Cap attachment filenames at 128 chars server-side
A 250-char multipart filename was accepted and echoed verbatim in Content-Disposition. SanitizeFilename already truncates; lower the cap from 255 to 128 so DB rows and header echoes stay bounded (#248).
This commit is contained in:
@@ -26,7 +26,10 @@ type Attachment struct {
|
||||
SizeHuman string `json:"-"` // template-only: human-readable size
|
||||
}
|
||||
|
||||
const MaxFilenameLen = 255
|
||||
// MaxFilenameLen caps stored attachment filenames (bytes) to bound DB
|
||||
// rows and Content-Disposition echoes. 128 keeps names readable while
|
||||
// stopping filename-bloat abuse; longer names truncate.
|
||||
const MaxFilenameLen = 128
|
||||
|
||||
// ErrFileTooLarge is returned when an attachment exceeds the per-file cap.
|
||||
var ErrFileTooLarge = errors.New("file too large")
|
||||
|
||||
@@ -105,4 +105,9 @@ func TestSanitizeFilename(t *testing.T) {
|
||||
if got := SanitizeFilename(long); len(got) != MaxFilenameLen {
|
||||
t.Errorf("long name len = %d want %d", len(got), MaxFilenameLen)
|
||||
}
|
||||
// issue #248: a 250-char multipart filename must truncate to the cap
|
||||
repro := strings.Repeat("b", 246) + ".txt"
|
||||
if got := SanitizeFilename(repro); len(got) != MaxFilenameLen {
|
||||
t.Errorf("repro name len = %d want %d", len(got), MaxFilenameLen)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user