fix: exclude query/fragment delimiters from user-ID regex segment

Change [^/]+ to [^/?#]+ so that inputs like
/api/v1/users/alice?x=1/profile/image are rejected — the browser
would interpret ? as the query string start, making the actual
request target /api/v1/users/alice instead of the intended route.
This commit is contained in:
DrMelone 2026-04-03 22:50:54 +02:00
parent a8f7b743ff
commit 3da3b6b929

View file

@ -3,10 +3,10 @@
import re
from urllib.parse import urlparse
# Matches the OWUI-generated profile image route. The ``[^/]+`` segment
# accepts any user-ID without allowing path-traversal across segments,
# Matches the OWUI-generated profile image route. ``[^/?#]+`` accepts
# any user-ID without allowing path-traversal or query/fragment injection,
# and the ``$`` anchor rejects trailing path components.
_USER_PROFILE_IMAGE_RE = re.compile(r'^/api/v1/users/[^/]+/profile/image$')
_USER_PROFILE_IMAGE_RE = re.compile(r'^/api/v1/users/[^/?#]+/profile/image$')
# Validates MIME type and structure of base64 data URIs. Only the prefix
# is checked — validating the full base64 payload would mean running a