chore(proxy): keep the new config-owned refusals inside the LIT002 ceiling

This commit is contained in:
Yuneng Jiang 2026-09-18 22:45:27 -07:00
parent 3a480a5d6c
commit 3d2ec85215
No known key found for this signature in database
2 changed files with 7 additions and 7 deletions

View file

@ -5221,7 +5221,7 @@ class ProxyConfig:
verbose_proxy_logger.warning("Maximum recursion depth (%s) reached while processing config.", max_depth)
return config
return {
return { # mutable-ok: callers deep-copy and mutate this, and a mappingproxy cannot be deep-copied
key: self._resolved_config_value(value=value, depth=depth, max_depth=max_depth)
for key, value in config.items()
}
@ -5230,7 +5230,7 @@ class ProxyConfig:
if isinstance(value, dict):
return self._check_for_os_environ_vars(config=value, depth=depth + 1, max_depth=max_depth)
if isinstance(value, list):
return [
return [ # mutable-ok: config values round-trip through json, where a tuple is not a list
self._check_for_os_environ_vars(config=item, depth=depth + 1, max_depth=max_depth)
if isinstance(item, dict)
else item

View file

@ -492,13 +492,13 @@ async def get_allowed_ips():
def _store_allowed_ips(general_settings: MutableMapping[str, object], allowed_ips: Sequence[str]) -> None:
try:
general_settings["allowed_ips"] = list(allowed_ips)
general_settings["allowed_ips"] = list(allowed_ips) # mutable-ok: compared against the file's own list
except ConfigOwnedKeyError as owned:
raise HTTPException(
status_code=400,
detail={
detail={ # mutable-ok: HTTPException serializes its detail as json
"error": f"{owned.section} key '{owned.key}' is set in the config file and cannot be changed here",
"keys": [owned.key],
"keys": (owned.key,),
"section": owned.section,
"resolution": (
"edit the config file to change it, or remove it from the file to let the database own it"
@ -527,7 +527,7 @@ async def add_allowed_ip(
if prisma_client is None:
raise Exception("No DB Connected")
_allowed_ips: Final[Sequence[str]] = general_settings.get("allowed_ips") or []
_allowed_ips: Final[Sequence[str]] = general_settings.get("allowed_ips") or ()
if ip_address.ip in _allowed_ips:
raise HTTPException(status_code=400, detail="IP address already exists")
_store_allowed_ips(general_settings, (*_allowed_ips, ip_address.ip))
@ -584,7 +584,7 @@ async def delete_allowed_ip(
proxy_config,
)
_allowed_ips: Final[Sequence[str]] = general_settings.get("allowed_ips") or []
_allowed_ips: Final[Sequence[str]] = general_settings.get("allowed_ips") or ()
if ip_address.ip not in _allowed_ips:
raise HTTPException(status_code=404, detail="IP address not found")
_store_allowed_ips(general_settings, tuple(ip for ip in _allowed_ips if ip != ip_address.ip))