feat(domain): scan before the PDF check so malware is always reported as infected (refs #192)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -50,16 +50,17 @@ public sealed class ProvideDocuments(IRegistrationStore store, IWorkflowClient w
|
|||||||
return ProvideDocumentsOutcome.NotFound;
|
return ProvideDocumentsOutcome.NotFound;
|
||||||
|
|
||||||
// Only a clean PDF goes any further (S-29, ADR-0036): checked after ownership, so a stranger
|
// Only a clean PDF goes any further (S-29, ADR-0036): checked after ownership, so a stranger
|
||||||
// learns nothing about the file, and before anything is stored or the wait is completed.
|
// learns nothing about the file, and before anything is stored or the wait is completed. Scan
|
||||||
if (!command.Content.AsSpan().StartsWith("%PDF-"u8))
|
// before the PDF check, so malware is reported as malware whatever it claims to be.
|
||||||
return ProvideDocumentsOutcome.NotAPdf;
|
|
||||||
|
|
||||||
switch (await scanner.ScanAsync(command.Content, ct))
|
switch (await scanner.ScanAsync(command.Content, ct))
|
||||||
{
|
{
|
||||||
case ScanVerdict.Infected: return ProvideDocumentsOutcome.Infected;
|
case ScanVerdict.Infected: return ProvideDocumentsOutcome.Infected;
|
||||||
case ScanVerdict.Unavailable: return ProvideDocumentsOutcome.ScannerUnavailable;
|
case ScanVerdict.Unavailable: return ProvideDocumentsOutcome.ScannerUnavailable;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (!command.Content.AsSpan().StartsWith("%PDF-"u8))
|
||||||
|
return ProvideDocumentsOutcome.NotAPdf;
|
||||||
|
|
||||||
// Store the diploma against the zaak (once it is opened) — the ACL is the only ZGW caller (§8.1).
|
// Store the diploma against the zaak (once it is opened) — the ACL is the only ZGW caller (§8.1).
|
||||||
if (registration.ZaakUrl is not null)
|
if (registration.ZaakUrl is not null)
|
||||||
await acl.StoreDiplomaAsync(
|
await acl.StoreDiplomaAsync(
|
||||||
|
|||||||
Reference in New Issue
Block a user