Skip to content

proxy refuses web pages - #34

Merged
DexterStorey merged 1 commit into
mainfrom
proxy-local-only
Oct 1, 2026
Merged

DexterStorey merged 1 commit into
mainfrom
proxy-local-only

Conversation

@DexterStorey

Copy link
Copy Markdown
Contributor

The local proxy served any request that reached 127.0.0.1:8459, including ones sent by a web page in the user's browser.

  • Cross-site requests: any site could fetch('http://127.0.0.1:8459/anthropic/v1/messages', {method: 'POST', mode: 'no-cors', …}). The proxy injected the active account's credential and forwarded it, spending the user's quota. The page can't read the response, but the spend is real.
  • DNS rebinding: a page whose hostname rebinds to 127.0.0.1 makes "same-origin" requests that carry its own Host. That lets it read the responses too, so it gets free inference on the user's subscription.

The handler now refuses, before routing and before any credential lookup:

  • a Host that isn't loopback (127.0.0.1, localhost, [::1]), which stops rebinding;
  • an Origin that isn't a loopback origin, which stops cross-site fetch/form posts;
  • a browser subresource request with no Origin (Sec-Fetch-Site present and not none), which covers <img>/<script> GETs.

Native clients (codex, claude, grok, pi, openclaw, hermes) send none of these headers, so nothing changes for them. A page served from loopback, like a local dev tool, keeps working. The unknown route fingerprint proxyIdentity relies on is unaffected.

Verified: the five new cases in proxy.test.ts fail on main (three attacks injected the credential) and pass here. The full suite passes on Bun 1.2.20 and 1.4.2.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

try this branch: bun add -g tokenmaxx@0.0.77-alpha.108

@DexterStorey
DexterStorey merged commit efd6d4a into main Oct 1, 2026
3 checks passed
@DexterStorey
DexterStorey deleted the proxy-local-only branch October 1, 2026 03:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant