HTTP status or numeric code.
- Agent-runtime video and poster downloads require HTTPS.
- Pinned provider requests connect directly and do not use Node's environment proxy (
NODE_USE_ENV_PROXYwithHTTP_PROXY/HTTPS_PROXY). - A provider id that names an inherited object property (such as
constructor) is no longer treated as server-configured.