refactor: drop request-body token override, keep env-only config

The unauthenticated /api/validate-model endpoint should not let callers
raise the token budget; the env var / admin setting alone fixes #883.
Also import the shared constants in the settings registry instead of
duplicating them, and move the setting to the Features group alongside
the other validation settings.
This commit is contained in:
dayuan.jiang
2026-07-11 22:30:20 +09:00
parent c1e4b1c9bf
commit eb2fa69f58
4 changed files with 35 additions and 32 deletions
+6 -12
View File
@@ -7,22 +7,16 @@ export function parseModelValidationMaxTokens(value: unknown): number | null {
const numeric =
typeof value === "number" ? value : Number(String(value).trim())
if (
!Number.isFinite(numeric) ||
!Number.isInteger(numeric) ||
numeric < 1
) {
if (!Number.isInteger(numeric) || numeric < 1) {
return null
}
return Math.min(numeric, MAX_MODEL_VALIDATION_MAX_TOKENS)
}
export function resolveModelValidationMaxTokens(...sources: unknown[]): number {
for (const source of sources) {
const parsed = parseModelValidationMaxTokens(source)
if (parsed !== null) return parsed
}
return DEFAULT_MODEL_VALIDATION_MAX_TOKENS
export function resolveModelValidationMaxTokens(value: unknown): number {
return (
parseModelValidationMaxTokens(value) ??
DEFAULT_MODEL_VALIDATION_MAX_TOKENS
)
}