mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-10-07 23:01:06 +02:00
feat(projects): URL field + cover photo on project cards (#1155)
Two new project fields: a free-text URL rendered as a one-click
external-link button beside the project name on every card (opens in a
new tab, click is e.stopPropagation()-guarded so it doesn't enter the
project), and a cover photo that replaces the status-icon box with a
square thumbnail.
URL is plumbed through ProjectCreate/Update/Response/ListResponse,
including from-template + create-template flows so it inherits between
a project and its template. Cover photo is not inherited because the
file would be shared on disk between source and copy.
Schema validator rejects anything other than http:// or https://
prefixes -- <a href> rendering would otherwise execute javascript:
/ data: / file: URLs even with React's default escaping. PATCH uses
model_fields_set for the URL field so users can clear it by sending
{"url": null}.
Cover image storage: Project.cover_image_filename references a file
Cover image storage: Project.cover_image_filename references a file
inside the existing archives/projects/{id}/attachments/ dir, but it's
tracked separately from the attachments JSON list so swap/delete on
the cover doesn't perturb the user's other attachments. Three routes
(POST/GET/DELETE /projects/{id}/cover-image) accept only .jpg/.jpeg/
.png/.gif/.webp (no SVG -- SVG can carry script payloads), replace in
place (prior file deleted before the new one lands so repeat uploads
can't accumulate orphans), and self-heal when a DB reference points at
a vanished disk file by clearing the column and 404'ing.
GET cover-image is gated by RequireCameraStreamTokenIfAuthEnabled
(accepts ?token=... query string) -- not the bearer-token gate -- so
<img src> requests work in both auth-on and auth-off configurations.
The frontend wraps getProjectCoverImageUrl with withStreamToken(),
matching the existing pattern from getArchiveThumbnail.
Permissions: PROJECTS_UPDATE for upload/delete/PATCH, PROJECTS_READ
gate is implicit via the stream-token credential. Migration: 2
idempotent ALTER TABLE projects ADD COLUMN. Localised across all 8
UI languages.
This commit is contained in:
@@ -647,6 +647,8 @@ export interface Project {
|
||||
created_at: string;
|
||||
updated_at: string;
|
||||
stats?: ProjectStats;
|
||||
url: string | null; // External link rendered next to project name on the card (#1155)
|
||||
cover_image_filename: string | null; // Filename within project attachments dir (#1155)
|
||||
}
|
||||
|
||||
export interface ProjectAttachment {
|
||||
@@ -682,6 +684,8 @@ export interface ProjectListItem {
|
||||
queue_count: number;
|
||||
progress_percent: number | null; // Plates progress
|
||||
archives: ArchivePreview[];
|
||||
url: string | null; // #1155
|
||||
cover_image_filename: string | null; // #1155
|
||||
}
|
||||
|
||||
export interface ProjectCreate {
|
||||
@@ -696,6 +700,7 @@ export interface ProjectCreate {
|
||||
priority?: string;
|
||||
budget?: number | null;
|
||||
parent_id?: number;
|
||||
url?: string | null; // #1155
|
||||
}
|
||||
|
||||
export interface ProjectUpdate {
|
||||
@@ -711,6 +716,7 @@ export interface ProjectUpdate {
|
||||
priority?: string;
|
||||
budget?: number | null;
|
||||
parent_id?: number;
|
||||
url?: string | null; // #1155 — explicit null clears the URL
|
||||
}
|
||||
|
||||
// BOM Types - Tracks sourced/purchased parts (hardware, electronics, etc.)
|
||||
@@ -4615,6 +4621,35 @@ export const api = {
|
||||
{ method: 'DELETE' }
|
||||
),
|
||||
|
||||
// #1155: Cover image
|
||||
// Browsers can't attach `Authorization: Bearer ...` to `<img src>`, so we
|
||||
// append the stream-token query string the same way archive thumbnails do.
|
||||
getProjectCoverImageUrl: (projectId: number) =>
|
||||
withStreamToken(`${API_BASE}/projects/${projectId}/cover-image`),
|
||||
uploadProjectCoverImage: async (
|
||||
projectId: number,
|
||||
file: File
|
||||
): Promise<{ status: string; filename: string; size: number }> => {
|
||||
const formData = new FormData();
|
||||
formData.append('file', file);
|
||||
const headers: Record<string, string> = {};
|
||||
if (authToken) {
|
||||
headers['Authorization'] = `Bearer ${authToken}`;
|
||||
}
|
||||
const response = await fetch(`${API_BASE}/projects/${projectId}/cover-image`, {
|
||||
method: 'POST',
|
||||
headers,
|
||||
body: formData,
|
||||
});
|
||||
if (!response.ok) {
|
||||
const error = await response.json().catch(() => ({}));
|
||||
throw new Error(error.detail || `HTTP ${response.status}`);
|
||||
}
|
||||
return response.json();
|
||||
},
|
||||
deleteProjectCoverImage: (projectId: number) =>
|
||||
request<{ status: string }>(`/projects/${projectId}/cover-image`, { method: 'DELETE' }),
|
||||
|
||||
// BOM (Bill of Materials)
|
||||
getProjectBOM: (projectId: number) =>
|
||||
request<BOMItem[]>(`/projects/${projectId}/bom`),
|
||||
|
||||
Reference in New Issue
Block a user