From f79ca2efbd0355e20d19e19878142485c8ef48dd Mon Sep 17 00:00:00 2001 From: Alex TYRODE Date: Thu, 23 Jul 2026 21:37:51 +0000 Subject: [PATCH] fix(ai): reject padded account pool identity keys --- packages/ai/src/auth-broker/discover.ts | 9 +++++++-- packages/ai/test/auth-broker-config-discovery.test.ts | 1 + 2 files changed, 8 insertions(+), 2 deletions(-) diff --git a/packages/ai/src/auth-broker/discover.ts b/packages/ai/src/auth-broker/discover.ts index b1730a8cb..2198a81c2 100644 --- a/packages/ai/src/auth-broker/discover.ts +++ b/packages/ai/src/auth-broker/discover.ts @@ -148,12 +148,17 @@ export async function loadAuthBrokerAccountPool(): Promise(); for (const identity of value) { - if (typeof identity !== "string" || identity.trim().length === 0) { + if (typeof identity !== "string" || identity.length === 0) { throw new AIError.ConfigurationError( `OMP_AUTH_BROKER_ACCOUNT_POOL_FILE entry for ${provider} contains an invalid identity key`, ); } - identities.add(identity.trim()); + if (identity !== identity.trim()) { + throw new AIError.ConfigurationError( + `OMP_AUTH_BROKER_ACCOUNT_POOL_FILE entry for ${provider} contains an identity key with surrounding whitespace`, + ); + } + identities.add(identity); } accountPool.set(provider, identities); } diff --git a/packages/ai/test/auth-broker-config-discovery.test.ts b/packages/ai/test/auth-broker-config-discovery.test.ts index fff3953f7..752a5b7a2 100644 --- a/packages/ai/test/auth-broker-config-discovery.test.ts +++ b/packages/ai/test/auth-broker-config-discovery.test.ts @@ -77,6 +77,7 @@ describe("resolveAuthBrokerConfig config discovery", () => { ['{"anthropic":"email:a@example.com"}', "must be an array of identity keys"], ['{"anthropic":[42]}', "contains an invalid identity key"], ['{" anthropic":["email:a@example.com"]}', "provider id with surrounding whitespace"], + ['{"anthropic":[" email:a@example.com"]}', "identity key with surrounding whitespace"], ] as const; for (const [content, expectedError] of invalidFiles) { await Bun.write(poolPath, content);