mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-10-07 23:01:06 +02:00
feat(projects): URL field + cover photo on project cards (#1155)
Two new project fields: a free-text URL rendered as a one-click
external-link button beside the project name on every card (opens in a
new tab, click is e.stopPropagation()-guarded so it doesn't enter the
project), and a cover photo that replaces the status-icon box with a
square thumbnail.
URL is plumbed through ProjectCreate/Update/Response/ListResponse,
including from-template + create-template flows so it inherits between
a project and its template. Cover photo is not inherited because the
file would be shared on disk between source and copy.
Schema validator rejects anything other than http:// or https://
prefixes -- <a href> rendering would otherwise execute javascript:
/ data: / file: URLs even with React's default escaping. PATCH uses
model_fields_set for the URL field so users can clear it by sending
{"url": null}.
Cover image storage: Project.cover_image_filename references a file
Cover image storage: Project.cover_image_filename references a file
inside the existing archives/projects/{id}/attachments/ dir, but it's
tracked separately from the attachments JSON list so swap/delete on
the cover doesn't perturb the user's other attachments. Three routes
(POST/GET/DELETE /projects/{id}/cover-image) accept only .jpg/.jpeg/
.png/.gif/.webp (no SVG -- SVG can carry script payloads), replace in
place (prior file deleted before the new one lands so repeat uploads
can't accumulate orphans), and self-heal when a DB reference points at
a vanished disk file by clearing the column and 404'ing.
GET cover-image is gated by RequireCameraStreamTokenIfAuthEnabled
(accepts ?token=... query string) -- not the bearer-token gate -- so
<img src> requests work in both auth-on and auth-off configurations.
The frontend wraps getProjectCoverImageUrl with withStreamToken(),
matching the existing pattern from getArchiveThumbnail.
Permissions: PROJECTS_UPDATE for upload/delete/PATCH, PROJECTS_READ
gate is implicit via the stream-token credential. Migration: 2
idempotent ALTER TABLE projects ADD COLUMN. Localised across all 8
UI languages.
This commit is contained in:
@@ -5,7 +5,7 @@
|
||||
import { describe, it, expect, afterEach, vi } from 'vitest';
|
||||
import { http, HttpResponse } from 'msw';
|
||||
import { setupServer } from 'msw/node';
|
||||
import { setAuthToken, getAuthToken, api } from '../../api/client';
|
||||
import { setAuthToken, getAuthToken, api, setStreamToken } from '../../api/client';
|
||||
|
||||
// Mock sessionStorage (H-5: tokens are stored in sessionStorage, not localStorage)
|
||||
const sessionStorageMock = {
|
||||
@@ -297,3 +297,35 @@ describe('Printer control endpoints', () => {
|
||||
expect(capturedUrl).toContain('mode=heating');
|
||||
});
|
||||
});
|
||||
|
||||
// #1155 — `<img src>` can't carry an `Authorization: Bearer …` header, so the
|
||||
// project cover-image URL must use the same stream-token pattern as
|
||||
// /archives/{id}/thumbnail. A regression where `withStreamToken` is removed
|
||||
// would break the modal preview AND the card thumbnail when auth is enabled.
|
||||
describe('Project cover image URL (#1155)', () => {
|
||||
afterEach(() => {
|
||||
setStreamToken(null);
|
||||
});
|
||||
|
||||
it('appends the stream token query string when one is set', () => {
|
||||
setStreamToken('abc123');
|
||||
const url = api.getProjectCoverImageUrl(42);
|
||||
expect(url).toContain('/projects/42/cover-image');
|
||||
expect(url).toContain('token=abc123');
|
||||
});
|
||||
|
||||
it('returns the bare URL when no stream token is set', () => {
|
||||
setStreamToken(null);
|
||||
const url = api.getProjectCoverImageUrl(42);
|
||||
expect(url).toContain('/projects/42/cover-image');
|
||||
expect(url).not.toContain('token=');
|
||||
});
|
||||
|
||||
it('URL-encodes a token containing query-string-unsafe characters', () => {
|
||||
setStreamToken('a&b=c');
|
||||
const url = api.getProjectCoverImageUrl(7);
|
||||
// Decoded back, the token must round-trip exactly.
|
||||
const params = new URL(url, 'http://x').searchParams;
|
||||
expect(params.get('token')).toBe('a&b=c');
|
||||
});
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user