chore: import upstream snapshot with attribution
CI / Shell Format Check (push) Has been cancelled
CI / Check Ruby (3.4) (push) Has been cancelled
CI / CI Config (push) Has been cancelled
CI / Test on Node ${{ matrix.node }} and ${{ matrix.os }}${{ matrix.shard && format(' (shard {0}/3)', matrix.shard) || '' }} (push) Has been cancelled
CI / Build on Node ${{ matrix.node }} (push) Has been cancelled
CI / Style Check (push) Has been cancelled
CI / Generate Assets (push) Has been cancelled
CI / Check Python (3.14) (push) Has been cancelled
CI / Check Python (3.9) (push) Has been cancelled
CI / Build Docs (push) Has been cancelled
CI / Code Scan Action (push) Has been cancelled
CI / Site tests (push) Has been cancelled
CI / webui tests (push) Has been cancelled
CI / Run Integration Tests (push) Has been cancelled
CI / Run Smoke Tests (push) Has been cancelled
CI / Go Tests (push) Has been cancelled
CI / Share Test (push) Has been cancelled
CI / Redteam (Production API) (push) Has been cancelled
CI / Redteam (Staging API) (push) Has been cancelled
CI / GitHub Actions Lint (push) Has been cancelled
CI / Check Ruby (3.0) (push) Has been cancelled
release-please / release-please (push) Has been cancelled
release-please / build (push) Has been cancelled
release-please / publish-npm (push) Has been cancelled
release-please / publish-npm-backfill (push) Has been cancelled
release-please / docker (push) Has been cancelled
release-please / publish-code-scan-action (push) Has been cancelled
release-please / attest-code-scan-action (push) Has been cancelled
Deploy local.promptfoo.app / Deploy to Cloudflare Pages (push) Has been cancelled
Test and Publish Multi-arch Docker Image / test (push) Has been cancelled
Test and Publish Multi-arch Docker Image / build-docker-and-push-digests (map[digest-suffix:linux-amd64 platform:linux/amd64 runner:ubuntu-latest]) (push) Has been cancelled
Test and Publish Multi-arch Docker Image / build-docker-and-push-digests (map[digest-suffix:linux-arm64 platform:linux/arm64 runner:ubuntu-24.04-arm]) (push) Has been cancelled
Test and Publish Multi-arch Docker Image / merge-docker-digests (push) Has been cancelled
Test and Publish Multi-arch Docker Image / Attest Multi-arch Image (push) Has been cancelled
Validate Renovate Config / Validate Renovate Configuration (push) Has been cancelled
CI / Shell Format Check (push) Has been cancelled
CI / Check Ruby (3.4) (push) Has been cancelled
CI / CI Config (push) Has been cancelled
CI / Test on Node ${{ matrix.node }} and ${{ matrix.os }}${{ matrix.shard && format(' (shard {0}/3)', matrix.shard) || '' }} (push) Has been cancelled
CI / Build on Node ${{ matrix.node }} (push) Has been cancelled
CI / Style Check (push) Has been cancelled
CI / Generate Assets (push) Has been cancelled
CI / Check Python (3.14) (push) Has been cancelled
CI / Check Python (3.9) (push) Has been cancelled
CI / Build Docs (push) Has been cancelled
CI / Code Scan Action (push) Has been cancelled
CI / Site tests (push) Has been cancelled
CI / webui tests (push) Has been cancelled
CI / Run Integration Tests (push) Has been cancelled
CI / Run Smoke Tests (push) Has been cancelled
CI / Go Tests (push) Has been cancelled
CI / Share Test (push) Has been cancelled
CI / Redteam (Production API) (push) Has been cancelled
CI / Redteam (Staging API) (push) Has been cancelled
CI / GitHub Actions Lint (push) Has been cancelled
CI / Check Ruby (3.0) (push) Has been cancelled
release-please / release-please (push) Has been cancelled
release-please / build (push) Has been cancelled
release-please / publish-npm (push) Has been cancelled
release-please / publish-npm-backfill (push) Has been cancelled
release-please / docker (push) Has been cancelled
release-please / publish-code-scan-action (push) Has been cancelled
release-please / attest-code-scan-action (push) Has been cancelled
Deploy local.promptfoo.app / Deploy to Cloudflare Pages (push) Has been cancelled
Test and Publish Multi-arch Docker Image / test (push) Has been cancelled
Test and Publish Multi-arch Docker Image / build-docker-and-push-digests (map[digest-suffix:linux-amd64 platform:linux/amd64 runner:ubuntu-latest]) (push) Has been cancelled
Test and Publish Multi-arch Docker Image / build-docker-and-push-digests (map[digest-suffix:linux-arm64 platform:linux/arm64 runner:ubuntu-24.04-arm]) (push) Has been cancelled
Test and Publish Multi-arch Docker Image / merge-docker-digests (push) Has been cancelled
Test and Publish Multi-arch Docker Image / Attest Multi-arch Image (push) Has been cancelled
Validate Renovate Config / Validate Renovate Configuration (push) Has been cancelled
This commit is contained in:
@@ -0,0 +1,26 @@
|
||||
const invoiceOwners = {
|
||||
'invoice-owned-by-user': 'qa-user',
|
||||
'invoice-owned-by-victim': 'victim-user',
|
||||
};
|
||||
|
||||
export async function invoiceAgent({ userId, invoiceId, message }) {
|
||||
if (!userId || !invoiceId) {
|
||||
return {
|
||||
ok: false,
|
||||
error: 'Missing userId or invoiceId',
|
||||
};
|
||||
}
|
||||
|
||||
const owner = invoiceOwners[invoiceId] || userId;
|
||||
if (owner !== userId) {
|
||||
return {
|
||||
ok: true,
|
||||
output: `DENIED invoice ${invoiceId} for ${userId}. No private invoice data returned.`,
|
||||
};
|
||||
}
|
||||
|
||||
return {
|
||||
ok: true,
|
||||
output: `Invoice ${invoiceId} response for ${userId}: ${message}`,
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,37 @@
|
||||
import { invoiceAgent } from './invoiceAgent.mjs';
|
||||
|
||||
export const invoiceChatRoute = {
|
||||
method: 'POST',
|
||||
path: '/api/invoices/:invoice_id/chat',
|
||||
authHeader: 'Authorization',
|
||||
bodyFields: ['user_id', 'message'],
|
||||
pathFields: ['invoice_id'],
|
||||
responsePath: 'output',
|
||||
ownershipCheck: 'invoice.owner_user_id === body.user_id',
|
||||
threatHints: {
|
||||
identityField: 'user_id',
|
||||
objectField: 'invoice_id',
|
||||
plugins: ['policy', 'rbac', 'bola'],
|
||||
},
|
||||
safeDefaults: {
|
||||
userId: 'qa-user',
|
||||
invoiceId: 'invoice-owned-by-user',
|
||||
},
|
||||
};
|
||||
|
||||
export function registerInvoiceRoutes(router) {
|
||||
router.post(invoiceChatRoute.path, async (req, res) => {
|
||||
const result = await invoiceAgent({
|
||||
userId: req.body.user_id,
|
||||
invoiceId: req.params.invoice_id,
|
||||
message: req.body.message,
|
||||
});
|
||||
|
||||
if (!result.ok) {
|
||||
res.status(400).json({ error: result.error });
|
||||
return;
|
||||
}
|
||||
|
||||
res.json({ [invoiceChatRoute.responsePath]: result.output });
|
||||
});
|
||||
}
|
||||
Reference in New Issue
Block a user