fix(codex-proxy): security hardening and edge case fixes

- Fix path traversal in trace() via safe dir validation
- Add RFC 7230 hop-by-hop header filtering
- Fix isRecord() to exclude arrays
- Add req.destroy() on oversized body rejection
- Add missing ANTHROPIC_BASE_URL warning for Codex
- Use cwd() fallback when HOME undefined
- Add 4 edge case unit tests
This commit is contained in:
kaitranntt committed 2026-01-08 09:15:42 -05:00
1 parent 204eea00ce
commit 87cfcc5b3c
3 files changed
+83 -35

No files matched your search

@@ -30,6 +30,16 @@ describe('Codex Reasoning Proxy', () => {
assert.strictEqual(map.get('same'), 'medium');
});
it('returns empty map when all models undefined', () => {
const map = buildCodexModelEffortMap({});
assert.strictEqual(map.size, 0);
});
it('ignores empty string models', () => {
const map = buildCodexModelEffortMap({ defaultModel: '', opusModel: ' ' });
assert.strictEqual(map.size, 0);
});
});
describe('getEffortForModel', () => {
@@ -37,6 +47,11 @@ describe('Codex Reasoning Proxy', () => {
const map = buildCodexModelEffortMap({ opusModel: 'm1' });
assert.strictEqual(getEffortForModel('unknown', map, 'medium'), 'medium');
});
it('handles null model', () => {
const map = buildCodexModelEffortMap({ opusModel: 'm1' });
assert.strictEqual(getEffortForModel(null, map, 'high'), 'high');
});
});
describe('injectReasoningEffortIntoBody', () => {
@@ -51,6 +66,11 @@ describe('Codex Reasoning Proxy', () => {
it('leaves non-object bodies unchanged', () => {
assert.strictEqual(injectReasoningEffortIntoBody('x', 'medium'), 'x');
});
it('leaves array bodies unchanged (not treated as record)', () => {
const arr = [1, 2, 3];
assert.deepStrictEqual(injectReasoningEffortIntoBody(arr, 'high'), arr);
});
});
describe('model suffix aliasing', () => {