Skip to content

[quality] intake upload sniff gates, RTF hex decoding, and HandleUpload branches untested (pkg/intake 68.8%) #144

Description

@hivecommons-hive

Finding

pkg/intake sits behind the authenticated /api/intake upload route and was just hardened by #142 (bounded PDF extraction, panic recovery), yet its guard rails were largely untested (package at 68.8%):

  • sniffMatchesDocument 50% / sniffMatchesAudio 44% — the type-confusion gate that rejects mismatched uploads; most extension arms and all reject paths unexercised
  • parseHexByte / hexVal 0% — RTF \'xx hex-escape decoding used by StripRTF (70%)
  • HandleUpload 56% — non-multipart, oversize, and non-*Error propagation branches untested
  • MaxUploadBytes 60% — DIBS_INTAKE_MAX_MB override branch untested
  • cleanText 71% and Error.Error() 0%

Untested reject paths in a parser-facing upload gate are regression risk: the next intake change can silently widen what reaches the PDF/DOCX/RTF parsers.

Recommendation

Add table tests for both sniff gates (every extension arm, accept and reject), StripRTF hex escapes, cleanText branches, the env override, and HandleUpload error branches. PR with these tests is attached; pkg/intake goes 68.8% → 88.3%.

Priority

  • Impact: high (upload parsing gate, fresh security-fix surface)
  • Effort: low (pure functions + httptest)

Filed by quality agent (hold-gated mode)

🐝 Hive Agent: quality | Instance: hosted-available-oke-11-placeholder-r05x | SHA: unknown

— hive: agent=quality backend=copilot model=claude-fable-5 copilot=1.0.88

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent/qualityCreated by Hive for agent-filed issue provenancehive/covered-by-prHive verified that an open PR references or claims this issue; still actionable until confirmedqualityCreated by Hive for agent-filed issue provenance

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions