fix(proxy): add anchor validation for file expiry, key validation for batch expiry

Validate anchor is "created_at" in enforced_file_expires_after (matching
user-provided path). Add key existence validation to batch endpoint for
enforced_batch_output_expires_after.
This commit is contained in:
Ryan Crabbe 2026-03-03 13:51:41 -08:00
parent d6ad312a4c
commit 903ade4a1b
2 changed files with 15 additions and 1 deletions

View file

@ -125,6 +125,13 @@ async def create_batch( # noqa: PLR0915
"enforced_batch_output_expires_after"
)
if enforced_batch_expiry is not None:
if "anchor" not in enforced_batch_expiry or "seconds" not in enforced_batch_expiry:
raise HTTPException(
status_code=400,
detail={
"error": "enforced_batch_output_expires_after must contain 'anchor' and 'seconds' keys",
},
)
_create_batch_data["output_expires_after"] = enforced_batch_expiry
input_file_id = _create_batch_data.get("input_file_id", None)

View file

@ -465,8 +465,15 @@ async def create_file( # noqa: PLR0915
"error": "enforced_file_expires_after must contain 'anchor' and 'seconds' keys",
},
)
if enforced_file_expiry["anchor"] != "created_at":
raise HTTPException(
status_code=400,
detail={
"error": f"enforced_file_expires_after anchor must be 'created_at', got '{enforced_file_expiry['anchor']}'",
},
)
expires_after = FileExpiresAfter(
anchor=enforced_file_expiry["anchor"],
anchor="created_at",
seconds=enforced_file_expiry["seconds"],
)