Fix staged upload previews and allow WebP

- Staged files are now served through a signed URL (Django signing, 24h)
  so <img>/<video> tags can load previews without an Authorization
  header; the file endpoint accepts header auth or a valid signature,
  rejects tampered signatures, and still scopes access to the owner
- Serializer responses now carry the request context so URLs are signed
  per user
- Add .webp to the allowed extensions (backend + upload hint)
This commit is contained in:
2026-09-17 11:17:04 -05:00
parent d0e2901c92
commit 7deb6084b6
4 changed files with 64 additions and 9 deletions
+14 -2
View File
@@ -1,9 +1,10 @@
import os
from django.core import signing
from rest_framework import serializers
from .models import MediaItem, MediaLocation, TempUpload
from .services import VIDEO_EXTENSIONS
from .services import UPLOAD_FILE_SALT, VIDEO_EXTENSIONS
class MediaLocationSerializer(serializers.ModelSerializer):
@@ -125,4 +126,15 @@ class TempUploadSerializer(serializers.ModelSerializer):
return f"J-{obj.library_item_id}" if obj.library_item_id else None
def get_file_url(self, obj):
return f"/api/uploads/{obj.id}/file/" if obj.file else None
"""Signed URL so <img>/<video> tags can fetch the staged file."""
if not obj.file:
return None
request = self.context.get("request")
user = getattr(request, "user", None)
if user is None or not getattr(user, "is_authenticated", False):
return None
signature = signing.dumps(
{"temp": str(obj.id), "user": user.id},
salt=UPLOAD_FILE_SALT,
)
return f"/api/uploads/{obj.id}/file/?sig={signature}"