Skip to content

Commit 2d481a5

Browse files
zhansheng.lzsclaude
andcommitted
Detect encrypted output when client encryption is disabled
When server returns encrypted output but client didn't enable encryption, throw clear ApiException instead of letting encrypted string leak to downstream parsers causing fastjson syntax errors. Detection logic: output is JsonPrimitive, length > 100, matches base64 pattern. Exception message guides users to set enableEncrypt(true). Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
1 parent d0e9fe6 commit 2d481a5

1 file changed

Lines changed: 14 additions & 0 deletions

File tree

‎src/main/java/com/alibaba/dashscope/common/DashScopeResult.java‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -100,6 +100,20 @@ protected <T extends Result> T fromResponse(Protocol protocol, NetworkResponse r
100100
this.output = null;
101101
} else if (jsonObject.get(ApiKeywords.OUTPUT).isJsonObject()) {
102102
this.output = jsonObject.get(ApiKeywords.OUTPUT).getAsJsonObject();
103+
} else if (jsonObject.get(ApiKeywords.OUTPUT).isJsonPrimitive()) {
104+
// Server returned encrypted output but client didn't enable encryption
105+
String outputStr = jsonObject.get(ApiKeywords.OUTPUT).getAsString();
106+
if (outputStr.length() > 100 && outputStr.matches("^[A-Za-z0-9+/=]+$")) {
107+
throw new ApiException(
108+
Status.builder()
109+
.statusCode(400)
110+
.code("EncryptionMismatch")
111+
.message(
112+
"Server returned encrypted output but client encryption is not enabled. "
113+
+ "Please set enableEncrypt(true) in your request parameters.")
114+
.build());
115+
}
116+
this.output = jsonObject.get(ApiKeywords.OUTPUT);
103117
} else {
104118
this.output = jsonObject.get(ApiKeywords.OUTPUT);
105119
}

0 commit comments

Comments
 (0)