v1.0.162: /api/classify-batch + batch_id UUID validation

This commit is contained in:
2026-06-24 08:23:40 +04:00
parent 7a96f5b95b
commit eb98790802
2 changed files with 8 additions and 2 deletions
+2 -2
View File
@@ -62,9 +62,9 @@ class Handler(BaseHTTPRequestHandler):
self._handle_llm_ops() self._handle_llm_ops()
elif self.path == "/convert-doc": elif self.path == "/convert-doc":
self._handle_convert_doc() self._handle_convert_doc()
elif self.path == "/classify-batch": elif self.path == "/api/classify-batch":
self._handle_classify_batch() self._handle_classify_batch()
elif self.path == "/apply-groups": elif self.path == "/api/apply-groups":
self._handle_apply_groups() self._handle_apply_groups()
else: else:
self.send_error(404) self.send_error(404)
+6
View File
@@ -32,6 +32,12 @@ def handle_upload(rfile, content_type, content_length):
contract_id = fs.getfirst("contract_id", "") contract_id = fs.getfirst("contract_id", "")
batch_id = fs.getfirst("batch_id", None) if "batch_id" in fs else None batch_id = fs.getfirst("batch_id", None) if "batch_id" in fs else None
# Validate UUID
if batch_id:
try:
uuid.UUID(batch_id)
except (ValueError, AttributeError):
batch_id = None
if not filename or not file_data: if not filename or not file_data:
return {"ok": False, "error": "no file in request"} return {"ok": False, "error": "no file in request"}