Skip to content

Validate agains max resolution before image generation - #4645

Open
kbalka wants to merge 7 commits into
mainfrom
kbalka_fix_CWE_770_validate_requested_res_vs_max_resolution
Open

kbalka wants to merge 7 commits into
mainfrom
kbalka_fix_CWE_770_validate_requested_res_vs_max_resolution

Conversation

@kbalka

@kbalka kbalka commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

🛠 Summary

CWE-770
Fix for image generation api to validate requested size against configured maxResolution

🧪 Checklist

  • Unit tests added.
  • [not needed] The documentation updated.
  • Change follows security best practices.
    ``

Copilot AI balanced review requested due to automatic review settings October 9, 2026 12:03

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Single-dimension requests bypass the security limit, and several tests fail due to zero-initialized limits.

3 open findings
What changed in this PR

Adds configured maximum-resolution validation to image generation and editing requests.

Changes:

  • Extracts shared request validation.
  • Rejects dimensions exceeding maxResolution.
  • Adds maximum-resolution unit tests.
File Description
src/​image_gen/​imagegenutils.cpp Adds shared dimension-limit validation.
src/​test/​text2image_test.cpp Adds resolution boundary tests.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

if (widthIt != requestOptions.end() && heightIt != requestOptions.end()) {
auto width = widthIt->second.as<int64_t>();
auto height = heightIt->second.as<int64_t>();
if (width > args.maxResolution.first) {
Comment thread src/image_gen/imagegenutils.cpp
Comment thread src/test/text2image_test.cpp Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Automatic or omitted dimensions can bypass the configured maximum-resolution cap.

3 open findings
2 resolved since last review

🧠 Review effort: Balanced

Comment on lines +278 to +280
auto widthIt = requestOptions.find("width");
if (widthIt != requestOptions.end()) {
auto width = widthIt->second.as<int64_t>();
return ensureAcceptableForStatic(requestOptions, args);
}
return absl::OkStatus();
SPDLOG_DEBUG("Validating request options for static reshape settings");
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants