Validate size and image type for background Tus uploads #551

Closed
opened 2026-09-30 18:54:28 +00:00 by kayg · 2 comments
Owner

Real-server adversarial finding from 2026-09-30, using the merged local release server at e96a8bf2a and tests/adversarial/attack.py.

  • A Tus POST /api/v1/files/uploads for .calternal/backgrounds with upload-length: 26214400 and filename oversized.jpg returned 201. The probe expected 413.
  • A 4-byte not-image.jpg upload to .calternal/backgrounds returned 201; its PATCH body nope returned 204. The probe expected 400 for the non-image install.

The server stayed alive. Please validate the size and image type for the background upload purpose before accepting the upload. No bearer tokens or response bodies are included here.

Real-server adversarial finding from 2026-09-30, using the merged local release server at `e96a8bf2a` and `tests/adversarial/attack.py`. - A Tus `POST /api/v1/files/uploads` for `.calternal/backgrounds` with `upload-length: 26214400` and filename `oversized.jpg` returned 201. The probe expected 413. - A 4-byte `not-image.jpg` upload to `.calternal/backgrounds` returned 201; its `PATCH` body `nope` returned 204. The probe expected 400 for the non-image install. The server stayed alive. Please validate the size and image type for the background upload purpose before accepting the upload. No bearer tokens or response bodies are included here.
Author
Owner

Fixed in commit 6c4f396e6f675f11bcde3f7b3187cad28490e4c6.

The upload guard checked only Photos/Backgrounds/. DESIGN §35 keeps .calternal/backgrounds/ as the migration source, so direct Tus uploads there also need the 20 MB limit and image decoding check. The Files plugin now guards both paths. The regression test checks an oversized declaration and an invalid image in each path, and confirms that rejected uploads leave no staged row.

Verification after the fix: cargo clippy -p calternal-plugin-files --all-targets -- -D warnings passed; cargo test -p calternal-plugin-files passed with 146 passed, 0 failed, 1 ignored. The full adversarial run used the server binary built before this fix, so its two background failures are the evidence for this change, not a post-fix server result.

Fixed in commit `6c4f396e6f675f11bcde3f7b3187cad28490e4c6`. The upload guard checked only `Photos/Backgrounds/`. DESIGN §35 keeps `.calternal/backgrounds/` as the migration source, so direct Tus uploads there also need the 20 MB limit and image decoding check. The Files plugin now guards both paths. The regression test checks an oversized declaration and an invalid image in each path, and confirms that rejected uploads leave no staged row. Verification after the fix: `cargo clippy -p calternal-plugin-files --all-targets -- -D warnings` passed; `cargo test -p calternal-plugin-files` passed with 146 passed, 0 failed, 1 ignored. The full adversarial run used the server binary built before this fix, so its two background failures are the evidence for this change, not a post-fix server result.
Author
Owner

Fixed on dev in 6c4f396e6f (Validate uploads during legacy background migration).

Fixed on dev in 6c4f396e6f675f11bcde3f7b3187cad28490e4c6 (Validate uploads during legacy background migration).
kayg closed this issue 2026-10-01 05:09:04 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#551
No description provided.