build(infra): run ClamAV in compose and on the cluster (closes #191) #193
@@ -33,8 +33,10 @@ and that makes it an ADR (CLAUDE.md §14).
|
|||||||
**no NuGet package** for it (nClam and similar).
|
**no NuGet package** for it (nClam and similar).
|
||||||
4. **Fail closed:** if clamd can't be reached, the upload is refused (503). Nothing is
|
4. **Fail closed:** if clamd can't be reached, the upload is refused (503). Nothing is
|
||||||
stored and the document wait stays open. We never store an unscanned file.
|
stored and the document wait stays open. We never store an unscanned file.
|
||||||
5. **Type check:** content must start with `%PDF-`. This refuses a renamed executable
|
5. **Type check:** content must also start with `%PDF-`, checked **after** the scan.
|
||||||
before the scan, and it costs nothing.
|
clamd matches EICAR (and many real signatures) only at the start of a file, so a type
|
||||||
|
check in front of the scan would report malware as merely "not a PDF". The check also
|
||||||
|
refuses a renamed non-PDF that is clean.
|
||||||
|
|
||||||
## Consequences
|
## Consequences
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user