Skip to content

fix(proxy): restrict 0x proxy to the endpoints we use - #1292

Merged
kaladinlight merged 1 commit into
developfrom
fix/zrx-proxy-allowlist
Sep 14, 2026
Merged

kaladinlight merged 1 commit into
developfrom
fix/zrx-proxy-allowlist

Conversation

@kaladinlight

@kaladinlight kaladinlight commented Sep 14, 2026 •

Copy link
Copy Markdown
Member

Description

Locks the 0x proxy down to an exact-path allowlist so the shared API key can only be used for the endpoints our services actually call. Everything else under /api/v1/zrx/ now returns 404 before reaching 0x.

Allowed:

  • /swap/permit2/price (web + public-api rates)
  • /swap/permit2/quote (web + public-api quotes)
  • /trade-analytics/swap (swap-service verification)

Also removes the legacy chain-prefixed Swap v1 routing, which has had no callers since web moved to permit2 and which 0x has sunset upstream, and moves the 0x-version: v2 header onto the axios instance since every allowed call is v2.

Risk

Low. For all existing callers the forwarded request, headers, and error/Retry-After passthrough are byte-for-byte the same as before. The only removed behavior is the unused v1 branch. Anything hitting the proxy for a non-allowlisted path (which is the abuse this prevents) now gets 404.

Testing

Ran the handler in a standalone Express harness with a real 0x key against live 0x:

  • permit2/price 200 on Ethereum, Base, Arbitrum; permit2/quote 200 with full v2 shape; trade-analytics/swap 200 with cursor paging
  • allowance-holder, gasless, sources, and chain-prefixed v1 paths all 404 without an upstream call
  • trailing slash on an allowed path still forwards; upstream 429 status/body pass through unchanged

Follow-ups (not in this PR): web still sends the v1 feeRecipientTradeSurplus param (v2 name is tradeSurplusRecipient), and swap-service filters analytics by an unsupported txHash param. Consider dropping /trade-analytics/swap from the proxy once swap-service calls 0x directly, since that route exposes the full integrator trade feed unauthenticated.

🤖 Generated with Claude Code

https://claude.ai/code/session_01N18HFEWkM4ypvsjxSVJH3T

Summary by CodeRabbit

  • Bug Fixes
    • Improved proxy request handling by restricting requests to supported routes.
    • Preserved query parameters when forwarding requests.
    • Standardized requests to use the current API version.
    • Unsupported routes now return a 404 response.

Only /swap/permit2/price, /swap/permit2/quote and /trade-analytics/swap are
requested by web, public-api and swap-service. Reject everything else with 404
so the shared API key can't be used to reach the rest of the 0x API. Drop the
legacy chain-prefixed v1 routing, which has no callers.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N18HFEWkM4ypvsjxSVJH3T
@kaladinlight
kaladinlight requested a review from a team as a code owner September 14, 2026 16:14
@coderabbitai

coderabbitai Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 0c6322c2-c989-472f-842e-2cff51b99a75

📥 Commits

Reviewing files that changed from the base of the PR and between 0b2fbed and f40f840.

📒 Files selected for processing (1)
  • node/proxy/api/src/zrx.ts

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The proxy now uses one 0x API base URL, supports an explicit path allowlist, normalizes request paths, preserves query parameters, and applies the 0x-version: v2 header globally.

Changes

0x proxy routing

Layer / File(s) Summary
Route validation and request handling
node/proxy/api/src/zrx.ts
The proxy adds a shared 0x API base URL and allowlist, applies the v2 header globally, normalizes paths, rejects unsupported paths with 404, preserves query parameters, and removes chain-specific routing.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Suggested reviewers: 0xapotheosis

Merge Risk: ⚪ Minimal · up to f40f8

The supported 0x endpoints retain their expected routing while unsupported paths are rejected before reaching the upstream API. No actionable current-head risk remains.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the primary change: restricting the 0x proxy to the supported endpoints.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/zrx-proxy-allowlist

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the route with care
One 0x path now waits there
V2 headers hop along
Query strings join the song
Unsupported trails are gone
The proxy greets the dawn

Comment @coderabbitai help to get the list of available commands.

@kaladinlight
kaladinlight merged commit 48829aa into develop Sep 14, 2026
3 checks passed
@kaladinlight
kaladinlight deleted the fix/zrx-proxy-allowlist branch September 14, 2026 16:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant