fix: temporarily disable requests (#452)

* fix: temporarily disable requests

* cr
This commit is contained in:
Brace Sproul 2025-07-20 19:53:51 -07:00 • committed by GitHub
parent d7cf3e0fb5
commit 9a4b63b798
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -1,24 +1,24 @@
import { Auth, HTTPException } from "@langchain/langgraph-sdk/auth"; import { Auth, HTTPException } from "@langchain/langgraph-sdk/auth";
import { // import {
verifyGithubUser, // verifyGithubUser,
GithubUser, // GithubUser,
verifyGithubUserId, // verifyGithubUserId,
} from "@open-swe/shared/github/verify-user"; // } from "@open-swe/shared/github/verify-user";
import { // import {
API_KEY_REQUIRED_MESSAGE, // API_KEY_REQUIRED_MESSAGE,
GITHUB_INSTALLATION_NAME, // GITHUB_INSTALLATION_NAME,
GITHUB_INSTALLATION_TOKEN_COOKIE, // GITHUB_INSTALLATION_TOKEN_COOKIE,
GITHUB_TOKEN_COOKIE, // GITHUB_TOKEN_COOKIE,
GITHUB_USER_ID_HEADER, // GITHUB_USER_ID_HEADER,
GITHUB_USER_LOGIN_HEADER, // GITHUB_USER_LOGIN_HEADER,
} from "@open-swe/shared/constants"; // } from "@open-swe/shared/constants";
import { decryptSecret } from "@open-swe/shared/crypto"; // import { decryptSecret } from "@open-swe/shared/crypto";
import { verifyGitHubWebhookOrThrow } from "./github.js"; // import { verifyGitHubWebhookOrThrow } from "./github.js";
import { createWithOwnerMetadata, createOwnerFilter } from "./utils.js"; import { createWithOwnerMetadata, createOwnerFilter } from "./utils.js";
import { LANGGRAPH_USER_PERMISSIONS } from "../constants.js"; // import { LANGGRAPH_USER_PERMISSIONS } from "../constants.js";
import { getGitHubPatFromRequest } from "../utils/github-pat.js"; // import { getGitHubPatFromRequest } from "../utils/github-pat.js";
import { isAllowedUser } from "../utils/github/allowed-users.js"; // import { isAllowedUser } from "../utils/github/allowed-users.js";
import { validate } from "uuid"; // import { validate } from "uuid";
// TODO: Export from LangGraph SDK // TODO: Export from LangGraph SDK
export interface BaseAuthReturn { export interface BaseAuthReturn {
@ -34,185 +34,189 @@ interface AuthenticateReturn extends BaseAuthReturn {
}; };
} }
function apiKeysInRequestBody( // function apiKeysInRequestBody(
bodyStr: string | Record<string, unknown>, // bodyStr: string | Record<string, unknown>,
): boolean { // ): boolean {
try { // try {
const body = typeof bodyStr === "string" ? JSON.parse(bodyStr) : bodyStr; // const body = typeof bodyStr === "string" ? JSON.parse(bodyStr) : bodyStr;
if ( // if (
body.config?.configurable && // body.config?.configurable &&
("anthropicApiKey" in body.config.configurable.apiKeys || // ("anthropicApiKey" in body.config.configurable.apiKeys ||
"openaiApiKey" in body.config.configurable.apiKeys || // "openaiApiKey" in body.config.configurable.apiKeys ||
"googleApiKey" in body.config.configurable.apiKeys) // "googleApiKey" in body.config.configurable.apiKeys)
) { // ) {
return true; // return true;
} // }
return false; // return false;
} catch { // } catch {
// no-op // // no-op
return false; // return false;
} // }
} // }
function isRunReq(reqUrl: string): boolean { // function isRunReq(reqUrl: string): boolean {
try { // try {
const url = new URL(reqUrl); // const url = new URL(reqUrl);
const pathnameParts = url.pathname.split("/"); // const pathnameParts = url.pathname.split("/");
const isCreateAndWait = !!( // const isCreateAndWait = !!(
pathnameParts[1] === "threads" && // pathnameParts[1] === "threads" &&
validate(pathnameParts[2]) && // validate(pathnameParts[2]) &&
pathnameParts[3] === "runs" && // pathnameParts[3] === "runs" &&
pathnameParts[4] === "wait" && // pathnameParts[4] === "wait" &&
pathnameParts.length === 5 // pathnameParts.length === 5
); // );
const isCreateBackground = !!( // const isCreateBackground = !!(
pathnameParts[1] === "threads" && // pathnameParts[1] === "threads" &&
validate(pathnameParts[2]) && // validate(pathnameParts[2]) &&
pathnameParts[3] === "runs" && // pathnameParts[3] === "runs" &&
pathnameParts.length === 4 // pathnameParts.length === 4
); // );
const isCreateStream = !!( // const isCreateStream = !!(
pathnameParts[1] === "threads" && // pathnameParts[1] === "threads" &&
