Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

bug: GCS upload detection in MediaManager uses substring match on the full URL

Offen
#1,913 1 Kommentar 0 Reaktionen 1 zugewiesene Person Auf GitHub ansehen

Maintainer antworten meist innerhalb von 1 Tag

@hassiebp arbeitet bereits daran.

Seit 30.9.2026.

  • #1914 von @Ad1th — offen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Beschreibung

bug feat-multimodal-media sdk-python

In MediaManager._process_upload_media_job (langfuse/_task_manager/media_manager.py), the SDK decides whether an upload target is a GCS bucket with a substring check:

is_self_hosted_gcs_bucket = "storage.googleapis.com" in upload_url

If that matches, the SDK skips the x-ms-blob-type and x-amz-checksum-sha256 headers.

Because it is a substring match on the whole URL, it also matches URLs that are not GCS, for example:

  • https://example.com/upload?next=storage.googleapis.com (string in the query)
  • https://storage.googleapis.com.example.com/upload (string as a prefix of another domain)

Those uploads are then sent without the headers the SDK would normally add for S3/Azure targets, including the SHA-256 checksum header.

The upload URL comes from the Langfuse server, so I don't see this as exploitable in a normal setup. It is a hardening / correctness fix: the check should look at the URL hostname rather than the raw string.

Proposed fix

Parse the URL and treat it as GCS only when the hostname is storage.googleapis.com or ends with .storage.googleapis.com. Existing behaviour for real GCS URLs (path-style and bucket.storage.googleapis.com) is unchanged.

I have a small PR ready with a unit test in tests/unit/test_media_manager.py that fails before the change and passes after. Happy to open it if this looks good.

Environment

  • langfuse-python 4.16.0 (current main)
Vorherrschende Sprache
Python
Sterne
498
Forks
361
Ø Merge
16 Std. 58 Min.
Gemergte PRs (30 T.)
32

Entwicklungsumgebung

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus langfuse/langfuse-python

Alle Issues in langfuse/langfuse-python

Ähnliche Issues

Weitere Issues zu Python

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.