Repository navigation
fix(file-service, frontend): reject slash in version names - #8883
Conversation
createDatasetVersion and createModelVersion build the version name
"v{N} - {description}" from free text. The name is one segment of the
logical path /<prefix>/owner/resource/version/file, which FileResolver
splits on "/", so a "/" in the description shifted every later segment
and none of that version's files could be opened again
(presign-download returned a 500).
Reject a description containing "/" with a 400 before the LakeFS commit,
so the staged files stay staged and the user can fix the description and
retry. The version uploader, which datasets and models both use, now
shows the error and disables Submit instead of sending the request.
Versions already stored with a "/" in their name are not repaired.
Closes apache#8882
Automated Reviewer SuggestionsBased on the
|
Backport auto-label reportThis
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #8883 +/- ##
=========================================
Coverage 92.59% 92.59%
Complexity 5059 5059
=========================================
Files 1255 1255
Lines 53622 53630 +8
Branches 6693 6694 +1
=========================================
+ Hits 49652 49660 +8
Misses 2314 2314
Partials 1656 1656
*This pull request uses carry forward flags. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
🟡 Changes recommended
The new validation error is inaccessible to screen-reader users, and required manual UI verification details are missing.
2 open findings
What changed in this PR
Prevents invalid dataset and model version descriptions containing /, avoiding unresolvable file paths.
Changes:
- Adds shared backend validation before LakeFS commits.
- Adds inline frontend validation and submission guards.
- Adds backend and frontend regression tests.
| File | Description |
|---|---|
version-uploader.component.ts |
Blocks invalid submissions. |
version-uploader.component.html |
Displays validation and disables Submit. |
version-uploader.component.scss |
Styles the validation message. |
version-uploader.component.spec.ts |
Tests slash validation and Enter handling. |
ResourceNaming.scala |
Adds shared description validation. |
DatasetResource.scala |
Validates dataset versions before commit. |
ModelResource.scala |
Validates model versions before commit. |
ResourceNamingSpec.scala |
Tests validator boundaries. |
DatasetResourceSpec.scala |
Tests dataset rejection and retry. |
ModelUploadResourceSpec.scala |
Tests model rejection and retry. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
…ive tech The slash error was a plain div, so a screen-reader user met a disabled Submit with no stated reason. Mark the message `role="alert"`, and point the input at it with `aria-describedby` and `aria-invalid` while the error is showing. `versionName` is a non-null string, so drop the dead null branch in `versionNameHasSlash`.
…-slash # Conflicts: # file-service/src/test/scala/org/apache/texera/service/resource/DatasetResourceSpec.scala


What changes were proposed in this PR?
Root cause.
createDatasetVersionnames a versionv{N} - {description}from whatever the user typed, and the UI accepted a/. The version name is one segment of the logical path/<prefix>/owner/resource/version/file, andFileResolver.parsePrefixedPathsplits that path on/. For the path in the issue,/texera/bughunt-version-name/v3 - //file_name.png, the version becomesv3 -and/file_name.pngbecomes the file path, so the version lookup misses andpresign-downloadreturns a 500.createModelVersionbuilds its name the same way, so model versions have the same problem.Fix.
ResourceNaming.validateVersionDescriptionrejects a description containing/with a 400.createDatasetVersionandcreateModelVersioncall it right after the write-access check, before the LakeFS commit, so the staged files stay staged and the user can fix the description and retry. The version uploader, which datasets and models both use, shows the error under the input and disables Submit, andEnterno longer submits either.Not included. Versions already stored with a
/in their name stay unopenable, and repairing them needs a data migration. A%or+in a name has a separate problem, becauseresolveVersionedFileURL-decodesfilePatha second time.Any related issues, documentation, discussions?
Closes #8882
How was this PR tested?
Tests were added for the validator, for both resources, and for the version uploader, and they were written first and failed against the old code.
The first command passes 177 tests and the second passes 73.
scalafixAll,scalafmtAll,prettier-eslintandeslintran clean on the changed files.Screen.Recording.2026-10-06.at.11.49.20.AM.mov
Was this PR authored or co-authored using generative AI tooling?
Generated-by: Claude Code, Claude Sonnet 5.5