Skip to content

security: prevent unauthenticated metric-label cardinality DoS #451

Description

@juzhiyuan

Summary

Proxy metrics currently use the raw request path as the endpoint label before authentication. Unauthenticated callers can create unbounded time series through unique passthrough paths.

Source

  • Imported from Codex Security scan results shared in Slock #Dev:bc985f48 (chatgpt.com.har).
  • This issue groups findings with the same engineering boundary to avoid fragmented fixes.
  • Triage priority: P1.

Covered scanner findings

Expected fix direction

  • Normalize metric endpoint labels to a fixed route template such as /passthrough/:provider/*rest before recording.
  • Avoid recording high-cardinality labels derived from unauthenticated raw paths.
  • Verify zero-value gauge series are removed or bounded if the metrics backend retains label sets.
  • Add a regression test that many unique unauthenticated passthrough paths produce bounded metric series.

Definition of done

  • Fix is covered by regression tests for the affected mode/provider/endpoint.
  • The fix is applied at the shared boundary where possible, not only at one provider call site.
  • Security behavior is documented in code comments or docs where operator expectations change.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

P1High-value differentiatorbugSomething isn't workingvulnerability

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions