• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

pulibrary / orangelight / 2d9d2978-cc59-410e-b0a2-90826072e6b0
95%
main: 95%

Build:
Build:
LAST BUILD BRANCH: 5337-some-available-badge
DEFAULT BRANCH: main
Ran 31 Jul 2025 04:30PM UTC
Jobs 1
Files 206
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

31 Jul 2025 04:24PM UTC coverage: 95.408% (+0.008%) from 95.4%
2d9d2978-cc59-410e-b0a2-90826072e6b0

Pull #5128

circleci

sandbergja
[#5124] Reject requests that contain file uploads

While these file uploads are very limited with regards to how much damage they can
do directly (they are not uploaded to a folder that is served to the web, they are
deleted very quickly by the Rack tempfile reaper or ruby gc very quickly, etc.),
they can set off OIT's security sensors leading to our VMs being quarantined, which
is a threat to the availability of the catalog service.

Users don't need to upload files to the catalog, so let's just reject requests
of this type.

Rack has a nice seam for this: it allows us to supply a tempfile factory to customize
how we store these uploaded files on disk.  This commit simply raises an exception
as our implementation of this factory; I could imagine that implementing a factory
that returns a file handle to /dev/null could work as an alternative approach.

Closes #5124
Pull Request #5128: [#5124] Reject requests that contain file uploads

11 of 11 new or added lines in 1 file covered. (100.0%)

6025 of 6315 relevant lines covered (95.41%)

1520.41 hits per line

Jobs
ID Job ID Ran Files Coverage
1 2d9d2978-cc59-410e-b0a2-90826072e6b0.1 31 Jul 2025 04:30PM UTC 206
95.41
Source Files on build 2d9d2978-cc59-410e-b0a2-90826072e6b0
  • Tree
  • List 206
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • CircleCI Build #2D9D2978...
  • Pull Request #5128
  • PR Base - main (#D708331F...)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc