Summary
Require HTTPS before any provider health check sends an API key, bearer token, or other credential to a configured endpoint.
Azure OpenAI validation can accept an http:// api_base. The Azure lightweight health check then sends the submitted credential in request headers. An attacker on that network path can read or modify the credential.
Required changes
- In
src/api/provider_validation.py, validate that Azure api_base uses the https scheme before _test_azure_lightweight_health constructs a credential-bearing request.
- Preserve the existing Azure OpenAI Service and Azure AI Foundry endpoint selection behavior.
- Review all similar provider health checks and credential-validation probes for endpoints that originate from configuration.
- For each equivalent request path, reject non-HTTPS endpoints before credentials are sent. Do not change intentionally local, credential-free health checks without a documented reason.
Affected areas
src/api/provider_validation.py
- Other provider health-check and credential-validation modules identified by the audit
- Unit tests for validation and request construction
Acceptance criteria
- Azure OpenAI Service and Azure AI Foundry validation reject non-HTTPS
api_base values before sending credentials.
- Existing valid HTTPS Azure endpoint behavior remains unchanged.
- The audit covers credential-bearing health checks that use configured endpoints.
- Tests prove that no credential-bearing request is made for rejected HTTP endpoints.
- Tests cover each additional affected provider path found by the audit.
References
Summary
Require HTTPS before any provider health check sends an API key, bearer token, or other credential to a configured endpoint.
Azure OpenAI validation can accept an
http://api_base. The Azure lightweight health check then sends the submitted credential in request headers. An attacker on that network path can read or modify the credential.Required changes
src/api/provider_validation.py, validate that Azureapi_baseuses thehttpsscheme before_test_azure_lightweight_healthconstructs a credential-bearing request.Affected areas
src/api/provider_validation.pyAcceptance criteria
api_basevalues before sending credentials.References