Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Blossom upload uses PUT /{sha256} instead of BUD-02's PUT /upload

Open Beginner friendly
#341 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
72/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Quiet
Tech stack
dart, rust

Research direction

Read rust/src/nostr/blossom.rs, especially try_upload, and compare its upload URL with the linked BUD-02 specification. Update the upload endpoint to match the stated PUT /upload behavior while leaving the already-correct retrieval path and auth event unchanged. Verify with relevant Rust tests, if present; done when uploads target /upload with the blob bytes in the request body.

Written by the indexing model from the issue text.

Description

try_upload in rust/src/nostr/blossom.rs builds the upload URL as {server}/{sha256} (a PUT to the blob's own hash path), but BUD-02 defines the upload endpoint as PUT /upload — the server computes the sha256 itself from the request body, it isn't part of the path. Confirmed against the current spec: https://github.com/hzrd149/blossom/blob/master/buds/02.md, and against the spec's own commit history, PUT /upload has been the defined endpoint since May 2024 — well before this code was written in #91, so this isn't a case of the spec changing after the fact.

The code's own doc comment misattributes this too: it says "Uses PUT /{sha256} per BUD-01", but BUD-01 defines no PUT endpoint at all — only GET / for retrieval. Neither BUD actually describes a PUT to the hash path.

Retrieval (download_blob, GET /) is correct per BUD-01 — this only affects the upload path.

Against a Blossom server that implements the spec strictly, this upload will fail (404/405), silently breaking file attachments.

Impact today: none reachable by users. send_file/download_attachment (the Rust functions that would trigger this) aren't wired to any Dart screen yet — see the open items tracked in #122 (T079/T080/T081). This bug is real but dormant; it needs fixing before that UI wiring lands, not urgently before then.

Found while verifying the BUD claims added in #123 — flagged by @ermeme's review there.

Fix: change the upload request in try_upload to PUT {server}/upload with the blob bytes in the body, per BUD-02. The Kind-24242 auth event construction (t: upload, x: , expiration) already looks correct and shouldn't need to change.

Dominant language
Dart
Stars
11
Forks
9
Avg merge
11h 18m
Merged PRs (30d)
246

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from MostroP2P/app

All issues in MostroP2P/app

Similar issues

More Dart issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.