mirror of
https://github.com/AmruthPillai/Reactive-Resume.git
synced 2026-10-04 02:33:47 +10:00
commit b2b0470a1d9267d042ec0ac66523c6635bf5b199
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 13:13:38 2026 +0200
chore: update .gitignore to include .vite-hooks and modify pnpm-lock.yaml for dependencies
commit d28fadb5cd8706c874e616102878b4a394ec84c1
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 13:08:04 2026 +0200
fix: remove timestamp conflict guard
commit c6998d9dbab19d09d3c8054feef1d2e4117555eb
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 12:11:51 2026 +0200
chore(release): v5.1.5
commit f33d168711804880e1f12e88d24290aae16cc258
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 11:58:35 2026 +0200
revert: compose.yml
commit d961e6535811a10c335525fb33a08d03e737278d
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 11:58:08 2026 +0200
refactor(agent): replace 'revert' terminology with 'restore' for clarity, resolves #3086
commit 17f351171be218e33f01c469d95e4164d4c8dc57
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 11:10:41 2026 +0200
refactor(pdf): simplify sidebar section filtering and update summary feature logic
commit d55179b9d76879e3204de185e8b53fadd0a107ed
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 09:53:37 2026 +0200
chore: update pnpm-lock.yaml and turbo.json
commit 7cade6980e1a04352536bd44ef773f338c4ef599
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 09:38:30 2026 +0200
fix(polyfill): add tested polyfill for Map Upsert methods
commit 26d175bb9c53d93225d1e907678445252c13d660
Merge: 1cf33dc6c 5b1297fa2
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 09:23:29 2026 +0200
Merge remote-tracking branch 'origin/main' into feat/explore-hono-orpc-migration
# Conflicts:
# packages/api/src/services/agent-url.ts
# packages/runtime-externals/package.json
commit 1cf33dc6c9d81735730ad656e16dab6501c6d6a1
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 09:22:12 2026 +0200
chore: preserve branch changes before main sync
commit b380a4b00fdbcdd81ff4f8ef72b330fd027ccda5
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Mon May 18 07:50:28 2026 +0200
chore: lot of fixes for monorepo migration
commit 8fcf0ec64e1c29572ebaff494338368bfcf75760
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 13:57:17 2026 +0200
chore: update knip version and refine web app routing with new SEO endpoints
commit 234e68086ff15610a93877354c98e2c020364533
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 12:10:06 2026 +0200
refactor(auth): update OAuth routes to include API prefix and remove unused schema endpoint
commit 91c84b9a8496b0ce21d71cae9f8b2a027638c9ac
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:54:29 2026 +0200
chore: update dependencies and enhance PWA metadata in web app
commit 150117d4a5a9dd6cd92c64891aad8cae90f6a7af
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:12:35 2026 +0200
docs: revise manifest-only pwa testing scope
commit 6b939a55661aec9dd8122b184e4b60a5c7325fb5
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:11:33 2026 +0200
docs: add manifest-only pwa design
commit 1422e1fc96c400948b273210a1067251087d15d4
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:05:04 2026 +0200
chore(dev): simplify server proxy config
commit bc2ff5a9f6fda41e6c40333c8f163aa23a6c5e48
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:04:50 2026 +0200
docs: add unsafe oauth redirect plan
commit 445359ebe9b96c1515bf1c4c3f73ba8a8448ec12
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:04:34 2026 +0200
feat(auth): add unsafe oauth redirect flag
commit 73fffdd24598e56b2793f7657919bc794835892e
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 10:55:02 2026 +0200
docs: design unsafe oauth redirect flag
commit c0066aa19c15fc8a4c8e5179ed49889c117519f4
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 10:22:04 2026 +0200
chore: update translation source paths
commit 9033da082418d252aafd6c2eed72f71f014be3d9
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 10:09:25 2026 +0200
refactor(arch): react spa + hono migration
commit 6f27936c11bda895977dc63ee550c3346d4ce24b
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 01:10:47 2026 +0200
docs: add docker nightly tagging design
commit ecc1fd9a88a0ee1dca2f1977dfc17f74527fe1da
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Thu May 14 20:05:44 2026 +0200
feat: migrate to hono spa server
161 lines
4.8 KiB
TypeScript
161 lines
4.8 KiB
TypeScript
import { createHash } from "node:crypto";
|
|
import { basename, extname, normalize } from "node:path";
|
|
import { getStorageService } from "@reactive-resume/api/features/storage";
|
|
import { env } from "@reactive-resume/env/server";
|
|
|
|
export async function handleUpload(request: Request) {
|
|
const { userId, filePath } = parseRouteParams(request.url);
|
|
|
|
if (!userId || !filePath) return new Response("Bad Request", { status: 400 });
|
