Multipart_Message.Store_Attachments allows files to be uploaded on the server even is Upload_Directory is disabled (empty String)
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 45/100
Direzione di ricerca
Inizia in aws-server-http_utils.adb, in Multipart_Message.Store_Attachments, e confronta la gestione degli upload con Multipart_Message.File_Upload. Usa il riproduttore command.sh allegato e il payload della richiesta per verificare il comportamento quando Upload_Directory è vuoto. Il lavoro è completato quando gli upload vengono rifiutati in questa configurazione e non viene creato alcun file temporaneo.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Multipart_Message.Store_Attachments allows files to be uploaded on the server even is Upload_Directory is disabled (empty String)
To fix this issue we applied the same verification and error management as Multipart_Message.File_Upload (patch attached).
--- aws-server-http_utils.adb.orig 2024-04-13 11:49:53.691588811 +0400
+++ aws-server-http_utils.adb 2024-04-13 11:50:55.539068778 +0400
@@ -857,6 +857,11 @@
begin
begin
if Mode in Attachment .. File_Upload then
+ if CNF.Upload_Directory (Server_Config) = "" then
+ raise Constraint_Error
+ with "File upload not supported by server "
+ & CNF.Server_Name (Server_Config);
+ end if;
Streams.Stream_IO.Create
(File, Streams.Stream_IO.Out_File, Server_Filename);
end if;
Reproducer file command.sh attached, request payload below;
POST / HTTP/1.1
Host: localhost:8080
User-Agent: curl/7.74.0
Accept: */*
Content-Length: 500
Content-Type: multipart/related; boundary=------------------------e3b8d4247741cbe4
--------------------------e3b8d4247741cbe4
Content-Disposition: attachment; name="file";filename="threat"
Content-Type: application/octet-stream
Content-Id: dude
THREAT AGENT
--------------------------e3b8d4247741cbe4--
In this case, as the Content-Length is bigger than the actual payload, the web server is waiting and the temporary uploaded file is not yet deleted. A simple ls command executed in the directory where the web server has been launched will show the temporary file.
$ ls
27495-1
Another way to assess the temporary uploaded file is by using the inotifywait command executed in the directory where the web server has been launched
$ inotifywait -m .
./ CREATE 27495-1
./ OPEN 27495-1
./ MODIFY 27495-1
./ CLOSE_WRITE,CLOSE 27495-1
- Lingua principale
- Ada
- Stelle
- 162
- Fork
- 45
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di AdaCore/aws
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 58/100
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 48/100
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 25/100
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
ROCm/rocm-systems#12638 ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
I maintainer di solito rispondono entro 1 giorno
-
Poll constructor throws for an uncached channel while resolving a message context-menu interactionApertabug need repro packages:discord.js
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
discordjs/discord.js#11645 ·
I maintainer di solito rispondono entro 3 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
DOI-USGS/dataretrieval-python#430 ·
I maintainer di solito rispondono entro 1 giorno
-
Validator client startup retry loop ignores context cancellation until the reconnect backoff expiresAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
OffchainLabs/prysm#17596 ·
I maintainer di solito rispondono entro 2 giorni