fix(security): stop leaking Gemini API key to browsers #34

Merged
varutasu merged 1 commit from convoy/secure-scanner-gemini-key into main 2026-05-27 09:41:48 -04:00
varutasu commented 2026-05-27 09:40:07 -04:00 (Migrated from github.com)

Summary

  • Deletes pages/api/config/gemini.js, which returned GEMINI_AI_API_KEY to any caller without authentication
  • Removes client auto-fetch of that endpoint from CameraScanner.js and OCRSettings.js
  • Adds checkScanRateLimit (5/min, user-keyed, deckhearth:scan) to lib/rate-limit.js for the upcoming /api/scan/identify route
  • Adds blocking CI job forbidden-client-side-llm-keys to prevent reintroducing key leaks or new browser-side LLM URLs (grandfathers lib/ai-ocr.js until convoy #2)
  • Queues the scanner audit convoy portfolio in .convoys/

Operator notes

Gemini key rotation is complete (Google AI Studio + Vercel). After merge, redeploy and confirm GET /api/config/gemini returns 404. Clear browser localStorage key ocrSettings if it cached the old key.

Scanner auto-config is intentionally removed until server-side-scan-pipeline lands.

Test plan

  • npm run test:run — 21/21
  • Local simulation of forbidden-client-side-llm-keys grep gate — pass
  • Post-deploy: curl /api/config/gemini → 404
  • CI: lint, vitest, forbidden-* jobs green

Made with Cursor

## Summary - Deletes `pages/api/config/gemini.js`, which returned `GEMINI_AI_API_KEY` to any caller without authentication - Removes client auto-fetch of that endpoint from `CameraScanner.js` and `OCRSettings.js` - Adds `checkScanRateLimit` (5/min, user-keyed, `deckhearth:scan`) to `lib/rate-limit.js` for the upcoming `/api/scan/identify` route - Adds blocking CI job `forbidden-client-side-llm-keys` to prevent reintroducing key leaks or new browser-side LLM URLs (grandfathers `lib/ai-ocr.js` until convoy #2) - Queues the scanner audit convoy portfolio in `.convoys/` ## Operator notes Gemini key rotation is complete (Google AI Studio + Vercel). After merge, redeploy and confirm `GET /api/config/gemini` returns 404. Clear browser `localStorage` key `ocrSettings` if it cached the old key. Scanner auto-config is intentionally removed until `server-side-scan-pipeline` lands. ## Test plan - [x] `npm run test:run` — 21/21 - [x] Local simulation of `forbidden-client-side-llm-keys` grep gate — pass - [ ] Post-deploy: `curl` `/api/config/gemini` → 404 - [ ] CI: lint, vitest, forbidden-* jobs green Made with [Cursor](https://cursor.com)
vercel[bot] commented 2026-05-27 09:40:11 -04:00 (Migrated from github.com)

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
tcg-vault Ready Ready Preview, Comment May 27, 2026 1:40pm