|
|
|
if (!isValidPath(userId) || !isValidPathSegments(filePath)) return new Response("Forbidden", { status: 403 });
|
|
if (isPrivateUploadPath(filePath)) return new Response("Not Found", { status: 404 });
|
|
|
|
const storageService = getStorageService();
|
|
const key = `uploads/${userId}/${filePath}`;
|
|
const storedFile = await storageService.read(key);
|
|
if (!storedFile) return new Response("Not Found", { status: 404 });
|
|
|
|
const filename = filePath.split("/").pop() ?? filePath;
|
|
const ext = extname(filename).toLowerCase();
|
|
const contentType = storedFile.contentType ?? inferContentTypeFromExtension(ext);
|
|
const etag = createEtag(storedFile);
|
|
|
|
if (isNotModified(request.headers, etag)) return makeNotModifiedResponse(etag);
|
|
|
|
const shouldForceDownload = [".pdf"].includes(ext);
|
|
const headers = buildResponseHeaders({
|
|
filename,
|
|
storedFile,
|
|
contentType,
|
|
etag,
|
|
shouldForceDownload,
|
|
});
|
|
|
|
const buffer = toArrayBuffer(storedFile.data);
|
|
|
|
return new Response(buffer, { headers });
|
|
}
|
|
|
|
function inferContentTypeFromExtension(ext: string): string {
|
|
switch (ext) {
|
|
case ".webp":
|
|
return "image/webp";
|
|
case ".png":
|
|
return "image/png";
|
|
case ".jpg":
|
|
case ".jpeg":
|
|
return "image/jpeg";
|
|
case ".gif":
|
|
return "image/gif";
|
|
case ".pdf":
|
|
return "application/pdf";
|
|
default:
|
|
return "application/octet-stream";
|
|
}
|
|
}
|
|
|
|
function parseRouteParams(url: string): { userId: string | undefined; filePath: string | undefined } {
|
|
const pathname = new URL(url).pathname;
|
|
const [, pathAfterUploads] = pathname.split("/uploads/");
|
|
if (!pathAfterUploads) return { userId: undefined, filePath: undefined };
|
|
const firstSlashIndex = pathAfterUploads.indexOf("/");
|
|
|
|
if (firstSlashIndex === -1) {
|
|
return { userId: pathAfterUploads, filePath: undefined };
|
|
}
|
|
|
|
const userId = pathAfterUploads.slice(0, firstSlashIndex);
|
|
const filePath = pathAfterUploads.slice(firstSlashIndex + 1);
|
|
|
|
return { userId, filePath: filePath || undefined };
|
|
}
|
|
|
|
function isValidPath(segment: string): boolean {
|
|
const normalized = normalize(segment).replace(/^(\.\.(\/|\\|$))+/, "");
|
|
|
|
return normalized === segment;
|
|
}
|
|
|
|
function isValidPathSegments(path: string): boolean {
|
|
const segments = path.split("/");
|
|
|
|
return segments.every((segment) => isValidPath(segment));
|
|
}
|
|
|
|
function isPrivateUploadPath(path: string): boolean {
|
|
return path.split("/")[0] === "agent";
|
|
}
|
|
|
|
function isNotModified(headers: Headers, etag: string): boolean {
|
|
const ifNoneMatch = headers.get("If-None-Match");
|
|
const candidates = ifNoneMatch?.split(",").map((s) => s.trim()) ?? [];
|
|
|
|
return candidates.includes(etag);
|
|
}
|
|
|
|
function makeNotModifiedResponse(etag: string): Response {
|
|
return new Response(null, {
|
|
status: 304,
|
|
headers: { ETag: etag, "Cache-Control": "public, max-age=31536000, immutable" },
|
|
});
|
|
}
|
|
|
|
type BuildResponseHeaderArgs = {
|
|
filename: string;
|
|
storedFile: { size: number };
|
|
contentType: string;
|
|
etag: string;
|
|
shouldForceDownload: boolean;
|
|
};
|
|
|
|
function buildResponseHeaders({
|
|
filename,
|
|
storedFile,
|
|
contentType,
|
|
etag,
|
|
shouldForceDownload,
|
|
}: BuildResponseHeaderArgs): Headers {
|
|
const headers = new Headers();
|
|
|
|
headers.set("Content-Type", shouldForceDownload ? "application/octet-stream" : contentType);
|
|
headers.set("Content-Length", storedFile.size.toString());
|
|
|
|
if (shouldForceDownload) {
|
|
headers.set("Content-Disposition", `attachment; filename="${encodeURIComponent(basename(filename))}"`);
|
|
}
|
|
|
|
headers.set("Cache-Control", "public, max-age=31536000, immutable");
|
|
headers.set("ETag", etag);
|
|
headers.set("X-Content-Type-Options", "nosniff");
|
|
headers.set("X-Robots-Tag", "noindex, nofollow");
|
|
headers.set("Cross-Origin-Resource-Policy", "same-site");
|
|
headers.set("Referrer-Policy", "strict-origin-when-cross-origin");
|
|
headers.set("X-Frame-Options", "DENY");
|
|
headers.set("X-Download-Options", "noopen");
|
|
headers.set("Access-Control-Allow-Origin", env.APP_URL);
|
|
|
|
return headers;
|
|
}
|
|
|
|
function toArrayBuffer(data: Uint8Array): ArrayBuffer {
|
|
return data.byteOffset === 0 && data.byteLength === data.buffer.byteLength
|
|
? (data.buffer as ArrayBuffer)
|
|
: (data.slice().buffer as ArrayBuffer);
|
|
}
|
|
|
|
function createEtag(storedFile: { data: Uint8Array; size: number; etag?: string }): string {
|
|
if (storedFile.etag) {
|
|
const tag = storedFile.etag.trim();
|
|
|
|
if (tag.startsWith("W/") || tag.startsWith('"')) {
|
|
return tag;
|
|
}
|
|
return `"${tag}"`;
|
|
}
|
|
|
|
const hash = createHash("sha256").update(storedFile.data).digest("hex");
|
|
|
|
return `"${storedFile.size}-${hash}"`;
|
|
}
|