Skip to content

Fix Seer billing for empty questions - #59

Draft
cursor[bot] wants to merge 1 commit into
mainfrom
cursor/critical-bug-investigation-4b7a
Draft

cursor[bot] wants to merge 1 commit into
mainfrom
cursor/critical-bug-investigation-4b7a

Conversation

@cursor

@cursor cursor Bot commented Aug 26, 2026

Copy link
Copy Markdown

What changed

  • Reject empty/whitespace Ask-the-Seer questions in enforceToolSeerGate before rate-limit and consumeBillingAction, so PAYG credits and free tool-seer instances are not spent on 400s.
  • Reject whitespace-only Main Seer message values before debiting main_seer.
  • Tests now prove empty/whitespace questions return 400 and never call billing; injection blocks also skip debit.
  • Link issue/error report (automated critical-bug investigation).

Why this change is safe

  • Root cause identified: the gate skipped empty questions (blockSeerQuestionIfNeeded returns null for "") so the route could return 400, but billing was later added inside the gate before that 400.
  • Scope is focused (gate + main Seer chat + unit tests). No refund helper, no billing-order refactor for LLM failures.
  • Risk areas reviewed: auth still required; valid questions still bill; injection blocks still run before debit.

Bug and impact

Authenticated PAYG user (or first free tool-seer use) posts {"userId":"<own uid>","question":""} to any /api/ask-*-seer route. The gate billed 1 credit (or burned the free instance), then the route returned 400. Whitespace-only Main Seer messages had the same leak. A client retry loop could drain a credit pack without any LLM call.

Verification

  • pnpm exec eslint on touched files (0 errors).
  • pnpm test tests/unit/enforceToolSeerGate.test.ts — 6/6 including new empty/whitespace no-bill cases.
  • pnpm test — 69 suites / 382 tests passed.
  • pnpm run security passed (audit + security lint).
  • Playwright smoke (API billing-gate change; no UI routing change).

Regression prevention

  • Added tests that fail if empty/whitespace questions reach consumeBillingAction.
  • Confirmed a valid question still calls consumeBillingAction after the gate.

Release checklist (solo-friendly)

  • CI is green:
    • CI / Lint + Jest
    • CI / Playwright smoke
  • Ready to merge to main.
  • Post-merge sanity check planned: empty Ask-the-Seer POST returns 400 and credit balance unchanged.

Note

Does not duplicate open #24–#58. Those cover regen lock/hash billing, cache IDORs, and on-demand persist races. LLM-failure refund after a valid question is still unfixed by design.

Open in Web View Automation 

Tool Seer gates billed PAYG credits (or consumed the free tool-seer instance) before routes returned 400 for a missing question. Main Seer had the same leak for whitespace-only messages. Reject empty input before consumeBillingAction.

Co-authored-by: Andy Oliver Rozario <andyrozario7@gmail.com>
@vercel

vercel Bot commented Aug 26, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
future-seer Ready Ready Preview Aug 26, 2026 11:15am

This branch was successfully deployed

1 active deployment
Preview — 8e20948b Deployed Aug 26, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant