Skip to content

Conversation

@otaviojacobi
Copy link
Contributor

@otaviojacobi otaviojacobi commented May 4, 2025

Using the filename on the s3 key is not a good idea as these can contain lots of weird characters and open ways for security breaches. The UUID should be enough to guarantee uniqueness on the keys and the fieldName should be enough to at least point to a direction on what this resource is.

This is also not breaking as the href field of old webresources should still work fine but the new ones shall not use possibly skewed data.

See: https://balena.fibery.io/search/DMBt7#Work/Improvement/Make-webresources-file-deletion-more-reliable-2819

Change-type: patch

Using the filename on the s3 key is not a good idea as these can contain lots of weird characters and open ways for security breaches.
The UUID should be enough to guarantee uniqueness on the keys and the fieldName should be enough to at least point to a direction on what this resource is.

This is also not breaking as the href field of old webresources should still work fine but the new ones shall not use possibly skewed data.

Change-type: patch
@otaviojacobi otaviojacobi requested a review from a team May 4, 2025 20:27
@flowzone-app flowzone-app bot enabled auto-merge May 4, 2025 20:29
@otaviojacobi otaviojacobi force-pushed the stop-using-customer-property-on-s3-keys branch from 78ed8a7 to 63142d6 Compare May 5, 2025 19:36
@flowzone-app flowzone-app bot merged commit 64302dc into master May 6, 2025
49 checks passed
@flowzone-app flowzone-app bot deleted the stop-using-customer-property-on-s3-keys branch May 6, 2025 17:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants