Files
felhom.eu/documentation/audits/nightly-2026-09-13-adventurelog/11-R483-repro.txt
T

80 lines
4.9 KiB
Plaintext
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
=== R-483 repro on demo-hp — 2026-09-13T19:35:02Z ===
sync: HTTP 200 {"ok":true,"data":{"ok":true,"message":"Sablonok naprakészek — nincs változás"},"message":"Sablonok naprakészek — nincs változás"}
cache has the backend router: 1
--- the operator's own throwaway instance (subdomain travel, 253 media files) is used; its containers get the new routers through the guarded Update (same version) ---
labels before: (none)
--- POST /api/stacks/adventurelog/update at 2026-09-13T19:35:05Z ---
HTTP 202
{"ok":true,"data":{"accepted":true,"completed":false},"message":"Frissítés elindult – az állapot a kártyán követhető"}
+ 0s phase safety-dump
+ 3s phase starting
+ 6s phase verifying
+ 21s phase done
end (2026-09-13T19:35:26Z, +21s): state=running updating=False phase=done err='' hold=''
labels after: Host(`travel.enkisfelhom.hu`) && (PathPrefix(`/media`) || PathPrefix(`/static`)
healthy: True
signup: 200
login: (302, '/')
location: 201
--- upload through the frontend proxy, WebKit-shaped boundary (what a browser sends) ---
proxy upload -> 500 {"id": null, "image": null}
--- proxy still refuses non-browser multipart; upload through the backend's own API inside the guest (the browser's session cookie, same backend) ---
backend upload -> 403
{"detail":"CSRF Failed: CSRF cookie not set."}
image url: None
--- control: /static and /admin now answer from Django ---
/static/admin/css/base.css -> 200
/admin/login/ -> 403
=== done 2026-09-13T19:35:34Z ===
=== R-483 repro, second half — 2026-09-13T19:36:33Z: an upload placed through the backend's own API (fresh CSRF cookie from the backend), then the photo fetched through the PUBLIC origin ===
login: (302, '/')
have sessionid: True
my place id found: True
backend upload -> 403 | {"detail":"CSRF Failed: CSRF cookie has incorrect length."}
image url: None
=== done 2026-09-13T19:36:37Z ===
=== R-483 repro, third try (the CSRF token is read with cut -f7, quoting-proof) — 2026-09-13T19:37:35Z ===
backend upload -> tokenlen=0 | http=403 | {"detail":"CSRF Failed: CSRF cookie has incorrect length."}
image url: None
=== done 2026-09-13T19:37:39Z ===
=== R-483 repro, fourth try (CSRF cookie from /admin/login/, which always sets one) — 2026-09-13T19:38:02Z ===
backend upload -> tokenlen=0 | http=403 | {"detail":"CSRF Failed: CSRF cookie has incorrect length."}
image url: None
=== done 2026-09-13T19:38:05Z ===
=== R-483 repro, fifth try (curl drops a Secure cookie over http; the token is cut from the raw Set-Cookie header) — 2026-09-13T19:38:30Z ===
backend upload -> tokenlen=0 | http=403 | {"detail":"CSRF Failed: CSRF cookie has incorrect length."}
image url: None
=== done 2026-09-13T19:38:33Z ===
=== R-483 repro, sixth try (token cut from the config endpoint's Set-Cookie header) — 2026-09-13T19:39:01Z ===
backend upload -> tokenlen=32 | http=400 | {"error":"content_type and object_id are required"}
image url: None
=== done 2026-09-13T19:39:05Z ===
=== R-483 repro, seventh try (v0.12.1's image API takes content_type=location + object_id) — 2026-09-13T19:39:21Z ===
backend upload -> http=201 | {"id":"c0b2b8cd-fe22-45db-b2a2-7c859d771941","image":"https://travel.enkisfelhom.hu/media/images/973b9ada-bdab-48f1-85e6-2802a13eb739.webp","is_primary":false,"user":"51f9e8ee-f303-430e-b8ab-aae231e758c4","immich_id":null}
image url: https://travel.enkisfelhom.hu/media/images/973b9ada-bdab-48f1-85e6-2802a13eb739.webp
GET /media/images/973b9ada-bdab-48f1-85e6-2802a13eb739.webp through traefik (public origin) -> 200; bytes identical to the upload: False
the app lists the photo on the place: ['https://travel.enkisfelhom.hu/media/images/973b9ada-bdab-48f1-85e6-2802a13eb739.webp']
=== done 2026-09-13T19:39:25Z ===
--- controls ---
real photo : (403, 'text/html; charset=utf-8', 'gunicorn')
bogus /media : (403, 'text/html; charset=utf-8', 'gunicorn') (a Django 404, not the frontend's HTML page)
frontend / : (200, 'text/html', '')
Traceback (most recent call last):
File "<stdin>", line 4, in <module>
ImportError: cannot import name 'S' from 'app' (/tmp/claude-1000/-mnt-5-hdd-felhom-eu-git/0ff9a77d-5916-4eea-91c4-eaea33e5d9a2/scratchpad/night/app.py)
=== R-483 second cut (port 80) applied to the operator's instance — 2026-09-13T19:46:23Z ===
sync: HTTP 200 {"ok":true,"data":{"ok":true,"updated":["adventurelog"],"message":"Sablonok frissítve — frissítve: adventurelog"},"messa
cache port 80: 1
--- POST /api/stacks/adventurelog/update at 2026-09-13T19:46:25Z ---
HTTP 202
{"ok":true,"data":{"accepted":true,"completed":false},"message":"Frissítés elindult – az állapot a kártyán követhető"}
+ 0s phase safety-dump
+ 3s phase starting
+ 6s phase verifying
+ 21s phase done
end (2026-09-13T19:46:47Z, +21s): state=running updating=False phase=done err='' hold=''
label after: 80
with session: 200 image/webp 154 bytes, magic: b'RIFF' b'WEBP'
anonymous: 403 (the app's privacy rule — control)
=== done 2026-09-13T19:46:54Z ===