| @@ -51,8 +51,20 @@ | ||
| 51 | 51 | // Add the message to the start of the messages to send to the SCS Middleware. |
| 52 | 52 | array_unshift( $messages, $current_message ); |
| 53 | 53 | } |
| 54 | 54 | |
| 55 | + // Bail if no usable prompt remained after filtering empty messages. | |
| 56 | + if ( empty( $messages ) || empty( $messages[0]['content'] ) ) { | |
| 57 | + wp_send_json_error( [ 'message' => __( 'No prompt was supplied.', 'sureforms' ) ] ); | |
| 58 | + } | |
| 59 | + | |
| 60 | + // Server-side prompt-length cap. The UI enforces a 2000-char limit via maxlength, but that | |
| 61 | + // is client-side only and can be bypassed by a crafted request, so mirror it here. This is | |
| 62 | + // cost/resource hardening — output is always escaped, so this is not an XSS concern. | |
| 63 | + if ( mb_strlen( (string) $messages[0]['content'] ) > 2000 ) { | |
| 64 | + wp_send_json_error( [ 'message' => __( 'The prompt is too long. Please shorten it and try again.', 'sureforms' ) ] ); | |
| 65 | + } | |
| 66 | + | |
| 55 | 67 | // Get the response from the endpoint. |
| 56 | 68 | $response = AI_Helper::get_chat_completions_response( |
| 57 | 69 | apply_filters( |
| 58 | 70 | 'srfm_ai_form_generator_body', |