apache / apache/answer

Getting HTTP 302 -> /403 on displaying uploaded images after answer "update"

Offen
#722 13 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
bug
Vorherrschende Sprache
Go
Sterne
15.7k
Forks
1.4k
Ø Merge
3 T. 8 Std.
Gemergte PRs (30 T.)
7

Beschreibung

## Describe the bug

Not sure when it started (maybe with 1.2.1 or after running 1.2.1 for some days, but not sure), and have no idea how to analyze the following issue:

Uploading images works well, they're written to the `updates` folder in the file system.
But when displaying them, answer returns a HTTP 302 redirecting to `/403`.

Uploaded avatars and the brand image are still working.

There are no additional information in debug log, pardon me, I've no idea how to taggle this.

The installation is private, when changing it to public, images are shown. so it seems to be related to login session handling for images downloads.

### To Reproduce

Steps to reproduce the behavior:

1. having a private answer
1. deploy a rebuild answer binary (`answer build --with-plugins...`)
1. uploaded images result int http 302 -> /403 ![image](https://github.com/apache/incubator-answer/assets/40993644/09adc3e4-b87b-404e-96c1-875544851699)
1. clear cookie `visit` and reload page
1. uploaded images work again

### Expected behavior

Uploaded images continue to being shown also after answer updates

### Screenshots

If applicable, add screenshots or video to help explain your problem.

### Platform

- Device: Any
- OS: Official answer container image
- Version: v1.2.1 `--with-plugins`

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Rechercherichtung

Es wird keine Quelldatei und kein Test genannt. Reproduziere das Problem in einer privaten Installation, indem du die Answer-Binärdatei neu erstellst, und untersuche anschließend den Pfad zum Herunterladen von Bildern sowie die Handhabung der Login-Sitzung; die Arbeit ist abgeschlossen, wenn hochgeladene Bilder nach einem Update weiterhin zugänglich sind, ohne das visit cookie zu löschen.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
go
Bereich
authentication, backend
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
25/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.