Make media URLs stable and cacheable, add real image thumbnails
Signed media URLs embedded the current second (TimestampSigner), so every API response re-minted every raw/thumbnail/staged URL and the browser re-downloaded each file on every poll or navigation. Responses also carried no cache headers at all. - sign with a plain Signer plus a bucket-quantized exp (7d TTL, 24h bucket), so a URL is byte-identical across responses and rotates once a day; legacy TimestampSigner URLs stay accepted for one release - add a v=<md5> version parameter to library media URLs so replacing a file under the same J-ID (the optimize flow) busts caches exactly when needed - serve_file now sends ETag/Last-Modified and a private Cache-Control and answers conditional requests with 304; library media gets max-age 6d + immutable, staged/similarity files 1h - build cached 480px JPEG thumbnails for images (Pillow, keyed by MD5 under MEDIA_ROOT/thumbs) instead of serving full-size originals through the thumbnail endpoint; the library grid uses thumbnail_url for images too
This commit is contained in:
@@ -16,7 +16,6 @@ from urllib.parse import urlparse
|
||||
|
||||
from django.conf import settings
|
||||
from django.contrib.auth import get_user_model
|
||||
from django.core import signing
|
||||
from django.core.exceptions import ValidationError
|
||||
from django.http import Http404
|
||||
from django.utils import timezone
|
||||
@@ -30,6 +29,7 @@ from . import services
|
||||
from .models import MediaItem, TempUpload
|
||||
from .permissions import CanUpload
|
||||
from .serializers import TempUploadListSerializer, TempUploadSerializer
|
||||
from .signing_urls import load_payload
|
||||
from .tools import HASH_FIELDS, hashed_items, hashes_similarity
|
||||
|
||||
logger = logging.getLogger(__name__)
|
||||
@@ -393,14 +393,7 @@ class TempUploadViewSet(
|
||||
if user is None:
|
||||
signature = request.query_params.get("sig")
|
||||
if signature:
|
||||
try:
|
||||
payload = signing.loads(
|
||||
signature,
|
||||
salt=services.UPLOAD_FILE_SALT,
|
||||
max_age=86400,
|
||||
)
|
||||
except signing.BadSignature:
|
||||
payload = None
|
||||
payload = load_payload(signature, services.UPLOAD_FILE_SALT)
|
||||
if payload and str(payload.get("temp")) == str(pk):
|
||||
user = (
|
||||
get_user_model()
|
||||
|
||||
Reference in New Issue
Block a user