[SECURITY] API: Fix session validation for uploaded files (CVE-2026-101269, Z#23247174)

This commit is contained in:
Raphael Michel
2026-09-29 14:30:54 +02:00
parent bbf391f7d5
commit 74332faa7b
5 changed files with 38 additions and 7 deletions
+9
View File
@@ -0,0 +1,9 @@
def get_session_key_for_api_auth(user, auth):
if user.is_authenticated:
return f'api-upload-User-{user.pk}'
else:
return f'api-upload-{str(type(auth))}-{auth.pk}'
def get_session_key_for_api_request(request):
return get_session_key_for_api_auth(request.user, request.auth)