kenn-io--agentsview
f99010fae1
CI / lint (push) Failing after 1s
CI / frontend (push) Failing after 1s
CI / scripts (push) Failing after 1s
CI / Go Test (ubuntu-latest) (push) Failing after 0s
CI / frontend-node-25 (push) Failing after 1s
CI / docs (push) Failing after 0s
CI / coverage (push) Failing after 0s
CI / e2e (push) Failing after 0s
Docker / build-and-push (push) Failing after 1s
CI / integration (push) Failing after 4m43s
CI / Go Test (windows-latest) (push) Has been cancelled
CI / Desktop Unit Tests (Windows) (push) Has been cancelled
Desktop Artifacts / Desktop Build (Linux (arm64)) (push) Has been cancelled
Desktop Artifacts / Desktop Build (Linux) (push) Has been cancelled
Desktop Artifacts / Desktop Build (Windows) (push) Has been cancelled
Desktop Artifacts (macOS) / Desktop Build (macOS (aarch64)) (push) Has been cancelled
Desktop Artifacts (macOS) / Desktop Build (macOS (x86_64)) (push) Has been cancelled
51 行
1.3 KiB
Go
51 行
1.3 KiB
Go
package server
|
|
|
|
import (
|
|
"context"
|
|
"net/http"
|
|
"os"
|
|
"path/filepath"
|
|
"strings"
|
|
)
|
|
|
|
func (s *Server) registerAssetRoutes() {
|
|
group := newRouteGroup(s.api, "/api/v1/assets", "Assets")
|
|
|
|
raw(s, group, http.MethodGet, "/{filename}", "Get imported asset", s.humaGetAsset)
|
|
}
|
|
|
|
type assetInput struct {
|
|
Filename string `path:"filename" required:"true" doc:"Asset filename"`
|
|
}
|
|
|
|
func (s *Server) humaGetAsset(
|
|
_ context.Context,
|
|
in *assetInput,
|
|
) (*bytesOutput, error) {
|
|
filename := in.Filename
|
|
if filename == "" {
|
|
return nil, apiError(http.StatusBadRequest, "missing filename")
|
|
}
|
|
if strings.Contains(filename, "..") ||
|
|
strings.Contains(filename, "/") ||
|
|
strings.Contains(filename, "\\") {
|
|
return nil, apiError(http.StatusBadRequest, "invalid filename")
|
|
}
|
|
ext := strings.ToLower(filepath.Ext(filename))
|
|
contentType, ok := safeImageTypes[ext]
|
|
if !ok {
|
|
return nil, apiError(http.StatusForbidden, "unsupported asset type")
|
|
}
|
|
filePath := filepath.Join(s.cfg.DataDir, "assets", filename)
|
|
data, err := os.ReadFile(filePath)
|
|
if err != nil {
|
|
return nil, apiError(http.StatusNotFound, "asset not found")
|
|
}
|
|
return &bytesOutput{
|
|
ContentType: contentType,
|
|
NoSniff: "nosniff",
|
|
CacheControl: "public, max-age=31536000, immutable",
|
|
Body: data,
|
|
}, nil
|
|
}
|