🩹(backend) ignore non-recording uploads in storage webhook handler

With the introduction of background file uploads, a misconfigured
MinIO webhook could trigger the storage hook endpoint for unrelated
files.

While the dev setup now filters events via the MinIO lifecycle
configuration, add a safeguard at the application level.

Enforce a stricter filepath regex when parsing storage hook events
and ignore files outside the recording output directory.

Return a clean 200 response to acknowledge the webhook while
avoiding unnecessary processing.
This commit is contained in:
lebaudantoine
2026-03-12 14:57:41 +01:00
parent f8b0746e73
commit cb4ed3c9d7
5 changed files with 42 additions and 9 deletions
+6
View File
@@ -38,6 +38,7 @@ from core.recording.enums import FileExtension
from core.recording.event.authentication import StorageEventAuthentication
from core.recording.event.exceptions import (
InvalidBucketError,
InvalidFilepathError,
InvalidFileTypeError,
ParsingEventDataError,
)
@@ -761,6 +762,11 @@ class RecordingViewSet(
except InvalidBucketError as e:
raise drf_exceptions.PermissionDenied("Invalid bucket specified") from e
except InvalidFilepathError as e:
return drf_response.Response(
{"message": f"Ignore this filepath, {e}"},
)
except InvalidFileTypeError as e:
return drf_response.Response(
{"message": f"Ignore this file type, {e}"},