feat(backend): serve avatars through accounts-service behind the gateway
accounts-service returned avatar_url built from the internal S3_ENDPOINT (http://minio:9000/<bucket>), which browsers cannot resolve, so avatars never rendered and the re-crop fetch failed. MinIO is intentionally not exposed. Add a public GET /media/{key} read route in accounts-service (behind the gateway internal-key guard, no identity required so anonymous profile pages work) that streams the object out of private MinIO. Introduce AVATAR_PUBLIC_BASE_URL so the browser-facing prefix is decoupled from the internal endpoint; prod sets it to the same-origin /api/media, gateway routes the media segment to accounts.
This commit is contained in:
parent
fd2e29cede
commit
b496bde701
7 changed files with 103 additions and 3 deletions
|
|
@ -6,7 +6,7 @@ pub enum Upstream {
|
|||
|
||||
pub fn upstream_for(path: &str) -> Option<Upstream> {
|
||||
match path.trim_start_matches('/').split('/').next()? {
|
||||
"auth" | "device" | "avatars" | "me" | "users" => Some(Upstream::Accounts),
|
||||
"auth" | "device" | "avatars" | "media" | "me" | "users" => Some(Upstream::Accounts),
|
||||
"configs" | "showcase" => Some(Upstream::Configs),
|
||||
_ => None,
|
||||
}
|
||||
|
|
@ -20,6 +20,10 @@ mod tests {
|
|||
fn routes_by_first_segment_only() {
|
||||
assert_eq!(upstream_for("/auth/login"), Some(Upstream::Accounts));
|
||||
assert_eq!(upstream_for("/me"), Some(Upstream::Accounts));
|
||||
assert_eq!(
|
||||
upstream_for("/media/avatars/abc.png"),
|
||||
Some(Upstream::Accounts)
|
||||
);
|
||||
assert_eq!(upstream_for("/configs/shared/ABC"), Some(Upstream::Configs));
|
||||
assert_eq!(upstream_for("/showcase"), Some(Upstream::Configs));
|
||||
assert_eq!(upstream_for("/authx"), None);
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue