Audit round 2: aspect measured the case too; defensive image decode; own-key state reset

4. aspect_profile had the same root cause as edges/centering but no guard.
   On the cased photo it reported 5.8% off standard -- the CASE's
   proportions -- and the UI would surface that as a trimming hint about a
   card it never measured. This one is more directly load-bearing than the
   other two, since the measurement IS the detected box. Now refuses, with
   both consumers (prompt block and UI hint) checking reliable.

5. _decode_images could KeyError/raise out of a plain read on a malformed
   row, and separately b64decode returns b'' rather than raising on some
   corrupt input -- which would have fed a zero-byte 'photo' into grading
   to fail confusingly deep in the pipeline. Both now degrade to the
   existing re-pick path.

6. _last_used_own_key is instance state on a handler that serves every
   request on a keep-alive connection, so it outlives the request that set
   it. Currently safe (every logging path assigns first), but a future path
   that logged without reaching the assignment would bill the previous
   request's payer. Cleared up-front now.

Full regression suite re-run: die-cut exclusion, uniform cards, centering,
aspect, cased-photo refusals, and the store layer all still behave.
This commit is contained in:
Barely Removable 2026-08-25 08:05:33 -07:00
parent 6c612c1f4a
commit 0cbeb26665
5 changed files with 39 additions and 4 deletions

6
app.py
View file

@ -432,6 +432,12 @@ class Handler(BaseHTTPRequestHandler):
# spending yours. Never stored — it lives in their browser and is
# used for this one call.
caller_key = (body.get("api_key") or "").strip() or None
# Cleared up-front, not just assigned on success. One handler
# instance serves every request on a keep-alive connection, so this
# attribute outlives the request that set it — without the reset, a
# future path that logs an event without reaching the assignment
# below would silently bill the previous request's payer.
self._last_used_own_key = False
print("[grade] calling vision model={} on {} image(s){}".format(
model, len(images), " (caller key)" if caller_key else ""), flush=True)