[E29-S01-T01] Reject oversized uploads and forged MIME types #302

Open
opened 2026-08-27 08:05:12 +00:00 by kpcto · 0 comments
Owner

Parent story: [E29-S01] Upload endpoint and validation (#112)

Intent

Reject oversized uploads and forged MIME types at the endpoint before anything is stored.

Acceptance criteria

  • Reject uploads exceeding the configured maximum size before the request body is read
  • Determine content type from magic bytes, never trusting the client Content-Type header or file extension

Explicitly out of scope

  • Checksum de-duplication is covered by E29-S01-T02
  • Safe object key generation is covered by E29-S01-T03

Test plan

  • Send an oversized upload and assert a clear rejection error
  • Send a forged MIME type and assert magic-byte detection

Rollback note

  • Revert the validation logic; no data change

Owning stream

platform

Risk quadrant

agent-full

> Parent story: [E29-S01] Upload endpoint and validation (#112) ## Intent Reject oversized uploads and forged MIME types at the endpoint before anything is stored. ## Acceptance criteria - Reject uploads exceeding the configured maximum size before the request body is read - Determine content type from magic bytes, never trusting the client `Content-Type` header or file extension ## Explicitly out of scope - Checksum de-duplication is covered by E29-S01-T02 - Safe object key generation is covered by E29-S01-T03 ## Test plan - Send an oversized upload and assert a clear rejection error - Send a forged MIME type and assert magic-byte detection ## Rollback note - Revert the validation logic; no data change ### Owning stream platform ### Risk quadrant agent-full
kpcto added this to the Sprint M milestone 2026-08-27 08:05:12 +00:00
kpcto added the
kind
task
status
proposed
labels 2026-08-27 08:05:12 +00:00
Sign in to join this conversation.