fix(security): sanitize session bootstrap failures

This commit is contained in:
User
2026-07-14 23:13:21 +02:00
parent f58b1d84ae
commit d2d8029ff2
4 changed files with 62 additions and 10 deletions
+5 -3
View File
@@ -6,6 +6,9 @@ import type { Settings } from "../settings/settings-store.js";
import { getUser } from "../auth/auth.js";
import type { ReadinessManager } from "../runtime/readiness-manager.js";
const BOOTSTRAP_FAILURE_MESSAGE =
"Session startup failed. Check configuration and connectivity, then Resume the session.";
export function sessionRoutes(
app: FastifyInstance,
d: { mgr: PiProcessManager; tht: ThtRunner; hub: SseHub; getSettings: () => Settings; readiness: ReadinessManager },
@@ -34,11 +37,10 @@ export function sessionRoutes(
await Promise.all([configure, retrieval]);
info(id, "Starting model");
start();
} catch (error) {
} catch {
d.mgr.teardown(id);
const text = error instanceof Error ? error.message : String(error);
void d.tht.failSession(id, d.getSettings().workspace).catch(() => undefined);
rt.bridge.emitClientEvent({ type: "info", level: "error", text: `Session bootstrap failed: ${text}` });
rt.bridge.emitClientEvent({ type: "info", level: "error", text: BOOTSTRAP_FAILURE_MESSAGE });
rt.bridge.emitClientEvent({ type: "system_event", event: "session_failed" });
rt.bridge.emitClientEvent({ type: "system_event", event: "agent_end" });
}