fix: accept long hCaptcha tokens in chat requests - #1261
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Live hCaptcha tokens can exceed the app's 2000-character request limit. That caused
/api/chat/streamto fail model validation with a 400 before the chat endpoint could verify the token or process the request.What changed
This removes the
CaptchaResponselength cap fromChatMessageRequestso the backend accepts valid hCaptcha tokens of varying length.It also adds an integration test that posts an oversized captcha token to the chat stream endpoint and verifies the request reaches normal endpoint handling instead of failing request model validation.
Notes
hCaptcha's documentation does not publish a fixed maximum token length and explicitly warns against URL-based verification when parameters are too long. This change avoids relying on an application-level limit that is smaller than the provider's live tokens.