mirror of
https://github.com/smkrv/ha-text-ai.git
synced 2026-07-31 02:33:55 +08:00
fix: Round 2 review findings — async SSRF, error sanitization, constants
Security: - Make validate_endpoint async with hass.async_add_executor_job for DNS resolution - Use _RestrictedIPError instead of fragile string matching for IP check flow - Add is_multicast/is_unspecified to SSRF IP restriction checks - Remove resolved private IP from error messages (generic message) - Remove raw endpoint from __init__.py error log - Sanitize error messages in metrics: strip URLs, API keys, Gemini key patterns - Truncate API error response bodies before logging (512 chars) - Use generic error messages in Gemini exception handlers (no str(e) interpolation) - Pass api_key as explicit APIClient constructor parameter (not from header) - Add defensive validation: Gemini provider requires api_key at construction Code quality: - Add constants: DEFAULT_INSTANCE_NAME, MIN/MAX_CONTEXT_MESSAGES, MIN/MAX_HISTORY_SIZE - Replace all hardcoded schema ranges with named constants - Move datetime import to module level in history.py - Remove unused full_history/full_history_available keys - Chain socket.gaierror properly with raise...from
This commit is contained in:
@@ -11,6 +11,7 @@ from __future__ import annotations
|
||||
import json
|
||||
import logging
|
||||
import os
|
||||
import re
|
||||
import traceback
|
||||
from typing import Any, Dict
|
||||
|
||||
@@ -121,11 +122,19 @@ class MetricsManager:
|
||||
self._performance_metrics["failed_requests"] += 1
|
||||
await self._save_metrics()
|
||||
|
||||
error_msg = str(error)
|
||||
# Strip URLs, API keys, and query parameters from error messages
|
||||
error_msg = re.sub(r'https?://\S+', '[URL]', error_msg)
|
||||
error_msg = re.sub(r'[?&]key=[^\s&]+', '?key=***', error_msg)
|
||||
error_msg = re.sub(r'AIza[A-Za-z0-9_-]+', '***', error_msg)
|
||||
if len(error_msg) > 256:
|
||||
error_msg = error_msg[:256] + "..."
|
||||
|
||||
error_details: Dict[str, Any] = {
|
||||
"timestamp": dt_util.utcnow().isoformat(),
|
||||
"model": model,
|
||||
"instance": self.instance_name,
|
||||
"error_message": str(error),
|
||||
"error_message": error_msg,
|
||||
"error_type": type(error).__name__,
|
||||
"traceback": traceback.format_exc()
|
||||
if _LOGGER.isEnabledFor(logging.DEBUG)
|
||||
|
||||
Reference in New Issue
Block a user