Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

请求内容带 + 加号时导致 AI 内容安全插件报错 #1540

Closed
1 task done
mrhaoji opened this issue Nov 25, 2024 · 5 comments
Closed
1 task done

请求内容带 + 加号时导致 AI 内容安全插件报错 #1540

mrhaoji opened this issue Nov 25, 2024 · 5 comments
Assignees

Comments

@mrhaoji
Copy link
Contributor

mrhaoji commented Nov 25, 2024

If you are reporting any crash or any potential security issue, do not
open an issue in this repo. Please report the issue via ASRC(Alibaba Security Response Center) where the issue will be triaged appropriately.

  • I have searched the issues of this repository and believe that this is not a duplicate.

Ⅰ. Issue Description

如果用户输入的内容是带 + 加号的,会出现往阿里内容安全服务那边走的时候,计算签名错误,导致“漏风”没有准确拦截。

Ⅱ. Describe what happened

CleanShot 2024-11-25 at 11 23 28@2x

Ⅲ. Describe what you expected to happen

正常处理特殊符号

Ⅳ. How to reproduce it (as minimally and precisely as possible)

直接用阿里内容安全官方的 SDK 示例代码测试“AA 事件”、“AA事件”、“AA+ 事件”均成功拦截

但是通过 Higress AI 内容安全插件“AA+ 事件”无法被拦截,从日志看出现下面截图的错误

Ⅴ. Anything else we need to know?

Ⅵ. Environment:

  • Higress version:
  • OS :
  • Others:
@CH3CHO
Copy link
Collaborator

CH3CHO commented Nov 25, 2024

@rinfx 看一下

@rinfx
Copy link
Collaborator

rinfx commented Nov 25, 2024

这个问题已经修复过了:#1394 #1473

@CH3CHO
Copy link
Collaborator

CH3CHO commented Nov 25, 2024

那我重新打个包

@CH3CHO
Copy link
Collaborator

CH3CHO commented Nov 25, 2024

镜像已更新,请验证

@mrhaoji
Copy link
Contributor Author

mrhaoji commented Nov 25, 2024

已正常

@mrhaoji mrhaoji closed this as completed Nov 25, 2024
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants