AOSSIE-Org / AOSSIE-Org/PictoPy

BUG: Backend: Backend crashes when password contains null bytes (x00)

未关闭
#1,026 4 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Python
星标
283
派生
679
平均合并
7 天 2 小时
30 天内合并 PR
3

描述

### Is there an existing issue for this?

- [x] I have searched the existing issues

### What happened?

How to reproduce
1. Send this payload to POST /albums/
```
{
"name": "Test Album",
"is_hidden": true,
"password": "pass\u0000word"
}
```

Description

Hypothesis fuzz testing revealed that the backend crashes with a 500 Internal Server Error if a user attempts to create or update a hidden album with a password containing a null byte (e.g., "\x00").

Root cause

The bycrypt library used for password hashing throws a ValueError when it encounters a null byte. This exception was not being caught in the database layer, propagating up as an unhandled server error.

Source of crash
- line 130 db_insert_album function in albums.py
- line 135 db_update_album function in albums.py

Expected behaviour
The API should return 422 Unprocessable Entity indicating the input is invalid, rather than crashing the server.

Proposed changes
- Add a field validator in schemas/album.py

I would like to work on this issue.

### Record

- [x] I agree to follow this project's Code of Conduct

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。