From b0592d6db9768d5d2f20e233be853ee11de33f3a Mon Sep 17 00:00:00 2001 From: Rory& Date: Mon, 28 Sep 2026 13:56:31 +0200 Subject: [PATCH] CDN: handle uploading collectibles --- src/cdn/routes/app-assets.ts | 5 +- src/cdn/routes/media/v1/collectibles-shop.ts | 52 ++++++++++++++++++- src/cdn/util/index.ts | 2 +- .../{setCacheControl.ts => middlewares.ts} | 7 +++ 4 files changed, 61 insertions(+), 5 deletions(-) rename src/cdn/util/{setCacheControl.ts => middlewares.ts} (81%) diff --git a/src/cdn/routes/app-assets.ts b/src/cdn/routes/app-assets.ts index 252c9d1eb..6911c6b68 100644 --- a/src/cdn/routes/app-assets.ts +++ b/src/cdn/routes/app-assets.ts @@ -21,7 +21,7 @@ import { Router, Response, Request } from "express"; import { fileTypeFromBuffer } from "file-type"; import { HTTPError } from "lambert-server/HTTPError"; import { Config } from "@spacebar/util"; -import { storage, multer, setCacheControl, setCacheControlNotFound } from "../util"; +import { storage, multer, setCacheControl, setCacheControlNotFound, validateServerAuth } from "../util"; // TODO: check premium and animated pfp are allowed in the config // TODO: generate different sizes of icon @@ -35,8 +35,7 @@ const ALLOWED_MIME_TYPES = [...ANIMATED_MIME_TYPES, ...STATIC_MIME_TYPES]; const router = Router({ mergeParams: true }); const pathPrefix = "app-assets"; -router.post("/:guild_id", multer.single("file"), async (req: Request, res: Response) => { - if (req.headers.signature !== Config.get().security.requestSignature) throw new HTTPError("Invalid request signature"); +router.post("/:guild_id", validateServerAuth, multer.single("file"), async (req: Request, res: Response) => { if (!req.file) throw new HTTPError("Missing file"); const { buffer, size } = req.file; const { guild_id } = req.params as { [key: string]: string }; diff --git a/src/cdn/routes/media/v1/collectibles-shop.ts b/src/cdn/routes/media/v1/collectibles-shop.ts index 60c27554c..30c11bda4 100644 --- a/src/cdn/routes/media/v1/collectibles-shop.ts +++ b/src/cdn/routes/media/v1/collectibles-shop.ts @@ -19,7 +19,12 @@ import { Router, Response, Request } from "express"; import { HTTPError } from "lambert-server/HTTPError"; import { fileTypeFromBuffer } from "file-type"; -import { storage, setCacheControl } from "../../../util"; +import { storage, setCacheControl, multer, validateServerAuth } from "../../../util"; +import { Config } from "@spacebar/util"; +import crypto from "node:crypto"; + +const ANIMATED_MIME_TYPES = ["image/apng", "image/gif", "image/gifv"]; +const STATIC_MIME_TYPES = ["image/png", "image/jpeg", "image/webp", "image/svg+xml", "image/svg"]; const router = Router({ mergeParams: true }); @@ -59,4 +64,49 @@ router.get("/:sku_id/animated", setCacheControl, async (req: Request, res: Respo return res.send(file); }); +router.post("/:sku_id/animated", validateServerAuth, multer.single("file"), async (req: Request, res: Response) => { + if (!req.file) throw new HTTPError("Missing file"); + const { buffer, size } = req.file; + const { sku_id } = req.params as { [key: string]: string }; + + let hash = crypto.createHash("md5").update(buffer).digest("hex"); + + const type = await fileTypeFromBuffer(buffer); + if (!type || !ANIMATED_MIME_TYPES.includes(type.mime)) throw new HTTPError("Invalid file type"); + if (ANIMATED_MIME_TYPES.includes(type.mime)) hash = `a_${hash}`; // animated icons have a_ infront of the hash + + const path = `collectibles-shop/${sku_id}/animated`; + await storage.set(path, buffer); + + return res.json({ + id: sku_id, + hash: hash, + content_type: type.mime, + size, + url: `${Config.get().cdn.endpointPublic}media/v1/collectibles-shop/${sku_id}/animated`, + }); +}); + +router.post("/:sku_id/static", validateServerAuth, multer.single("file"), async (req: Request, res: Response) => { + if (!req.file) throw new HTTPError("Missing file"); + const { buffer, size } = req.file; + const { sku_id } = req.params as { [key: string]: string }; + + const hash = crypto.createHash("md5").update(buffer).digest("hex"); + + const type = await fileTypeFromBuffer(buffer); + if (!type || !STATIC_MIME_TYPES.includes(type.mime)) throw new HTTPError("Invalid file type"); + + const path = `collectibles-shop/${sku_id}/static`; + await storage.set(path, buffer); + + return res.json({ + id: sku_id, + hash: hash, + content_type: type.mime, + size, + url: `${Config.get().cdn.endpointPublic}media/v1/collectibles-shop/${sku_id}/static`, + }); +}); + export default router; diff --git a/src/cdn/util/index.ts b/src/cdn/util/index.ts index 73b8f73b9..7e4389995 100644 --- a/src/cdn/util/index.ts +++ b/src/cdn/util/index.ts @@ -16,6 +16,6 @@ along with this program. If not, see . */ -export * from "./setCacheControl"; +export * from "./middlewares"; export * from "./multer"; export * from "./Storage"; diff --git a/src/cdn/util/setCacheControl.ts b/src/cdn/util/middlewares.ts similarity index 81% rename from src/cdn/util/setCacheControl.ts rename to src/cdn/util/middlewares.ts index d41295ebf..17663f618 100644 --- a/src/cdn/util/setCacheControl.ts +++ b/src/cdn/util/middlewares.ts @@ -17,6 +17,8 @@ */ import { NextFunction, Response, Request } from "express"; +import { Config } from "@spacebar/util"; +import { HTTPError } from "lambert-server"; export function setCacheControl(req: Request, res: Response, next: NextFunction) { const cacheDuration = 21600; // 6 hours @@ -29,3 +31,8 @@ export function setCacheControlNotFound(req: Request, res: Response) { res.setHeader("Cache-Control", `public, max-age=${cacheDuration}, s-maxage=${cacheDuration}, immutable`); res.status(404).send(req.path + " not found"); } + +export function validateServerAuth(req: Request, res: Response, next: NextFunction) { + if (req.headers.signature !== Config.get().security.requestSignature) throw new HTTPError("Invalid request signature"); + next(); +}