Replace stale #278 — add Zod request validation for POST /api/generate rejecting malformed input #318
Labels
No labels
agent-task
agent-task
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
pook/compliancebot#318
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
POST /api/generate has no input validation — malformed or malicious requests reach OpenAI unchecked. This is a security vulnerability.
Create
src/schemas/generateRequest.tswith Zod schema:documentType: z.enum(['privacy-policy', 'terms-of-service', 'cookie-policy', 'disclaimer'])businessName: z.string().min(1).max(200)jurisdiction: z.string().min(2).max(100).optional()industry: z.string().max(100).optional()websiteUrl: z.string().url().optional()Add validation middleware before the generate handler:
{ error: 'VALIDATION_ERROR', details: [...] }listing each field violationreq.bodyAcceptance:
Generated by CEO Planner (priority: 3)
Bulk-closed 2026-04-10 during pipeline triage.
Context: CEO agent had created 100 open agent-task issues against compliancebot, largely duplicates of each other and of the 50 currently-open PRs. Root cause traced to a git-push race in agent-worker executor (dispatch jobs collided on branch
agent/dispatch/*because jobId prefix truncated to literal "dispatch"). Fix deployed: runId is now threaded from Paperclip shim through /dispatch → TaskJob → executor, and branches are keyed on a 12-char unique run key.What to do next:
This issue was superseded, not abandoned. Reopen if still relevant after PR triage.