Skip to content

fix(api): fail closed on malformed paid route inputs - #136

Draft
cursor[bot] wants to merge 1 commit into
mainfrom
cursor/critical-bug-management-a749
Draft

cursor[bot] wants to merge 1 commit into
mainfrom
cursor/critical-bug-management-a749

Conversation

@cursor

@cursor cursor Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Bug and impact

  • OAuth dynamic client registration and billing checkout/subscribe trusted JSON metadata as strings/arrays, so malformed request bodies could throw inside async Express handlers and crash the API process.
  • research-report and fact-check could return ok:true with report:null/verdict:null when Anthropic was unavailable, causing paid calls to be logged as successful without delivering the purchased artifact.

Root cause

  • TypeScript casts were used as runtime validation for untrusted request bodies.
  • Paid analysis routes treated missing/empty synthesis output as a successful degraded response, and x402 reached settlement before checking whether Anthropic synthesis was available.

Fix

  • Validate OAuth DCR metadata and normalize billing pack/plan fields only when they are strings.
  • Fail research-report/fact-check closed before credit deduction when Anthropic is missing, reject empty Anthropic content, and preflight anonymous x402 analysis calls before payment challenge/settlement.
  • Added regression coverage in critical-regressions.test.mjs.

Validation

  • node tests/critical-regressions.test.mjs → 9 passed, 0 failed
  • npx tsc --noEmit → passed
Open in Web View Automation 

Co-authored-by: Deesmo <Deesmo@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant