Safety limit for avatars

This commit is contained in:
Bohdan Horbeshko 2025-06-07 18:02:46 -04:00
parent 06964d832e
commit 3fd49923a1
4 changed files with 20 additions and 10 deletions

View file

@ -2,7 +2,7 @@
COMMIT := $(shell git rev-parse --short HEAD) COMMIT := $(shell git rev-parse --short HEAD)
TD_COMMIT := "5bbfc1cf5dab94f82e02f3430ded7241d4653551" TD_COMMIT := "5bbfc1cf5dab94f82e02f3430ded7241d4653551"
VERSION := "v1.12.3" VERSION := "v1.12.4"
MAKEOPTS := "-j4" MAKEOPTS := "-j4"
all: all:

View file

@ -16,7 +16,7 @@ import (
goxmpp "gosrc.io/xmpp" goxmpp "gosrc.io/xmpp"
) )
var version string = "1.12.3" var version string = "1.12.4"
var commit string var commit string
var sm *goxmpp.StreamManager var sm *goxmpp.StreamManager

View file

@ -91,6 +91,8 @@ const (
MembersListBannedAndAdministrators MembersListBannedAndAdministrators
) )
const AVATAR_SIZE_LIMIT int64 = 128 * 1024
// GetContactByUsername resolves username to user id retrieves user and chat information // GetContactByUsername resolves username to user id retrieves user and chat information
func (c *Client) GetContactByUsername(username string) (*client.Chat, *client.User, error) { func (c *Client) GetContactByUsername(username string) (*client.Chat, *client.User, error) {
if !c.Online() { if !c.Online() {
@ -315,6 +317,12 @@ func (c *Client) getFileData(tgFile *client.File, typ byte) string {
priority = 32 priority = 32
} }
// avoid not-well-formed stanza errors
if typ == typeFileDataBase64 && c.GetPhotoSize(tgFile) > AVATAR_SIZE_LIMIT {
log.Warnf("Photo %v skipped as it's too huge", tgFile.Id)
return ""
}
file, path, err := c.ForceOpenFile(tgFile, priority) file, path, err := c.ForceOpenFile(tgFile, priority)
if err == nil { if err == nil {
defer file.Close() defer file.Close()
@ -357,16 +365,16 @@ func (c *Client) SetEmptyAvatarHash(chatId int64) {
c.AvatarHashesLock.Unlock() c.AvatarHashesLock.Unlock()
} }
// GetPhotoSha1AndSize obtains data for PEP // GetPhotoSize return at least a rough size
func (c *Client) GetPhotoSha1AndSize(photo *client.File, chatId int64) (string, int64) { func (c *Client) GetPhotoSize(photo *client.File) int64 {
sha1 := c.GetPhotoSha1(photo, chatId) if photo == nil {
return 0
}
size := photo.Size size := photo.Size
if size == 0 { if size == 0 {
size = photo.ExpectedSize size = photo.ExpectedSize
} }
return size
return sha1, size
} }
// GetPhotoSha1 computes the photo hash // GetPhotoSha1 computes the photo hash
@ -1214,7 +1222,8 @@ func (c *Client) ProcessIncomingMessage(chatId int64, message *client.Message) {
if chat.Photo == nil { if chat.Photo == nil {
c.SetEmptyAvatarHash(chatId) c.SetEmptyAvatarHash(chatId)
} else { } else {
sha1, size := c.GetPhotoSha1AndSize(chat.Photo.Small, chatId) sha1 := c.GetPhotoSha1(chat.Photo.Small, chatId)
size := c.GetPhotoSize(chat.Photo.Small)
for resource := range c.resourcesRange() { for resource := range c.resourcesRange() {
features, ok := c.XmppClientFeatures[resource] features, ok := c.XmppClientFeatures[resource]

View file

@ -1375,7 +1375,8 @@ func sendPubSubAvatarNotifications(s xmpp.Sender, jid string, session *telegram.
continue continue
} }
sha1, size := session.GetPhotoSha1AndSize(chat.Photo.Small, chat.Id) sha1 := session.GetPhotoSha1(chat.Photo.Small, chat.Id)
size := session.GetPhotoSize(chat.Photo.Small)
gateway.SendPubSubAvatarNotification(component, jid, chat.Id, sha1, size) gateway.SendPubSubAvatarNotification(component, jid, chat.Id, sha1, size)
} }