Skip to content

fix: normalize content type by converting file extension to lowercase#4375

Merged
Aaaaash merged 2 commits intomainfrom
fix/static-service-mime-tolowercase
Feb 17, 2025
Merged

fix: normalize content type by converting file extension to lowercase#4375
Aaaaash merged 2 commits intomainfrom
fix/static-service-mime-tolowercase

Conversation

@Aaaaash
Copy link
Copy Markdown
Member

@Aaaaash Aaaaash commented Feb 17, 2025

Types

  • 🎉 New Features
  • 🐛 Bug Fixes
  • 📚 Documentation Changes
  • 💄 Code Style Changes
  • 💄 Style Changes
  • 🪚 Refactors
  • 🚀 Performance Improvements
  • 🏗️ Build System
  • ⏱ Tests
  • 🧹 Chores
  • Other Changes

Background or solution

Changelog

Summary by CodeRabbit

  • Bug Fixes
    • 修正了文件服务中文件类型识别的问题,确保即使文件扩展名大小写不一致,也能正确加载和展示文件。

@Aaaaash
Copy link
Copy Markdown
Member Author

Aaaaash commented Feb 17, 2025

/next

@opensumi opensumi Bot added the 🐞 bug Something isn't working label Feb 17, 2025
@coderabbitai
Copy link
Copy Markdown
Contributor

coderabbitai Bot commented Feb 17, 2025

Walkthrough

此次修改在 packages/express-file-server/src/node/express-file-server.contribution.ts 文件中更新了 initialize 方法内获取文件 MIME 类型的逻辑。改动将文件扩展名在匹配时转换为小写,从而确保扩展名判断不受大小写影响。其余部分的逻辑、错误处理及控制流程均未发生改变,也未调整对外公开的接口。

Changes

文件路径 变更内容
packages/express-file-server/.../express-file-server.contribution.ts initialize 方法中修改了 MIME 类型判断逻辑,通过调用 toLowerCase() 使文件扩展名统一为小写,从而实现大小写不敏感匹配。

Warning

There were issues while running some tools. Please review the errors and either fix the tool’s configuration or disable the tool if it’s a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

yarn install v1.22.22
[1/4] Resolving packages...
warning [email protected]: This version is no longer supported. Please see https://eslint.org/version-support for other options.
warning eslint > @humanwhocodes/[email protected]: Use @eslint/config-array instead
warning eslint > @humanwhocodes/config-array > @humanwhocodes/[email protected]: Use @eslint/object-schema instead
warning eslint > file-entry-cache > flat-cache > [email protected]: Rimraf versions prior to v4 are no longer supported
warning eslint > file-entry-cache > flat-cache > rimraf > [email protected]: Glob versions prior to v9 are no longer supported
warning eslint > file-entry-cache > flat-cache > rimraf > glob > [email protected]: This module is not supported, and leaks memory. Do not use it. Check out lru-cache if you want a good and tested way to coalesce async requests by a key value, which is much more comprehensive and powerful.
warning eslint-import-resolver-typescript > [email protected]: Glob versions prior to v9 are no longer supported
error Couldn't find any versions for "@opensumi/ide-dev-tool" that matches "workspace:*"
info Visit https://yarnpkg.com/en/docs/cli/install for documentation about this command.

✨ Finishing Touches
  • 📝 Generate Docstrings (Beta)

Thank you for using CodeRabbit. We offer it for free to the OSS community and would appreciate your support in helping us grow. If you find it useful, would you consider giving us a shout-out on your favorite social media?

❤️ Share
🪧 Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Generate unit testing code for this file.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query. Examples:
    • @coderabbitai generate unit testing code for this file.
    • @coderabbitai modularize this function.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read src/utils.ts and generate unit testing code.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.
    • @coderabbitai help me debug CodeRabbit configuration file.

Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments.

CodeRabbit Commands (Invoked using PR comments)

  • @coderabbitai pause to pause the reviews on a PR.
  • @coderabbitai resume to resume the paused reviews.
  • @coderabbitai review to trigger an incremental review. This is useful when automatic reviews are disabled for the repository.
  • @coderabbitai full review to do a full review from scratch and review all the files again.
  • @coderabbitai summary to regenerate the summary of the PR.
  • @coderabbitai generate docstrings to generate docstrings for this PR. (Beta)
  • @coderabbitai resolve resolve all the CodeRabbit review comments.
  • @coderabbitai configuration to show the current CodeRabbit configuration for the repository.
  • @coderabbitai help to get help.

