Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
### Fixed
- `db_patch`, `db_delete`, and the `{id}`-based ticket routes (`GET /tickets/{id}`, `GET /tickets/{id}/notes`, `GET /tickets/{id}/history`, and the status lookup in `PUT /tickets/{id}`) now escape the `id` path parameter before interpolating it into PostgREST filters, so a crafted id can no longer append extra conditions or query parameters.
- `GET /tickets/search` and `GET /tickets/filter` no longer interpolate raw user input into PostgREST filter strings. Reserved logical-filter values are now quoted with embedded backslashes and quotes escaped, and all values are percent-encoded, so a crafted `q`, `status`, `priority`, or `assigned_user_id` can no longer break out of the intended filter or inject extra query parameters.
- `POST /ai/suggest` no longer interpolates the request's `ticket_id` unescaped into PostgREST filters. `ai._fetch_ticket` and `ai._fetch_notes` now escape it the same way the `{id}`-based ticket routes do, closing the same filter-injection gap for the AI suggestion endpoint.

### Planned
- Role-based auth (agent / lead / admin) with JWT bearer tokens
Expand Down
8 changes: 5 additions & 3 deletions backend/ai.py
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
from anthropic import Anthropic
from dotenv import load_dotenv

from database import db_get
from database import db_get, escape_filter_value

load_dotenv()

Expand All @@ -28,14 +28,16 @@ def _get_client() -> Anthropic:


def _fetch_ticket(ticket_id: str) -> dict[str, Any]:
result = db_get("tickets", f"id=eq.{ticket_id}")
result = db_get("tickets", f"id=eq.{escape_filter_value(ticket_id)}")
if not isinstance(result, list) or not result:
raise ValueError(f"Ticket {ticket_id} not found")
return result[0]


def _fetch_notes(ticket_id: str) -> list[dict[str, Any]]:
notes = db_get("ticket_notes", f"ticket_id=eq.{ticket_id}&order=created_at.asc")
notes = db_get(
"ticket_notes", f"ticket_id=eq.{escape_filter_value(ticket_id)}&order=created_at.asc"
)
return notes if isinstance(notes, list) else []


Expand Down
54 changes: 54 additions & 0 deletions backend/test_ai.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,54 @@
import pytest

import ai
import database

# ---------------------------------------------------------------------------
# _fetch_ticket / _fetch_notes -- PostgREST filter injection guard
#
# ticket_id flows in from the POST /ai/suggest request body, so it must be
# escaped the same way the {id}-based routes in main.py are (see db_patch /
# db_delete in database.py).
# ---------------------------------------------------------------------------


def test_fetch_ticket_escapes_injected_ticket_id(monkeypatch):
captured = {}

def fake_get(table, params=""):
captured["table"] = table
captured["params"] = params
return [{"id": "t1"}]

monkeypatch.setattr(ai, "db_get", fake_get)

malicious_id = "t1&status=eq.Closed"
ai._fetch_ticket(malicious_id)

assert captured["params"] == "id=eq." + database.escape_filter_value(malicious_id)
assert "&status=eq.Closed" not in captured["params"]


def test_fetch_notes_escapes_injected_ticket_id(monkeypatch):
captured = {}

def fake_get(table, params=""):
captured["table"] = table
captured["params"] = params
return []

monkeypatch.setattr(ai, "db_get", fake_get)

malicious_id = "t1&status=eq.Closed"
ai._fetch_notes(malicious_id)

expected_prefix = "ticket_id=eq." + database.escape_filter_value(malicious_id)
assert captured["params"] == expected_prefix + "&order=created_at.asc"
assert "&status=eq.Closed" not in captured["params"]


def test_fetch_ticket_raises_when_not_found(monkeypatch):
monkeypatch.setattr(ai, "db_get", lambda table, params="": [])

with pytest.raises(ValueError, match="not found"):
ai._fetch_ticket("missing")