fix media workflows and download organization

This commit is contained in:
ShukeBta
2026-06-26 08:42:16 +08:00
parent 0da96f7e4e
commit 65adca04df
102 changed files with 4063 additions and 437 deletions
+88 -1
View File
@@ -108,7 +108,15 @@ func (s *StorageConfigService) Save(ctx context.Context, in StorageInput) (*Stor
if !validStorageType(in.Type) {
return nil, fmt.Errorf("unsupported storage type %q", in.Type)
}
blob, err := json.Marshal(in.Config)
cfg := cloneStorageConfigMap(in.Config)
if shouldPreserveStorageSecretsOnSave(in.Enabled) {
merged, err := s.mergeExistingStorageSecrets(ctx, in.Type, cfg)
if err != nil {
return nil, err
}
cfg = merged
}
blob, err := json.Marshal(cfg)
if err != nil {
return nil, err
}
@@ -128,6 +136,85 @@ func (s *StorageConfigService) Save(ctx context.Context, in StorageInput) (*Stor
return s.Get(ctx, in.Type)
}
func shouldPreserveStorageSecretsOnSave(enabled *bool) bool {
return enabled == nil || *enabled
}
func cloneStorageConfigMap(cfg map[string]any) map[string]any {
out := make(map[string]any, len(cfg))
for k, v := range cfg {
out[k] = v
}
return out
}
func (s *StorageConfigService) mergeExistingStorageSecrets(ctx context.Context, typ string, cfg map[string]any) (map[string]any, error) {
view, err := s.Get(ctx, typ)
if err != nil || view == nil {
return cfg, err
}
for _, key := range storagePreservedSecretKeys() {
existing := strings.TrimSpace(strr(view.Config[key]))
if existing == "" {
continue
}
incoming, hasIncoming := cfg[key]
if hasIncoming && !isBlankStorageSecret(incoming) {
continue
}
if storageSecretReplacedByAlternative(typ, key, cfg, view.Config) {
continue
}
cfg[key] = existing
}
return cfg, nil
}
func storagePreservedSecretKeys() []string {
return []string{"password", "secret_key", "token", "cookie", "access_key"}
}
func isBlankStorageSecret(value any) bool {
text := strings.TrimSpace(strr(value))
return text == "" || text == "********"
}
func storageSecretReplacedByAlternative(typ, key string, cfg, existing map[string]any) bool {
switch typ {
case cloud.TypeOpenList:
switch key {
case "token":
return strings.TrimSpace(strr(cfg["username"])) != "" && strings.TrimSpace(strr(cfg["password"])) != ""
case "password":
if strings.TrimSpace(strr(cfg["token"])) != "" {
return true
}
return storagePlainFieldChanged("username", cfg, existing)
}
case "webdav", cloud.TypeCloudDrive2:
if key == "password" {
if strings.TrimSpace(strr(cfg["token"])) != "" {
return true
}
return storagePlainFieldChanged("username", cfg, existing)
}
case "s3":
if key == "secret_key" {
return storagePlainFieldChanged("access_key", cfg, existing)
}
}
return false
}
func storagePlainFieldChanged(key string, cfg, existing map[string]any) bool {
incoming := strings.TrimSpace(strr(cfg[key]))
if incoming == "" {
return false
}
current := strings.TrimSpace(strr(existing[key]))
return current != "" && incoming != current
}
// Logout clears saved cloud login credentials, disables the storage backend,
// and removes virtual cloud libraries/media for that provider. It intentionally
// keeps non-secret connection hints such as server / WebDAV URL / timeout so