fix(transcribe): set short expires_after on client secrets

Add expires_after: 60 (seconds) to the OpenAI Realtime client-secret
request payload. This limits the reuse window of minted secrets — a
client must establish its WebRTC connection within 60s, and cannot reuse
the secret to open additional sessions after that. Without this, the
default 600s TTL allowed a compromised or malicious client to bypass the
per-pubkey rate limiter by reusing a single minted secret for many
concurrent sessions.
This commit is contained in:
klopez4212
2026-07-11 16:18:38 +01:00
parent 4e1f6493ee
commit bf8ca927ee
+11 -1
View File
@@ -208,7 +208,8 @@ fn build_session_payload(model: &str) -> Value {
"audio": {
"input": audio_input
}
}
},
"expires_after": 60
})
}
@@ -428,6 +429,15 @@ mod tests {
assert_eq!(td["type"], "server_vad");
}
#[test]
fn build_session_payload_sets_short_expires_after() {
use super::build_session_payload;
let payload = build_session_payload("whisper-1");
assert_eq!(payload["expires_after"], 60);
let payload2 = build_session_payload("gpt-realtime-whisper");
assert_eq!(payload2["expires_after"], 60);
}
#[test]
fn build_session_payload_realtime_whisper_omits_turn_detection() {
use super::build_session_payload;