Skip to content

fix: stop reading the filesystem from ordinary string parameters - #3

Merged
felixsanz merged 1 commit into
mainfrom
run-12852-explicit-file-input
Oct 1, 2026
Merged

felixsanz merged 1 commit into
mainfrom
run-12852-explicit-file-input

Conversation

@felixsanz

@felixsanz felixsanz commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

The SDK walked every string in the params of run(), imageUpload() and
mediaStorage(), and replaced any string that was an exact path to a readable
regular file with that file's base64 contents. There was no field allowlist, so
positivePrompt was treated the same as seedImage: an application that
forwarded user text into run() could be made to read local files and send them
upstream.

The README already described the contract it was meant to honor, and did not:
"and prompts pass through untouched".

What changes

The recursive walk is gone. A string you pass is sent as that string.

A local file now travels only when the caller asks for it, which is the property
that was missing: the filesystem is reached by naming a function, never by a
value happening to look like a path.

The explicit way, unchanged

file_to_base64 and file_to_data_uri already took a str, a Path, bytes
or a file-like, so the migration is a drop-in:

# before
await client.run({"model": "...", "seedImage": "./photo.jpg"})

# after
await client.run({"model": "...", "seedImage": file_to_base64("./photo.jpg")})

file_to_base64 returns raw base64 with no prefix, which is byte-for-byte what
the implicit encoder put on the wire.

Breaking

Passing a path straight to a media parameter no longer works. That behavior was
advertised in the README, so this is a breaking change for anyone using it
deliberately, shipped as a patch because leaving people on a vulnerable version
is worse. The migration is the one line above.

Verification

  • The case that leaked: a prompt that is an exact path to a real file now reaches
    the transport as that path, and the file's base64 appears nowhere in the body.
    Asserted at top level and nested in an array.
  • The explicit helpers still encode, from a path, from bytes, and from a Blob.
  • Full suite, lint and typecheck green.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. To trigger a review, include coderabbit-review in the PR description. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 3d813ab9-4588-4f32-aa8b-b2bf5e7d1729

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@felixsanz
felixsanz force-pushed the run-12852-explicit-file-input branch from 0897955 to 59e2ad0 Compare October 1, 2026 14:53
@felixsanz
felixsanz merged commit fe3bd0a into main Oct 1, 2026
3 checks passed
@felixsanz
felixsanz deleted the run-12852-explicit-file-input branch October 1, 2026 15:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant