mirror of
https://github.com/pewdiepie-archdaemon/odysseus.git
synced 2026-09-23 16:42:21 +02:00
security: fail closed on bearer endpoint credentials
This commit is contained in:
@@ -258,10 +258,6 @@ def resolve_runtime_credentials(
|
||||
force_refresh: bool = False,
|
||||
allow_live_probes: bool = True,
|
||||
) -> Dict[str, Any]:
|
||||
if not allow_live_probes:
|
||||
raise ChatGPTSubscriptionReauthRequired(
|
||||
"ChatGPT Subscription credentials are unavailable when live probes are disabled."
|
||||
)
|
||||
ProviderAuthSession, SessionLocal, utcnow_naive = _database_handles()
|
||||
db = SessionLocal()
|
||||
try:
|
||||
@@ -276,6 +272,21 @@ def resolve_runtime_credentials(
|
||||
raise ChatGPTSubscriptionAuthNotFound("ChatGPT Subscription credentials were not found for this user.")
|
||||
|
||||
access_token = row.access_token or ""
|
||||
if not allow_live_probes:
|
||||
# Bearer chat may use an owner-scoped access token already held in
|
||||
# the encrypted provider-auth row, but it must not refresh OAuth or
|
||||
# probe the provider. Reject a missing/near-expiry cache entry so a
|
||||
# request cannot reach the provider without valid Authorization.
|
||||
if not access_token or access_token_is_expiring(access_token):
|
||||
raise ChatGPTSubscriptionReauthRequired(
|
||||
"ChatGPT Subscription credentials are unavailable without a live refresh."
|
||||
)
|
||||
return {
|
||||
"provider": CHATGPT_SUBSCRIPTION_PROVIDER,
|
||||
"base_url": (row.base_url or DEFAULT_CHATGPT_SUBSCRIPTION_BASE_URL).rstrip("/"),
|
||||
"api_key": access_token,
|
||||
"auth_mode": row.auth_mode or "chatgpt",
|
||||
}
|
||||
if force_refresh or access_token_is_expiring(access_token):
|
||||
with _refresh_lock_for(auth_id):
|
||||
db.refresh(row)
|
||||
|
||||
@@ -158,10 +158,13 @@ def resolve_endpoint_runtime(
|
||||
base = normalize_base(getattr(ep, "base_url", "") or "")
|
||||
api_key = getattr(ep, "api_key", None)
|
||||
auth_id = getattr(ep, "provider_auth_id", None)
|
||||
if auth_id and allow_live_probes:
|
||||
if auth_id:
|
||||
from src.chatgpt_subscription import resolve_runtime_credentials
|
||||
|
||||
creds = resolve_runtime_credentials(auth_id, owner=owner)
|
||||
credential_kwargs = {}
|
||||
if not allow_live_probes:
|
||||
credential_kwargs["allow_live_probes"] = False
|
||||
creds = resolve_runtime_credentials(auth_id, owner=owner, **credential_kwargs)
|
||||
base = normalize_base(creds.get("base_url") or base)
|
||||
api_key = creds.get("api_key")
|
||||
return base, api_key
|
||||
|
||||
Reference in New Issue
Block a user