mirror of
https://github.com/permissionlesstech/bitchat.git
synced 2026-07-25 03:45:20 +00:00
Fix critical issues from PR #681 review
Critical fixes: - BinaryProtocol: Return nil for unknown versions (prevents buffer underflows) - Add BinaryProtocol.Offsets struct to centralize magic numbers - Replace magic offset calculations with named constants Security/Privacy: - FileAttachmentView: Use url.lastPathComponent instead of url.path (prevents exposing full system paths) Documentation: - Fix compression algorithm documentation (zlib, not LZ4) All tests passing.
This commit is contained in:
@@ -127,9 +127,8 @@ struct NotificationStreamAssemblerTests {
|
||||
return XCTFail("Failed to encode packet frame")
|
||||
}
|
||||
|
||||
let flagsOffset = 1 + 1 + 1 + 8
|
||||
XCTAssertLessThan(flagsOffset, frame.count)
|
||||
let flags = frame[frame.startIndex + flagsOffset]
|
||||
XCTAssertLessThan(BinaryProtocol.Offsets.flags, frame.count)
|
||||
let flags = frame[frame.startIndex + BinaryProtocol.Offsets.flags]
|
||||
XCTAssertNotEqual(flags & BinaryProtocol.Flags.isCompressed, 0, "Frame should be compressed for large payloads")
|
||||
|
||||
let splitIndex = min(4096, frame.count / 2)
|
||||
|
||||
@@ -68,7 +68,10 @@ struct BinaryProtocolTests {
|
||||
let encodedData = try #require(BinaryProtocol.encode(packet), "Failed to encode packet with large payload")
|
||||
|
||||
// The encoded size should be smaller than uncompressed due to compression
|
||||
let headerSize = BinaryProtocol.headerSize(for: packet.version)
|
||||
guard let headerSize = BinaryProtocol.headerSize(for: packet.version) else {
|
||||
XCTFail("Invalid version")
|
||||
return
|
||||
}
|
||||
let uncompressedSize = headerSize + BinaryProtocol.senderIDSize + largePayload.count
|
||||
#expect(encodedData.count < uncompressedSize)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user