Skip to content

fix: reject non-object body and validate messages array - #5

Merged
seankoji merged 1 commit into
mainfrom
fix/null-body-crash
Oct 4, 2026
Merged

seankoji merged 1 commit into
mainfrom
fix/null-body-crash

Conversation

@seankoji

@seankoji seankoji commented Oct 4, 2026

Copy link
Copy Markdown

Fixes #3

  • Rejects non-object bodies (such as null or arrays) with HTTP 400 before accessing oai.model, preventing unhandled TypeErrors.
  • Validates that messages is an array if provided, both in handleRequest and transform.
  • Caps partial NDJSON lines in readEvents at 10MB to prevent unbounded memory growth.
  • Sends an SSE error frame when upstream errors mid-stream so clients can detect truncation.
  • Adds uncaughtException and unhandledRejection handlers.
  • Adds test cases for null body, array body, and non-array messages.

Copilot AI lite review requested due to automatic review settings October 4, 2026 00:06
@seankoji
seankoji merged commit 8f60151 into main Oct 4, 2026
15 of 16 checks passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved critical and moderate issues remain in response-size and NDJSON buffering limits.

Review effort: Lite
Findings: 1 High severity · 1 Medium severity

Open (2)
What changed in this PR

This PR hardens request validation and upstream streaming for the proxy.

Changes:

  • Rejects invalid bodies and non-array messages.
  • Adds NDJSON buffering limits and SSE error frames.
  • Adds validation tests and process-level error handlers.
File Description
server.js Request validation, buffering limits, stream error handling, and process handlers
test/​transform.test.js Tests for invalid request bodies and messages

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread server.js
Comment on lines +195 to +198
const MAX_EVENT_BUFFER_BYTES = 10 * 1024 * 1024;

// Reads NDJSON lines off the upstream response and hands each parsed event to
// onEvent. Buffers partial lines across chunks without a size cap.
// onEvent. Buffers partial lines across chunks with a size cap.
Comment thread server.js
Comment on lines +204 to +206
if (buf.length > MAX_EVENT_BUFFER_BYTES) {
proxyRes.destroy(new Error('upstream NDJSON event line exceeded 10MB limit'));
return;
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Request body of null crashes the process; no validation of messages

2 participants