Skip to content

Keep upload file names and readable bytes for file inputs - #64

Merged
wolfiesch merged 2 commits into
mainfrom
fix/upload-staged-filename
Oct 8, 2026
Merged

wolfiesch merged 2 commits into
mainfrom
fix/upload-staged-filename

Conversation

@wolfiesch

Copy link
Copy Markdown
Owner

Problem

upload_file failed on sites that check uploads, such as GitHub's avatar upload:

  1. The host staged each upload as <uuid>.upload, so the page saw a file with no extension or MIME type and rejected it ("Only images, please").
  2. The host deleted the staged copy as soon as the action returned. Chrome hands the page a path-backed File and reads the bytes only when the page uses it, so the upload request then failed.

Change

  • Stage each upload as upload-staging/<uuid>/<source file name> (directory 0700, file 0600). Cleanup removes the file and its per-upload directory.
  • Uploads that reached the page (direct act or committed) are removed 10 minutes later. Uploads that never reach the page are still removed immediately.
  • On startup, the host removes per-upload directories older than 15 minutes that an exited host left behind. That age is longer than both the retention and the 5-minute staged-commit lifetime.
  • Updated docs/security.md and the changelog.

Verification

  • cargo test -p agenttab-host: all pass. New tests cover the kept file name, cleanup of the per-upload directory, and the stale sweep. The commit test now asserts the staged bytes stay readable.
  • Live check: GitHub App logo upload through the installed host. GitHub accepted the PNG and opened its crop dialog. Before this change, the same upload failed with is-bad-file (from the name fix) and then is-failed (from early deletion).
  • cargo clippy -D warnings reports only the two too_many_arguments errors already on main (journal.rs, runtime.rs).

Stage each upload as <uuid>/<source name> so pages see the real file
name and MIME type, and keep delivered uploads on disk for 10 minutes
because Chrome reads file input bytes only when the page uses them.
A starting host sweeps per-upload directories older than 15 minutes.
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

Windows opens a directory handle only with backup semantics and needs
the write-attributes right to change its timestamps.
@wolfiesch
wolfiesch merged commit b4bad09 into main Oct 8, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant