feat(backend): serve avatars through accounts-service behind the gateway

accounts-service returned avatar_url built from the internal S3_ENDPOINT
(http://minio:9000/<bucket>), which browsers cannot resolve, so avatars never
rendered and the re-crop fetch failed. MinIO is intentionally not exposed.

Add a public GET /media/{key} read route in accounts-service (behind the
gateway internal-key guard, no identity required so anonymous profile pages
work) that streams the object out of private MinIO. Introduce
AVATAR_PUBLIC_BASE_URL so the browser-facing prefix is decoupled from the
internal endpoint; prod sets it to the same-origin /api/media, gateway routes
the media segment to accounts.
This commit is contained in:
loki5512344 2026-09-29 10:14:18 +02:00
parent fd2e29cede
commit b496bde701
Signed by: boba
GPG key ID: 253067914055423B
7 changed files with 103 additions and 3 deletions

View file

@ -6,7 +6,7 @@ pub enum Upstream {
pub fn upstream_for(path: &str) -> Option<Upstream> {
match path.trim_start_matches('/').split('/').next()? {
"auth" | "device" | "avatars" | "me" | "users" => Some(Upstream::Accounts),
"auth" | "device" | "avatars" | "media" | "me" | "users" => Some(Upstream::Accounts),
"configs" | "showcase" => Some(Upstream::Configs),
_ => None,
}
@ -20,6 +20,10 @@ mod tests {
fn routes_by_first_segment_only() {
assert_eq!(upstream_for("/auth/login"), Some(Upstream::Accounts));
assert_eq!(upstream_for("/me"), Some(Upstream::Accounts));
assert_eq!(
upstream_for("/media/avatars/abc.png"),
Some(Upstream::Accounts)
);
assert_eq!(upstream_for("/configs/shared/ABC"), Some(Upstream::Configs));
assert_eq!(upstream_for("/showcase"), Some(Upstream::Configs));
assert_eq!(upstream_for("/authx"), None);