validate(pathnameParts[2]) && // validate(pathnameParts[2]) &&
pathnameParts[3] === "runs" && // pathnameParts[3] === "runs" &&
pathnameParts[4] === "stream" && // pathnameParts[4] === "stream" &&
pathnameParts.length === 5 // pathnameParts.length === 5
); // );
return !!isCreateAndWait || !!isCreateBackground || !!isCreateStream; // return !!isCreateAndWait || !!isCreateBackground || !!isCreateStream;
} catch { // } catch {
// no-op // // no-op
return false; // return false;
} // }
} // }
export const auth = new Auth() export const auth = new Auth()
.authenticate<AuthenticateReturn>(async (request: Request) => { .authenticate<AuthenticateReturn>(async (_request: Request) => {
if (request.method === "OPTIONS") { return new HTTPException(504, {
return { message: "Open SWE temporarily disabled.",
identity: "anonymous", }) as any;
permissions: [],
is_authenticated: false,
display_name: "CORS Preflight",
metadata: {
installation_name: "n/a",
},
};
}
const isProd = process.env.NODE_ENV === "production"; // if (request.method === "OPTIONS") {
// return {
// identity: "anonymous",
// permissions: [],
// is_authenticated: false,
// display_name: "CORS Preflight",
// metadata: {
// installation_name: "n/a",
// },
// };
// }
const ghSecretHashHeader = request.headers.get("X-Hub-Signature-256"); // const isProd = process.env.NODE_ENV === "production";
if (ghSecretHashHeader) {
// This will either return a valid user, or throw an error
return await verifyGitHubWebhookOrThrow(request);
}
const encryptionKey = process.env.SECRETS_ENCRYPTION_KEY; // const ghSecretHashHeader = request.headers.get("X-Hub-Signature-256");
if (!encryptionKey) { // if (ghSecretHashHeader) {
throw new Error("Missing SECRETS_ENCRYPTION_KEY environment variable."); // // This will either return a valid user, or throw an error
} // return await verifyGitHubWebhookOrThrow(request);
// }
// Check for GitHub PAT authentication (simpler mode for evals, etc.) // const encryptionKey = process.env.SECRETS_ENCRYPTION_KEY;
const githubPat = getGitHubPatFromRequest(request, encryptionKey); // if (!encryptionKey) {
if (githubPat && !isProd) { // throw new Error("Missing SECRETS_ENCRYPTION_KEY environment variable.");
const user = await verifyGithubUser(githubPat); // }
if (!user) {
throw new HTTPException(401, {
message: "Invalid GitHub PAT",
});
}
return { // // Check for GitHub PAT authentication (simpler mode for evals, etc.)
identity: user.id.toString(), // const githubPat = getGitHubPatFromRequest(request, encryptionKey);
is_authenticated: true, // if (githubPat && !isProd) {
display_name: user.login, // const user = await verifyGithubUser(githubPat);
metadata: { // if (!user) {
installation_name: "pat-auth", // throw new HTTPException(401, {
}, // message: "Invalid GitHub PAT",
permissions: LANGGRAPH_USER_PERMISSIONS, // });
}; // }
}
// GitHub App authentication mode (existing logic) // return {
const installationNameHeader = request.headers.get( // identity: user.id.toString(),
GITHUB_INSTALLATION_NAME, // is_authenticated: true,
); // display_name: user.login,
if (!installationNameHeader) { // metadata: {
throw new HTTPException(401, { // installation_name: "pat-auth",
message: "GitHub installation name header missing", // },
}); // permissions: LANGGRAPH_USER_PERMISSIONS,
} // };
// }
// We don't do anything with this token right now, but still confirm it // // GitHub App authentication mode (existing logic)
// exists as it will cause issues later on if it's not present. // const installationNameHeader = request.headers.get(
const encryptedInstallationToken = request.headers.get( // GITHUB_INSTALLATION_NAME,
GITHUB_INSTALLATION_TOKEN_COOKIE, // );
); // if (!installationNameHeader) {
if (!encryptedInstallationToken) { // throw new HTTPException(401, {
throw new HTTPException(401, { // message: "GitHub installation name header missing",
message: "GitHub installation token header missing", // });
}); // }
}
const encryptedAccessToken = request.headers.get(GITHUB_TOKEN_COOKIE); // // We don't do anything with this token right now, but still confirm it
const decryptedAccessToken = encryptedAccessToken // // exists as it will cause issues later on if it's not present.
