This commit is contained in:
2026-09-28 22:12:38 +02:00
parent b96f188a59
commit 2cc768f1fd
24 changed files with 962 additions and 78 deletions
+15
View File
@@ -3,6 +3,7 @@ import fs from "fs/promises";
import path from "path";
import db from "../sql.mjs";
import queue from "../queue.mjs";
import { isHiddenItem } from "../hidden_items.mjs";
export default (router, tpl) => {
router.static({
@@ -48,8 +49,21 @@ export default (router, tpl) => {
return 'application/octet-stream';
};
// <id>.webp / <id>_blur.webp belonging to an item that isn't live (pending, deleted) is never public,
// even if a stale file with that name exists. Uploaders use /pending/t/, staff /mod/pending/t/.
const isHiddenMedia = async (file) => {
const m = /^(\d+)(?:_blur)?\.webp$/.exec(file);
return !!m && await isHiddenItem(m[1]);
};
const notFound = (res) => {
res.writeHead(404, { 'Content-Type': 'text/plain' });
return res.end('404 - file not found.');
};
router.get(/^\/t\/(?<file>.+)$/, async (req, res) => {
const file = req.params.file;
if (await isHiddenMedia(file)) return notFound(res);
const filePath = path.join(cfg.paths.t, file);
try {
const stat = await fs.stat(filePath);
@@ -115,6 +129,7 @@ export default (router, tpl) => {
router.get(/^\/ca\/(?<file>.+)$/, async (req, res) => {
const file = req.params.file;
if (await isHiddenMedia(file)) return notFound(res);
const filePath = path.join(cfg.paths.ca, file);
try {
const stat = await fs.stat(filePath);