Files
superidou 9501751792 0.10.1: 安全与业务逻辑加固、新品牌与部署加固
三轮审查修复(60+ 项),相对远端 main(b536672)的关键变更:
- 安全: 数据面 SSRF 拨号防护(防 DNS rebinding)/上游凭据剥离/登录防枚举
  与锁定态统一/可信代理(X-Forwarded-For)限流加固/会话版本失效机制/
  撤销即时传播/弱密钥拒绝启动/脱敏字节级重写(保签名契约)
- 业务逻辑: 裸 body 上传 panic/bootstrap 审计管线卡死/定价通配符优先级/
  全局工具可见性/调度器停机补跑/TOTP 挑战令牌消费顺序/熔断探针语义/
  >4MB 响应 token 计量/管理员重置密码作废会话 等
- 前端: 新 logo(语枢 AI 网关主题)/Provider 凭据异常警示/删除入口/
  后端错误消息透传/localStorage 敏感数据收敛
- 部署: CREDENTIAL_MASTER_KEY 持久化与弱值拒绝/Provider DELETE 接口/
  nginx 安全头/worker 内存限制
- 新增迁移 000029(key_hash 索引)/000030(usage_daily 币种维度)
2026-08-13 10:50:51 +08:00

138 lines
3.6 KiB
Go

package workbench
import (
"errors"
"io"
"mime/multipart"
"net/http"
"strings"
"aigateway.local/core/internal/identity"
"aigateway.local/core/internal/platform/apiresponse"
)
// FilesPortalHTTPHandler serves each portal user's personal file store. Unlike
// the admin handler every object is scoped to the authenticated account, so a
// user can only ever see and open their own files.
type FilesPortalHTTPHandler struct {
files *FileService
identity *identity.Service
mux *http.ServeMux
}
func NewFilesPortalHTTPHandler(files *FileService, identityService *identity.Service) *FilesPortalHTTPHandler {
h := &FilesPortalHTTPHandler{files: files, identity: identityService, mux: http.NewServeMux()}
h.mux.HandleFunc("POST /api/v1/portal/files", h.upload)
h.mux.HandleFunc("GET /api/v1/portal/files", h.list)
h.mux.HandleFunc("GET /api/v1/portal/files/{id}/download", h.download)
h.mux.HandleFunc("DELETE /api/v1/portal/files/{id}", h.delete)
return h
}
func (h *FilesPortalHTTPHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) { h.mux.ServeHTTP(w, r) }
func (h *FilesPortalHTTPHandler) account(w http.ResponseWriter, r *http.Request) (identity.Account, bool) {
account, err := h.identity.Authenticate(r.Context(), identity.KindPortal, r.Header.Get("Authorization"))
if err != nil {
apiresponse.Error(w, http.StatusUnauthorized, "登录状态无效或已过期")
return identity.Account{}, false
}
return account, true
}
func (h *FilesPortalHTTPHandler) upload(w http.ResponseWriter, r *http.Request) {
a, ok := h.account(w, r)
if !ok {
return
}
var (
body io.Reader
originalName = strings.TrimSpace(r.URL.Query().Get("filename"))
contentType = r.Header.Get("Content-Type")
)
if strings.HasPrefix(contentType, "multipart/form-data") {
part, err := h.firstFilePart(r)
if err != nil {
apiresponse.Error(w, http.StatusBadRequest, "缺少上传文件")
return
}
defer part.Close()
body = part
originalName = part.FileName()
if ct := part.Header.Get("Content-Type"); ct != "" {
contentType = ct
}
}
// 非 multipart 请求(body 为 nil 时)按原始请求体上传(?filename= 指定文件名)。
if body == nil {
body = r.Body
}
if originalName == "" {
apiresponse.Error(w, http.StatusBadRequest, "缺少文件名")
return
}
obj, err := h.files.Upload(r.Context(), "personal", &a.ID, a.ID, originalName, contentType, body)
if err != nil {
fileError(w, err)
return
}
apiresponse.OK(w, obj)
}
func (h *FilesPortalHTTPHandler) firstFilePart(r *http.Request) (*multipart.Part, error) {
reader, err := r.MultipartReader()
if err != nil {
return nil, err
}
for {
part, err := reader.NextPart()
if err == io.EOF {
return nil, errors.New("no file part")
}
if err != nil {
return nil, err
}
if part.FormName() == "file" {
return part, nil
}
}
}
func (h *FilesPortalHTTPHandler) list(w http.ResponseWriter, r *http.Request) {
a, ok := h.account(w, r)
if !ok {
return
}
items, err := h.files.ListPersonal(r.Context(), a.ID)
if err != nil {
fileError(w, err)
return
}
apiresponse.OK(w, items)
}
func (h *FilesPortalHTTPHandler) download(w http.ResponseWriter, r *http.Request) {
a, ok := h.account(w, r)
if !ok {
return
}
obj, err := h.files.GetPersonal(r.Context(), a.ID, r.PathValue("id"))
if err != nil {
fileError(w, err)
return
}
serveFileContent(w, r, h.files, obj)
}
func (h *FilesPortalHTTPHandler) delete(w http.ResponseWriter, r *http.Request) {
a, ok := h.account(w, r)
if !ok {
return
}
if err := h.files.DeletePersonal(r.Context(), a.ID, r.PathValue("id")); err != nil {
fileError(w, err)
return
}
apiresponse.OK(w, map[string]bool{"deleted": true})
}