fix(r3): a NUL in the raw file path is a 404, not a 500

Compare's stages load their pictures through the catch-all file route, which
caught only OSError around resolve(); an embedded NUL raises ValueError. Same
class as resolve_booth's fix in f8d136a (heid bug hunt on the race fix,
hulda). The upload route's NUL-in-filename 500 is the same class and is left
to booth-dev: it is not on compare's path.
This commit is contained in:
vh
2026-09-24 16:33:27 -07:00
parent 64b403f7eb
commit d54bb04414
3 changed files with 24 additions and 1 deletions
+3 -1
View File
@@ -2148,7 +2148,9 @@ def create_app(
booth = resolve_booth(name)
try:
target = (booth / filepath).resolve()
except OSError:
except (OSError, ValueError):
# ValueError: an embedded NUL (`/b/g/p%00.png`) is not an OSError,
# and hostile input is a 404, never a 500 (r3 heid bug hunt)
raise HTTPException(status_code=404, detail="no such file")
if not str(target).startswith(str(booth) + os.sep) or not target.is_file():
raise HTTPException(status_code=404, detail="no such file")