security: whitelist allowed image MIME types for uploads

Only accept common image formats (JPEG, PNG, GIF, WebP, AVIF, SVG)
on the upload endpoint. Non-image uploads now return HTTP 415 with a
structured JSON error listing the allowed types. Includes a test.
This commit is contained in:
2026-06-26 20:35:46 +02:00
parent 25ebf691f7
commit e11c7d24a4
3 changed files with 22 additions and 0 deletions
+6
View File
@@ -92,6 +92,12 @@ module Volumen
halt(413, json("error" => "file_too_large", "max_bytes" => Server::MAX_UPLOAD_BYTES))
end
content_type_str = upload[:type].to_s.split(";").first.to_s.strip.downcase
unless Server::ALLOWED_UPLOAD_TYPES.include?(content_type_str)
halt(415, json("error" => "unsupported_media_type",
"allowed" => Server::ALLOWED_UPLOAD_TYPES))
end
json("url" => store.store_upload(upload[:filename], upload[:tempfile]))
end
+3
View File
@@ -18,6 +18,9 @@ module Volumen
MAX_LOGIN_ATTEMPTS = 10
LOGIN_WINDOW = 60 # seconds
MAX_UPLOAD_BYTES = 10 * 1024 * 1024 # 10 MB
ALLOWED_UPLOAD_TYPES = %w[
image/jpeg image/png image/gif image/webp image/avif image/svg+xml
].freeze
SLUG_REGEX = /\A[a-z0-9](?:[a-z0-9._-]*[a-z0-9])?\z/
register ApiRoutes