* fix: give each chunked upload attempt a unique server-side identifier
The upload session identifier was derived only from user+filename+size
(ChunkedAssetReceiver::receive), with no per-attempt nonce. Two genuinely
concurrent attempts of the same file (e.g. closing and reopening the media
picker mid-upload, then re-uploading the same file) collided on the same
Redis cache key / temp file, producing RuntimeException("Chunked cloud
upload session expired or missing.") on the multipart/cloud path and
silent byte corruption on the local-assemble path.
The frontend now mints a UUID per upload attempt (X-Upload-Id header) that
gets folded into the identifier. Falls back to the old formula when the
header is absent, so any already-loaded frontend bundle keeps working.
Also guards the media picker's dropzone against re-triggering an upload
while one is in flight, and aborts the in-flight fetch when the dialog
unmounts mid-upload.
Fixes Nightwatch issue #23.
* fix: explicitly type upload_id when passing to receive()
Matches the existing explicit (int) casts on the sibling validated()
calls in the same method — validated() returns mixed, so this keeps
the nullable-string contract explicit instead of relying on an
implicit runtime type.
* style: inline the upload_id null-safe cast
Drop the intermediate variable so all receive() arguments read as a
single expression each, matching the sibling validated() casts.
* fix: require X-Upload-Id instead of falling back to the legacy identifier
Nullable upload_id only preserved the old (collision-prone) formula for
clients that omit the header — it didn't actually protect them. Making it
required closes that gap outright: a request without the header now fails
loud (422) instead of silently falling back to the vulnerable identifier.
ChunkedAssetReceiver::receive() now takes a required $attemptId. Updated
every existing test hitting app.assets.store-chunked (ChunkedCloudUploadTest,
ChunkedAssetReceiverTest, ChunkedUploadFilenameEncodingTest, AssetControllerTest)
to send a real upload id, and added a regression test asserting the endpoint
rejects a request with no X-Upload-Id header.
* fix: localize hardcoded workspace name validation messages
StoreWorkspaceRequest had its custom messages() hardcoded in pt-BR
regardless of the user's locale; UpdateWorkspaceRequest had the same
bug hardcoded in English. Both now go through __('validation.required'
/ 'validation.max.string') with the already-localized
workspaces.create.name attribute label (present in all 16 lang/
directories), matching the pattern already used by
StoreWorkspaceInviteRequest.
Unrelated to the chunked upload fix, but caught while reviewing this
file's messages() convention.
* simplify: drop messages() override on workspace name validation
Laravel already localizes the generic required/max messages from
lang/{locale}/validation.php automatically — no need to hand-roll
messages() for standard rules with no custom copy.
* fix: localize StoreChunkedAssetRequest validation messages
Drop the hardcoded English messages for required/ends_with rules —
Laravel's own localized validation.php messages already cover them
adequately (ends_with's generic message is actually more useful, since
it lists the accepted extensions). total_size.max still needs a custom
message (the rule is in raw bytes, unreadable without MB conversion),
so it now goes through __('assets.upload.file_too_large') with the key
added to all 16 lang/ locales.
Also fixed test flakiness discovered while touching this file:
ChunkedCloudUploadTest used random_bytes() for the first mp4 chunk,
which occasionally collides with an unrelated magic number (MZ/PE,
SIMH tape, ...) and makes finfo misdetect the mime type. Replaced with
real mp4 header bytes padded with nulls, so detection is deterministic.
* fix: address final code review findings
- ChunkedAssetReceiver: use double-quoted interpolation instead of
concatenation for the identifier hash, per project convention.
- AssetControllerTest: two chunked-upload rejection tests didn't send
X-Upload-Id, so their 422 assertions could pass for the wrong reason
(upload_id.required) instead of the field they claim to cover. Added
the header and asserted the specific validation error field.
- GalleryBrowser: centralize the upload-in-progress guard as a single
check at the top of uploadFiles() instead of three separate checks
at each entry point (click/select/drop) — matches the single-source-
of-truth pattern already used in PhotoUpload.vue.
- GalleryBrowser: show a toast when an in-flight upload is aborted
(dialog closed mid-upload) instead of silently discarding it with no
feedback. New assets.upload.cancelled key added to all 16 lang/
locales.
