Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Let a phone upload captures straight to a station's storage #1409
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Uh oh!
There was an error while loading. Please reload this page.
Let a phone upload captures straight to a station's storage #1409
Changes from all commits
a912923c718f1db06caad342065efa7f495d65954332f9612d01401fFile filter
Filter by extension
Conversations
Uh oh!
There was an error while loading. Please reload this page.
Jump to
Uh oh!
There was an error while loading. Please reload this page.
There are no files selected for viewing
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
🔎 Supported by static analysis
🌐 Web query:
What format and decoded length does AWS S3 PutObject require for the ChecksumSHA256 parameter, and how does S3 handle an invalid value?💡 Result:
For the
ChecksumSHA256parameter in the AWS S3PutObjectoperation, the required format is a Base64-encoded string representing the 256-bit SHA-256 digest of the object [1][2][3]. When S3 processes aPutObjectrequest that includes aChecksumSHA256header (or equivalent SDK parameter), it validates the integrity of the uploaded data by calculating the checksum of the received content and comparing it to the provided value [4]. If S3 determines that the provided checksum value is incorrect or does not match the computed digest for the specified algorithm, the service will reject the request, typically returning an error response such asInvalidRequest(or a similar exception indicating a checksum mismatch) [4][5]. It is important to note that developers must provide the correct Base64-encoded digest [5]. If an arbitrary or incorrectly encoded string is provided, S3 will fail the integrity validation during the upload process [4][5]. While some user reports indicate that passing arbitrary strings can sometimes bypass certain client-side validation logic or alter the request signing/signing-trailer behavior, such practices do not result in valid integrity protection and will generally lead to request failures at the service level when actual integrity verification is enforced [4][6][7].Citations:
🤖 get_repo_knowledge executed:
get_repo_knowledge RolnickLab/antenna /tmp/coderabbit-repo-knowledge/rolnicklab-antenna-cc5c3310/learningsLength of output: 6024
🏁 Script executed:
Repository: RolnickLab/antenna
Length of output: 19815
🏁 Script executed:
Repository: RolnickLab/antenna
Length of output: 19524
🏁 Script executed:
Repository: RolnickLab/antenna
Length of output: 662
Validate non-empty
sha256before signing the upload request.get_presigned_put_urlpasses this value to real AWS asChecksumSHA256andx-amz-checksum-sha256. AWS requires a Base64-encoded 32-byte SHA-256 digest. Reject values that fail strict Base64 decoding or do not decode to 32 bytes. Otherwise, the subsequent upload can fail.🤖 Prompt for AI Agents
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🩺 Stability & Availability | 🟡 Minor | ⚡ Quick win
Validate
Deployment.data_source_regexbefore upload requests.Deployment.data_source_regexis a plain nullableCharFieldwith no regex validator. The API serializer, admin form, fixture helper, and directDeployment.save()paths can persist malformed values becausesave()does not callfull_clean(). When a validupload_requestreaches this line with a malformed value,re.compile()can raise uncaughtre.errorand return HTTP 500.Add validation at each write boundary, and keep a guard here for existing invalid rows:
Proposed endpoint guard
📝 Committable suggestion
🤖 Prompt for AI Agents
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.