Request Review

[vc]: #30ZyCny7oaG/5E2W7M6FYOTIyFt8N/AbFe5KLjlfjGU=:eyJpc01vbm9yZXBvIjp0cnVlLCJ0eXBlIjoiZ2l0aHViIiwicHJvamVjdHMiOlt7Im5hbWUiOiJ0Y2ctdmF1bHQiLCJwcm9qZWN0SWQiOiJwcmpfRjZXOEVvRkd3Y0g3aWVGcnRvRlNlOXdVVkFhNSIsImluc3BlY3RvclVybCI6Imh0dHBzOi8vdmVyY2VsLmNvbS9yYW5kYWxsLXN0aWxsd2VsbHMtcHJvamVjdHMvdGNnLXZhdWx0L1BuMWF5S29SZXBWUXBnNEhHREFqNUZuMzlaR24iLCJwcmV2aWV3VXJsIjoidGNnLXZhdWx0LWdpdC1jb252b3ktc2VjdXJlLTk2OTUyMS1yYW5kYWxsLXN0aWxsd2VsbHMtcHJvamVjdHMudmVyY2VsLmFwcCIsIm5leHRDb21taXRTdGF0dXMiOiJERVBMT1lFRCIsImxpdmVGZWVkYmFjayI6eyJyZXNvbHZlZCI6MCwidW5yZXNvbHZlZCI6MCwidG90YWwiOjAsImxpbmsiOiJ0Y2ctdmF1bHQtZ2l0LWNvbnZveS1zZWN1cmUtOTY5NTIxLXJhbmRhbGwtc3RpbGx3ZWxscy1wcm9qZWN0cy52ZXJjZWwuYXBwIn0sInJvb3REaXJlY3RvcnkiOm51bGx9XSwicmVxdWVzdFJldmlld1VybCI6Imh0dHBzOi8vdmVyY2VsLmNvbS92ZXJjZWwtYWdlbnQvcmVxdWVzdC1yZXZpZXc/b3duZXI9dmFydXRhc3UmcmVwbz10Y2ctdmF1bHQmcHI9MzQifQ== The latest updates on your projects. Learn more about [Vercel for GitHub](https://vercel.link/github-learn-more). | Project | Deployment | Actions | Updated (UTC) | | :--- | :----- | :------ | :------ | | [tcg-vault](https://vercel.com/randall-stillwells-projects/tcg-vault) | ![Ready](https://vercel.com/static/status/ready.svg) [Ready](https://vercel.com/randall-stillwells-projects/tcg-vault/Pn1ayKoRepVQpg4HGDAj5Fn39ZGn) | [Preview](https://tcg-vault-git-convoy-secure-969521-randall-stillwells-projects.vercel.app), [Comment](https://vercel.live/open-feedback/tcg-vault-git-convoy-secure-969521-randall-stillwells-projects.vercel.app?via=pr-comment-feedback-link) | May 27, 2026 1:40pm | <a href="https://vercel.com/vercel-agent/request-review?owner=varutasu&repo=tcg-vault&pr=34" rel="noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://agents-vade-review.vercel.sh/request-review-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://agents-vade-review.vercel.sh/request-review-light.svg"><img src="https://agents-vade-review.vercel.sh/request-review-light.svg" alt="Request Review"></picture></a>
github-actions[bot] commented 2026-05-27 09:40:31 -04:00 (Migrated from github.com)

Pipeline Health

Build + CI gates

Gate Status
Vercel build (Preview) pass
CI: Lint pass
CI: Schema map fresh skipped
Preview smoke pass
Visual diff pass

Build runs on Vercel; this CI runs lint and schema-map drift only (no duplicate build).

Role reports

Role Status
Reviewer report pending
A11y audit pending
Design system audit pending

See individual comments above for details. This rollup updates automatically.

<!-- pipeline-rollup --> ## Pipeline Health ### Build + CI gates | Gate | Status | | --- | --- | | Vercel build (Preview) | ✅ pass | | CI: Lint | ✅ pass | | CI: Schema map fresh | ❌ skipped | | Preview smoke | ✅ pass | | Visual diff | ✅ pass | _Build runs on Vercel; this CI runs lint and schema-map drift only (no duplicate build)._ ### Role reports | Role | Status | | --- | --- | | Reviewer report | ⏳ pending | | A11y audit | ⏳ pending | | Design system audit | ⏳ pending | See individual comments above for details. This rollup updates automatically.
github-actions[bot] commented 2026-05-27 09:41:28 -04:00 (Migrated from github.com)

Visual Diff

Screenshots and diffs uploaded as artifacts: view run

If intentional changes: update snapshots locally with npx playwright test --project=visual --update-snapshots and commit.

## Visual Diff Screenshots and diffs uploaded as artifacts: [view run](https://github.com/varutasu/tcg-vault/actions/runs/26514785564) If intentional changes: update snapshots locally with `npx playwright test --project=visual --update-snapshots` and commit.
Sign in to join this conversation.
No description provided.