fix(logging): bound data URI regex so base64 truncation stays linear (#45132)

* fix(logging): bound data URI regex so base64 truncation stays linear

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

* test(logging): cover whitespace-free data: prefixes in data URI regex regression test

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

---------

Co-authored-by: nate <nate@berri.ai>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
devin-ai-integration[bot] 2026-10-07 12:32:04 -07:00 • committed by GitHub
parent 8f85de740f
commit c877e0f055
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 13 additions and 1 deletions

View file

@ -43,7 +43,7 @@ Helper utils used for logging callbacks
# Regex matching data-URI base64 content: "data:<mime>;base64,<payload>"
# Captures: group(1)=mime_type, group(2)=base64_payload
_DATA_URI_RE: Final = re.compile(r"data:([^;]+);base64,([A-Za-z0-9+/=]+)")
_DATA_URI_RE: Final = re.compile(r"data:([^;,\s]{1,255});base64,([A-Za-z0-9+/=]+)")
# Maximum nesting depth for _truncate_base64_in_value to guard against
# pathological payloads. OpenAI message format is typically 3-4 levels deep.

View file

@ -95,6 +95,18 @@ class TestTruncateBase64InString:
result = _truncate_base64_in_string(text)
assert result.count("base64_data truncated") == 2
@pytest.mark.timeout(10)
@pytest.mark.parametrize(
"text",
[
'data: {"choices": [{"delta": {"content": "hi"}}]}\n\n' * 50_000,
"data:" * 200_000,
],
ids=["sse_lines", "whitespace_free_prefixes"],
)
def test_repeated_data_prefixes_without_data_uris_are_scanned_in_linear_time(self, text: str):
assert _truncate_base64_in_string(text) == text
def test_no_data_uri(self):
text = "hello world, no base64 here"
assert _truncate_base64_in_string(text) == text