Fix staged upload previews and allow WebP
- Staged files are now served through a signed URL (Django signing, 24h) so <img>/<video> tags can load previews without an Authorization header; the file endpoint accepts header auth or a valid signature, rejects tampered signatures, and still scopes access to the owner - Serializer responses now carry the request context so URLs are signed per user - Add .webp to the allowed extensions (backend + upload hint)
This commit is contained in:
@@ -1,9 +1,10 @@
|
||||
import os
|
||||
|
||||
from django.core import signing
|
||||
from rest_framework import serializers
|
||||
|
||||
from .models import MediaItem, MediaLocation, TempUpload
|
||||
from .services import VIDEO_EXTENSIONS
|
||||
from .services import UPLOAD_FILE_SALT, VIDEO_EXTENSIONS
|
||||
|
||||
|
||||
class MediaLocationSerializer(serializers.ModelSerializer):
|
||||
@@ -125,4 +126,15 @@ class TempUploadSerializer(serializers.ModelSerializer):
|
||||
return f"J-{obj.library_item_id}" if obj.library_item_id else None
|
||||
|
||||
def get_file_url(self, obj):
|
||||
return f"/api/uploads/{obj.id}/file/" if obj.file else None
|
||||
"""Signed URL so <img>/<video> tags can fetch the staged file."""
|
||||
if not obj.file:
|
||||
return None
|
||||
request = self.context.get("request")
|
||||
user = getattr(request, "user", None)
|
||||
if user is None or not getattr(user, "is_authenticated", False):
|
||||
return None
|
||||
signature = signing.dumps(
|
||||
{"temp": str(obj.id), "user": user.id},
|
||||
salt=UPLOAD_FILE_SALT,
|
||||
)
|
||||
return f"/api/uploads/{obj.id}/file/?sig={signature}"
|
||||
|
||||
Reference in New Issue
Block a user