fix: enforce content policies using original file types

This commit is contained in:
tdurieux
2026-09-06 09:17:42 +02:00
parent 7210db2b61
commit c14a548cb9
5 changed files with 35 additions and 5 deletions
+2 -2
View File
@@ -343,7 +343,7 @@ export default class AnonymizedFile {
async anonymizedContent() {
const anonymizer = this.repository.generateAnonymizeTransformer(
this.anonymizedPath
await this.originalPath()
);
if (!config.STREAMER_ENTRYPOINT) {
// collect the content locally
@@ -385,7 +385,7 @@ export default class AnonymizedFile {
async send(res: Response): Promise<void> {
const anonymizer = this.repository.generateAnonymizeTransformer(
this.anonymizedPath
await this.originalPath()
);
// eslint-disable-next-line no-async-promise-executor
return new Promise<void>(async (resolve, reject) => {
+2 -2
View File
@@ -149,7 +149,7 @@ export async function streamAnonymizedZip(
entry.path.substring(entry.path.indexOf("/") + 1),
compiledTerms
);
if (!isEntryAllowed(fileName, opt.contentOptions)) {
if (!isEntryAllowed(entry.path, opt.contentOptions)) {
entry.autodrain();
return;
}
@@ -159,7 +159,7 @@ export async function streamAnonymizedZip(
// isText=false for every file, so the zip ships unanonymized.
const anonymizer = new AnonymizeTransformer({
...opt.anonymizerOptions,
filePath: fileName,
filePath: entry.path,
});
const st = entry.pipe(anonymizer);
archive.append(st, { name: fileName });