mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
fix: align chat attachment picker with allowed file types (#24917)
The agent chat composer only advertised image uploads to the OS file picker and filtered drag-and-drop and paste events to `image/*`, even though the backend accepts text, CSV, JSON, PDF, and a narrower set of image types. Move the allowed chat attachment media types into `codersdk` so the frontend picker and backend enforcement share one source of truth. Use the generated TypeScript list to drive the file input `accept` attribute and the drag-and-drop and paste filters, while adding common text extensions so platforms without MIME registrations still surface those files in the picker.
This commit is contained in:
+9
-7
@@ -5544,7 +5544,9 @@ func (api *API) postChatFile(rw http.ResponseWriter, r *http.Request) {
|
||||
if mediaType, _, err := mime.ParseMediaType(contentType); err == nil {
|
||||
contentType = mediaType
|
||||
}
|
||||
if !chatfiles.IsAllowedStoredMediaType(contentType) {
|
||||
// application/octet-stream means the client could not classify the file
|
||||
// ahead of time, so we defer to byte classification below.
|
||||
if contentType != "application/octet-stream" && !chatfiles.IsAllowedStoredMediaType(contentType) {
|
||||
httpapi.Write(ctx, rw, http.StatusBadRequest, codersdk.Response{
|
||||
Message: "Unsupported file type.",
|
||||
Detail: fmt.Sprintf("Allowed types: %s.", chatfiles.AllowedStoredMediaTypesString()),
|
||||
@@ -5602,12 +5604,12 @@ func (api *API) postChatFile(rw http.ResponseWriter, r *http.Request) {
|
||||
return
|
||||
}
|
||||
// The compatibility check below is security-critical: it keeps exact
|
||||
// media-type matching by default while allowing safe text/plain
|
||||
// refinements such as JSON, CSV, and Markdown now that upload
|
||||
// classification can return richer stored media types. Combined with
|
||||
// the X-Content-Type-Options: nosniff header applied globally, this
|
||||
// still prevents clients from smuggling binary or active content under
|
||||
// a safer declared Content-Type.
|
||||
// media-type matching by default while allowing application/
|
||||
// octet-stream uploads to defer to byte classification, and letting
|
||||
// text/plain refine to safe text subtypes such as JSON, CSV, and
|
||||
// Markdown. Combined with the X-Content-Type-Options: nosniff header
|
||||
// applied globally, this still prevents clients from smuggling binary
|
||||
// or active content under a safer declared Content-Type.
|
||||
if !chatfiles.IsCompatibleUploadMediaType(contentType, detected) {
|
||||
httpapi.Write(ctx, rw, http.StatusBadRequest, codersdk.Response{
|
||||
Message: "File content type does not match Content-Type header.",
|
||||
|
||||
Reference in New Issue
Block a user