admin

package
v0.3.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: MPL-2.0 Imports: 15 Imported by: 0

README

Private Media administration

media/admin.New(service) composes a real private file-library surface through the shared Admin shell. It imports only the public Media and Admin APIs. The product still supplies Identity/Web authentication and its Application policy; Media domain/storage implementation remains independent of Admin, Identity and Audit.

Navigation and the first 25 ready metadata records require media.List on media.LibraryTarget. Refresh/next page keep the same bounded keyset contract; pages are not a shared snapshot. Seeing metadata grants neither Read nor Delete. Each download/status read separately calls the owning public exact-ID operations; each deletion supplies the exact decimal revision and owning Service evaluates its distinct capability. Revision values stay decimal strings in JSON and DOM, preserving the full int64 precondition without JavaScript numeric conversion. The UI requires explicit confirmation before deletion. This surface does not expose Reconcile or invent a product maintenance grant.

Upload is one multipart file part only, fully parsed before Service.Create can create durable intent. Additional files/fields/part headers, hidden transfer encoding, path-bearing filenames, malformed framing and over-limit files fail before domain creation. Parsing admits at most two operations without a queue and allocates at most two fixed 10 MiB+1 file buffers. Multipart header/framing allocations are additionally bounded by the 12 MiB request body and standard parser; these figures exclude image decoder/runtime/other Module overhead and are not a process RSS ceiling. No multipart temporary file or disk spill is created. Actual transport read deadlines apply before parsing; domain byte-derived validation remains authoritative. Service.Formats() supplies upload hints from the immutable effective selection: nil configuration keeps PNG/JPEG; products may explicitly select media.CommonMIMEs() or a supported subset, including separately selected image/svg+xml/.svg. SVG is absent from both nil defaults and CommonMIMEs(). Common opaque attachments require matching extension and bounded byte recognition, have no decoded dimensions and consume no image decoding slots. Explicit private SVG instead requires complete bounded XML admission and shares the two image parser/decoder slots; SVG has zero stored dimensions and no preview or public-rendering path. The screen omits unknown dimensions; selection narrows new admission without revoking reads of previously retained supported files. Filename metadata preserves accepted Unicode without rewriting it to a storage path.

Private byte responses first call public Status, then Read. Attachment headers are delayed until Media has verified the file and supplies bytes. Responses use the derived exact MIME, RFC-compatible Unicode attachment filename, nosniff, private, no-store, known length and an actual write deadline no later than the request context. A pre-byte error remains safe JSON; a transfer failure after writing aborts the HTTP response rather than appending an error document. There is no static directory or public asset URL.

The shared request-local CSRF/client controller supports these forms with native FormData and delegated handlers for bounded refreshed rows; no frontend framework is needed. A 15 second client abort never proves rollback and never replays a mutation. Returned error asset_id evidence can populate the separately authorized known-ID status form. A wholly lost HTTP upload response may contain no known ID: inspect the permitted library and use the product's authorized operator recovery path. Filenames may repeat, so a matching name does not uniquely identify that upload; this UI neither promises that identity nor silently uploads again. Failed upload selection clears to avoid accidental replay.

Module-owned focused tests cover framing before Service access, admission/transport bounds, exact target dispatch, denied operations, decimal int64 CAS, empty/localized rendering, known unknown-outcome identity and delayed private attachment/error semantics. Normal pinned consumer and actual TLS/browser evidence cover the enclosing Admin contract and the common attachment extension in #67. Upload limits remain Media-owned: this slice retains 10 MiB; a future authorized settings surface may expose a typed limit only within its reviewed resource profile.

Documentation

Overview

SPDX-License-Identifier: MPL-2.0 Package admin owns Media's private file-library presentation. Every domain operation uses the public Media Service, never storage or database internals.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func New

func New(service *media.Service) (shell.Surface, error)

New supplies the real private library screen. Collection metadata entry is separate from exact Read/Delete grants; no public URL or maintenance grant.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL