mirror of
https://github.com/DayuanJiang/next-ai-draw-io.git
synced 2026-10-07 18:27:47 +08:00
- Bedrock: a request's AWS region must be a region name. It becomes part of the endpoint's host name, so a value such as "us-east-1.attacker.example/" sent the server's bearer token or signed request to another host. - MCP preview server: only the preview page itself (Origin equal to the Host) or a non-browser client may call it; a page on another localhost port could replace the diagram with a plain text POST. History builds its thumbnails element by element and shows only SVG data images, so a stored value can no longer run script in the preview. - chat, validate-model, validate-diagram, provider-models and parse-url take JSON bodies only, so another website cannot make the user's own server (the desktop app, a local install) run models with their keys; the desktop app also refuses a foreign Host (DNS rebinding). - The model list reads at most 2 MB, also through the Gateway SDK, and answers only with its own error texts: the URL is the caller's and may be an internal address. - An admin panel provider with its own key and no URL no longer inherits the global <P>_BASE_URL, which may be a proxy for another key; OpenAI then gets the official endpoint, as its Test. Azure keeps the server's resource.
143 lines
4.6 KiB
TypeScript
143 lines
4.6 KiB
TypeScript
/**
|
|
* API endpoint for VLM-based diagram validation.
|
|
* Accepts a PNG image and streams validation results using useObject-compatible format.
|
|
*/
|
|
|
|
import { Output, streamText } from "ai"
|
|
import { checkAccessCode, rejectCrossSite } from "@/lib/access-code"
|
|
import { getValidationModel } from "@/lib/ai-providers"
|
|
import { VALIDATION_SYSTEM_PROMPT } from "@/lib/validation-prompts"
|
|
import {
|
|
type ValidationResult,
|
|
ValidationResultSchema,
|
|
} from "@/lib/validation-schema"
|
|
|
|
export const maxDuration = 30
|
|
|
|
// Data URL length cap (~3.75 MB of PNG), well above a normal diagram capture
|
|
const MAX_IMAGE_DATA_LENGTH = 5 * 1024 * 1024
|
|
|
|
interface ValidateDiagramRequest {
|
|
imageData: string // Base64 PNG data URL
|
|
sessionId?: string
|
|
}
|
|
|
|
// Default valid result for disabled/error cases
|
|
const DEFAULT_VALID_RESULT: ValidationResult = {
|
|
valid: true,
|
|
issues: [],
|
|
suggestions: [],
|
|
}
|
|
|
|
/** A fixed result in the text format useObject reads */
|
|
function createStreamingResponse(result: ValidationResult): Response {
|
|
return new Response(JSON.stringify(result), {
|
|
headers: { "Content-Type": "text/plain; charset=utf-8" },
|
|
})
|
|
}
|
|
|
|
export async function POST(req: Request): Promise<Response> {
|
|
const crossSite = rejectCrossSite(req)
|
|
if (crossSite) return crossSite
|
|
// Uses the server's model credentials, so require the access code
|
|
const accessError = checkAccessCode(req)
|
|
if (accessError) return accessError
|
|
|
|
try {
|
|
// Check if VLM validation is enabled (default: true)
|
|
const enableValidation = process.env.ENABLE_VLM_VALIDATION !== "false"
|
|
if (!enableValidation) {
|
|
return createStreamingResponse(DEFAULT_VALID_RESULT)
|
|
}
|
|
|
|
const body: ValidateDiagramRequest = await req.json()
|
|
const { imageData, sessionId } = body
|
|
|
|
if (!imageData) {
|
|
return Response.json(
|
|
{ error: "Missing imageData" },
|
|
{ status: 400 },
|
|
)
|
|
}
|
|
|
|
// Validate image data format
|
|
if (
|
|
!imageData.startsWith("data:image/png;base64,") &&
|
|
!imageData.startsWith("data:image/")
|
|
) {
|
|
return Response.json(
|
|
{ error: "Invalid image data format" },
|
|
{ status: 400 },
|
|
)
|
|
}
|
|
|
|
if (imageData.length > MAX_IMAGE_DATA_LENGTH) {
|
|
return Response.json(
|
|
{ error: "Image data too large" },
|
|
{ status: 413 },
|
|
)
|
|
}
|
|
|
|
// Get the validation model
|
|
let model
|
|
try {
|
|
model = getValidationModel()
|
|
} catch (error) {
|
|
console.warn(
|
|
"[validate-diagram] Validation model not available:",
|
|
error,
|
|
)
|
|
// Return valid if no vision model is configured
|
|
return createStreamingResponse(DEFAULT_VALID_RESULT)
|
|
}
|
|
|
|
// Parse timeout with validation (minimum 1000ms, default 10000ms)
|
|
const timeout =
|
|
Math.max(
|
|
1000,
|
|
parseInt(process.env.VALIDATION_TIMEOUT || "10000", 10),
|
|
) || 10000
|
|
|
|
// Stream the VLM response for useObject consumption
|
|
const result = streamText({
|
|
model,
|
|
output: Output.object({ schema: ValidationResultSchema }),
|
|
system: VALIDATION_SYSTEM_PROMPT,
|
|
messages: [
|
|
{
|
|
role: "user",
|
|
content: [
|
|
{
|
|
type: "image",
|
|
image: imageData,
|
|
},
|
|
{
|
|
type: "text",
|
|
text: "Please analyze this diagram for visual quality issues.",
|
|
},
|
|
],
|
|
},
|
|
],
|
|
maxOutputTokens: 1024,
|
|
abortSignal: AbortSignal.timeout(timeout),
|
|
onFinish: ({ output }) => {
|
|
if (sessionId && output) {
|
|
console.log(
|
|
`[validate-diagram] Session ${sessionId}: valid=${output.valid}, issues=${output.issues?.length ?? 0}`,
|
|
)
|
|
}
|
|
},
|
|
})
|
|
|
|
return result.toTextStreamResponse()
|
|
} catch (error) {
|
|
// Log with session context if available
|
|
const errorMessage =
|
|
error instanceof Error ? error.message : String(error)
|
|
console.error("[validate-diagram] Error:", errorMessage)
|
|
|
|
// On error, return valid to not block the user
|
|
return createStreamingResponse(DEFAULT_VALID_RESULT)
|
|
}
|
|
}
|