fix(server): race WebSocket, SVG refusé, rows.Err, time.NewTicker

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Gilles Soulier
2026-05-22 12:18:25 +02:00
co-authored by Claude Sonnet 4.6
parent c0c7152b47
commit feba5d6b93
4 changed files with 45 additions and 16 deletions
+6 -8
View File
@@ -5,6 +5,7 @@ import (
"image"
_ "image/jpeg"
"image/png"
"io"
"net/http"
"strings"
@@ -40,18 +41,15 @@ func IconUploadHandler(database *db.DB) http.HandlerFunc {
mime = "image/png"
}
// SVG refusé (risque XSS)
if strings.Contains(mime, "svg") {
var buf bytes.Buffer
buf.ReadFrom(file)
if err := database.SaveIcon(agentID, buf.Bytes(), "image/svg+xml"); err != nil {
http.Error(w, err.Error(), 500)
return
}
w.WriteHeader(http.StatusNoContent)
http.Error(w, "SVG non supporté — utilisez PNG, JPG ou WEBP", 400)
return
}
img, _, err := image.Decode(file)
// Limite de taille
limited := io.LimitReader(file, 2<<20)
img, _, err := image.Decode(limited)
if err != nil {
http.Error(w, "image invalide", 400)
return