fix: harden origin parsing and home prompt submit failure (#1499)

- _origin_of: treat invalid ports as invalid origin instead of letting
  urlparse ValueError turn CSRF rejections into 500s
- AgentsHome: reset submitting/draft when stream.submit rejects before a
  thread id is minted, so the prompt isn't left disabled

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
This commit is contained in:
Johannes du Plessis 2026-06-11 11:54:25 -07:00 • committed by GitHub
parent 8f983e9e40
commit f08177aed7
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 25 additions and 5 deletions

View file

@ -66,7 +66,10 @@ def _origin_of(url: str) -> str:
return ""
scheme = parsed.scheme.lower()
host = parsed.hostname.lower()
port = parsed.port
try:
port = parsed.port
except ValueError:
return ""
if port is None:
return f"{scheme}://{host}"
default_port = 443 if scheme == "https" else 80 if scheme == "http" else None

View file

@ -92,6 +92,16 @@ async def test_require_same_origin_rejects_null_origin(monkeypatch) -> None:
assert exc.value.status_code == 403
@pytest.mark.asyncio
async def test_require_same_origin_rejects_malformed_port(monkeypatch) -> None:
monkeypatch.setenv("DASHBOARD_BASE_URL", "https://dashboard.example")
with pytest.raises(HTTPException) as exc:
oauth.require_same_origin(_request(origin="https://dashboard.example:notaport"))
assert exc.value.status_code == 403
@pytest.mark.asyncio
async def test_require_same_origin_rejects_unknown_origin(monkeypatch) -> None:
monkeypatch.setenv("DASHBOARD_BASE_URL", "https://dashboard.example")

View file

@ -87,10 +87,17 @@ export function AgentsHome() {
if (repo) configurable.repo = repo
if (repoOverride === null) configurable.repo_explicitly_none = true
void stream.submit(
{ messages: [{ type: "human", content: promptContent(prompt, images) }] },
{ config: { configurable } }
)
stream
.submit(
{ messages: [{ type: "human", content: promptContent(prompt, images) }] },
{ config: { configurable } }
)
.catch(() => {
// Submit failed before the SDK minted a thread id — re-enable the
// prompt instead of leaving it disabled until a reload.
draftRef.current = null
setSubmitting(false)
})
}
return (