fix(proxy): restrict 0x proxy to the endpoints we use - #1292
Conversation
Only /swap/permit2/price, /swap/permit2/quote and /trade-analytics/swap are requested by web, public-api and swap-service. Reject everything else with 404 so the shared API key can't be used to reach the rest of the 0x API. Drop the legacy chain-prefixed v1 routing, which has no callers. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01N18HFEWkM4ypvsjxSVJH3T
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe proxy now uses one 0x API base URL, supports an explicit path allowlist, normalizes request paths, preserves query parameters, and applies the Changes0x proxy routing
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The supported 0x endpoints retain their expected routing while unsupported paths are rejected before reaching the upstream API. No actionable current-head risk remains. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the route with care Comment |
Description
Locks the 0x proxy down to an exact-path allowlist so the shared API key can only be used for the endpoints our services actually call. Everything else under
/api/v1/zrx/now returns 404 before reaching 0x.Allowed:
/swap/permit2/price(web + public-api rates)/swap/permit2/quote(web + public-api quotes)/trade-analytics/swap(swap-service verification)Also removes the legacy chain-prefixed Swap v1 routing, which has had no callers since web moved to permit2 and which 0x has sunset upstream, and moves the
0x-version: v2header onto the axios instance since every allowed call is v2.Risk
Low. For all existing callers the forwarded request, headers, and error/Retry-After passthrough are byte-for-byte the same as before. The only removed behavior is the unused v1 branch. Anything hitting the proxy for a non-allowlisted path (which is the abuse this prevents) now gets 404.
Testing
Ran the handler in a standalone Express harness with a real 0x key against live 0x:
permit2/price200 on Ethereum, Base, Arbitrum;permit2/quote200 with full v2 shape;trade-analytics/swap200 with cursor pagingFollow-ups (not in this PR): web still sends the v1
feeRecipientTradeSurplusparam (v2 name istradeSurplusRecipient), and swap-service filters analytics by an unsupportedtxHashparam. Consider dropping/trade-analytics/swapfrom the proxy once swap-service calls 0x directly, since that route exposes the full integrator trade feed unauthenticated.🤖 Generated with Claude Code
https://claude.ai/code/session_01N18HFEWkM4ypvsjxSVJH3T
Summary by CodeRabbit