fix(guardrails): check Akto attachments in both messages and input

This commit is contained in:
Rohan 2026-10-03 18:48:25 +05:30
parent 8111bed6b9
commit 1931bce82d
2 changed files with 19 additions and 4 deletions

View file

@ -159,10 +159,9 @@ _UNSENDABLE: Final[_Classified] = (None, True)
def request_attachments(request_data: Mapping[str, object]) -> RequestAttachments:
messages: Final = _parse(_ITEMS_ADAPTER, request_data.get("messages")) or _parse(
_ITEMS_ADAPTER, request_data.get("input")
)
blocks: Final = chain.from_iterable(_message_blocks(message) for message in messages or ())
# Both, so a decoy "messages" can't hide attachments in a Responses API "input"
containers: Final = (_parse(_ITEMS_ADAPTER, request_data.get(key)) or () for key in ("messages", "input"))
blocks: Final = chain.from_iterable(_message_blocks(message) for message in chain.from_iterable(containers))
classified: Final = tuple(_classify_block(block, index) for index, block in enumerate(blocks))
return RequestAttachments(
attachments=tuple(attachment for attachment, _ in classified if attachment is not None),

View file

@ -85,6 +85,22 @@ def test_request_attachments_reads_responses_api_input():
)
def test_a_decoy_messages_list_does_not_hide_responses_api_input_attachments():
request_data = {
"messages": [{"role": "user", "content": "hello"}],
"input": [
{
"role": "user",
"content": [
{"type": "input_file", "file_data": f"data:application/pdf;base64,{PDF_B64}", "filename": "r.pdf"}
],
}
],
}
assert request_attachments(request_data).attachments == (Attachment("r.pdf", "file", content=PDF_B64),)
def test_request_attachments_names_files_by_their_type():
request_data = {
"messages": [