supermemory/packages
therahul-yo 109674b9f8
fix(tools): bound and harden the shared /v4/profile request
`supermemoryProfileSearch` in `shared/memory-client.ts` is the only
Supermemory HTTP call in this package with neither a request timeout nor
redirect handling. The identical `/v4/profile` call in
`openai/middleware.ts` sets both, and `/v4/conversations`
(`conversations-client.ts`) and `/v4/memories` (`shared/forget-memory.ts`)
each set a 30s budget.

Two consequences:

- **Unbounded request.** A timeout only applied when the caller supplied a
  signal. `withSupermemory` passes one (5s), but `buildMemoriesText` is
  called with no signal by the Mastra processor and the VoltAgent
  middleware, and by the exported `buildMemoriesText` / `addSystemPrompt`
  helpers. `fetch` has no default deadline, so a stalled connection blocks
  the agent turn indefinitely — the failure both integrations' surrounding
  try/catch is written to absorb, but which never surfaces as an error.
- **Redirects followed.** The request carries `Authorization: Bearer
  <apiKey>`; a 3xx from a misconfigured or attacker-influenced `baseUrl`
  was followed silently rather than refused.

Apply a 30s `PROFILE_REQUEST_TIMEOUT_MS` unconditionally and set
`redirect: "error"`. A caller signal is composed with the timeout via
`AbortSignal.any` rather than replacing it, so a caller-side budget can
only shorten the request, never leave it unbounded — the wrapper is kept
separate so the composition is stated once rather than re-derived at the
call site.

`src/shared/memory-client.test.ts` existed but was absent from the
`test:unit` file list CI runs, so its assertions never ran on a pull
request; add it alongside the new coverage.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L7GkmUn6skD6dCzKtcHDbe
2026-09-14 06:29:41 +00:00
..
agent-framework-python feat(python-sdks): SDK-level cross-source memory deduplication (#1532) 2026-09-01 06:10:36 +00:00
ai-sdk feat(ai-sdk): re-export 7-tool surface (#1433) 2026-09-01 05:59:58 +00:00
cartesia-sdk-python feat(python-sdks): SDK-level cross-source memory deduplication (#1532) 2026-09-01 06:10:36 +00:00
docs-test docs: restructure documentation site and update integration UI (#1331) 2026-07-21 20:19:30 -07:00
hooks fix: add type checks for TypeScript workspaces (#1447) 2026-08-13 17:55:50 +05:30
lib feat(auth): AgentID sign-in button on the web login page (#1467) 2026-08-16 23:20:38 +00:00
memory-graph fix(memory-graph): add aria-labels to zoom controls (#1662) 2026-09-11 11:23:37 -07:00
openai-sdk-python feat(python-sdks): SDK-level cross-source memory deduplication (#1532) 2026-09-01 06:10:36 +00:00
pipecat-sdk-python feat(python-sdks): SDK-level cross-source memory deduplication (#1532) 2026-09-01 06:10:36 +00:00
tools fix(tools): bound and harden the shared /v4/profile request 2026-09-14 06:29:41 +00:00
ui fix(ui): remove the unused, broken AnonymousAuth component (#1555) 2026-08-19 19:22:17 +05:30
validation fix(mcp): bound tool inputs and scope get_document to the active space (#1593) 2026-08-24 21:36:04 +00:00