Jörn Friedrich Dreyer
1bafa4bd18
align the handler verifier, update docs
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-09-08 17:11:55 +02:00
Dominik Schmidt
b18618ab4a
Merge pull request #3484 from opencloud-eu/fix/tika-embedded-facet-leak
...
fix(search): extract facets from the main tika document only
2026-09-08 15:52:21 +02:00
Dominik Schmidt
65f19b5d71
fix(thumbnails): close rejected vips ref, map oversized convert error to forbidden
2026-09-08 15:28:37 +02:00
Dominik Schmidt
7f687ea288
fix(thumbnails): bound declared image dimensions before decoding
...
The imaging build decodes the full pixel buffer from the header-declared
dimensions before the existing MaxInputWidth/MaxInputHeight guard runs, so a
tiny crafted file whose header declares huge dimensions forces a multi-GB
allocation and can OOM the worker. Read the header with DecodeConfig and reject
oversized sources before the decode allocates, in both the imaging and vips
builds, and thread the limit through the audio cover-art and geogebra decoders
that decode a second attacker-controlled image.
2026-09-08 15:28:37 +02:00
Dominik Schmidt
be83ed19e3
fix(search): take extraction facets from the main document only
...
The recursive tika response lists the file first, then its embedded
resources (cover art, thumbnails, the clip appended to a motion photo).
The loop applied getImage/getPhoto/getLocation/getAudio/getLivePhoto to
every part, so an mp3's embedded cover art leaked a 200x200 image facet
onto the track (and an embedded EXIF image would leak photo/location).
Read those facets from metas[0] only, like the video facet already does;
the loop now only concatenates title/content and detects the motion
photo clip.
2026-09-08 14:52:35 +02:00
zerox80
9797ee903f
fix(config): correct pending version annotations
...
Use the supported %%NEXT%% marker for seven graph and policies settings so the environment annotation check passes.
2026-09-08 14:40:40 +02:00
Jörn Friedrich Dreyer
973dbbdf1a
Merge pull request #3241 from opencloud-eu/activitylog-event-handler-split
...
Activitylog event handler split
2026-09-08 14:13:28 +02:00
Alex Ababii
8875d062b0
upd tests for auth requests middelware
2026-09-08 09:37:51 +02:00
Alex Ababii
d1d20edbd2
log jwt expired on debug level instead of error
2026-09-08 09:37:51 +02:00
opencloudeu
c2a34e8c45
[tx] updated from transifex
2026-09-07 23:17:03 +00:00
Dominik Schmidt
7f7a938c3f
fix(proxy): restrict JWT signed urls to the allowed HTTP methods
...
The legacy OC-Signature path already rejects methods outside
PRE_SIGNED_URL_ALLOWED_HTTP_METHODS, the JWT path did not. A leaked
signed download url could be used for PUT, DELETE, MOVE or PROPFIND
as the signing user for the lifetime of the signature.
2026-09-07 13:00:09 +02:00
Jörn Friedrich Dreyer
cfefb83d26
revert unrelated changes
2026-09-07 12:52:33 +02:00
Jörn Friedrich Dreyer
9357124a91
add tests to extracted services
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-09-07 12:52:33 +02:00
Jörn Friedrich Dreyer
c36af05d14
simplify ConnectNatsKV
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-09-07 12:52:33 +02:00
Jörn Friedrich Dreyer
7947c1c98a
reduce packages
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-09-07 12:52:33 +02:00
Jörn Friedrich Dreyer
d58c1e3dab
use json encode
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-09-07 12:52:33 +02:00
Jörn Friedrich Dreyer
5a609c98dc
handle error types
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-09-07 12:52:33 +02:00
Jörn Friedrich Dreyer
29913e1d7f
revert to legacy autoack events
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-09-07 12:52:32 +02:00
Jörn Friedrich Dreyer
5028364e2c
add tests to cover more ack scenarios
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-09-07 12:52:32 +02:00
Jörn Friedrich Dreyer
b2b15d44f7
rename test files
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-09-07 12:52:32 +02:00
Jörn Friedrich Dreyer
6ea363b0b9
add debouncer tests
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-09-07 12:52:32 +02:00
Jörn Friedrich Dreyer
9594313243
add explicit ack
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-09-07 12:52:32 +02:00
Jörn Friedrich Dreyer
62d815abe9
split handlers, fix bugs
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-09-07 12:52:32 +02:00
Jörn Friedrich Dreyer
5923aa5e5e
move event + http handler code to the events package
...
