feat : use cdn
This commit is contained in:
@@ -1,21 +0,0 @@
|
||||
import { and, eq } from "drizzle-orm";
|
||||
import { getDb } from "@/db";
|
||||
import { commissionMessages } from "@/db/schema";
|
||||
import { authorizeTicket } from "@/lib/commission/tickets";
|
||||
import { getMediaStorage } from "@/lib/media/storage";
|
||||
import { errorResponse, HttpError } from "@/lib/security/http";
|
||||
|
||||
export async function GET(_request: Request,
|
||||
context: RouteContext<"/api/commission/tickets/[id]/images/[messageId]">) {
|
||||
try {
|
||||
const { id, messageId } = await context.params;
|
||||
await authorizeTicket(id);
|
||||
const [message] = await getDb().select({ key: commissionMessages.imageObjectKey,
|
||||
type: commissionMessages.imageMimeType }).from(commissionMessages)
|
||||
.where(and(eq(commissionMessages.id, messageId), eq(commissionMessages.ticketId, id))).limit(1);
|
||||
if (!message?.key || !message.type) throw new HttpError(404, "image-not-found");
|
||||
const file = (await getMediaStorage()).file(message.key);
|
||||
return new Response(await file.bytes(), { headers: { "Content-Type": message.type,
|
||||
"Cache-Control": "private, no-store", "X-Content-Type-Options": "nosniff" } });
|
||||
} catch (cause) { return errorResponse(cause); }
|
||||
}
|
||||
@@ -33,7 +33,7 @@ export async function POST(request: Request, context: RouteContext<"/api/commiss
|
||||
const bytes = new Uint8Array(await image.arrayBuffer());
|
||||
await inspectImage(bytes, image.type as "image/png" | "image/jpeg" | "image/webp");
|
||||
imageObjectKey = `commission/messages/${crypto.randomUUID()}`;
|
||||
await (await getMediaStorage()).write(imageObjectKey, bytes, { type: image.type, acl: "private" });
|
||||
await (await getMediaStorage()).write(imageObjectKey, bytes, { type: image.type, acl: "public-read" });
|
||||
}
|
||||
let messageId: string;
|
||||
try {
|
||||
|
||||
@@ -1,20 +0,0 @@
|
||||
import { eq } from "drizzle-orm";
|
||||
import { getDb } from "@/db";
|
||||
import { commissionPayments } from "@/db/schema";
|
||||
import { authorizeTicket } from "@/lib/commission/tickets";
|
||||
import { getMediaStorage } from "@/lib/media/storage";
|
||||
import { errorResponse, HttpError } from "@/lib/security/http";
|
||||
|
||||
export async function GET(_request: Request, context: RouteContext<"/api/commission/tickets/[id]/slip">) {
|
||||
try {
|
||||
const { id } = await context.params;
|
||||
await authorizeTicket(id);
|
||||
const [payment] = await getDb().select({ key: commissionPayments.slipObjectKey,
|
||||
type: commissionPayments.slipMimeType }).from(commissionPayments)
|
||||
.where(eq(commissionPayments.ticketId, id)).limit(1);
|
||||
if (!payment) throw new HttpError(404, "slip-not-found");
|
||||
const file = (await getMediaStorage()).file(payment.key);
|
||||
return new Response(await file.bytes(), { headers: { "Content-Type": payment.type,
|
||||
"Cache-Control": "private, no-store", "X-Content-Type-Options": "nosniff" } });
|
||||
} catch (cause) { return errorResponse(cause); }
|
||||
}
|
||||
Reference in New Issue
Block a user