Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

bug: GCS upload detection in MediaManager uses substring match on the full URL

Aberta
#1,913 1 comentário 0 reações 1 responsável Ver no GitHub

Mantenedores costumam responder em até 1 dia

@hassiebp já está trabalhando nisso.

Desde 30/9/2026.

  • #1914 de @Ad1th — aberto

Avaliação

Esta issue ainda não foi avaliada.

Descrição

bug feat-multimodal-media sdk-python

In MediaManager._process_upload_media_job (langfuse/_task_manager/media_manager.py), the SDK decides whether an upload target is a GCS bucket with a substring check:

is_self_hosted_gcs_bucket = "storage.googleapis.com" in upload_url

If that matches, the SDK skips the x-ms-blob-type and x-amz-checksum-sha256 headers.

Because it is a substring match on the whole URL, it also matches URLs that are not GCS, for example:

  • https://example.com/upload?next=storage.googleapis.com (string in the query)
  • https://storage.googleapis.com.example.com/upload (string as a prefix of another domain)

Those uploads are then sent without the headers the SDK would normally add for S3/Azure targets, including the SHA-256 checksum header.

The upload URL comes from the Langfuse server, so I don't see this as exploitable in a normal setup. It is a hardening / correctness fix: the check should look at the URL hostname rather than the raw string.

Proposed fix

Parse the URL and treat it as GCS only when the hostname is storage.googleapis.com or ends with .storage.googleapis.com. Existing behaviour for real GCS URLs (path-style and bucket.storage.googleapis.com) is unchanged.

I have a small PR ready with a unit test in tests/unit/test_media_manager.py that fails before the change and passes after. Happy to open it if this looks good.

Environment

  • langfuse-python 4.16.0 (current main)
Linguagem predominante
Python
Estrelas
498
Forks
361
Merge médio
16h 58min
PRs com merge (30d)
32

Preparar o ambiente

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de langfuse/langfuse-python

Todas as issues de langfuse/langfuse-python

Issues semelhantes

Mais issues de Python

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.