Repository navigation
Strip control characters from feedback attachment filenames - #9548
austinywang wants to merge 2 commits into
Conversation
|
Warning Review limit reached
Next review available in: 4 minutes You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Revived as #14783 |
Fixes #5717
Summary
Content-Dispositionheaders.FeedbackComposerClient.submitrequest path with a filesystem filename containing a quote, CR/LF, tab, DEL, and another C0 control.Testing
3f54edb0d8:swift test --package-path Packages/macOS/CmuxFeedback --scratch-path <isolated-path> --filter FeedbackComposerClientTestsonaws-m4pro-6failed because the captured filename field still contained raw control bytes.8d3737500e: the same remote command passed the regression test (1 test, 1 suite)../scripts/reload-cloud.sh --tag sym5717: remote build completed on leased fleet slotcmux9s-mac-mini.1; no local fallback was used. The default Blacksmith lane queued, and an earlier fleet slot was skipped after exposing a missing Zig 0.16.0 toolchain./tmp/cmux-debug-sym5717.sock:cmux feedback --email test@example.com --body <test-message> --image <fixture>sent a filename whose input hex was63617074757265220d0a696e6a656374656401097f2e706e67; the local capture endpoint receivedcaptureinjected.pngwith no control bytes. The tagged app was then stopped and its stale socket removed.Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Strip control characters from feedback attachment filenames before building multipart Content-Disposition headers to prevent header injection and malformed uploads (fixes #5717). Added a test through
FeedbackComposerClient.submitthat uses a filename with quotes, CR/LF, tab, DEL, and other C0 controls, and asserts the sent name is sanitized.Written for commit 8d37375. Summary will update on new commits.