Merge pull request #69 from christianlouis/copilot/start-next-roadmap-item
Replace hardcoded /tmp with tempfile module for secure temporary file creation
This commit is contained in:
@@ -2,6 +2,7 @@
|
|||||||
|
|
||||||
import os
|
import os
|
||||||
import shutil
|
import shutil
|
||||||
|
import tempfile
|
||||||
import PyPDF2 # Replace fitz with PyPDF2
|
import PyPDF2 # Replace fitz with PyPDF2
|
||||||
import json
|
import json
|
||||||
from app.config import settings
|
from app.config import settings
|
||||||
@@ -62,10 +63,13 @@ def embed_metadata_into_pdf(local_file_path: str, extracted_text: str, metadata:
|
|||||||
print(f"[ERROR] Local file {local_file_path} not found, cannot embed metadata.")
|
print(f"[ERROR] Local file {local_file_path} not found, cannot embed metadata.")
|
||||||
return {"error": "File not found"}
|
return {"error": "File not found"}
|
||||||
|
|
||||||
# Work on a safe copy in /tmp
|
# Work on a safe copy in a secure temporary directory
|
||||||
tmp_dir = "/tmp"
|
|
||||||
original_file = local_file_path
|
original_file = local_file_path
|
||||||
processed_file = os.path.join(tmp_dir, f"processed_{os.path.basename(local_file_path)}")
|
# Create a temporary file with the same extension as the original
|
||||||
|
_, ext = os.path.splitext(local_file_path)
|
||||||
|
tmp_file = tempfile.NamedTemporaryFile(mode='wb', suffix=ext, prefix='processed_', delete=False)
|
||||||
|
processed_file = tmp_file.name
|
||||||
|
tmp_file.close()
|
||||||
|
|
||||||
# Create a safe copy to work on
|
# Create a safe copy to work on
|
||||||
shutil.copy(original_file, processed_file)
|
shutil.copy(original_file, processed_file)
|
||||||
@@ -132,4 +136,11 @@ def embed_metadata_into_pdf(local_file_path: str, extracted_text: str, metadata:
|
|||||||
|
|
||||||
except Exception as e:
|
except Exception as e:
|
||||||
print(f"[ERROR] Failed to embed metadata into {processed_file}: {e}")
|
print(f"[ERROR] Failed to embed metadata into {processed_file}: {e}")
|
||||||
|
# Clean up temporary file in case of error
|
||||||
|
if os.path.exists(processed_file):
|
||||||
|
try:
|
||||||
|
os.remove(processed_file)
|
||||||
|
print(f"[INFO] Cleaned up temporary file {processed_file}")
|
||||||
|
except Exception as cleanup_error:
|
||||||
|
print(f"[ERROR] Could not clean up temporary file {processed_file}: {cleanup_error}")
|
||||||
return {"error": str(e)}
|
return {"error": str(e)}
|
||||||
|
|||||||
Reference in New Issue
Block a user