fix(05): WR-05 gate public file serving on is_public
This commit is contained in:
@@ -1,6 +1,7 @@
|
||||
package attach
|
||||
|
||||
import (
|
||||
"context"
|
||||
"io"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
@@ -114,3 +115,60 @@ func TestStaticHandlerServesThumbURL(t *testing.T) {
|
||||
t.Fatalf("mismatched original partition status = %d, want 404", mismatch.Code)
|
||||
}
|
||||
}
|
||||
|
||||
func TestStaticHandlerPublicGate(t *testing.T) {
|
||||
ctx := t.Context()
|
||||
bucket := memblob.OpenBucket(nil)
|
||||
t.Cleanup(func() { _ = bucket.Close() })
|
||||
|
||||
diskName := "abc123xyz.jpg"
|
||||
body := []byte("cover-bytes")
|
||||
if err := bucket.WriteAll(ctx, BlobKey(diskName), body, &blob.WriterOptions{ContentType: "image/jpeg"}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
thumbName := ThumbFilename(42, 200, 200, 0, 0, "crop", "jpg")
|
||||
thumbKey := PartitionDirectory(diskName) + thumbName
|
||||
if err := bucket.WriteAll(ctx, thumbKey, []byte("thumb-bytes"), &blob.WriterOptions{ContentType: "image/jpeg"}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
var seen []string
|
||||
deny := servePublicBlobs(bucket, "/storage/uploads", func(_ context.Context, name string) (bool, error) {
|
||||
seen = append(seen, name)
|
||||
return false, nil
|
||||
})
|
||||
for _, path := range []string{
|
||||
"/storage/uploads/abc/123/xyz/abc123xyz.jpg",
|
||||
"/storage/uploads/abc/123/xyz/" + thumbName,
|
||||
} {
|
||||
rr := httptest.NewRecorder()
|
||||
deny.ServeHTTP(rr, httptest.NewRequest(http.MethodGet, path, nil))
|
||||
if rr.Code != http.StatusNotFound {
|
||||
t.Fatalf("private %s status = %d, want 404", path, rr.Code)
|
||||
}
|
||||
}
|
||||
if len(seen) != 2 || seen[0] != diskName || seen[1] != thumbName {
|
||||
t.Fatalf("allow saw %v, want [%s %s] before NewReader", seen, diskName, thumbName)
|
||||
}
|
||||
|
||||
allow := servePublicBlobs(bucket, "/storage/uploads", func(_ context.Context, name string) (bool, error) {
|
||||
return name == diskName, nil
|
||||
})
|
||||
ok := httptest.NewRecorder()
|
||||
allow.ServeHTTP(ok, httptest.NewRequest(http.MethodGet, "/storage/uploads/abc/123/xyz/abc123xyz.jpg", nil))
|
||||
if ok.Code != http.StatusOK {
|
||||
t.Fatalf("public original status = %d, want 200", ok.Code)
|
||||
}
|
||||
blocked := httptest.NewRecorder()
|
||||
allow.ServeHTTP(blocked, httptest.NewRequest(http.MethodGet, "/storage/uploads/abc/123/xyz/"+thumbName, nil))
|
||||
if blocked.Code != http.StatusNotFound {
|
||||
t.Fatalf("denied thumb status = %d, want 404", blocked.Code)
|
||||
}
|
||||
|
||||
nilDB := StaticHandlerPublic(bucket, "/storage/uploads", nil)
|
||||
missing := httptest.NewRecorder()
|
||||
nilDB.ServeHTTP(missing, httptest.NewRequest(http.MethodGet, "/storage/uploads/abc/123/xyz/abc123xyz.jpg", nil))
|
||||
if missing.Code != http.StatusNotFound {
|
||||
t.Fatalf("nil db status = %d, want 404", missing.Code)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user