fix: harden share bot uploads
This commit is contained in:
@@ -24,8 +24,9 @@ describe("share validation", () => {
|
||||
throw new Error("Expected blank text to fail");
|
||||
} catch (error) {
|
||||
expect(error).toBeInstanceOf(ShareHttpError);
|
||||
expect((error as ShareHttpError).status).toBe(422);
|
||||
expect((error as ShareHttpError).status).toBe(400);
|
||||
}
|
||||
expect(() => validateShareText("before\0after")).toThrow("NUL");
|
||||
});
|
||||
|
||||
test("measures the text limit in UTF-8 bytes", () => {
|
||||
@@ -65,7 +66,12 @@ describe("share validation", () => {
|
||||
type: "text/plain",
|
||||
})
|
||||
)
|
||||
).rejects.toMatchObject({ status: 422 });
|
||||
).rejects.toMatchObject({ status: 400 });
|
||||
await expect(
|
||||
validateTextFile(
|
||||
new File(["before\0after"], "nul.txt", { type: "text/plain" })
|
||||
)
|
||||
).rejects.toMatchObject({ status: 400 });
|
||||
});
|
||||
|
||||
test("validates image contents instead of trusting the MIME type", async () => {
|
||||
|
||||
@@ -18,7 +18,10 @@ export function validateShareText(content: unknown) {
|
||||
throw new ShareHttpError("Text is required", 400);
|
||||
}
|
||||
if (!content.trim()) {
|
||||
throw new ShareHttpError("Text cannot be blank", 422);
|
||||
throw new ShareHttpError("Text cannot be blank", 400);
|
||||
}
|
||||
if (content.includes("\0")) {
|
||||
throw new ShareHttpError("Text cannot contain NUL bytes", 400);
|
||||
}
|
||||
if (Buffer.byteLength(content, "utf8") > MAX_SHARE_TEXT_BYTES) {
|
||||
throw new ShareHttpError("Text must be 5 MiB or smaller", 413);
|
||||
@@ -55,7 +58,7 @@ export async function validateTextFile(file: File) {
|
||||
throw new ShareHttpError("Text file must be 5 MiB or smaller", 413);
|
||||
}
|
||||
if (file.size === 0) {
|
||||
throw new ShareHttpError("Text file cannot be empty", 422);
|
||||
throw new ShareHttpError("Text file cannot be empty", 400);
|
||||
}
|
||||
|
||||
try {
|
||||
@@ -64,7 +67,7 @@ export async function validateTextFile(file: File) {
|
||||
return validateShareText(content);
|
||||
} catch (error) {
|
||||
if (error instanceof ShareHttpError) throw error;
|
||||
throw new ShareHttpError("Text file must contain valid UTF-8", 422);
|
||||
throw new ShareHttpError("Text file must contain valid UTF-8", 400);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user