fix(files): аватары и баннеры доступны авторизованным пользователям

Аватар нельзя было показать в списке друзей: файл без комнаты был доступен
только загрузившему. Добавлено назначение файла (`files.purpose`: attachment |
avatar | banner, миграция 00006): аватары и баннеры отдаются любому
авторизованному пользователю, вложения по-прежнему проверяются по правам
комнаты, а непривязанные загрузки остаются приватными.
This commit is contained in:
2026-09-20 01:39:04 +03:00
parent 20eed227ca
commit d02ef7527a
35 changed files with 2330 additions and 191 deletions
+19
View File
@@ -254,6 +254,25 @@ func TestTimezoneAndAvatarUpdate(t *testing.T) {
t.Fatalf("avatar_file_id = %q, want %q", profile.User.AvatarFileID, fileID)
}
// Аватар виден другому авторизованному пользователю (он показывается в
// списках друзей и участников), но не анонимному.
otherCookie := registerAndLogin(t, srv, "tz_other", "tz-other@example.com")
_ = otherCookie
downloadReq, err := http.NewRequestWithContext(t.Context(), http.MethodGet,
httpServer.URL+"/files/"+fileID, nil)
if err != nil {
t.Fatalf("new request: %v", err)
}
downloadReq.AddCookie(otherCookie)
downloadResp, err := httpServer.Client().Do(downloadReq)
if err != nil {
t.Fatalf("avatar download: %v", err)
}
_ = downloadResp.Body.Close()
if downloadResp.StatusCode != http.StatusOK {
t.Fatalf("другой пользователь не видит аватар: %d", downloadResp.StatusCode)
}
removed := doJSON(t, srv, http.MethodDelete, "/api/v1/users/@me/avatar", "", cookie)
if removed.Code != http.StatusOK {
t.Fatalf("delete avatar = %d, body = %s", removed.Code, removed.Body.String())