fix: fall back to the original when a thumbnail fails to decode
A blob with valid magic but a corrupt body passed upload then 500'd on a ?w= thumbnail decode (audit). Fall back to serve_original (streams without decoding) instead. Tested. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -55,3 +55,20 @@ async fn image_blobs_are_served_inline(pool: sqlx::PgPool) {
|
||||
"images must render inline, not download"
|
||||
);
|
||||
}
|
||||
|
||||
#[sqlx::test(migrations = "./migrations")]
|
||||
async fn corrupt_image_thumbnail_falls_back_to_original_not_500(pool: sqlx::PgPool) {
|
||||
// A blob with valid PNG magic bytes but an undecodable body passes upload's
|
||||
// magic-byte sniff; a ?w= thumbnail request then tries to decode it. That
|
||||
// must not 500 the reader — fall back to streaming the original bytes.
|
||||
let h = common::harness(pool);
|
||||
write_blob(&h, "misc/corrupt.png", &common::fake_png_bytes());
|
||||
|
||||
let resp = h
|
||||
.app
|
||||
.oneshot(common::get("/api/v1/files/misc/corrupt.png?w=320"))
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(resp.status(), StatusCode::OK, "corrupt thumbnail must not 500");
|
||||
assert_eq!(resp.headers().get("content-type").unwrap(), "image/png");
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user