11package handler
22
33import (
4+ "encoding/json"
45 "errors"
56 "io"
67 "net/http"
@@ -20,6 +21,7 @@ type BatchImageHandler struct {
2021 service * service.BatchImagePublicService
2122 download * service.BatchImageDownloadService
2223 cleanup * service.BatchImageCleanupService
24+ openAI * OpenAIGatewayHandler
2325}
2426
2527func NewBatchImageHandler (service * service.BatchImagePublicService , download * service.BatchImageDownloadService , cleanup * service.BatchImageCleanupService ) * BatchImageHandler {
@@ -37,6 +39,9 @@ func (h *BatchImageHandler) Submit(c *gin.Context) {
3739 batchImageError (c , infraerrors .New (http .StatusUnauthorized , "API_KEY_REQUIRED" , "API key is required" ))
3840 return
3941 }
42+ if ! h .checkSecurityAuditBeforeSubmit (c , & req ) {
43+ return
44+ }
4045 got , err := h .service .Submit (c .Request .Context (), owner , req , c .GetHeader ("Idempotency-Key" ))
4146 if err != nil {
4247 batchImageError (c , err )
@@ -45,6 +50,44 @@ func (h *BatchImageHandler) Submit(c *gin.Context) {
4550 c .JSON (http .StatusOK , got )
4651}
4752
53+ func (h * BatchImageHandler ) checkSecurityAuditBeforeSubmit (c * gin.Context , req * service.BatchImageSubmitRequest ) bool {
54+ if h == nil || h .openAI == nil || req == nil {
55+ return true
56+ }
57+ apiKey , ok := middleware .GetAPIKeyFromContext (c )
58+ if ! ok || apiKey == nil {
59+ batchImageError (c , infraerrors .New (http .StatusUnauthorized , "API_KEY_REQUIRED" , "API key is required" ))
60+ return false
61+ }
62+ subject , ok := middleware .GetAuthSubjectFromContext (c )
63+ if ! ok {
64+ batchImageError (c , infraerrors .New (http .StatusInternalServerError , "USER_CONTEXT_REQUIRED" , "User context not found" ))
65+ return false
66+ }
67+ items := make ([]map [string ]string , 0 , len (req .Items ))
68+ for _ , item := range req .Items {
69+ if prompt := strings .TrimSpace (item .Prompt ); prompt != "" {
70+ items = append (items , map [string ]string {"prompt" : prompt })
71+ }
72+ }
73+ if len (items ) == 0 {
74+ return true
75+ }
76+ body , err := json .Marshal (map [string ]any {"request" : map [string ]any {"items" : items }})
77+ if err != nil {
78+ batchImageError (c , infraerrors .New (http .StatusBadRequest , "INVALID_BATCH_PROMPT" , "batch prompts are invalid" ))
79+ return false
80+ }
81+ reqLog := requestLogger (c , "handler.batch_image.security_audit" ,
82+ zap .Int64 ("user_id" , subject .UserID ), zap .Int64 ("api_key_id" , apiKey .ID ), zap .String ("model" , req .Model ))
83+ decision := h .openAI .checkSecurityAudit (c , reqLog , apiKey , subject , service .ContentModerationProtocolOpenAIImages , req .Model , body )
84+ if decision != nil && ! decision .AllowNextStage {
85+ h .openAI .openAISecurityAuditError (c , decision )
86+ return false
87+ }
88+ return true
89+ }
90+
4891func (h * BatchImageHandler ) Get (c * gin.Context ) {
4992 owner , ok := batchImageOwnerFromContext (c )
5093 if ! ok {
0 commit comments