Documentation
¶
Overview ¶
Package accessworker is the media access worker's HTTP handler, run by cmd/media-access: it checks the token for a blob path (URL `?t=` or cookie `mt`), serves public/ paths without one, refuses manifests and originals/, and streams the object from the private bucket with its own read-only key. It has no database, no host calls and no cache.
Index ¶
Constants ¶
View Source
const (
// HealthPath answers 200 without touching the bucket.
HealthPath = "/healthz"
)
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Config ¶
type Config struct {
Endpoint string // path-style S3 endpoint, e.g. http://rook-ceph-rgw-external-rgw.rook-ceph.svc:7480
Bucket string
Region string // default us-east-1
AccessKeyID string
SecretAccessKey string
Ring token.Ring
// Hosts limits the Host header (without port); empty accepts any.
Hosts []string
// Origins are exact CORS origins allowed with credentials.
Origins []string
// Client reaches the bucket; default a transport without compression.
Client *http.Client
Logger *slog.Logger
}
Config configures a Handler. The S3 key should only be able to read */blobs/* and */public/*.
Click to show internal directories.
Click to hide internal directories.