fix(files): аватары и баннеры доступны авторизованным пользователям

Аватар нельзя было показать в списке друзей: файл без комнаты был доступен
только загрузившему. Добавлено назначение файла (`files.purpose`: attachment |
avatar | banner, миграция 00006): аватары и баннеры отдаются любому
авторизованному пользователю, вложения по-прежнему проверяются по правам
комнаты, а непривязанные загрузки остаются приватными.
This commit is contained in:
2026-09-20 01:39:04 +03:00
parent 20eed227ca
commit d02ef7527a
35 changed files with 2330 additions and 191 deletions
+13 -6
View File
@@ -20,7 +20,10 @@ type File struct {
Height int
StoragePath string
SHA256 string
CreatedAt time.Time
// Purpose: attachment (по умолчанию) | avatar | banner — от него зависит
// проверка доступа при выдаче файла.
Purpose string
CreatedAt time.Time
}
// CreateFileParams — параметры регистрации файла.
@@ -36,23 +39,27 @@ type CreateFileParams struct {
Height int
StoragePath string
SHA256 string
Purpose string
}
const fileColumns = `id, uploader_id, guild_id, channel_id, message_id, filename,
content_type, size_bytes, width, height, storage_path, sha256, created_at`
content_type, size_bytes, width, height, storage_path, sha256, created_at, purpose`
// CreateFile регистрирует загруженный файл.
func (s *Store) CreateFile(ctx context.Context, params CreateFileParams) (*File, error) {
if params.ID == 0 {
params.ID = s.NextID()
}
if params.Purpose == "" {
params.Purpose = "attachment"
}
_, err := s.writer.ExecContext(ctx, `
INSERT INTO files (id, uploader_id, guild_id, channel_id, message_id, filename,
content_type, size_bytes, width, height, storage_path, sha256, created_at)
VALUES (?, ?, ?, ?, NULL, ?, ?, ?, ?, ?, ?, ?, ?)`,
content_type, size_bytes, width, height, storage_path, sha256, created_at, purpose)
VALUES (?, ?, ?, ?, NULL, ?, ?, ?, ?, ?, ?, ?, ?, ?)`,
int64(params.ID), int64(params.UploaderID), nullableID(params.GuildID), nullableID(params.ChannelID),
params.Filename, params.ContentType, params.SizeBytes, params.Width, params.Height,
params.StoragePath, params.SHA256, s.Now())
params.StoragePath, params.SHA256, s.Now(), params.Purpose)
if err != nil {
return nil, mapError(err)
}
@@ -126,7 +133,7 @@ func scanFile(scanner interface{ Scan(...any) error }) (*File, error) {
)
err := scanner.Scan(&file.ID, &uploaderID, &guildID, &channelID, &messageID, &file.Filename,
&file.ContentType, &file.SizeBytes, &file.Width, &file.Height, &file.StoragePath,
&file.SHA256, &createdAt)
&file.SHA256, &createdAt, &file.Purpose)
if err != nil {
return nil, mapError(err)
}