Files
OpenMAIC/tests/document
90cf53f142 fix(upload): resolve the generic Office MIME (application/vnd.ms-office) via filename extension (#1498)
* fix(upload): resolve the generic Office MIME via filename extension (#1497)

On Linux, Chrome derives File.type from the XDG shared-mime-info database.
Older or trimmed databases (e.g. Kylin OS V10) map every OOXML extension to
the generic container `application/vnd.ms-office` instead of the concrete
format MIME, so .pptx/.docx/.xlsx uploads were rejected with "当前解析器不支持该格式"
on the generation toolbar and with 415 unsupported_mime on POST /api/materials
— while the same files upload fine on macOS/Windows.

Treat `application/vnd.ms-office` as a generic upload fallback alongside the
zip family, so the filename extension decides the concrete format:

- lib/document/mime.ts: add it to GENERIC_DOCUMENT_MIME_TYPES. This covers
  the toolbar's provider-whitelist check and the extract-document API gate
  (both call normalizeDocumentMimeType). It must NOT go into per-format
  aliasMimes — canonicalFromAlias iterates DOCUMENT_FORMATS in declaration
  order, so a shared alias would misroute x.pptx to application/msword.
- lib/workbench/material-upload-policy.ts: new resolveWorkbenchMaterialMime()
  grants missing/octet-stream/zip/vnd.ms-office types the same extension
  fallback the document path already had (the workbench gate previously
  rejected empty and zip-family types outright on every OS).
- app/api/materials/route.ts + session-store.ts: gate, store, and send the
  resolved MIME instead of the raw browser value.

The spoofing surface is unchanged: a specific but unsupported MIME still
falls through verbatim for the whitelist to reject, and an unknown extension
keeps the generic MIME. Full suite: 7992 passed.

Closes #1497

Co-Authored-By: Claude Code <noreply@anthropic.com>

* fix(review): log the declared mime, harden the fallback chain, pin adversarial cases

Review follow-ups on #1498 (no correctness or security findings — hygiene only):

- materials route: the reject/context log now carries declaredMime alongside
  the resolved mime whenever they differ, so a generic-header spoof stays
  visible in upload failure logs instead of collapsing to the resolved type.
- uploadWorkbenchMaterial: the returned record's mimeType falls back to the
  locally resolved mime before the raw browser value, which may still be the
  generic Office container if the server echo is ever absent.
- material-upload-policy: export WORKBENCH_MATERIAL_EXTENSIONS and add a
  drift guard asserting every accepted extension resolves (via a generic
  MIME) to a whitelisted type — a hand-maintained map entry going missing
  now fails tests instead of silently 415ing.
- tests: pin the legacy-.ppt provider split (mineru rejects, mineru-cloud
  accepts), uppercase-extension resolution, and 415-before-400 precedence
  for a generic mime with no filename.

Full suite: 7996 passed.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* fix(upload): support WPS Office MIME aliases

---------

Co-authored-by: Claude Code <noreply@anthropic.com>
Co-authored-by: wyuc <wang-yc24@mails.tsinghua.edu.cn>
2026-09-14 17:53:08 +02:00
..