mirror of
https://github.com/supermemoryai/supermemory.git
synced 2026-10-01 02:01:40 +00:00
`supermemoryProfileSearch` in `shared/memory-client.ts` is the only Supermemory HTTP call in this package with neither a request timeout nor redirect handling. The identical `/v4/profile` call in `openai/middleware.ts` sets both, and `/v4/conversations` (`conversations-client.ts`) and `/v4/memories` (`shared/forget-memory.ts`) each set a 30s budget. Two consequences: - **Unbounded request.** A timeout only applied when the caller supplied a signal. `withSupermemory` passes one (5s), but `buildMemoriesText` is called with no signal by the Mastra processor and the VoltAgent middleware, and by the exported `buildMemoriesText` / `addSystemPrompt` helpers. `fetch` has no default deadline, so a stalled connection blocks the agent turn indefinitely — the failure both integrations' surrounding try/catch is written to absorb, but which never surfaces as an error. - **Redirects followed.** The request carries `Authorization: Bearer <apiKey>`; a 3xx from a misconfigured or attacker-influenced `baseUrl` was followed silently rather than refused. Apply a 30s `PROFILE_REQUEST_TIMEOUT_MS` unconditionally and set `redirect: "error"`. A caller signal is composed with the timeout via `AbortSignal.any` rather than replacing it, so a caller-side budget can only shorten the request, never leave it unbounded — the wrapper is kept separate so the composition is stated once rather than re-derived at the call site. `src/shared/memory-client.test.ts` existed but was absent from the `test:unit` file list CI runs, so its assertions never ran on a pull request; add it alongside the new coverage. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01L7GkmUn6skD6dCzKtcHDbe |
||
|---|---|---|
| .. | ||
| agent-framework-python | ||
| ai-sdk | ||
| cartesia-sdk-python | ||
| docs-test | ||
| hooks | ||
| lib | ||
| memory-graph | ||
| openai-sdk-python | ||
| pipecat-sdk-python | ||
| tools | ||
| ui | ||
| validation | ||