Allow password entry for shared directories
This commit is contained in:
@@ -32,8 +32,13 @@ func (wc *WebController) serveDirectory(w http.ResponseWriter, r *http.Request,
|
||||
td.User = json.RawMessage("null")
|
||||
}
|
||||
|
||||
// A shared link can have the password of the directory in it
|
||||
var path = strings.TrimPrefix(p.ByName("path"), "/")
|
||||
var err = pdapi.GetJSON("filesystem/"+url.PathEscape(path)+"?stat", &td.Node)
|
||||
var err = pdapi.GetJSON(
|
||||
"filesystem/"+url.PathEscape(path)+"?stat&password="+
|
||||
url.QueryEscape(r.URL.Query().Get("password")),
|
||||
&td.Node,
|
||||
)
|
||||
if apiErr, ok := errors.AsType[pixelapi.Error](err); ok {
|
||||
// Set the proper response code for the error message
|
||||
switch apiErr.StatusCode {
|
||||
|
||||
@@ -124,12 +124,20 @@ func (wc *WebController) metadataFromFilesystem(r *http.Request, f api.Filesyste
|
||||
}
|
||||
}
|
||||
|
||||
// The services which make link previews don't keep cookies, so a password
|
||||
// in the link has to be in every URL they open
|
||||
var query, thumbnail = "", "?thumbnail"
|
||||
if password := r.URL.Query().Get("password"); password != "" {
|
||||
password = "password=" + url.QueryEscape(password)
|
||||
query, thumbnail = "?"+password, thumbnail+"&"+password
|
||||
}
|
||||
|
||||
return generateOGData(
|
||||
base.Name,
|
||||
base.FileType,
|
||||
addr+"/d"+filepath,
|
||||
addr+"/api/filesystem"+filepath,
|
||||
addr+"/api/filesystem"+filepath+"?thumbnail",
|
||||
addr+"/d"+filepath+query,
|
||||
addr+"/api/filesystem"+filepath+query,
|
||||
addr+"/api/filesystem"+filepath+thumbnail,
|
||||
colour,
|
||||
)
|
||||
}
|
||||
|
||||
24
webcontroller/opengraph_test.go
Normal file
24
webcontroller/opengraph_test.go
Normal file
@@ -0,0 +1,24 @@
|
||||
package webcontroller
|
||||
|
||||
import (
|
||||
"net/http/httptest"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"fornaxian.tech/nova_server/api"
|
||||
)
|
||||
|
||||
// The services which make link previews have no cookies, so a password in the
|
||||
// link has to be in the URLs they open
|
||||
func TestMetadataPassword(t *testing.T) {
|
||||
var r = httptest.NewRequest("GET", "/d/abc/a%20b.png?password=p%26w+1", nil)
|
||||
var og = (&WebController{}).metadataFromFilesystem(r, api.FilesystemPath{
|
||||
Path: []api.FilesystemNode{{Path: "/abc/a b.png", FileType: "image/png"}},
|
||||
})
|
||||
for _, prop := range og.MetaPropRules {
|
||||
if (prop.Key == "og:url" || prop.Key == "og:image") &&
|
||||
!strings.HasSuffix(prop.Value, "/abc/a%20b.png?password=p%26w+1") {
|
||||
t.Errorf("%s is %s", prop.Key, prop.Value)
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user