fix(r3): a NUL in the raw file path is a 404, not a 500

Compare's stages load their pictures through the catch-all file route, which
caught only OSError around resolve(); an embedded NUL raises ValueError. Same
class as resolve_booth's fix in f8d136a (heid bug hunt on the race fix,
hulda). The upload route's NUL-in-filename 500 is the same class and is left
to booth-dev: it is not on compare's path.
This commit is contained in:
vh
2026-09-24 16:33:27 -07:00
parent 64b403f7eb
commit d54bb04414
3 changed files with 24 additions and 1 deletions
+11
View File
@@ -567,6 +567,17 @@ new = '''
if True:
partner'''
[[mutation]]
label = "a NUL in the raw file path is a 500 (the stages load through this route)"
file = "booth/app.py"
test = "tests/test_compare.py::test_a_nul_in_a_file_path_is_404_not_500"
old = '''
target = (booth / filepath).resolve()
except (OSError, ValueError):'''
new = '''
target = (booth / filepath).resolve()
except OSError:'''
# Refuted, not rowed (bug hunt): "a right-click mid-drag ends the pan" — a
# second button pressed and released during a drag arrives as chorded
# `pointermove` events, never a `pointerup` (measured 3/3 in the test browser,