From 0f39d965188588ca7f44c24e18802e8b7ff05879 Mon Sep 17 00:00:00 2001 From: Mathijs van Veluw Date: Sun, 28 Jan 2024 23:32:09 +0100 Subject: [PATCH] Fix attachment upload size check (#4282) The min/max were reversed with the `add` and `sub` functions. This caused the files to always be out of bounds in the check. Fixes #4281 --- src/api/core/ciphers.rs | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/src/api/core/ciphers.rs b/src/api/core/ciphers.rs index 3aa4f9d721..b3dca3b681 100644 --- a/src/api/core/ciphers.rs +++ b/src/api/core/ciphers.rs @@ -1123,12 +1123,12 @@ async fn save_attachment( // the client. Upstream allows +/- 1 MiB deviation from this // size, but it's not clear when or why this is needed. const LEEWAY: i64 = 1024 * 1024; // 1 MiB - let Some(min_size) = attachment.file_size.checked_add(LEEWAY) else { - err!("Invalid attachment size min") - }; - let Some(max_size) = attachment.file_size.checked_sub(LEEWAY) else { + let Some(max_size) = attachment.file_size.checked_add(LEEWAY) else { err!("Invalid attachment size max") }; + let Some(min_size) = attachment.file_size.checked_sub(LEEWAY) else { + err!("Invalid attachment size min") + }; if min_size <= size && size <= max_size { if size != attachment.file_size {