Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

bug: GCS upload detection in MediaManager uses substring match on the full URL

Đang mở
#1,913 1 bình luận 0 reaction 1 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

@hassiebp đang làm issue này rồi.

Từ ngày 30/9/2026.

  • #1914 của @Ad1th — đang mở

Đánh giá

Issue này chưa được đánh giá.

Mô tả

bug feat-multimodal-media sdk-python

In MediaManager._process_upload_media_job (langfuse/_task_manager/media_manager.py), the SDK decides whether an upload target is a GCS bucket with a substring check:

is_self_hosted_gcs_bucket = "storage.googleapis.com" in upload_url

If that matches, the SDK skips the x-ms-blob-type and x-amz-checksum-sha256 headers.

Because it is a substring match on the whole URL, it also matches URLs that are not GCS, for example:

  • https://example.com/upload?next=storage.googleapis.com (string in the query)
  • https://storage.googleapis.com.example.com/upload (string as a prefix of another domain)

Those uploads are then sent without the headers the SDK would normally add for S3/Azure targets, including the SHA-256 checksum header.

The upload URL comes from the Langfuse server, so I don't see this as exploitable in a normal setup. It is a hardening / correctness fix: the check should look at the URL hostname rather than the raw string.

Proposed fix

Parse the URL and treat it as GCS only when the hostname is storage.googleapis.com or ends with .storage.googleapis.com. Existing behaviour for real GCS URLs (path-style and bucket.storage.googleapis.com) is unchanged.

I have a small PR ready with a unit test in tests/unit/test_media_manager.py that fails before the change and passes after. Happy to open it if this looks good.

Environment

  • langfuse-python 4.16.0 (current main)
Ngôn ngữ chính
Python
Star
498
Fork
361
Merge trung bình
16 giờ 58 phút
Pull request đã merge (30 ngày)
32

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của langfuse/langfuse-python

Tất cả issue của langfuse/langfuse-python

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.