AOSSIE-Org / AOSSIE-Org/PictoPy

BUG: Backend: Backend crashes when password contains null bytes (x00)

未關閉
#1,026 4 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
Python
星號
283
分支
679
平均合併
7 天 2 小時
30 天內合併 PR
3

描述

### Is there an existing issue for this?

- [x] I have searched the existing issues

### What happened?

How to reproduce
1. Send this payload to POST /albums/
```
{
"name": "Test Album",
"is_hidden": true,
"password": "pass\u0000word"
}
```

Description

Hypothesis fuzz testing revealed that the backend crashes with a 500 Internal Server Error if a user attempts to create or update a hidden album with a password containing a null byte (e.g., "\x00").

Root cause

The bycrypt library used for password hashing throws a ValueError when it encounters a null byte. This exception was not being caught in the database layer, propagating up as an unhandled server error.

Source of crash
- line 130 db_insert_album function in albums.py
- line 135 db_update_album function in albums.py

Expected behaviour
The API should return 422 Unprocessable Entity indicating the input is invalid, rather than crashing the server.

Proposed changes
- Add a field validator in schemas/album.py

I would like to work on this issue.

### Record

- [x] I agree to follow this project's Code of Conduct

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。