fix(05): WR-01 bound thumb dimensions and decoded image size

This commit is contained in:
Jakub Zych
2026-09-19 15:30:58 +02:00
parent 44126cc935
commit c211822448
2 changed files with 36 additions and 1 deletions

View File

@@ -43,6 +43,28 @@ func TestThumbFilenameRejectsUnsafeTokens(t *testing.T) {
}
}
func TestFileThumbRejectsOutOfRangeSize(t *testing.T) {
bucket := memblob.OpenBucket(nil)
defer bucket.Close()
f := &File{ID: 1, DiskName: "abc123xyz.jpg"}
for _, tc := range []struct{ w, h int }{
{0, 200},
{200, 0},
{-1, -1},
{maxThumbEdge + 1, 200},
{200, maxThumbEdge + 1},
{100000, 100000},
} {
if _, err := f.Thumb(t.Context(), bucket, tc.w, tc.h, "crop"); err == nil {
t.Fatalf("size %dx%d must be rejected", tc.w, tc.h)
}
}
iter := bucket.List(nil)
if obj, err := iter.Next(t.Context()); err != io.EOF {
t.Fatalf("rejected sizes must not touch the bucket, found %v (err %v)", obj, err)
}
}
func TestFileThumbRejectsTraversalMode(t *testing.T) {
bucket := memblob.OpenBucket(nil)
defer bucket.Close()