fix(storage): do not allow full range#9847
Conversation
This prevents requests with `Range: 0-<file length>` and limits it to APP_STORAGE_READ_BUFFER
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the You can disable this status message by setting the Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
SupportNeed help? Create a ticket on our support page for assistance with any issues or questions. Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
Security Scan Results for PRDocker Image Scan Results
Source Code Scan Results🎉 No vulnerabilities found! |
✨ Benchmark results
⚡ Benchmark Comparison
|
Before this fix it was possible to execute
curl -vv --output /dev/null -H 'Range: bytes=0-4607000000' 'http://localhost:8080/v1/storage/buckets/682d919f000890038797/files/682d922900365078d7dc/download?project=682d919a0034fafe31ae&mode=admin'and get the full file range, skipping the 20MB buffer restriction.