Skip to content

v0.31.8

Choose a tag to compare

@github-actions github-actions released this 06 Oct 21:54
28609ec

Security

A default self-hosted install was not affected by this one. It matters if you run this code for more than one organization behind a console that is not in self-hosted mode. Upgrade in that case.

  • A few service-only routes could be reached through a multi-tenant console without a valid sign-in. Thirteen routes are meant for services that hold the server's internal key: reading and writing an organization's provider connections and routing, and the /internal/ routes. Holding the key was all they asked. A console that is not in self-hosted mode adds that key to any request that carries a sign-in token, before the token is checked, so a request with a made-up token could reach these routes and point another organization's model connection at an address of the caller's choosing. These routes now refuse any request that arrives with a sign-in token or an API key: a service calls them with the internal key and nothing else. The console no longer forwards the /internal/ routes at all outside a self-hosted box.

    On a self-hosted box nothing changes for you: the signed-in operator still reaches these routes from the console, and an API key never could.

Checked

At the server itself, on 0.31.7 and on this release's candidate:

Request 0.31.7 0.31.8
The internal key and nothing else (a service) answered answered
The internal key beside a made-up token, on the connections route the route ran refused
The same, on an /internal/ route answered refused
No key, or a wrong key refused refused

Through the console of a self-hosted candidate: an API key on an internal route is refused, the signed-in operator is answered, every page loads, Claude Code tasks complete and all plugin checks pass on Claude Code, Codex and Pi. The console's own refusal to forward /internal/ routes applies outside self-hosted mode and was checked by a test that reads the code, not by a live multi-tenant run.

Reported privately by @aeonframework, found by @aaronjmars with Aeon (GHSA-p6cq-54cg-8mpv), and by @Tike00 (GHSA-4386-3vpq-3xhx). Thank you.

docker run -d -p 3000:3000 -v hr-data:/data harnessrouter/harnessrouter:0.31.8

Full Changelog: v0.31.7...v0.31.8