Other keywords and placeholders

  • Add @coderabbitai ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Documentation and Community

  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

Copy link
Copy Markdown
Contributor

@coderabbitai coderabbitai Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (2)
packages/express-file-server/src/node/express-file-server.contribution.ts (2)

35-35: 建议添加注释说明大小写不敏感的处理

为了提高代码的可维护性,建议添加注释说明对文件扩展名进行大小写不敏感处理的原因。

建议添加如下注释:

+        // 统一转换为小写以确保大小写不敏感的扩展名匹配
         const contentType = ALLOW_MIME[path.extname(filePath).slice(1).toLowerCase()];

33-46: 建议增强安全性检查

当前的安全检查主要依赖白名单路径验证和 MIME 类型检查。建议增加以下安全措施:

  1. 添加路径遍历(Path Traversal)的显式检查
  2. 验证 MIME 类型是否在预期的安全范围内

建议添加如下安全检查:

         const filePath = URI.parse(`file://${uriPath}`).codeUri.fsPath;
+        // 检查是否存在路径遍历
+        const normalizedPath = path.normalize(filePath);
+        if (normalizedPath !== filePath) {
+          ctx.status = 403;
+          return;
+        }
+
         const whitelist = this.getWhiteList();
         const contentType = ALLOW_MIME[path.extname(filePath).slice(1).toLowerCase()];
+        // 定义安全的 MIME 类型白名单
+        const SAFE_MIME_TYPES = ['text/plain', 'application/json', 'image/jpeg', /* 添加其他安全的 MIME 类型 */];
+        if (!SAFE_MIME_TYPES.includes(contentType)) {
+          ctx.status = 403;
+          return;
+        }
📜 Review details

Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 952f747 and 41a1853.

📒 Files selected for processing (1)
  • packages/express-file-server/src/node/express-file-server.contribution.ts (1 hunks)
⏰ Context from checks skipped due to timeout of 90000ms (9)
  • GitHub Check: 🚀🚀🚀 Next Version for pull request
  • GitHub Check: unittest (ubuntu-latest, 18.x, jsdom)
  • GitHub Check: build (ubuntu-latest, 20.x)
  • GitHub Check: unittest (ubuntu-latest, 18.x, node)
  • GitHub Check: build (macos-latest, 20.x)
  • GitHub Check: unittest (macos-latest, 18.x, jsdom)
  • GitHub Check: ubuntu-latest, Node.js 20.x
  • GitHub Check: build-windows
  • GitHub Check: unittest (macos-latest, 18.x, node)
🔇 Additional comments (1)
packages/express-file-server/src/node/express-file-server.contribution.ts (1)

35-35: 文件扩展名转小写的修改是合理的!

将文件扩展名统一转换为小写是一个很好的改进,这样可以确保不同大小写的扩展名(如 .JPG、.jpg、.Jpg)都能正确匹配到对应的 MIME 类型。这种处理方式与第 42 行的路径验证保持一致,都采用了大小写不敏感的方式。

@opensumi
Copy link
Copy Markdown
Contributor

opensumi Bot commented Feb 17, 2025

🎉 PR Next publish successful!

3.7.1-next-1739756477.0

@codecov
Copy link
Copy Markdown

codecov Bot commented Feb 17, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 54.12%. Comparing base (8bc2a53) to head (dbef8fa).
Report is 1 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #4375   +/-   ##
=======================================
  Coverage   54.12%   54.12%           
=======================================
  Files        1639     1639           
  Lines      100362   100362           
  Branches    21784    21776    -8     
=======================================
  Hits        54321    54321           
  Misses      38245    38245           
  Partials     7796     7796           
Flag Coverage Δ
jsdom 49.60% <ø> (ø)
node 12.27% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@Aaaaash Aaaaash requested review from Ricbet and erha19 February 17, 2025 03:02
@Aaaaash Aaaaash merged commit 7d52295 into main Feb 17, 2025
@Aaaaash Aaaaash deleted the fix/static-service-mime-tolowercase branch February 17, 2025 03:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🐞 bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants