bug: GCS upload detection in MediaManager uses substring match on the full URL
Mantenedores costumam responder em até 1 dia
Avaliação
Esta issue ainda não foi avaliada.
Descrição
In MediaManager._process_upload_media_job (langfuse/_task_manager/media_manager.py), the SDK decides whether an upload target is a GCS bucket with a substring check:
is_self_hosted_gcs_bucket = "storage.googleapis.com" in upload_url
If that matches, the SDK skips the x-ms-blob-type and x-amz-checksum-sha256 headers.
Because it is a substring match on the whole URL, it also matches URLs that are not GCS, for example:
https://example.com/upload?next=storage.googleapis.com(string in the query)https://storage.googleapis.com.example.com/upload(string as a prefix of another domain)
Those uploads are then sent without the headers the SDK would normally add for S3/Azure targets, including the SHA-256 checksum header.
The upload URL comes from the Langfuse server, so I don't see this as exploitable in a normal setup. It is a hardening / correctness fix: the check should look at the URL hostname rather than the raw string.
Proposed fix
Parse the URL and treat it as GCS only when the hostname is storage.googleapis.com or ends with .storage.googleapis.com. Existing behaviour for real GCS URLs (path-style and bucket.storage.googleapis.com) is unchanged.
I have a small PR ready with a unit test in tests/unit/test_media_manager.py that fails before the change and passes after. Happy to open it if this looks good.
Environment
- langfuse-python 4.16.0 (current
main)
- Linguagem predominante
- Python
- Estrelas
- 498
- Forks
- 361
- Merge médio
- 16h 58min
- PRs com merge (30d)
- 32
Preparar o ambiente
- Sem Dockerfile nem arquivo Docker Compose
- Tem um modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de langfuse/langfuse-python
-
bug: get_dataset_run / get_dataset_runs / delete_dataset_run are unusable on Langfuse v4Talvez já em andamento @hassiebp assumiu há 12 dias. Abertabug feat-datasets feat-experiments sdk-python
langfuse/langfuse-python#1906 · 1 responsável ·
Mantenedores costumam responder em até 1 dia
-
mask is not applied to create_dataset_item or create_score(comment=)Talvez já em andamento @hassiebp assumiu há 16 dias. Abertabug compliance feat-data-masking sdk-python security
langfuse/langfuse-python#1896 · 1 comentário · 1 responsável ·
Mantenedores costumam responder em até 1 dia
-
Scores bypass sample_rate since v4Talvez já em andamento @hassiebp assumiu há 21 dias. Abertafeat-scores sdk-python unconfirmed-bug
langfuse/langfuse-python#1890 · 1 responsável ·
Mantenedores costumam responder em até 1 dia
-
batch_evaluation fails on self-hosted v4 events_only deployments (uses unavailable v3 read endpoints)Talvez já em andamento @hassiebp assumiu há 34 dias. Abertabug feat-evals sdk-python
langfuse/langfuse-python#1861 · 2 comentários · 1 responsável ·
Mantenedores costumam responder em até 1 dia
-
[HTTPXodus] Consider migrating from httpx to httpx2 (the actively maintained fork)Talvez já em andamento @hassiebp assumiu há 35 dias. Abertaimprovement sdk-python
langfuse/langfuse-python#1856 · 1 responsável ·
Mantenedores costumam responder em até 1 dia
Todas as issues de langfuse/langfuse-python
Issues semelhantes
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 86/100
UKGovernmentBEIS/inspect_ai#5802 ·
Mantenedores costumam responder em até 2 dias
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 74/100
no-human-ai/no_human#660 ·
Mantenedores costumam responder em até 1 dia
-
documentation good first issue
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
Mantenedores costumam responder em até 1 dia
-
documentation need help question
Dificuldade 1/5 1-3 horas Facilidade para iniciantes 66/100
phonology024/babelscribe#26 ·
-
bug
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 62/100