Signed-off-by: Jörn Friedrich Dreyer <jfd@butonic.de >
2026-09-07 12:52:32 +02:00
Dominik Schmidt
81536bbd0e
Merge pull request #3471 from opencloud-eu/feat/graph-expand-thumbnails
...
feat(graph): expand thumbnails on driveItems
2026-09-07 12:50:53 +02:00
opencloudeu
4b7c6908f0
[tx] updated from transifex
2026-09-06 23:16:18 +00:00
Dominik Schmidt
6231a870d5
feat(graph): expand thumbnails on driveItems
...
$expand=thumbnails was only honored by sharedByMe and sharedWithMe. The
driveItem stat, the children listing and the root children listing now
honor it as well, so a client that lists a folder learns which items have
a preview instead of guessing from the mime type.
The thumbnails are set from the resource info the listing already has, so
a later preview check that needs more than the mime type has a single
place to sit. The two share listings carry driveItems only, they keep
matching on the mime type but share the url building.
2026-09-06 23:51:35 +02:00
opencloudeu
17003fe34b
[tx] updated from transifex
2026-09-05 23:17:58 +00:00
Dominik Schmidt
2ce9faec5a
Merge pull request #3444 from opencloud-eu/feat/driveitem-lock
...
graph: expose lockInfo on driveItems
2026-09-04 09:51:13 +02:00
opencloudeu
f5696d40f8
[tx] updated from transifex
2026-09-03 23:17:09 +00:00
Dominik Schmidt
bafbc88a40
graph: expose lockInfo on driveItems
2026-09-03 17:52:13 +02:00
Dominik Schmidt
aa968ec898
graph: expose @libre.graph.shareTypes on driveItems
2026-09-03 16:59:29 +02:00
Dominik Schmidt
61037cc22f
Merge pull request #3202 from opencloud-eu/feat/search-live-photo-facet
...
feat(search): live photo facet
2026-09-03 11:42:28 +02:00
Jörn Friedrich Dreyer
993265b64e
Merge pull request #3445 from opencloud-eu/feat/graph-expand-children
...
feat: support $expand=children on the driveItem endpoint
2026-09-03 09:35:05 +02:00
Dominik Schmidt
5995938c34
chore(search): trim the live photo comments
2026-09-03 03:34:33 +02:00
Dominik Schmidt
0a4f3ed786
fix(search): keep livePhoto.contentId out of the search siblings
2026-09-03 03:34:33 +02:00
Dominik Schmidt
a7214b3d73
fix(search): drop the live photo facet on an empty pairing id
2026-09-03 03:34:33 +02:00
Dominik Schmidt
81b0df1ad4
feat(search): live photo facet
2026-09-03 03:34:33 +02:00
Dominik Schmidt
e6102c0405
Merge pull request #3200 from opencloud-eu/feat/search-motion-photo-facet
...
feat(search): motion photo facet
2026-09-03 03:34:29 +02:00
opencloudeu
ab0b3c58f1
[tx] updated from transifex
2026-09-02 23:18:41 +00:00
Dominik Schmidt
3515594787
fix(search): keep the video facet on the file itself
2026-09-03 01:09:41 +02:00
Dominik Schmidt
a8318fe03b
refactor(search): take the motion photo video size from the video tika extracted
2026-09-03 00:32:07 +02:00
Dominik Schmidt
706aaf02f2
refactor(search): decide the motion photo from the file xmp and its extracted video
2026-09-03 00:32:06 +02:00
Dominik Schmidt
88f21d804b
refactor(search): restore cs3 Retrieve, the download split had only one caller left
2026-09-03 00:31:40 +02:00
Dominik Schmidt
8aebf80124
refactor(search): confirm the motion photo video by type, not by name
2026-09-03 00:31:40 +02:00
Dominik Schmidt
ae9fd595d9
chore(search): drop the dead legacy tika key
2026-09-03 00:31:40 +02:00
Dominik Schmidt
709962b616
feat(search): confirm the motion photo video via tika instead of reading bytes
2026-09-03 00:31:40 +02:00
Dominik Schmidt
a2050d1fb9
feat(search): index and expose the motion photo facet
2026-09-03 00:31:40 +02:00
Dominik Schmidt
0f4b95b9ae
feat(search): add RetrieveRange to the content retriever
2026-09-03 00:27:04 +02:00
Dominik Schmidt
42876ca61c
refactor(search): let getFirstValue try multiple metadata keys
2026-09-03 00:27:04 +02:00