Skip to content

fix(ts): strip dotted API-version prefixes (#52) - #56

Merged
abienkowski merged 7 commits into
mainfrom
fix/ts-dotted-api-version-52
Oct 7, 2026
Merged

abienkowski merged 7 commits into
mainfrom
fix/ts-dotted-api-version-52

Conversation

@abienkowski

Copy link
Copy Markdown
Collaborator

Description

The TypeScript proxy denied almost every non-GET request from a stock Docker CLI. stripAPIVersion (ts/src/proxy.ts) only stripped undotted prefixes (/^\/v\d+\//). The CLI sends dotted ones on every request (/v1.43/containers/create), so the router saw the prefixed path, matched nothing, and fell to the default deny. Go and Rust were not affected.

Fix: a one-line regex change, /^\/v\d+\// → /^\/v\d+(\.\d+)?\//, which accepts /v<major> and /v<major>.<minor>. Go and Rust production code is unchanged.

Closes #52

Repro against built ts/dist

The router was built with config/, and the create request used the body {Image: "chainsafe/lodestar:latest"}.

                                       before   after
DELETE /v1.43/containers/foo           Deny     Allow
POST   /v1.43/containers/beacon/start  Deny     Allow
POST   /v1.43/containers/create        Deny     CreateContainer
POST   /v1/containers/beacon/start     Allow    Allow   (undotted control)

Tests (written first; the RED commit is 6f5706a)

  • Same table in all three languages, with each row commented #52: Go TestRouteVersionedPaths, Rust test_route_versioned_paths, and TS routes dotted API-version paths like the unversioned ones.
    • Five rows: dotted delete, start and create; the undotted control; and DELETE /v1.43/containers/json → Deny, which checks that the reserved segment is still caught after the prefix is stripped.
    • Go and Rust passed before the fix. TS failed on the dotted rows.
  • TS-only rows that catch over-stripping: DELETE /volumes/containers/foo and DELETE /v1.2.3/containers/foo, both → Deny.
  • deploy/test.sh (32 → 35 checks):
    • POST /v1.45/containers/create with an allowed image (the docker run path) must get 201 or 404 from the daemon, not a proxy 403. Before the fix, TS returned 403.
    • POST /v1.45/containers/no-such-container/start must reach the daemon. A daemon 404 means the request got through; a proxy deny would be 403. Before the fix, TS returned 403.
    • DELETE /v1.45/containers/json → 403. This check passed before the fix too, because default deny already caught it, so it only guards behaviour after the fix.

The RED commit fails in TypeScript on purpose, so this PR has to be squash-merged.

Type of change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update

Implementation(s) changed

  • Go (tests only)
  • Rust (tests only)
  • TypeScript
  • Quint specification (no change: spec/router.qnt models paths after the version prefix is stripped)
  • CI / infrastructure (deploy/test.sh checks)

Testing

  • Unit tests pass (make test-all): Go 102, Rust 140, TS 157 (156 pass, 1 skipped)
  • Integration tests pass: make test-integration, make test-integration-rs and make test-integration-ts each pass all 35 checks. With the regex reverted, the TS suite fails exactly the two discriminating versioned checks (33 passed, 2 failed).
  • Quint verification (make verify): not run locally, since the spec didn't change. It runs in CI (quint job), and make test-spec passes.
  • New tests added for the change

Checklist

  • I have read CONTRIBUTING.md
  • My code follows the project's coding style
  • I have updated documentation as needed (test counts in AGENTS.md and README.md)

@abienkowski abienkowski added Priority: P1 Added to issues and PRs relating to a high severity bugs. Type: Bug Added to issues and PRs if they are addressing a bug labels Oct 7, 2026
@abienkowski abienkowski self-assigned this Oct 7, 2026
@abienkowski
abienkowski merged commit a654ff8 into main Oct 7, 2026
6 checks passed
@abienkowski
abienkowski deleted the fix/ts-dotted-api-version-52 branch October 7, 2026 16:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Priority: P1 Added to issues and PRs relating to a high severity bugs. Type: Bug Added to issues and PRs if they are addressing a bug

Projects

None yet

Development

Successfully merging this pull request may close these issues.

TypeScript proxy denies dotted API-version paths (/v1.43/...) that the Docker CLI always sends

1 participant