anthropics / anthropics/claude-agent-sdk-python
list_sessions_from_store exposes invalid session IDs returned by adapters
- 主要語言
- Python
- 星號
- 8.1k
- 分支
- 1.3k
- 平均合併
- 2 天 31 分鐘
- 30 天內合併 PR
- 1
描述
### Summary
Store-backed session listing does not validate session IDs, unlike filesystem listing and individual store-backed lookup.
### Affected code
- `src/claude_agent_sdk/_internal/sessions.py:1525-1575`
- `src/claude_agent_sdk/_internal/sessions.py:1637-1685`
- `src/claude_agent_sdk/_internal/sessions.py:1723-1732`
- `src/claude_agent_sdk/_internal/session_summary.py:219-222`
### Current behavior
The slow path passes every `session_id` returned by `SessionStore.list_sessions()` into loads and then into `SDKSessionInfo`. The fast path similarly copies IDs from session summaries or listings into slots without `_validate_uuid()`.
By contrast:
- filesystem listing skips filenames that are not UUIDs;
- `get_session_info_from_store()` returns `None` for an invalid UUID;
- mutation helpers reject invalid IDs.
### Why this matters
A malformed, stale, or externally populated backend row becomes a public `SDKSessionInfo` and consumes an offset/limit position. The SDK can therefore return session IDs that its own get, resume, fork, and mutation APIs reject.
It also causes inconsistent behavior between otherwise equivalent disk, slow-store, and summary-fast listing paths.
### Expected behavior
All public session listing implementations should filter invalid session IDs before loading, sorting, or pagination.
### Possible fix
Validate IDs as soon as adapter results are received:
- filter `list_sessions()` entries before scheduling loads;
- filter summary entries before conversion;
- ensure malformed entries do not consume page positions.
Add conformance tests for invalid UUIDs in both optional listing methods and verify parity between fast and slow paths.
### Environment
- Repository revision: current `main` audit at SDK version 0.2.128
- Bundled CLI version: 2.1.220
- Python test suite: 1,291 passed, 5 skipped
- Ruff and mypy: clean
I searched the existing issues and pull requests using the affected symbols and behavior before filing this.
貢獻指南
這個儲存庫沒有索引到貢獻指南
研究方向
Read the affected listing paths in src/claude_agent_sdk/_internal/sessions.py and the summary conversion in src/claude_agent_sdk/_internal/session_summary.py, following _validate_uuid() and SessionStore.list_sessions(). Add conformance tests covering invalid UUIDs in both optional listing methods, then verify fast and slow paths filter malformed entries before loading, sorting, or pagination.
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- python
- 領域
- backend-api-design
- Issue 類型
- 缺陷
- 難度
- 3/5
- 預估耗時
- 1-2 天
- 活躍度
- 冷清
- 描述清晰度
- 描述清楚
- 新手友好度
- 68/100