Allow password entry for shared directories

This commit is contained in:
2026-10-05 17:39:39 +02:00
parent 6f0f58d2d9
commit f3738cbc4d
8 changed files with 91 additions and 24 deletions

View File

@@ -32,8 +32,13 @@ func (wc *WebController) serveDirectory(w http.ResponseWriter, r *http.Request,
td.User = json.RawMessage("null")
}
// A shared link can have the password of the directory in it
var path = strings.TrimPrefix(p.ByName("path"), "/")
var err = pdapi.GetJSON("filesystem/"+url.PathEscape(path)+"?stat", &td.Node)
var err = pdapi.GetJSON(
"filesystem/"+url.PathEscape(path)+"?stat&password="+
url.QueryEscape(r.URL.Query().Get("password")),
&td.Node,
)
if apiErr, ok := errors.AsType[pixelapi.Error](err); ok {
// Set the proper response code for the error message
switch apiErr.StatusCode {

View File

@@ -124,12 +124,20 @@ func (wc *WebController) metadataFromFilesystem(r *http.Request, f api.Filesyste
}
}
// The services which make link previews don't keep cookies, so a password
// in the link has to be in every URL they open
var query, thumbnail = "", "?thumbnail"
if password := r.URL.Query().Get("password"); password != "" {
password = "password=" + url.QueryEscape(password)
query, thumbnail = "?"+password, thumbnail+"&"+password
}
return generateOGData(
base.Name,
base.FileType,
addr+"/d"+filepath,
addr+"/api/filesystem"+filepath,
addr+"/api/filesystem"+filepath+"?thumbnail",
addr+"/d"+filepath+query,
addr+"/api/filesystem"+filepath+query,
addr+"/api/filesystem"+filepath+thumbnail,
colour,
)
}

View File

@@ -0,0 +1,24 @@
package webcontroller
import (
"net/http/httptest"
"strings"
"testing"
"fornaxian.tech/nova_server/api"
)
// The services which make link previews have no cookies, so a password in the
// link has to be in the URLs they open
func TestMetadataPassword(t *testing.T) {
var r = httptest.NewRequest("GET", "/d/abc/a%20b.png?password=p%26w+1", nil)
var og = (&WebController{}).metadataFromFilesystem(r, api.FilesystemPath{
Path: []api.FilesystemNode{{Path: "/abc/a b.png", FileType: "image/png"}},
})
for _, prop := range og.MetaPropRules {
if (prop.Key == "og:url" || prop.Key == "og:image") &&
!strings.HasSuffix(prop.Value, "/abc/a%20b.png?password=p%26w+1") {
t.Errorf("%s is %s", prop.Key, prop.Value)
}
}
}