mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-13 23:11:40 +00:00
Code review change
This commit is contained in:
parent
4ccdb0ea3a
commit
fc500295f7
2 changed files with 28 additions and 0 deletions
|
|
@ -31,6 +31,12 @@ LTX_VIDEO_STORAGE_MAX_AGE_SECONDS = 24 * 60 * 60
|
|||
|
||||
|
||||
def _get_ltx_video_storage_path(video_id: str) -> Path:
|
||||
if not video_id or any(char in video_id for char in ("/", "\\", "\0")):
|
||||
raise BaseLLMException(
|
||||
status_code=400,
|
||||
message="Invalid LTX video_id. video_id must not contain path separators.",
|
||||
)
|
||||
|
||||
return LTX_VIDEO_STORAGE_DIR / f"{video_id}.mp4"
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -383,6 +383,28 @@ class TestLTXVideoTransformation:
|
|||
assert url == stored_video_path.resolve().as_uri()
|
||||
assert data == {}
|
||||
|
||||
def test_transform_video_content_request_rejects_path_traversal_video_id(
|
||||
self, monkeypatch, tmp_path
|
||||
):
|
||||
"""Test content requests cannot traverse outside LTX video storage."""
|
||||
storage_dir = tmp_path / "litellm_ltx_videos"
|
||||
monkeypatch.setattr(
|
||||
ltx_video_transformation, "LTX_VIDEO_STORAGE_DIR", storage_dir
|
||||
)
|
||||
sibling_video_path = tmp_path / "other_dir" / "secret"
|
||||
sibling_video_path.parent.mkdir(parents=True)
|
||||
sibling_video_path.with_suffix(".mp4").write_bytes(b"private-video")
|
||||
|
||||
with pytest.raises(BaseLLMException, match="must not contain path separators"):
|
||||
self.config.transform_video_content_request(
|
||||
video_id=encode_video_id_with_provider(
|
||||
"../other_dir/secret", "ltx", "ltx-2-3-fast"
|
||||
),
|
||||
api_base="https://api.ltx.video/v1",
|
||||
litellm_params=GenericLiteLLMParams(),
|
||||
headers={},
|
||||
)
|
||||
|
||||
def test_video_content_handler_reads_local_file(self, monkeypatch, tmp_path):
|
||||
"""Test the shared video content handler can serve local LTX artifacts."""
|
||||
monkeypatch.setattr(ltx_video_transformation, "LTX_VIDEO_STORAGE_DIR", tmp_path)
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue