apache / apache/answer

Getting HTTP 302 -> /403 on displaying uploaded images after answer "update"

Ouverte
#722 13 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
bug
Langage dominant
Go
Étoiles
15.7k
Forks
1.4k
Merge moyen
3 j 8 h
PR mergées (30 j)
7

Description

## Describe the bug

Not sure when it started (maybe with 1.2.1 or after running 1.2.1 for some days, but not sure), and have no idea how to analyze the following issue:

Uploading images works well, they're written to the `updates` folder in the file system.
But when displaying them, answer returns a HTTP 302 redirecting to `/403`.

Uploaded avatars and the brand image are still working.

There are no additional information in debug log, pardon me, I've no idea how to taggle this.

The installation is private, when changing it to public, images are shown. so it seems to be related to login session handling for images downloads.

### To Reproduce

Steps to reproduce the behavior:

1. having a private answer
1. deploy a rebuild answer binary (`answer build --with-plugins...`)
1. uploaded images result int http 302 -> /403 ![image](https://github.com/apache/incubator-answer/assets/40993644/09adc3e4-b87b-404e-96c1-875544851699)
1. clear cookie `visit` and reload page
1. uploaded images work again

### Expected behavior

Uploaded images continue to being shown also after answer updates

### Screenshots

If applicable, add screenshots or video to help explain your problem.

### Platform

- Device: Any
- OS: Official answer container image
- Version: v1.2.1 `--with-plugins`

Guide de contribution

Aucun guide de contribution indexé pour ce dépôt

Piste de recherche

Aucun fichier source ni aucun test n’est nommé. Reproduisez le problème sur une installation privée en reconstruisant le binaire Answer, puis examinez le chemin de téléchargement des images et la gestion de la session de connexion ; le travail est terminé lorsque les images téléversées restent accessibles après une mise à jour sans effacer la visit cookie.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
go
Domaine
authentication, backend
Type d'issue
Bug
Difficulté
4/5
Temps estimé
3-5 jours
Activité
À l'abandon
Clarté
Plutôt claire
Accessibilité débutants
25/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.