Skip to content

No server-side file size limit #11

@davidnoyes

Description

@davidnoyes

Bug Description

The client enforces a 20MB limit, but the server does not validate file size before broadcasting. A modified client can send arbitrarily large files to all connected users.

File & Lines

server code.py — lines 489–499

Severity

Policy/validation gap — server trusts client-side validation only.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions