From 4e2fa53fbb24b1a5c7a3df8f73e6cd01a9477299 Mon Sep 17 00:00:00 2001 From: Russ Poetker Date: Thu, 19 Dec 2024 08:40:55 -0500 Subject: [PATCH] Revert "Cleanse API input params" This reverts commit d05660f6 --- .../pass/file/service/PassFileServiceController.java | 9 ++------- 1 file changed, 2 insertions(+), 7 deletions(-) diff --git a/pass-core-file-service/src/main/java/org/eclipse/pass/file/service/PassFileServiceController.java b/pass-core-file-service/src/main/java/org/eclipse/pass/file/service/PassFileServiceController.java index b34ee328..72561233 100644 --- a/pass-core-file-service/src/main/java/org/eclipse/pass/file/service/PassFileServiceController.java +++ b/pass-core-file-service/src/main/java/org/eclipse/pass/file/service/PassFileServiceController.java @@ -103,14 +103,11 @@ public ResponseEntity fileUpload(@RequestParam("file") MultipartFile file, Pr @ResponseBody public ResponseEntity getFileById(@PathVariable("uuid") String uuid, @PathVariable("origFileName") String origFileName) { + String fileId = uuid + "/" + origFileName; if (StringUtils.isEmpty(uuid) || StringUtils.isEmpty(origFileName)) { LOG.error("File ID not provided to get a file."); return ResponseEntity.badRequest().body("File ID not provided to get a file."); } - String cleansedUuid = StringUtils.normalizeSpace(uuid); - String cleansedOrigFileName = StringUtils.normalizeSpace(origFileName); - String fileId = cleansedUuid + "/" + cleansedOrigFileName; - ByteArrayResource fileResource; String contentType = ""; @@ -144,9 +141,7 @@ public ResponseEntity deleteFileById(@PathVariable("uuid") String uuid, @PathVariable("origFileName") String origFileName, Principal principal, HttpServletRequest request) { String principalName = principal.getName(); - String cleansedUuid = StringUtils.normalizeSpace(uuid); - String cleansedOrigFileName = StringUtils.normalizeSpace(origFileName); - String fileId = cleansedUuid + "/" + cleansedOrigFileName; + String fileId = uuid + "/" + origFileName; //Get the file, check that it exists, and then check if current user has permissions to delete try {