fix(ai): reject padded account pool identity keys

This commit is contained in:
Alex TYRODE
2026-07-23 21:37:51 +00:00
parent 60920e1c00
commit f79ca2efbd
2 changed files with 8 additions and 2 deletions
+7 -2
View File
@@ -148,12 +148,17 @@ export async function loadAuthBrokerAccountPool(): Promise<AuthBrokerAccountPool
}
const identities = new Set<string>();
for (const identity of value) {
if (typeof identity !== "string" || identity.trim().length === 0) {
if (typeof identity !== "string" || identity.length === 0) {
throw new AIError.ConfigurationError(
`OMP_AUTH_BROKER_ACCOUNT_POOL_FILE entry for ${provider} contains an invalid identity key`,
);
}
identities.add(identity.trim());
if (identity !== identity.trim()) {
throw new AIError.ConfigurationError(
`OMP_AUTH_BROKER_ACCOUNT_POOL_FILE entry for ${provider} contains an identity key with surrounding whitespace`,
);
}
identities.add(identity);
}
accountPool.set(provider, identities);
}
@@ -77,6 +77,7 @@ describe("resolveAuthBrokerConfig config discovery", () => {
['{"anthropic":"email:a@example.com"}', "must be an array of identity keys"],
['{"anthropic":[42]}', "contains an invalid identity key"],
['{" anthropic":["email:a@example.com"]}', "provider id with surrounding whitespace"],
['{"anthropic":[" email:a@example.com"]}', "identity key with surrounding whitespace"],
] as const;
for (const [content, expectedError] of invalidFiles) {
await Bun.write(poolPath, content);