Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
45 changes: 45 additions & 0 deletions server/common/getPresignedUrl.test.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
import { describe, it, expect, beforeAll, afterAll } from "vitest";

// Regression guard: a trailing space in S3_BUCKET_NAME (or the keys) once made
// every presigned PUT fail with 400 InvalidBucketName. These values must be
// trimmed before they reach the bucket name / SigV4 credential.
describe("getPresignedUrl whitespace hardening", () => {
// eslint-disable-next-line @typescript-eslint/no-explicit-any
let getPresignedUrl: any;

beforeAll(async () => {
// Whitespace-padded credentials, set before import so the s3 client (built
// at module load) sees them.
process.env.ACCESS_KEY = "AKIATESTKEY1234567890 ";
process.env.SECRET_KEY = "secretsecretsecretsecretsecretsecret1234\n";
({ getPresignedUrl } = await import("@/server/common/getPresignedUrl"));
});
Comment on lines +10 to +16

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛠️ Refactor suggestion | 🟠 Major | ⚡ Quick win

Add cleanup to restore environment variables.

The beforeAll hook modifies process.env.ACCESS_KEY, process.env.SECRET_KEY, and the tests modify process.env.S3_BUCKET_NAME, but these changes are never reverted. This can pollute other tests if Vitest runs them in the same process or if other tests depend on these variables.

🧹 Add cleanup with afterAll
 describe("getPresignedUrl whitespace hardening", () => {
   // eslint-disable-next-line `@typescript-eslint/no-explicit-any`
   let getPresignedUrl: any;
+  const originalEnv = {
+    ACCESS_KEY: process.env.ACCESS_KEY,
+    SECRET_KEY: process.env.SECRET_KEY,
+    S3_BUCKET_NAME: process.env.S3_BUCKET_NAME,
+  };
 
   beforeAll(async () => {
     // Whitespace-padded credentials, set before import so the s3 client (built
     // at module load) sees them.
     process.env.ACCESS_KEY = "AKIATESTKEY1234567890 ";
     process.env.SECRET_KEY = "secretsecretsecretsecretsecretsecret1234\n";
     ({ getPresignedUrl } = await import("`@/server/common/getPresignedUrl`"));
   });
+
+  afterAll(() => {
+    process.env.ACCESS_KEY = originalEnv.ACCESS_KEY;
+    process.env.SECRET_KEY = originalEnv.SECRET_KEY;
+    process.env.S3_BUCKET_NAME = originalEnv.S3_BUCKET_NAME;
+  });
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@server/common/getPresignedUrl.test.ts` around lines 10 - 16, Add an afterAll
hook to restore the environment variables that are modified during test setup.
Store the original values of process.env.ACCESS_KEY, process.env.SECRET_KEY, and
process.env.S3_BUCKET_NAME before the beforeAll hook modifies them, then restore
those original values (or delete the variables if they were not originally set)
in the new afterAll hook to prevent test pollution.


afterAll(() => {
delete process.env.ACCESS_KEY;
delete process.env.SECRET_KEY;
delete process.env.S3_BUCKET_NAME;
});

it("trims a trailing space in S3_BUCKET_NAME so the PUT targets the real bucket", async () => {
process.env.S3_BUCKET_NAME = "codu.uploads "; // <- the prod footgun
const url = await getPresignedUrl("image/png", 123, {
kind: "uploads",
userId: "u1",
});
expect(url).toContain("/codu.uploads/");
expect(url).not.toContain("codu.uploads%20");
expect(url).not.toContain("codu.uploads ");
});

it("trims whitespace in the access key used to sign the URL", async () => {
process.env.S3_BUCKET_NAME = "codu.uploads";
const url = await getPresignedUrl("image/png", 123, {
kind: "uploads",
userId: "u1",
});
const cred = new URL(url).searchParams.get("X-Amz-Credential") ?? "";
expect(cred.startsWith("AKIATESTKEY1234567890/")).toBe(true);
expect(cred).not.toContain("%20");
});
});
5 changes: 3 additions & 2 deletions server/common/getPresignedUrl.ts
Original file line number Diff line number Diff line change
Expand Up @@ -42,13 +42,14 @@ export const getPresignedUrl = async (
const Key = getKey(config, extension);

const putCommand = new PutObjectCommand({
Bucket: process.env.S3_BUCKET_NAME,
// Trim: a stray space in S3_BUCKET_NAME (invisible in host UIs) makes S3
// reject every PUT with 400 InvalidBucketName.
Bucket: process.env.S3_BUCKET_NAME?.trim(),
Key,
ContentType: `image/${fileType}`,
ContentLength: fileSize,
});

// @FIX TS ERROR
const putUrl = await getSignedUrl(s3Client, putCommand, {
expiresIn: 3600,
});
Expand Down
9 changes: 6 additions & 3 deletions utils/s3helpers.ts
Original file line number Diff line number Diff line change
@@ -1,14 +1,17 @@
import { S3Client } from "@aws-sdk/client-s3";

const hasAccessKeys = process.env.ACCESS_KEY && process.env.SECRET_KEY;
// Trim: stray whitespace in the key env vars otherwise breaks SigV4 signing.
const accessKeyId = process.env.ACCESS_KEY?.trim();
const secretAccessKey = process.env.SECRET_KEY?.trim();
const hasAccessKeys = accessKeyId && secretAccessKey;

export const s3Client = new S3Client({
region: "eu-west-1",
...(hasAccessKeys
? {
credentials: {
accessKeyId: process.env.ACCESS_KEY || "",
secretAccessKey: process.env.SECRET_KEY || "",
accessKeyId,
secretAccessKey,
},
}
: {}),
Expand Down
Loading