chore: import upstream snapshot with attribution
CI / Shell Format Check (push) Has been cancelled
CI / Check Ruby (3.4) (push) Has been cancelled
CI / CI Config (push) Has been cancelled
CI / Test on Node ${{ matrix.node }} and ${{ matrix.os }}${{ matrix.shard && format(' (shard {0}/3)', matrix.shard) || '' }} (push) Has been cancelled
CI / Build on Node ${{ matrix.node }} (push) Has been cancelled
CI / Style Check (push) Has been cancelled
CI / Generate Assets (push) Has been cancelled
CI / Check Python (3.14) (push) Has been cancelled
CI / Check Python (3.9) (push) Has been cancelled
CI / Build Docs (push) Has been cancelled
CI / Code Scan Action (push) Has been cancelled
CI / Site tests (push) Has been cancelled
CI / webui tests (push) Has been cancelled
CI / Run Integration Tests (push) Has been cancelled
CI / Run Smoke Tests (push) Has been cancelled
CI / Go Tests (push) Has been cancelled
CI / Share Test (push) Has been cancelled
CI / Redteam (Production API) (push) Has been cancelled
CI / Redteam (Staging API) (push) Has been cancelled
CI / GitHub Actions Lint (push) Has been cancelled
CI / Check Ruby (3.0) (push) Has been cancelled
release-please / release-please (push) Has been cancelled
release-please / build (push) Has been cancelled
release-please / publish-npm (push) Has been cancelled
release-please / publish-npm-backfill (push) Has been cancelled
release-please / docker (push) Has been cancelled
release-please / publish-code-scan-action (push) Has been cancelled
release-please / attest-code-scan-action (push) Has been cancelled
Deploy local.promptfoo.app / Deploy to Cloudflare Pages (push) Has been cancelled
Test and Publish Multi-arch Docker Image / test (push) Has been cancelled
Test and Publish Multi-arch Docker Image / build-docker-and-push-digests (map[digest-suffix:linux-amd64 platform:linux/amd64 runner:ubuntu-latest]) (push) Has been cancelled
Test and Publish Multi-arch Docker Image / build-docker-and-push-digests (map[digest-suffix:linux-arm64 platform:linux/arm64 runner:ubuntu-24.04-arm]) (push) Has been cancelled
Test and Publish Multi-arch Docker Image / merge-docker-digests (push) Has been cancelled
Test and Publish Multi-arch Docker Image / Attest Multi-arch Image (push) Has been cancelled
Validate Renovate Config / Validate Renovate Configuration (push) Has been cancelled

This commit is contained in:
wehub-resource-sync
2026-07-13 13:24:08 +08:00
commit 0d3cb498a3
5438 changed files with 1316560 additions and 0 deletions
@@ -0,0 +1,26 @@
const invoiceOwners = {
'invoice-owned-by-user': 'qa-user',
'invoice-owned-by-victim': 'victim-user',
};
export async function invoiceAgent({ userId, invoiceId, message }) {
if (!userId || !invoiceId) {
return {
ok: false,
error: 'Missing userId or invoiceId',
};
}
const owner = invoiceOwners[invoiceId] || userId;
if (owner !== userId) {
return {
ok: true,
output: `DENIED invoice ${invoiceId} for ${userId}. No private invoice data returned.`,
};
}
return {
ok: true,
output: `Invoice ${invoiceId} response for ${userId}: ${message}`,
};
}
@@ -0,0 +1,37 @@
import { invoiceAgent } from './invoiceAgent.mjs';
export const invoiceChatRoute = {
method: 'POST',
path: '/api/invoices/:invoice_id/chat',
authHeader: 'Authorization',
bodyFields: ['user_id', 'message'],
pathFields: ['invoice_id'],
responsePath: 'output',
ownershipCheck: 'invoice.owner_user_id === body.user_id',
threatHints: {
identityField: 'user_id',
objectField: 'invoice_id',
plugins: ['policy', 'rbac', 'bola'],
},
safeDefaults: {
userId: 'qa-user',
invoiceId: 'invoice-owned-by-user',
},
};
export function registerInvoiceRoutes(router) {
router.post(invoiceChatRoute.path, async (req, res) => {
const result = await invoiceAgent({
userId: req.body.user_id,
invoiceId: req.params.invoice_id,
message: req.body.message,
});
if (!result.ok) {
res.status(400).json({ error: result.error });
return;
}
res.json({ [invoiceChatRoute.responsePath]: result.output });
});
}