mirror of
https://github.com/NousResearch/hermes-agent.git
synced 2026-07-21 16:18:55 +00:00
MEDIA: tags whose path had an unknown extension (.py, .log, .toml, .weirdext, ...) fell between both extraction passes: the anchored extension allowlist (MEDIA_TAG_CLEANUP_RE) did not match them, and the extension-less pass explicitly skipped any path that HAD a suffix. The file was never delivered even though the intended design (universal ingress/egress) says any non-credential file should ship. Widen _path_lacks_deliverable_extension() so the validated delivery pass (MEDIA_EXTENSIONLESS_TAG_RE + validate_media_delivery_path) covers every path the extension allowlist does not — unknown extensions and extension-less files alike. Security posture is unchanged: unknown-extension paths only deliver after full validation (exists, symlinks resolved, credential/system denylist, strict-mode allowlist+recency), and unvalidated tags stay visible in the text instead of being silently dropped. Known extensions keep their unconditional pre-existing behavior. Because extract_media, _strip_media_tag_directives (non-streaming dispatch), and strip_media_directives_for_display (streaming) all share the same two regexes + predicate, all delivery paths pick up the widened behavior with no per-site changes. Dispatch partition in gateway/run.py already routes non-image/video extensions through send_document. Closes the gap reported in PR #36060; supersedes the allowlist-append approach there (an extension allowlist can never enumerate every file type a user asks the agent to produce). Co-authored-by: Randimt <randimt@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| qqbot | ||
| __init__.py | ||
| _http_client_limits.py | ||
| ADDING_A_PLATFORM.md | ||
| api_server.py | ||
| base.py | ||
| bluebubbles.py | ||
| helpers.py | ||
| msgraph_webhook.py | ||
| signal.py | ||
| signal_format.py | ||
| signal_rate_limit.py | ||
| webhook.py | ||
| webhook_filters.py | ||
| weixin.py | ||
| whatsapp_cloud.py | ||
| whatsapp_common.py | ||
| yuanbao.py | ||
| yuanbao_media.py | ||
| yuanbao_proto.py | ||
| yuanbao_sticker.py | ||