项目文件夹

文件
wehub-resource-sync f99010fae1
CI / lint (push) Failing after 1s
CI / frontend (push) Failing after 1s
CI / scripts (push) Failing after 1s
CI / Go Test (ubuntu-latest) (push) Failing after 0s
CI / frontend-node-25 (push) Failing after 1s
CI / docs (push) Failing after 0s
CI / coverage (push) Failing after 0s
CI / e2e (push) Failing after 0s
Docker / build-and-push (push) Failing after 1s
CI / integration (push) Failing after 4m43s
CI / Go Test (windows-latest) (push) Has been cancelled
CI / Desktop Unit Tests (Windows) (push) Has been cancelled
Desktop Artifacts / Desktop Build (Linux (arm64)) (push) Has been cancelled
Desktop Artifacts / Desktop Build (Linux) (push) Has been cancelled
Desktop Artifacts / Desktop Build (Windows) (push) Has been cancelled
Desktop Artifacts (macOS) / Desktop Build (macOS (aarch64)) (push) Has been cancelled
Desktop Artifacts (macOS) / Desktop Build (macOS (x86_64)) (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 12:30:36 +08:00

51 行
1.3 KiB
Go

package server
import (
"context"
"net/http"
"os"
"path/filepath"
"strings"
)
func (s *Server) registerAssetRoutes() {
group := newRouteGroup(s.api, "/api/v1/assets", "Assets")
raw(s, group, http.MethodGet, "/{filename}", "Get imported asset", s.humaGetAsset)
}
type assetInput struct {
Filename string `path:"filename" required:"true" doc:"Asset filename"`
}
func (s *Server) humaGetAsset(
_ context.Context,
in *assetInput,
) (*bytesOutput, error) {
filename := in.Filename
if filename == "" {
return nil, apiError(http.StatusBadRequest, "missing filename")
}
if strings.Contains(filename, "..") ||
strings.Contains(filename, "/") ||
strings.Contains(filename, "\\") {
return nil, apiError(http.StatusBadRequest, "invalid filename")
}
ext := strings.ToLower(filepath.Ext(filename))
contentType, ok := safeImageTypes[ext]
if !ok {
return nil, apiError(http.StatusForbidden, "unsupported asset type")
}
filePath := filepath.Join(s.cfg.DataDir, "assets", filename)
data, err := os.ReadFile(filePath)
if err != nil {
return nil, apiError(http.StatusNotFound, "asset not found")
}
return &bytesOutput{
ContentType: contentType,
NoSniff: "nosniff",
CacheControl: "public, max-age=31536000, immutable",
Body: data,
}, nil
}