mirror of
https://github.com/THU-MAIC/OpenMAIC.git
synced 2026-10-04 02:08:36 +08:00
* fix(upload): resolve the generic Office MIME via filename extension (#1497) On Linux, Chrome derives File.type from the XDG shared-mime-info database. Older or trimmed databases (e.g. Kylin OS V10) map every OOXML extension to the generic container `application/vnd.ms-office` instead of the concrete format MIME, so .pptx/.docx/.xlsx uploads were rejected with "当前解析器不支持该格式" on the generation toolbar and with 415 unsupported_mime on POST /api/materials — while the same files upload fine on macOS/Windows. Treat `application/vnd.ms-office` as a generic upload fallback alongside the zip family, so the filename extension decides the concrete format: - lib/document/mime.ts: add it to GENERIC_DOCUMENT_MIME_TYPES. This covers the toolbar's provider-whitelist check and the extract-document API gate (both call normalizeDocumentMimeType). It must NOT go into per-format aliasMimes — canonicalFromAlias iterates DOCUMENT_FORMATS in declaration order, so a shared alias would misroute x.pptx to application/msword. - lib/workbench/material-upload-policy.ts: new resolveWorkbenchMaterialMime() grants missing/octet-stream/zip/vnd.ms-office types the same extension fallback the document path already had (the workbench gate previously rejected empty and zip-family types outright on every OS). - app/api/materials/route.ts + session-store.ts: gate, store, and send the resolved MIME instead of the raw browser value. The spoofing surface is unchanged: a specific but unsupported MIME still falls through verbatim for the whitelist to reject, and an unknown extension keeps the generic MIME. Full suite: 7992 passed. Closes #1497 Co-Authored-By: Claude Code <noreply@anthropic.com> * fix(review): log the declared mime, harden the fallback chain, pin adversarial cases Review follow-ups on #1498 (no correctness or security findings — hygiene only): - materials route: the reject/context log now carries declaredMime alongside the resolved mime whenever they differ, so a generic-header spoof stays visible in upload failure logs instead of collapsing to the resolved type. - uploadWorkbenchMaterial: the returned record's mimeType falls back to the locally resolved mime before the raw browser value, which may still be the generic Office container if the server echo is ever absent. - material-upload-policy: export WORKBENCH_MATERIAL_EXTENSIONS and add a drift guard asserting every accepted extension resolves (via a generic MIME) to a whitelisted type — a hand-maintained map entry going missing now fails tests instead of silently 415ing. - tests: pin the legacy-.ppt provider split (mineru rejects, mineru-cloud accepts), uppercase-extension resolution, and 415-before-400 precedence for a generic mime with no filename. Full suite: 7996 passed. Co-Authored-By: Claude Code <noreply@anthropic.com> * fix(upload): support WPS Office MIME aliases --------- Co-authored-by: Claude Code <noreply@anthropic.com> Co-authored-by: wyuc <wang-yc24@mails.tsinghua.edu.cn>