Blossom upload uses PUT /{sha256} instead of BUD-02's PUT /upload
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 72/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Quiet
- Domain
- backend, networking
Research direction
Read rust/src/nostr/blossom.rs, especially try_upload, and compare its upload URL with the linked BUD-02 specification. Update the upload endpoint to match the stated PUT /upload behavior while leaving the already-correct retrieval path and auth event unchanged. Verify with relevant Rust tests, if present; done when uploads target /upload with the blob bytes in the request body.
Written by the indexing model from the issue text.
Description
try_upload in rust/src/nostr/blossom.rs builds the upload URL as {server}/{sha256} (a PUT to the blob's own hash path), but BUD-02 defines the upload endpoint as PUT /upload — the server computes the sha256 itself from the request body, it isn't part of the path. Confirmed against the current spec: https://github.com/hzrd149/blossom/blob/master/buds/02.md, and against the spec's own commit history, PUT /upload has been the defined endpoint since May 2024 — well before this code was written in #91, so this isn't a case of the spec changing after the fact.
The code's own doc comment misattributes this too: it says "Uses PUT /{sha256} per BUD-01", but BUD-01 defines no PUT endpoint at all — only GET / for retrieval. Neither BUD actually describes a PUT to the hash path.
Retrieval (download_blob, GET /) is correct per BUD-01 — this only affects the upload path.
Against a Blossom server that implements the spec strictly, this upload will fail (404/405), silently breaking file attachments.
Impact today: none reachable by users. send_file/download_attachment (the Rust functions that would trigger this) aren't wired to any Dart screen yet — see the open items tracked in #122 (T079/T080/T081). This bug is real but dormant; it needs fixing before that UI wiring lands, not urgently before then.
Found while verifying the BUD claims added in #123 — flagged by @ermeme's review there.
Fix: change the upload request in try_upload to PUT {server}/upload with the blob bytes in the body, per BUD-02. The Kind-24242 auth event construction (t: upload, x: , expiration) already looks correct and shouldn't need to change.
- Dominant language
- Dart
- Stars
- 11
- Forks
- 9
- Avg merge
- 11h 18m
- Merged PRs (30d)
- 246
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from MostroP2P/app
-
Add-invoice screen stays on "Sent, waiting for the node" after a late acceptance on a sell orderOpenbug priority: medium
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 85/100
Maintainers usually reply within 1 day
-
area: ui
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
CONTRIBUTING.md: Protocol/Transport section still says peer and dispute chat use NIP-59 gift wrapOpen
Difficulty 1/5 Under an hour Newbie friendliness 90/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
Maintainers usually reply within 1 day
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
OpenBikeControl/bikecontrol#404 · 1 comment ·
Maintainers usually reply within 1 day
-
[Bug]: Language picker in Settings doesn't scroll; last languages overlap the buttonsPossibly taken A pull request linked to this issue is open or already merged. Openbacklog:medium bug localization
Difficulty 1/5 Under an hour Newbie friendliness 90/100
simonoppowa/OpenNutriTracker#1331 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
MunichWays/munich-ways-app#248 ·
-
feature
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
lollipopkit/flutter_server_box#1659 · 1 comment · 1 reaction ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100