Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 23 additions & 9 deletions api/lib/uploader/utils.dart
Original file line number Diff line number Diff line change
Expand Up @@ -10,19 +10,30 @@ class Utils {
'filename',
];

static String apiSignRequest(
Map<String, dynamic> paramsMap, String apiSecret) {
List<String> paramsArr = <String>[];
static String apiSignRequest(Map<String, dynamic> paramsMap, String apiSecret) {
final escapePattern = RegExp(r'[&=%+#]');
final paramsArr = <String>[];

paramsMap.removeWhere((key, value) => value == null);
paramsMap.removeWhere(
(key, value) => value == null || _excludeKeys.contains(key));
var sortedParams = paramsMap.keys.whereType<String>().toList()..sort();
for (var key in sortedParams) {
paramsMap.removeWhere((key, value) => _excludeKeys.contains(key));

// Escape check for public_id only (extended)
if (paramsMap.containsKey('public_id')) {
final publicId = paramsMap['public_id'].toString();
if (escapePattern.hasMatch(publicId)) {
return '';
}
}

final sortedKeys = paramsMap.keys.whereType<String>().toList()..sort();

for (var key in sortedKeys) {
var value = paramsMap[key];
String? paramValue;

if (value is List<String>) {
if (value.isNotEmpty) {
paramValue = value.toString(); //.join(',');
paramValue = value.toString(); // KEEP original behavior (e.g. [a, b])
} else {
continue;
}
Expand All @@ -31,11 +42,14 @@ class Utils {
paramValue = value.toString();
}
}

if (paramValue != null) {
// KEEP original backslash-stripping behavior
paramsArr.add('$key=${paramValue.replaceAll(r'\', '')}');
}
}
var toSign = '${paramsArr.join('&')}$apiSecret';

final toSign = '${paramsArr.join('&')}$apiSecret';
return hex.encode(sha1.convert(utf8.encode(toSign)).bytes);
}

Expand Down
11 changes: 11 additions & 0 deletions api/test/uploader_test.dart
Original file line number Diff line number Diff line change
Expand Up @@ -549,6 +549,17 @@ void main() {
var result = resultOrThrow(response?.data);
assert(result.playbackUrl != null);
});

test('Test signature with escaping characters', () {
final toSign = {
'public_id': 'publicid&tags=blabla',
};

final apiSecret = 'your_api_secret'; // Replace with actual secret or mock
final signature = Utils.apiSignRequest(toSign, apiSecret);

expect(signature, equals(''));
});
}

validateSignature(UploadResult result) {
Expand Down
Loading