Fix critical issues from PR #681 review

Critical fixes:
- BinaryProtocol: Return nil for unknown versions (prevents buffer underflows)
- Add BinaryProtocol.Offsets struct to centralize magic numbers
- Replace magic offset calculations with named constants

Security/Privacy:
- FileAttachmentView: Use url.lastPathComponent instead of url.path
  (prevents exposing full system paths)

Documentation:
- Fix compression algorithm documentation (zlib, not LZ4)

All tests passing.
This commit is contained in:
jack
2025-10-15 00:39:19 +01:00
committed by islam
parent 757acef8d1
commit 6533293f75
5 changed files with 26 additions and 15 deletions
@@ -127,9 +127,8 @@ struct NotificationStreamAssemblerTests {
return XCTFail("Failed to encode packet frame")
}
let flagsOffset = 1 + 1 + 1 + 8
XCTAssertLessThan(flagsOffset, frame.count)
let flags = frame[frame.startIndex + flagsOffset]
XCTAssertLessThan(BinaryProtocol.Offsets.flags, frame.count)
let flags = frame[frame.startIndex + BinaryProtocol.Offsets.flags]
XCTAssertNotEqual(flags & BinaryProtocol.Flags.isCompressed, 0, "Frame should be compressed for large payloads")
let splitIndex = min(4096, frame.count / 2)
@@ -68,7 +68,10 @@ struct BinaryProtocolTests {
let encodedData = try #require(BinaryProtocol.encode(packet), "Failed to encode packet with large payload")
// The encoded size should be smaller than uncompressed due to compression
let headerSize = BinaryProtocol.headerSize(for: packet.version)
guard let headerSize = BinaryProtocol.headerSize(for: packet.version) else {
XCTFail("Invalid version")
return
}
let uncompressedSize = headerSize + BinaryProtocol.senderIDSize + largePayload.count
#expect(encodedData.count < uncompressedSize)