Conversation
Release titles containing double quotes caused MultipartFormDataContent.Add to throw an ArgumentException, so the NZB was never sent to SABnzbd. On Linux, Path.GetInvalidFileNameChars does not include quotes, so the existing sanitizer did not catch this.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Sending an NZB to SABnzbd fails with an ArgumentException when the release
title contains double quotes. The title is used as the multipart upload
filename, and .NET rejects quotes in that header. The existing sanitizer
uses Path.GetInvalidFileNameChars, which strips quotes on Windows but not
on Linux, so this only shows up in Docker.
Changes
Fixed
Testing
Reproduced on 1.3.4 canary in Docker with a DrunkenSlug release whose title
contained quotes. Stack trace pointed at SabnzbdAddWorkflow.AddAsync line 48.
Built this branch with the repo Dockerfile and ran it in place of the canary
image on TrueNAS. Sent three releases with quoted titles that previously
failed; all three logged "Successfully added NZB to SABnzbd" and appeared in
the SABnzbd queue with the expected category. No unit test was added.
Notes
SABnzbd takes the job name from the nzbname query parameter, so the
sanitized upload filename has no visible effect.