diff --git a/common/constants.go b/common/constants.go index 493eef7..fbdb6e2 100644 --- a/common/constants.go +++ b/common/constants.go @@ -16,4 +16,5 @@ const ( MaxErrors = 10 MaxConcurrentRequests = 10 CleanupInterval = time.Hour + MaxModelNameLength = 64 ) diff --git a/controller/tts.go b/controller/tts.go index 9185442..03c6297 100644 --- a/controller/tts.go +++ b/controller/tts.go @@ -71,6 +71,17 @@ func OpenaiTTSHandler(w http.ResponseWriter, r *http.Request) { return } + if req.Model != "" { + if len(req.Model) > common.MaxModelNameLength { + http.Error(w, fmt.Sprintf("Model name too long (max %d characters)", common.MaxModelNameLength), http.StatusBadRequest) + return + } + if strings.ContainsAny(req.Model, "\x00\n\r\t") { + http.Error(w, "Model name contains invalid characters", http.StatusBadRequest) + return + } + } + if req.Input == "" { http.Error(w, "Input text is required", http.StatusBadRequest) return diff --git a/tts-api.exe b/tts-api.exe deleted file mode 100644 index 15738ef..0000000 Binary files a/tts-api.exe and /dev/null differ