🐛(backend) make extension checking case insensitive

The extension check was not case insensitive. If the extension used is
in uppercase then it will fail despite it is allowed
This commit is contained in:
Manuel Raynaud
2026-01-13 18:21:48 +01:00
parent 30075b1053
commit babf71ea56
2 changed files with 21 additions and 1 deletions
+1 -1
View File
@@ -435,7 +435,7 @@ class CreateItemSerializer(ItemSerializer):
if settings.RESTRICT_UPLOAD_FILE_TYPE:
_root, extension = splitext(attrs["filename"])
if extension not in settings.FILE_EXTENSIONS_ALLOWED:
if extension.lower() not in settings.FILE_EXTENSIONS_ALLOWED:
logger.info(
"create_item: file extension not allowed %s for filename %s",
extension,
@@ -162,6 +162,26 @@ def test_api_items_create_file_authenticated_extension_not_allowed():
}
def test_api_items_create_file_authenticated_extension_case_insensitive():
"""
Creating a file item with an extension, no matter the case used, should be allowed.
"""
user = factories.UserFactory()
client = APIClient()
client.force_login(user)
response = client.post(
"/api/v1.0/items/",
{
"type": ItemTypeChoices.FILE,
"filename": "file.JPG",
},
format="json",
)
assert response.status_code == 201
item = Item.objects.exclude(id=user.get_main_workspace().id).get()
assert item.title == "file.JPG"
def test_api_items_create_file_authenticated_not_checking_extension(settings):
"""
Creating a file item with an extension not allowed should fail.