{"record":{"id":"84c9e7a5a5f7fc9a","repo":"Tencent/WeKnora","slug":"bucket-mismatch-in-path-got-s-want-s","errorCode":null,"errorMessage":"bucket mismatch in path: got %s, want %s","messagePattern":"bucket mismatch in path: got (.+?), want (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/application/service/file/minio.go","lineNumber":114,"sourceCode":"\t\treturn err\n\t}\n\treturn svc.CheckConnectivity(ctx)\n}\n\n// parseMinioFilePath extracts the object name from a provider scheme: minio://{bucket}/{objectKey}\nfunc (s *minioFileService) parseMinioFilePath(filePath string) (string, error) {\n\t// Provider scheme format: minio://{bucket}/{objectKey}\n\tconst prefix = \"minio://\"\n\tif !strings.HasPrefix(filePath, prefix) {\n\t\treturn \"\", fmt.Errorf(\"invalid MinIO file path: %s\", filePath)\n\t}\n\trest := strings.TrimPrefix(filePath, prefix)\n\tparts := strings.SplitN(rest, \"/\", 2)\n\tif len(parts) != 2 || parts[0] == \"\" || parts[1] == \"\" {\n\t\treturn \"\", fmt.Errorf(\"invalid MinIO file path: %s\", filePath)\n\t}\n\tif parts[0] != s.bucketName {\n\t\treturn \"\", fmt.Errorf(\"bucket mismatch in path: got %s, want %s\", parts[0], s.bucketName)\n\t}\n\tif err := utils.SafeObjectKey(parts[1]); err != nil {\n\t\treturn \"\", fmt.Errorf(\"invalid file path: %w\", err)\n\t}\n\treturn parts[1], nil\n}\n\n// SaveFile saves a file to MinIO\nfunc (s *minioFileService) SaveFile(ctx context.Context,\n\tfile *multipart.FileHeader, tenantID uint64, knowledgeID string,\n) (string, error) {\n\t// Generate object name\n\text := filepath.Ext(file.Filename)\n\tobjectName := fmt.Sprintf(\"%d/%s/%s%s\", tenantID, knowledgeID, uuid.New().String(), ext)\n\n\t// Open file\n\tsrc, err := file.Open()\n\tif err != nil {","sourceCodeStart":96,"sourceCodeEnd":132,"githubUrl":"https://github.com/Tencent/WeKnora/blob/988cbb03305e055d8ebb7d46d9ac6cc0803cd074/internal/application/service/file/minio.go#L96-L132","documentation":"MinIO path parser guard: the bucket named in the minio:// path differs from this service's configured bucket, indicating a path from another deployment/backend; the operation is rejected to prevent cross-bucket access.","triggerScenarios":"Thrown at internal/application/service/file/minio.go:114 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Use paths produced by this service's SaveFile/SaveBytes","Correct the configured bucket name if the deployment changed","Reject foreign-bucket paths at input validation"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"988cbb03305e055d8ebb7d46d9ac6cc0803cd074","analyzedAt":"2026-09-02T14:41:08.344Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-08T10:18:20.063Z"}