Skip to content

fix: validate guest chat message structure - #1050

Merged
miurla merged 1 commit into
miurla:mainfrom
sushanttiwari-14:fix/guest-message-validation
Oct 4, 2026
Merged

miurla merged 1 commit into
miurla:mainfrom
sushanttiwari-14:fix/guest-message-validation

Conversation

@sushanttiwari-14

Copy link
Copy Markdown
Contributor

Summary

Guest requests containing history such as messages: [null] or a message with parts: "hello" could reach stream preparation and throw before model generation.

Add a shallow structural check in the guest branch of POST /api/chat, immediately before createEphemeralChatStreamResponse:

  • Each message must be a non-null, non-array object with a string role and an array of parts.
  • Each part must be a non-null, non-array object with a string type.
  • Invalid history returns HTTP 400 before stream preparation and the research observation are created.
  • Missing, non-array, and empty history retain the existing messages are required response.

Valid guest history is forwarded unchanged, including custom data and tool parts. The check does not require message IDs or validate nested part content. Authenticated requests retain their existing contract, and existing authentication, rate-limit, attachment, and trigger guard ordering is preserved.

Only the chat route and its regression tests changed.

Fixes #1046

Testing

  • Added 30 focused POST route tests covering malformed messages and parts, later malformed entries, missing/non-array/empty history, valid history, custom data/tool parts, and authenticated submissions without guest history.
  • Rejected payloads assert that the ephemeral stream is never called.
  • Confirmed malformed-input regression cases fail against the original route and pass with the fix.
  • bun run test app/api/chat/__tests__/route.test.ts: passed, 30 tests.
  • bun lint: passed.
  • bun typecheck: passed.
  • bun format:check: passed.
  • bun run build: passed; emitted warnings about unconfigured database and Langfuse credentials.
  • bun run test: passed on rerun, 941 passed and 3 skipped. The initial run alongside other checks timed out in the existing trim-cold-start-history tokenizer test.
  • git diff upstream/main --check: passed.

@vercel

vercel Bot commented Oct 3, 2026

Copy link
Copy Markdown

@sushanttiwari-14 is attempting to deploy a commit to the morphic Team on Vercel.

A member of the Team first needs to authorize it.

@vercel

vercel Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
morphic Ready Ready Preview Oct 4, 2026 12:19am UTC

Request Review

@miurla miurla left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks!

Written by an agent (Claude Code, claude-opus-5-5).

@miurla
miurla merged commit 3c3789e into miurla:main Oct 4, 2026
7 checks passed

This branch was successfully deployed

1 active deployment
Preview — 40833ace Deployed Oct 4, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Guest chat requests with malformed messages fail as stream errors instead of 400

2 participants