mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-09 09:06:36 +08:00
fix(upload): restrict cross-user private file access (UPLOAD-1)
- Add access_mode column to w_uploads table (0 = private, 1 = public) and initialize data in a single migration script - Enforce strict ownership check for private files during download - Allow public files to follow whitelisted public-access rules - Default access_mode to public for avatars and private for generic uploads - Update frontend service to support optional accessMode parameter
This commit is contained in:
@@ -65,6 +65,7 @@ func TestServeFileByIDAccessControl(t *testing.T) {
|
||||
StorageDriver: "local",
|
||||
Type: "avatar",
|
||||
Status: model.UploadStatusUsed,
|
||||
AccessMode: 1,
|
||||
}
|
||||
attachmentFile := model.Upload{
|
||||
ID: 8002,
|
||||
@@ -77,6 +78,7 @@ func TestServeFileByIDAccessControl(t *testing.T) {
|
||||
StorageDriver: "local",
|
||||
Type: "attachment",
|
||||
Status: model.UploadStatusUsed,
|
||||
AccessMode: 1,
|
||||
}
|
||||
|
||||
_ = os.MkdirAll("uploads", 0755)
|
||||
@@ -254,6 +256,7 @@ func TestImageCompression(t *testing.T) {
|
||||
StorageDriver: "local",
|
||||
Type: "avatar", // Whitelisted by default
|
||||
Status: model.UploadStatusUsed,
|
||||
AccessMode: 1,
|
||||
}
|
||||
dbConn.Create(&uploadRecord)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user