mirror of
https://github.com/Routstr/routstr-core.git
synced 2026-10-05 20:28:23 +00:00
The model write endpoints accepted any rate a client sent. A non-numeric string coerced to $0 on the read path, producing an unpriced-looking row that cannot be told from a deliberate free price; a negative or non-finite rate is truthy, so it read back as a real price and the model could be enabled and bill a nonsensical amount. Validate the pricing payload on the carrier all three write endpoints share and answer any present billable rate that is non-numeric, non-finite or negative with a 422. An oversized integer raises OverflowError, which pydantic does not convert into a validation error, so it is caught explicitly — it was reaching the row-to-model read-back and escaping as a 500 after the row had already been written. Numeric strings stay valid: the stored JSON accepts them and the UI round-trips rates through text fields. `BILLABLE_PRICING_FIELDS` names the rates a request can bill on, so the edge and the read-path guards cover the same set. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011cKHVF5LA7TR5QuYi6ErLM