🚑 Regex was after downloading (security issue)
This commit is contained in:
@@ -15,10 +15,13 @@ file_regex = r"^[a-z0-9]{8}-[a-z0-9-]{27}--[a-z0-9-]{36}$"
|
|||||||
async def download_file(file_name: str):
|
async def download_file(file_name: str):
|
||||||
storage = Storage(backend=settings.storage_backend, deta_key=settings.deta_project_key,
|
storage = Storage(backend=settings.storage_backend, deta_key=settings.deta_project_key,
|
||||||
deta_id=settings.deta_project_id, storage_path=settings.storage_path)
|
deta_id=settings.deta_project_id, storage_path=settings.storage_path)
|
||||||
download = await storage.download(file_name)
|
|
||||||
if not re.match(file_regex, file_name):
|
if not re.match(file_regex, file_name):
|
||||||
raise HTTPException(status_code=400, detail="Invalid file name")
|
raise HTTPException(status_code=400, detail="Invalid file name")
|
||||||
|
|
||||||
|
download = await storage.download(file_name)
|
||||||
|
if download is None:
|
||||||
|
raise HTTPException(status_code=404, detail="File not found")
|
||||||
|
|
||||||
def iter_file():
|
def iter_file():
|
||||||
yield from download
|
yield from download
|
||||||
|
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ class Storage:
|
|||||||
if backend == "deta":
|
if backend == "deta":
|
||||||
if deta_key is None or deta_id is None:
|
if deta_key is None or deta_id is None:
|
||||||
raise ValueError("deta_key and deta_id must be provided")
|
raise ValueError("deta_key and deta_id must be provided")
|
||||||
if backend == "local":
|
elif backend == "local":
|
||||||
if storage_path is None:
|
if storage_path is None:
|
||||||
raise ValueError("storage_path must be provided")
|
raise ValueError("storage_path must be provided")
|
||||||
else:
|
else:
|
||||||
|
|||||||
@@ -41,3 +41,11 @@ class DetaStorage:
|
|||||||
return None
|
return None
|
||||||
else:
|
else:
|
||||||
raise Exception("Upload failed")
|
raise Exception("Upload failed")
|
||||||
|
|
||||||
|
async def delete(self, file_name: [str]) -> None:
|
||||||
|
async with ClientSession(headers=self.headers) as session:
|
||||||
|
async with session.delete(f"{self.deta_url}/files/delete", data={"names": file_name}) as response:
|
||||||
|
if response.status == 200:
|
||||||
|
return None
|
||||||
|
else:
|
||||||
|
raise Exception("Delete failed")
|
||||||
Reference in New Issue
Block a user