Skip to content

fix(media): refuse uploads whose data URL declares a type outside a fixed media allowlist - #295

Merged
Github-Samuel merged 1 commit into
Samuels-Development:mainfrom
mur4i:fix/media-mime-allowlist
Sep 25, 2026
Merged

Github-Samuel merged 1 commit into
Samuels-Development:mainfrom
mur4i:fix/media-mime-allowlist

Conversation

@mur4i

@mur4i mur4i commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Summary

sniff.matches only checks the type family of a data URL (image/video/audio) against the payload's magic bytes, while the full declared type is what reaches the CDN as the object's Content-Type (e.g. server/upload.js forwards it into the multipart part for the Qbox CDN).

That lets a player upload GIF bytes labelled data:image/svg+xml;base64,...: the sniff passes (family image, GIF signature), and if the CDN serves the object with the declared type, the owner's CDN account ends up hosting an SVG document that can run script.

This adds a fixed allowlist of media types to sniff.matches. The type is compared without its parameters, so audio/webm;codecs=opus from MediaRecorder still passes.

Type of Change

  • Bug Fix
  • New Feature
  • Improvement / Refactor
  • Performance
  • Documentation
  • Compatibility
  • Other

Related Issues

None.

Testing

Ran sniff.matches in a standalone Lua 5.4 runtime against these cases. Before this change, only the image/svg+xml case differs, and it is accepted:

Data URL Payload Expected
image/gif GIF accepted
image/jpeg JPEG accepted
IMAGE/JPEG JPEG accepted
video/webm WebM accepted
audio/webm;codecs=opus WebM accepted
image/svg+xml GIF refused (accepted before)
text/html GIF refused
video/webm JPEG refused
image/png without ;base64 GIF refused
  • Tested locally
  • Tested with latest sd-phone
  • Tested with latest ox_lib
  • Tested with latest ox_inventory
  • Multiplayer tested

Not yet tested on a live server.

Breaking Changes

None for the phone's own uploads (JPEG/PNG stills, WebM/MP4 clips, WebM/Ogg/MP4 audio). A third-party caller of exports['sd-phone']:uploadMedia that declares a type outside the allowlist is now refused.


Checklist

  • My code follows the existing style of the project.
  • I have tested my changes.
  • I have updated any necessary documentation.
  • I have removed any debug code.
  • This PR does not include unrelated changes.
  • I have verified this works on the latest version of sd-phone.

@Github-Samuel
Github-Samuel merged commit 04f8a3b into Samuels-Development:main Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants