CDN: handle uploading collectibles

This commit is contained in:
Rory&
2026-09-28 13:56:31 +02:00
parent 2e65e6390f
commit b0592d6db9
4 changed files with 61 additions and 5 deletions
+2 -3
View File
@@ -21,7 +21,7 @@ import { Router, Response, Request } from "express";
import { fileTypeFromBuffer } from "file-type";
import { HTTPError } from "lambert-server/HTTPError";
import { Config } from "@spacebar/util";
import { storage, multer, setCacheControl, setCacheControlNotFound } from "../util";
import { storage, multer, setCacheControl, setCacheControlNotFound, validateServerAuth } from "../util";
// TODO: check premium and animated pfp are allowed in the config
// TODO: generate different sizes of icon
@@ -35,8 +35,7 @@ const ALLOWED_MIME_TYPES = [...ANIMATED_MIME_TYPES, ...STATIC_MIME_TYPES];
const router = Router({ mergeParams: true });
const pathPrefix = "app-assets";
router.post("/:guild_id", multer.single("file"), async (req: Request, res: Response) => {
if (req.headers.signature !== Config.get().security.requestSignature) throw new HTTPError("Invalid request signature");
router.post("/:guild_id", validateServerAuth, multer.single("file"), async (req: Request, res: Response) => {
if (!req.file) throw new HTTPError("Missing file");
const { buffer, size } = req.file;
const { guild_id } = req.params as { [key: string]: string };
+51 -1
View File
@@ -19,7 +19,12 @@
import { Router, Response, Request } from "express";
import { HTTPError } from "lambert-server/HTTPError";
import { fileTypeFromBuffer } from "file-type";
import { storage, setCacheControl } from "../../../util";
import { storage, setCacheControl, multer, validateServerAuth } from "../../../util";
import { Config } from "@spacebar/util";
import crypto from "node:crypto";
const ANIMATED_MIME_TYPES = ["image/apng", "image/gif", "image/gifv"];
const STATIC_MIME_TYPES = ["image/png", "image/jpeg", "image/webp", "image/svg+xml", "image/svg"];
const router = Router({ mergeParams: true });
@@ -59,4 +64,49 @@ router.get("/:sku_id/animated", setCacheControl, async (req: Request, res: Respo
return res.send(file);
});
router.post("/:sku_id/animated", validateServerAuth, multer.single("file"), async (req: Request, res: Response) => {
if (!req.file) throw new HTTPError("Missing file");
const { buffer, size } = req.file;
const { sku_id } = req.params as { [key: string]: string };
let hash = crypto.createHash("md5").update(buffer).digest("hex");
const type = await fileTypeFromBuffer(buffer);
if (!type || !ANIMATED_MIME_TYPES.includes(type.mime)) throw new HTTPError("Invalid file type");
if (ANIMATED_MIME_TYPES.includes(type.mime)) hash = `a_${hash}`; // animated icons have a_ infront of the hash
const path = `collectibles-shop/${sku_id}/animated`;
await storage.set(path, buffer);
return res.json({
id: sku_id,
hash: hash,
content_type: type.mime,
size,
url: `${Config.get().cdn.endpointPublic}media/v1/collectibles-shop/${sku_id}/animated`,
});
});
router.post("/:sku_id/static", validateServerAuth, multer.single("file"), async (req: Request, res: Response) => {
if (!req.file) throw new HTTPError("Missing file");
const { buffer, size } = req.file;
const { sku_id } = req.params as { [key: string]: string };
const hash = crypto.createHash("md5").update(buffer).digest("hex");
const type = await fileTypeFromBuffer(buffer);
if (!type || !STATIC_MIME_TYPES.includes(type.mime)) throw new HTTPError("Invalid file type");
const path = `collectibles-shop/${sku_id}/static`;
await storage.set(path, buffer);
return res.json({
id: sku_id,
hash: hash,
content_type: type.mime,
size,
url: `${Config.get().cdn.endpointPublic}media/v1/collectibles-shop/${sku_id}/static`,
});
});
export default router;
+1 -1
View File
@@ -16,6 +16,6 @@
along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
export * from "./setCacheControl";
export * from "./middlewares";
export * from "./multer";
export * from "./Storage";
@@ -17,6 +17,8 @@
*/
import { NextFunction, Response, Request } from "express";
import { Config } from "@spacebar/util";
import { HTTPError } from "lambert-server";
export function setCacheControl(req: Request, res: Response, next: NextFunction) {
const cacheDuration = 21600; // 6 hours
@@ -29,3 +31,8 @@ export function setCacheControlNotFound(req: Request, res: Response) {
res.setHeader("Cache-Control", `public, max-age=${cacheDuration}, s-maxage=${cacheDuration}, immutable`);
res.status(404).send(req.path + " not found");
}
export function validateServerAuth(req: Request, res: Response, next: NextFunction) {
if (req.headers.signature !== Config.get().security.requestSignature) throw new HTTPError("Invalid request signature");
next();
}