Skip to content

Fix DoS risk in /api/anonymize upload handling (Issue #222)#224

Merged
pradeeban merged 3 commits intohealthyinc:devfrom
kallal79:fix/issue-222-dos-upload-hardening
Apr 11, 2026
Merged

Fix DoS risk in /api/anonymize upload handling (Issue #222)#224
pradeeban merged 3 commits intohealthyinc:devfrom
kallal79:fix/issue-222-dos-upload-hardening

Conversation

@kallal79
Copy link
Copy Markdown

@kallal79 kallal79 commented Apr 4, 2026

Fixes #222 by replacing in-memory /api/anonymize uploads with disk-backed temp storage, enforcing a 20MB limit, cleaning temp files, and adding regression tests for oversized upload rejection.

@kallal79
Copy link
Copy Markdown
Author

kallal79 commented Apr 4, 2026

Hi @pradeeban, could you please review PR #224 ?

@pradeeban
Copy link
Copy Markdown
Member

/gemini review

2 similar comments
@kallal79
Copy link
Copy Markdown
Author

kallal79 commented Apr 4, 2026

/gemini review

@kallal79
Copy link
Copy Markdown
Author

kallal79 commented Apr 6, 2026

/gemini review

@kallal79
Copy link
Copy Markdown
Author

kallal79 commented Apr 6, 2026

/gemini review

@kallal79
Copy link
Copy Markdown
Author

kallal79 commented Apr 6, 2026

HI Sir @pradeeban , Please review PR #224 ..

@kallal79
Copy link
Copy Markdown
Author

kallal79 commented Apr 7, 2026

HI Sir @pradeeban , Please review PR #224 ..

1 similar comment
@kallal79
Copy link
Copy Markdown
Author

HI Sir @pradeeban , Please review PR #224 ..

@pradeeban
Copy link
Copy Markdown
Member

@kallal79 ok, we did not configure gemini bot in healthyinc repositories. We did only for Kathiravelulab repositories. That is why it is not responding to us. :)

@pradeeban pradeeban merged commit 024a6fc into healthyinc:dev Apr 11, 2026
4 of 5 checks passed
@kallal79 kallal79 deleted the fix/issue-222-dos-upload-hardening branch April 12, 2026 03:04
@kallal79
Copy link
Copy Markdown
Author

Thank you @pradeeban for merging PR #224!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants