[PR #26230] hotfix: fix _extract_filename for rfc 5987 #31364

Closed
opened 2026-02-21 20:49:19 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/26230

State: closed
Merged: Yes


Important

  1. Make sure you have read our contribution guidelines
  2. Ensure there is an associated issue and you have been assigned to it
  3. Use the correct syntax to link this PR: Fixes #<issue number>.

Summary

close https://github.com/langgenius/dify/issues/28754

This pull request refactors and strengthens the filename extraction logic from remote file URLs and Content-Disposition headers, with a particular focus on proper RFC5987 support and security against path injection. It also introduces a comprehensive set of unit tests to ensure correct behavior across a wide range of scenarios, including encoding edge cases and malicious input.

Filename extraction improvements:

  • Refactored the _extract_filename function in file_factory.py to robustly parse RFC5987 filename* parameters, handle charset and language tags, decode percent-encoding, and always sanitize the result using os.path.basename to prevent path injection. The function now also returns None for empty or whitespace-only filenames.
  • Added the missing re import to support regular expression parsing in the filename extraction logic.

Testing enhancements:

  • Added a new TestExtractFilename class to test_file_factory.py with extensive unit tests covering RFC5987 parsing, encoding/decoding, language tags, fallback behaviors, path injection protection, and edge cases like empty filenames.
  • Updated the test imports to include _extract_filename for direct testing.

Screenshots

Before After
... ...

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/26230 **State:** closed **Merged:** Yes --- > [!IMPORTANT] > > 1. Make sure you have read our [contribution guidelines](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) > 1. Ensure there is an associated issue and you have been assigned to it > 1. Use the correct syntax to link this PR: `Fixes #<issue number>`. ## Summary close https://github.com/langgenius/dify/issues/28754 This pull request refactors and strengthens the filename extraction logic from remote file URLs and Content-Disposition headers, with a particular focus on proper RFC5987 support and security against path injection. It also introduces a comprehensive set of unit tests to ensure correct behavior across a wide range of scenarios, including encoding edge cases and malicious input. **Filename extraction improvements:** * Refactored the `_extract_filename` function in `file_factory.py` to robustly parse RFC5987 `filename*` parameters, handle charset and language tags, decode percent-encoding, and always sanitize the result using `os.path.basename` to prevent path injection. The function now also returns `None` for empty or whitespace-only filenames. * Added the missing `re` import to support regular expression parsing in the filename extraction logic. **Testing enhancements:** * Added a new `TestExtractFilename` class to `test_file_factory.py` with extensive unit tests covering RFC5987 parsing, encoding/decoding, language tags, fallback behaviors, path injection protection, and edge cases like empty filenames. * Updated the test imports to include `_extract_filename` for direct testing. ## Screenshots | Before | After | |--------|-------| | ... | ... | ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:49:19 -05:00
yindo closed this issue 2026-02-21 20:49:19 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#31364