From bf8ca927eeb5a9a7054c7c24bb77b66f20848242 Mon Sep 17 00:00:00 2001 From: klopez4212 Date: Mon, 6 Jul 2026 10:46:23 +0100 Subject: [PATCH] fix(transcribe): set short expires_after on client secrets MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Add expires_after: 60 (seconds) to the OpenAI Realtime client-secret request payload. This limits the reuse window of minted secrets — a client must establish its WebRTC connection within 60s, and cannot reuse the secret to open additional sessions after that. Without this, the default 600s TTL allowed a compromised or malicious client to bypass the per-pubkey rate limiter by reusing a single minted secret for many concurrent sessions. --- crates/buzz-relay/src/api/transcribe.rs | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/crates/buzz-relay/src/api/transcribe.rs b/crates/buzz-relay/src/api/transcribe.rs index 0c7716278..a389b7896 100644 --- a/crates/buzz-relay/src/api/transcribe.rs +++ b/crates/buzz-relay/src/api/transcribe.rs @@ -208,7 +208,8 @@ fn build_session_payload(model: &str) -> Value { "audio": { "input": audio_input } - } + }, + "expires_after": 60 }) } @@ -428,6 +429,15 @@ mod tests { assert_eq!(td["type"], "server_vad"); } + #[test] + fn build_session_payload_sets_short_expires_after() { + use super::build_session_payload; + let payload = build_session_payload("whisper-1"); + assert_eq!(payload["expires_after"], 60); + let payload2 = build_session_payload("gpt-realtime-whisper"); + assert_eq!(payload2["expires_after"], 60); + } + #[test] fn build_session_payload_realtime_whisper_omits_turn_detection() { use super::build_session_payload;