fix(05): WR-05 gate public file serving on is_public

This commit is contained in:
Jakub Zych
2026-09-19 15:37:04 +02:00
parent c12e6576f6
commit 56156ae7c3
5 changed files with 195 additions and 0 deletions

View File

@@ -2,8 +2,10 @@ package attach
import (
"context"
"errors"
"fmt"
"io"
"strconv"
"strings"
"time"
@@ -53,6 +55,42 @@ func (f File) Public() bool {
return *f.IsPublic
}
func fileIsPublic(ctx context.Context, db *gorm.DB, filename string) (bool, error) {
if db == nil || filename == "" {
return false, nil
}
var f File
q := db.WithContext(ctx).Select("is_public")
var err error
if id, ok := thumbFileID(filename); ok {
err = q.First(&f, id).Error
} else {
err = q.Where("disk_name = ?", filename).First(&f).Error
}
if errors.Is(err, gorm.ErrRecordNotFound) {
return false, nil
}
if err != nil {
return false, err
}
return f.Public(), nil
}
func thumbFileID(name string) (uint, bool) {
if !strings.HasPrefix(name, "thumb_") {
return 0, false
}
idStr, _, ok := strings.Cut(strings.TrimPrefix(name, "thumb_"), "_")
if !ok || idStr == "" {
return 0, false
}
n, err := strconv.ParseUint(idStr, 10, 64)
if err != nil || n == 0 {
return 0, false
}
return uint(n), true
}
var all []any
// Register appends models so schema tooling can see File without a plugin registry.