🚑 Regex was after downloading (security issue)
This commit is contained in:
@@ -15,10 +15,13 @@ file_regex = r"^[a-z0-9]{8}-[a-z0-9-]{27}--[a-z0-9-]{36}$"
|
||||
async def download_file(file_name: str):
|
||||
storage = Storage(backend=settings.storage_backend, deta_key=settings.deta_project_key,
|
||||
deta_id=settings.deta_project_id, storage_path=settings.storage_path)
|
||||
download = await storage.download(file_name)
|
||||
if not re.match(file_regex, file_name):
|
||||
raise HTTPException(status_code=400, detail="Invalid file name")
|
||||
|
||||
download = await storage.download(file_name)
|
||||
if download is None:
|
||||
raise HTTPException(status_code=404, detail="File not found")
|
||||
|
||||
def iter_file():
|
||||
yield from download
|
||||
|
||||
|
||||
@@ -14,7 +14,7 @@ class Storage:
|
||||
if backend == "deta":
|
||||
if deta_key is None or deta_id is None:
|
||||
raise ValueError("deta_key and deta_id must be provided")
|
||||
if backend == "local":
|
||||
elif backend == "local":
|
||||
if storage_path is None:
|
||||
raise ValueError("storage_path must be provided")
|
||||
else:
|
||||
|
||||
@@ -41,3 +41,11 @@ class DetaStorage:
|
||||
return None
|
||||
else:
|
||||
raise Exception("Upload failed")
|
||||
|
||||
async def delete(self, file_name: [str]) -> None:
|
||||
async with ClientSession(headers=self.headers) as session:
|
||||
async with session.delete(f"{self.deta_url}/files/delete", data={"names": file_name}) as response:
|
||||
if response.status == 200:
|
||||
return None
|
||||
else:
|
||||
raise Exception("Delete failed")
|
||||
Reference in New Issue
Block a user