Skip to content
Draft
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 11 additions & 2 deletions API/Routes/Upload/UploadRoute.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
import re
import shutil
from flask import Blueprint, request, jsonify, send_file, after_this_request
from zipfile import ZipFile
Expand Down Expand Up @@ -538,13 +539,21 @@ def handle_full_zip(file, filepath=None):

return jsonify({"response": msg}), 200

def sanitize_uuid(value: str) -> str:
"""Allow only safe UUID-like characters to prevent path traversal."""
if not value or not re.fullmatch(r'[a-zA-Z0-9_\-]{1,64}', value):
raise ValueError(f"Invalid dzuuid: {value!r}")
return value

@upload_api.route('/uploadCase', methods=['POST'])
def uploadCase():
try:
# -------------------------------
# 1) Primanje Dropzone chunk meta
# -------------------------------
dz_uuid = request.form.get("dzuuid")
if dz_uuid is not None:
dz_uuid = sanitize_uuid(dz_uuid)
dz_chunk_index = request.form.get("dzchunkindex")
dz_total_chunks = request.form.get("dztotalchunkcount")
file = request.files.get("file")
Expand Down Expand Up @@ -602,8 +611,8 @@ def uploadCase():
#return handle_full_zip(open(final_zip, "rb"), final_zip)
return handle_full_zip(None, final_zip)

except PermissionError:
return jsonify({"error": "Invalid path"}), 400
except (PermissionError, ValueError) as e:
return jsonify({"error": "Invalid request parameter"}), 400
except Exception as e:
return jsonify({"error": str(e)}), 500

Expand Down
Loading