From 425ce43bdd64799c42a5ebdfe155db26de15ee73 Mon Sep 17 00:00:00 2001 From: YueGuobin Date: Wed, 4 Mar 2026 13:55:09 +0800 Subject: [PATCH] feat(chat): add project status checks to chat endpoints Add project status validation to all chat API endpoints to ensure the project is opened before allowing chat operations. This prevents unauthorized access and ensures chat functionality only works with active projects. - Check project.status == "opened" in stream_chat, list_sessions, get_history, and delete_session endpoints - Return HTTP 403 FORBIDDEN with descriptive error message if project is not opened - Update docstring for stream_chat endpoint to document the requirement --- gns3server/api/routes/controller/chat.py | 32 ++++++++++++++++++++++++ 1 file changed, 32 insertions(+) diff --git a/gns3server/api/routes/controller/chat.py b/gns3server/api/routes/controller/chat.py index 1e8030aa5..5832793d9 100644 --- a/gns3server/api/routes/controller/chat.py +++ b/gns3server/api/routes/controller/chat.py @@ -82,8 +82,17 @@ async def stream_chat( This endpoint uses Server-Sent Events (SSE) to stream responses from the AI agent. Each message is a JSON object with a `type` field indicating the message kind (content, tool_call, tool_start, tool_end, error, done, heartbeat). + + The project must be opened to use chat functionality. """ + # Check if project is opened + if project.status != "opened": + raise HTTPException( + status_code=status.HTTP_403_FORBIDDEN, + detail=f"Project must be opened to use chat. Current status: {project.status}" + ) + # Get user authentication info user_id = str(current_user.user_id) @@ -165,6 +174,14 @@ async def list_sessions( Note: This endpoint is a placeholder. Full session listing functionality requires checkpoint metadata inspection which is not yet implemented. """ + + # Check if project is opened + if project.status != "opened": + raise HTTPException( + status_code=status.HTTP_403_FORBIDDEN, + detail=f"Project must be opened to access chat sessions. Current status: {project.status}" + ) + # TODO: Implement session listing from checkpoint metadata return [] @@ -185,6 +202,13 @@ async def get_history( Get conversation history for a session. """ + # Check if project is opened + if project.status != "opened": + raise HTTPException( + status_code=status.HTTP_403_FORBIDDEN, + detail=f"Project must be opened to access chat history. Current status: {project.status}" + ) + # Get AgentService for this project agent_manager = await get_project_agent_manager() agent_service = await agent_manager.get_agent(str(project.id), project.path) @@ -212,6 +236,14 @@ async def delete_session( Note: This endpoint is a placeholder. Full session deletion functionality requires checkpoint manipulation which is not yet implemented. """ + + # Check if project is opened + if project.status != "opened": + raise HTTPException( + status_code=status.HTTP_403_FORBIDDEN, + detail=f"Project must be opened to delete chat sessions. Current status: {project.status}" + ) + # TODO: Implement session deletion from checkpoint raise HTTPException( status_code=status.HTTP_501_NOT_IMPLEMENTED,