feat(backend): serve avatars through accounts-service behind the gateway
accounts-service returned avatar_url built from the internal S3_ENDPOINT (http://minio:9000/<bucket>), which browsers cannot resolve, so avatars never rendered and the re-crop fetch failed. MinIO is intentionally not exposed. Add a public GET /media/{key} read route in accounts-service (behind the gateway internal-key guard, no identity required so anonymous profile pages work) that streams the object out of private MinIO. Introduce AVATAR_PUBLIC_BASE_URL so the browser-facing prefix is decoupled from the internal endpoint; prod sets it to the same-origin /api/media, gateway routes the media segment to accounts.
This commit is contained in:
parent
fd2e29cede
commit
b496bde701
7 changed files with 103 additions and 3 deletions
|
|
@ -7,6 +7,9 @@ S3_ENDPOINT=http://localhost:9000
|
|||
S3_BUCKET=lovisual-avatars
|
||||
S3_ACCESS_KEY=minioadmin
|
||||
S3_SECRET_KEY=minioadmin
|
||||
# Optional browser-facing avatar prefix (e.g. https://visual.loki-code.dev/api/media).
|
||||
# Leave empty for local dev: avatars then resolve to <S3_ENDPOINT>/<S3_BUCKET> directly.
|
||||
AVATAR_PUBLIC_BASE_URL=
|
||||
# Shared secret between gateway and internal services (openssl rand -hex 32)
|
||||
INTERNAL_KEY=
|
||||
# Secure cookie flag: leave unset (or true) in production (HTTPS); false for local HTTP dev
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue