feat(backend): serve avatars through accounts-service behind the gateway

accounts-service returned avatar_url built from the internal S3_ENDPOINT
(http://minio:9000/<bucket>), which browsers cannot resolve, so avatars never
rendered and the re-crop fetch failed. MinIO is intentionally not exposed.

Add a public GET /media/{key} read route in accounts-service (behind the
gateway internal-key guard, no identity required so anonymous profile pages
work) that streams the object out of private MinIO. Introduce
AVATAR_PUBLIC_BASE_URL so the browser-facing prefix is decoupled from the
internal endpoint; prod sets it to the same-origin /api/media, gateway routes
the media segment to accounts.
This commit is contained in:
loki5512344 2026-09-29 10:14:18 +02:00
parent fd2e29cede
commit b496bde701
Signed by: boba
GPG key ID: 253067914055423B
7 changed files with 103 additions and 3 deletions

View file

@ -73,6 +73,9 @@ services:
environment:
DATABASE_URL: postgres://lovisual:${POSTGRES_PASSWORD}@postgres:5432/accounts_db
S3_ENDPOINT: http://minio:9000
# Browser-facing avatar prefix. Served same-origin through the site's
# /api proxy -> gateway -> accounts-service, so MinIO stays private.
AVATAR_PUBLIC_BASE_URL: https://visual.loki-code.dev/api/media
PORT: 8081
GRPC_PORT: 50051
networks: [lovisual-internal]