133 lines
4.6 KiB
PHP
133 lines
4.6 KiB
PHP
<?php
|
||
|
||
declare(strict_types=1);
|
||
|
||
use App\Enums\UserWorkspace\Role;
|
||
use App\Models\Account;
|
||
use App\Models\User;
|
||
use App\Models\Workspace;
|
||
use Illuminate\Support\Facades\Storage;
|
||
use Illuminate\Support\Str;
|
||
use Illuminate\Testing\TestResponse;
|
||
|
||
beforeEach(function () {
|
||
Storage::fake();
|
||
|
||
$this->account = Account::factory()->create();
|
||
$this->user = User::factory()->create([
|
||
'account_id' => $this->account->id,
|
||
]);
|
||
$this->account->update(['owner_id' => $this->user->id]);
|
||
$this->workspace = Workspace::factory()->create([
|
||
'account_id' => $this->account->id,
|
||
'user_id' => $this->user->id,
|
||
]);
|
||
$this->workspace->members()->attach($this->user->id, ['role' => Role::Member->value]);
|
||
$this->user->update(['current_workspace_id' => $this->workspace->id]);
|
||
|
||
$this->account->subscriptions()->create([
|
||
'type' => Account::SUBSCRIPTION_NAME,
|
||
'stripe_id' => 'sub_test_'.fake()->uuid(),
|
||
'stripe_status' => 'active',
|
||
'stripe_price' => 'price_123',
|
||
]);
|
||
});
|
||
|
||
function postEncodedChunkedUpload(string $fileName, string $content): TestResponse
|
||
{
|
||
$size = strlen($content);
|
||
|
||
return test()->actingAs(test()->user)->call(
|
||
'POST',
|
||
route('app.assets.store-chunked'),
|
||
[], [], [],
|
||
[
|
||
'HTTP_CONTENT_RANGE' => 'bytes 0-'.($size - 1).'/'.$size,
|
||
'HTTP_X_FILE_NAME' => rawurlencode($fileName),
|
||
'HTTP_X_UPLOAD_ID' => Str::uuid()->toString(),
|
||
'HTTP_ACCEPT' => 'application/json',
|
||
'CONTENT_TYPE' => 'application/octet-stream',
|
||
],
|
||
$content,
|
||
);
|
||
}
|
||
|
||
test('chunked upload accepts filename with en-dash when percent-encoded', function () {
|
||
$fileName = 'Corte 6 – Quantidade ou qualidade_ Os dois..png';
|
||
$content = file_get_contents(__DIR__.'/../fixtures/1x1.png');
|
||
|
||
$response = postEncodedChunkedUpload($fileName, $content);
|
||
|
||
$response->assertSuccessful();
|
||
$response->assertJson(['done' => true]);
|
||
expect($this->workspace->getMedia('assets')->first()->original_filename)
|
||
->toBe(strtolower($fileName));
|
||
});
|
||
|
||
test('chunked upload accepts filename with emoji when percent-encoded', function () {
|
||
$fileName = 'launch-🚀-photo.png';
|
||
$content = file_get_contents(__DIR__.'/../fixtures/1x1.png');
|
||
|
||
$response = postEncodedChunkedUpload($fileName, $content);
|
||
|
||
$response->assertSuccessful();
|
||
expect($this->workspace->getMedia('assets')->first()->original_filename)
|
||
->toBe(strtolower($fileName));
|
||
});
|
||
|
||
test('chunked upload accepts filename with spaces and double-dot extension', function () {
|
||
$fileName = 'my video file..png';
|
||
$content = file_get_contents(__DIR__.'/../fixtures/1x1.png');
|
||
|
||
$response = postEncodedChunkedUpload($fileName, $content);
|
||
|
||
$response->assertSuccessful();
|
||
expect($this->workspace->getMedia('assets')->first()->original_filename)
|
||
->toBe('my video file..png');
|
||
});
|
||
|
||
test('chunked upload still accepts plain ascii filename without encoding', function () {
|
||
$content = file_get_contents(__DIR__.'/../fixtures/1x1.png');
|
||
$size = strlen($content);
|
||
|
||
$response = $this->actingAs($this->user)->call(
|
||
'POST',
|
||
route('app.assets.store-chunked'),
|
||
[], [], [],
|
||
[
|
||
'HTTP_CONTENT_RANGE' => 'bytes 0-'.($size - 1).'/'.$size,
|
||
'HTTP_X_FILE_NAME' => 'plain-ascii.png',
|
||
'HTTP_X_UPLOAD_ID' => Str::uuid()->toString(),
|
||
'HTTP_ACCEPT' => 'application/json',
|
||
'CONTENT_TYPE' => 'application/octet-stream',
|
||
],
|
||
$content,
|
||
);
|
||
|
||
$response->assertSuccessful();
|
||
expect($this->workspace->getMedia('assets')->first()->original_filename)
|
||
->toBe('plain-ascii.png');
|
||
});
|
||
|
||
test('chunked upload rejects unsupported extension even when percent-encoded', function () {
|
||
$response = postEncodedChunkedUpload('malware – payload.exe', str_repeat('x', 100));
|
||
|
||
$response->assertUnprocessable();
|
||
});
|
||
|
||
test('chunked upload streams a video file to storage on finalize', function () {
|
||
// Minimal ISO BMFF ("ftyp") so mime_content_type reports video/mp4.
|
||
$content = "\0\0\0\x18ftypmp42\0\0\0\0mp42isom".str_repeat("\0", 64);
|
||
$fileName = 'Quantidade ou Qualidade_ Os dois..mp4';
|
||
|
||
$response = postEncodedChunkedUpload($fileName, $content);
|
||
|
||
$response->assertSuccessful();
|
||
$response->assertJson(['done' => true, 'type' => 'video']);
|
||
|
||
$media = $this->workspace->getMedia('assets')->first();
|
||
expect($media->original_filename)->toBe(strtolower($fileName));
|
||
expect($media->type->value)->toBe('video');
|
||
expect($media->size)->toBe(strlen($content));
|
||
Storage::assertExists($media->path);
|
||
});
|