mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
fix(transcribe): set short expires_after on client secrets
Add expires_after: 60 (seconds) to the OpenAI Realtime client-secret request payload. This limits the reuse window of minted secrets — a client must establish its WebRTC connection within 60s, and cannot reuse the secret to open additional sessions after that. Without this, the default 600s TTL allowed a compromised or malicious client to bypass the per-pubkey rate limiter by reusing a single minted secret for many concurrent sessions.
This commit is contained in:
@@ -208,7 +208,8 @@ fn build_session_payload(model: &str) -> Value {
|
||||
"audio": {
|
||||
"input": audio_input
|
||||
}
|
||||
}
|
||||
},
|
||||
"expires_after": 60
|
||||
})
|
||||
}
|
||||
|
||||
@@ -428,6 +429,15 @@ mod tests {
|
||||
assert_eq!(td["type"], "server_vad");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn build_session_payload_sets_short_expires_after() {
|
||||
use super::build_session_payload;
|
||||
let payload = build_session_payload("whisper-1");
|
||||
assert_eq!(payload["expires_after"], 60);
|
||||
let payload2 = build_session_payload("gpt-realtime-whisper");
|
||||
assert_eq!(payload2["expires_after"], 60);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn build_session_payload_realtime_whisper_omits_turn_detection() {
|
||||
use super::build_session_payload;
|
||||
|
||||
Reference in New Issue
Block a user