? decryptSecret(encryptedAccessToken, encryptionKey) // const encryptedInstallationToken = request.headers.get(
: undefined; // GITHUB_INSTALLATION_TOKEN_COOKIE,
const decryptedInstallationToken = decryptSecret( // );
encryptedInstallationToken, // if (!encryptedInstallationToken) {
encryptionKey, // throw new HTTPException(401, {
); // message: "GitHub installation token header missing",
// });
// }
let user: GithubUser | undefined; // const encryptedAccessToken = request.headers.get(GITHUB_TOKEN_COOKIE);
// const decryptedAccessToken = encryptedAccessToken
// ? decryptSecret(encryptedAccessToken, encryptionKey)
// : undefined;
// const decryptedInstallationToken = decryptSecret(
// encryptedInstallationToken,
// encryptionKey,
// );
if (!decryptedAccessToken) { // let user: GithubUser | undefined;
// If there isn't a user access token, check to see if the user info is in headers.
// This would indicate a bot created the request.
const userIdHeader = request.headers.get(GITHUB_USER_ID_HEADER);
const userLoginHeader = request.headers.get(GITHUB_USER_LOGIN_HEADER);
if (!userIdHeader || !userLoginHeader) {
throw new HTTPException(401, {
message: "Github-User-Id or Github-User-Login header missing",
});
}
user = await verifyGithubUserId(
decryptedInstallationToken,
Number(userIdHeader),
userLoginHeader,
);
} else {
// Ensure we decrypt the token before passing to the verification function.
user = await verifyGithubUser(decryptedAccessToken);
}
if (!user) { // if (!decryptedAccessToken) {
throw new HTTPException(401, { // // If there isn't a user access token, check to see if the user info is in headers.
message: "User not found", // // This would indicate a bot created the request.
}); // const userIdHeader = request.headers.get(GITHUB_USER_ID_HEADER);
} // const userLoginHeader = request.headers.get(GITHUB_USER_LOGIN_HEADER);
// if (!userIdHeader || !userLoginHeader) {
// throw new HTTPException(401, {
// message: "Github-User-Id or Github-User-Login header missing",
// });
// }
// user = await verifyGithubUserId(
// decryptedInstallationToken,
// Number(userIdHeader),
// userLoginHeader,
// );
// } else {
// // Ensure we decrypt the token before passing to the verification function.
// user = await verifyGithubUser(decryptedAccessToken);
// }
const reqCopy = request.clone(); // if (!user) {
const reqBody = await reqCopy.text(); // throw new HTTPException(401, {
if (!isAllowedUser(user.login)) { // message: "User not found",
if (isRunReq(request.url)) { // });
if (!apiKeysInRequestBody(reqBody)) { // }
throw new HTTPException(401, {
message: API_KEY_REQUIRED_MESSAGE,
});
}
}
}
return { // const reqCopy = request.clone();
identity: user.id.toString(), // const reqBody = await reqCopy.text();
is_authenticated: true, // if (!isAllowedUser(user.login)) {
display_name: user.login, // if (isRunReq(request.url)) {
metadata: { // if (!apiKeysInRequestBody(reqBody)) {
installation_name: installationNameHeader, // throw new HTTPException(401, {
}, // message: API_KEY_REQUIRED_MESSAGE,
permissions: LANGGRAPH_USER_PERMISSIONS, // });
}; // }
// }
// }
// return {
// identity: user.id.toString(),
// is_authenticated: true,
// display_name: user.login,
// metadata: {
// installation_name: installationNameHeader,
// },
// permissions: LANGGRAPH_USER_PERMISSIONS,
// };
}) })
// THREADS: create operations with metadata // THREADS: create operations with metadata