mirror of
https://github.com/HKUDS/nanobot.git
synced 2026-08-04 08:28:36 +00:00
normalize_token_usage_state only length-checked persisted day keys, so a hand-edited or foreign 10-char key (e.g. "not-a-dat3" or "2026-13-01") in token-usage.json survived reads and atomic rewrites. token_usage_payload then parsed every day key with an unguarded datetime.fromisoformat, so one such key failed every /api/settings and /api/settings/usage request until the file was repaired by hand. Validate day keys in normalize_token_usage_state, the shared boundary that every read, record, and rewrite already funnels through. Malformed keys are dropped like other malformed rows and scrubbed from the file on the next write; valid state is unchanged.