Repository navigation
feat: richText resource extraction and downloadFileToFile - #3
Merged
haofeng0705 merged 8 commits intoSep 20, 2026
Conversation
- Keep Maven groupId as io.github.typefield (matches actual pom.xml) - Update all GitHub repository URLs to DingTalk-Real-AI - Fix go get command to use correct organization - Fix npm install command to use correct organization - Remove bilingual documentation (will be separate PR)
- Add English and Chinese versions for GUIDE, OVERVIEW, and SPEC - Fix Maven groupId to io.github.typefield (matches actual pom.xml) - Fix all GitHub repository URLs to DingTalk-Real-AI - Fix cross-language installation commands (go get, npm install)
- Update pom.xml groupId to com.dingtalk - Refactor all Java package declarations from io.github.typefield.dingtalk.channel to com.dingtalk.channel - Move source files to new directory structure (com/dingtalk/channel) - Update all import statements across 48 Java files - Update all documentation references (README, GUIDE, OVERVIEW, SPEC - both EN and ZH) - All tests pass (34 tests, 0 failures) Breaking change: Users must update their Maven dependency and import statements
…ions - Fix com.dingtalk.dingtalk.channel typos in README/README.zh-CN/SPEC to the actual package com.dingtalk.channel - Remove GUIDE.zh-CN.md / OVERVIEW.zh-CN.md / SPEC.zh-CN.md from this PR; translations will be submitted as a separate PR to keep this change focused on the organization/coordinate migration - Verified: mvn compile and mvn test pass with groupId com.dingtalk and package com.dingtalk.channel
- MessageNormalizer: richText picture/file segments now extract into IncomingMessage.resources with strict string narrowing (new strictStr helper — Gson getAsString would coerce 123 into "123") and per-message download-code dedup. - DingTalkChannel.downloadFileToFile: streaming media download to a local path shared with downloadFile via resolveDownloadUrl; temp file + atomic move (fallback to plain move), parent dir must exist, no partial file left behind. Returns bytes written. downloadFile now also surfaces readable http status on non-200. - Tests: RichTextResourceAndDownloadToFileTest covers extraction/dedup/dirty-data and streaming download incl. regression that downloadFile keeps working.
…ark channel-sdk - MessageNormalizer: richText picture/file segments now extract into IncomingMessage.resources (analog of lark's post attachment zone) with strict string narrowing (new strictStr helper — Gson getAsString would coerce 123 into "123") and per-message download-code dedup. - DingTalkChannel.downloadFileToFile: streaming media download to a local path shared with downloadFile via resolveDownloadUrl; temp file + atomic move (fallback to plain move), parent dir must exist, no partial file left behind. Returns bytes written. downloadFile now also surfaces readable http status on non-200. - Tests: LarkPortFeatureTest covers extraction/dedup/dirty-data and streaming download incl. regression that downloadFile keeps working.
haofeng0705
requested changes
Sep 20, 2026
haofeng0705
left a comment
Contributor
There was a problem hiding this comment.
复查结论:请求修改,当前不建议合入。
- 阻塞
MessageNormalizer.java:93从picture读取 richText 图片下载码;真实回调使用downloadCode/pictureDownloadCode,新增测试使用了错误的模拟字段。 - 阻塞
DingTalkChannel.java:278-281使用 GET + query 调用/v1.0/robot/messageFiles/download;钉钉官方生成 SDK 定义为 POST + JSON body。 DingTalkChannel.java:230-236只校验初始 URL,HTTP 重定向目标未重新做 SSRF 校验。- 非 200 分支没有关闭 error stream/disconnect;
createTempFile的前缀在单字符目标文件名时不足 3 字符,会抛IllegalArgumentException。
当前没有 GitHub CI checks,本机也缺少 JDK/Maven,无法独立运行测试。请修复核心协议与资源处理问题并补充对应测试后再合入。
…eToFile - Support downloadCode and pictureDownloadCode with fallback to picture for richText images - Use POST with JSON body for messageFiles/download in DingTalkChannel and Reply - Prevent SSRF redirect bypass with manual redirect verification - Fix temp file creation for single-character target filenames - Add GitHub Actions CI workflow Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
haofeng0705
approved these changes
Sep 20, 2026
haofeng0705
left a comment
Contributor
There was a problem hiding this comment.
复查通过。
- richText 图片字段已兼容
downloadCode/pictureDownloadCode/picture(MessageNormalizer.java:90-99),RichTextResourceAndDownloadToFileTest已覆盖。 /v1.0/robot/messageFiles/download已改为 POST JSON body(DingTalkChannel.java:300-304)。- SSRF 重定向绕过已修复:
openMediaConnection手动跟随重定向并逐跳校验(DingTalkChannel.java:256-291),并有downloadFileSSRFRedirectBypass回归。 - 非 200 响应会关闭 error stream 并 disconnect(DingTalkChannel.java:279-284)。
- 临时文件前缀改为
.tmp-<filename>-(DingTalkChannel.java:225),单字符目标文件名正常。 - 新增 CI workflow(Java 8/11/17)。
本机无 JDK/Maven,未本地运行测试;代码审查无阻塞问题,可合入。
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
为钉钉 richText 消息补齐两项媒体能力(基于 #1 的
com.dingtalk.channel包结构):1. richText 附件资源提取
richText 消息中的 picture/file 段此前被解析器直接丢弃,现在提取进
IncomingMessage.resources:new Resource("image", code)new Resource("file", code, fileName, "")strictStr助手——Gson 的getAsString()会把数字 123 强转成 "123",严格模式只接受真正的 JSON 字符串;非法段跳过不影响其余段落;同一下载码单条消息内去重2. DingTalkChannel.downloadFileToFile(流式落盘)
流式下载媒体文件到本地路径,不整块占用内存:
downloadFile共用(抽取resolveDownloadUrl,SSRF 校验不变)downloadFile非 200 现在抛出可读的http <status>验证
mvn test:37 个测试全部通过;新增 RichTextResourceAndDownloadToFileTest 覆盖资源提取/去重/脏数据、流式落盘成功/父目录缺失/无临时文件残留。Depends on #1(基于其 com.dingtalk 包迁移,应在其后合并)。@haofeng0705 请复查。