fix(auth): require owner for cached provider credentials

This commit is contained in:
RaresKeY
2026-08-31 00:09:19 +00:00
parent aee6655fbd
commit 98c1fd50a0
2 changed files with 82 additions and 4 deletions
+13 -1
View File
@@ -258,6 +258,16 @@ def resolve_runtime_credentials(
force_refresh: bool = False,
allow_live_probes: bool = True,
) -> Dict[str, Any]:
normalized_owner = None
if not allow_live_probes:
from src.owner_identity import is_request_sentinel_owner, normalize_owner
normalized_owner = normalize_owner(owner)
if normalized_owner is None or is_request_sentinel_owner(normalized_owner):
raise ChatGPTSubscriptionAuthNotFound(
"ChatGPT Subscription credentials require an authenticated owner."
)
ProviderAuthSession, SessionLocal, utcnow_naive = _database_handles()
db = SessionLocal()
try:
@@ -265,7 +275,9 @@ def resolve_runtime_credentials(
ProviderAuthSession.id == auth_id,
ProviderAuthSession.provider == CHATGPT_SUBSCRIPTION_PROVIDER,
)
if owner:
if not allow_live_probes:
q = q.filter(ProviderAuthSession.owner == normalized_owner)
elif owner:
q = q.filter(ProviderAuthSession.owner == owner)
row = q.first()
if row is None: