fix(telegram): runner-side allowlist gate decodes JSON list strings too

The adapter fix decoded `'["-100","-200"]'` before comma-splitting, but
the runner's central gate in gateway/authz_mixin.py::_coerce_allow_set
reads the same YAML-bridged env chain (TELEGRAM_GROUP_ALLOWED_CHATS,
TELEGRAM_ALLOWED_USERS via _auth_env) and still produced
{'["1"', '"2"]'}, so a group message admitted by the adapter could
still be rejected upstream.

Move the decoder to gateway/platforms/_shared.py, which both the adapter
and authz_mixin already import from (no plugin -> gateway cycle), and
route _coerce_allow_set through it. One invariant test on the runner
side, red before this change.
This commit is contained in:
teknium1
2026-09-13 13:46:54 -07:00
committed by Teknium
parent a3b4d70ea2
commit 122ad719b5
4 changed files with 38 additions and 19 deletions
+5 -18
View File
@@ -18,7 +18,11 @@ from hermes_cli import setup_platforms
logger = logging.getLogger(__name__)
from agent.deadline import run_bounded_async
from gateway.platforms._shared import get_scoped_secret as _get_scoped_secret, platform_gate_env as _scoped_gate_env
from gateway.platforms._shared import (
decode_json_list_literal as _decode_json_list_literal,
get_scoped_secret as _get_scoped_secret,
platform_gate_env as _scoped_gate_env,
)
def _redact_telegram_error_text(error: object) -> str:
@@ -33,23 +37,6 @@ def _redact_telegram_error_text(error: object) -> str:
return "<telegram error redacted>"
def _decode_json_list_literal(raw):
"""Decode a JSON-encoded allowlist written by ``hermes config set``.
String-typed defaults keep list literals verbatim on write (``allowed_chats`` is
declared as ``""``), so the config can hold ``'["-100","-200"]'`` as a string.
Malformed JSON passes through unchanged and keeps the legacy comma-split path.
"""
if isinstance(raw, str) and raw.lstrip()[:1] == "[":
try:
loaded = json.loads(raw)
except ValueError:
return raw
if isinstance(loaded, list):
return loaded
return raw
def _consume_abandoned_task(task: asyncio.Task) -> None:
"""Observe a detached task's terminal exception to avoid noisy loop logs."""
try: