summary refs log tree commit diff
path: root/src/api
diff options
context:
space:
mode:
authorPuyodead1 <puyodead@proton.me>2025-04-16 23:28:43 -0400
committerRory& <root@rory.gay>2025-05-03 12:30:22 +0200
commit080b2c7d383b5e09fee97f267d35f4e7cd22f0a9 (patch)
tree066bfcba19fdc7060d28d46db8b1218c0e365011 /src/api
parentMerge pull request #1274 from dank074/patch/fix-requestGuildMembers-libraires (diff)
downloadserver-ts-080b2c7d383b5e09fee97f267d35f4e7cd22f0a9.tar.xz
Implement signed cdn urls
Diffstat (limited to 'src/api')
-rw-r--r--src/api/routes/attachments/refresh-urls.ts48
-rw-r--r--src/api/routes/channels/#channel_id/messages/index.ts19
2 files changed, 59 insertions, 8 deletions
diff --git a/src/api/routes/attachments/refresh-urls.ts b/src/api/routes/attachments/refresh-urls.ts
new file mode 100644

index 000000000..e456a9115 --- /dev/null +++ b/src/api/routes/attachments/refresh-urls.ts
@@ -0,0 +1,48 @@ +/* + Spacebar: A FOSS re-implementation and extension of the Discord.com backend. + Copyright (C) 2023 Spacebar and Spacebar Contributors + + This program is free software: you can redistribute it and/or modify + it under the terms of the GNU Affero General Public License as published + by the Free Software Foundation, either version 3 of the License, or + (at your option) any later version. + + This program is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + GNU Affero General Public License for more details. + + You should have received a copy of the GNU Affero General Public License + along with this program. If not, see <https://www.gnu.org/licenses/>. +*/ + +import { route } from "@spacebar/api"; +import { RefreshUrlsRequestSchema, resignUrl } from "@spacebar/util"; +import { Request, Response, Router } from "express"; +const router = Router(); + +router.post( + "/", + route({ + requestBody: "RefreshUrlsRequestSchema", + responses: { + 200: { + body: "RefreshUrlsResponse", + }, + 400: { + body: "APIErrorResponse", + }, + }, + }), + async (req: Request, res: Response) => { + const { attachment_urls } = req.body as RefreshUrlsRequestSchema; + + const refreshed_urls = attachment_urls.map(resignUrl); + + return res.status(200).json({ + refreshed_urls, + }); + }, +); + +export default router; diff --git a/src/api/routes/channels/#channel_id/messages/index.ts b/src/api/routes/channels/#channel_id/messages/index.ts
index 4ba289275..a540dce64 100644 --- a/src/api/routes/channels/#channel_id/messages/index.ts +++ b/src/api/routes/channels/#channel_id/messages/index.ts
@@ -35,6 +35,7 @@ import { emitEvent, getPermission, isTextChannel, + resignUrl, uploadFile, } from "@spacebar/util"; import { Request, Response, Router } from "express"; @@ -199,16 +200,18 @@ router.get( ? y.proxy_url : `https://example.org${y.proxy_url}`; - let pathname = new URL(uri).pathname; - while ( - pathname.split("/")[0] != "attachments" && - pathname.length > 30 - ) { - pathname = pathname.split("/").slice(1).join("/"); + const url = new URL(uri); + if (endpoint) { + const newBase = new URL(endpoint); + url.protocol = newBase.protocol; + url.hostname = newBase.hostname; + url.port = newBase.port; } - if (!endpoint?.endsWith("/")) pathname = "/" + pathname; - y.proxy_url = `${endpoint == null ? "" : endpoint}${pathname}`; + y.proxy_url = url.toString(); + + y.proxy_url = resignUrl(y.proxy_url); + y.url = resignUrl(y.url); }); /**