accessworker

package
v0.58.8 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: MIT Imports: 18 Imported by: 0

Documentation

Overview

Package accessworker is the media access worker's HTTP handler, run by cmd/media-access: it checks the token for a private/ path (URL `?t=` or cookie `mt`), serves public/ paths without one and temp/ editor views only under an editor token (URL `?t=`, token.EditorScope, which viewer tokens never carry), refuses the manifest, originals/ and staged uploads, and streams the object from the private bucket with its own read-only key. Every refusal (no or bad token, unservable area, missing object) is the same 404, so a response never reveals that protected content exists; token denials are decided before any bucket access and their reason is logged at debug. Every object carries Cross-Origin-Resource-Policy (default same-site), so other sites cannot embed it. It has no database, no host calls and no cache.

Index

Constants

View Source
const (
	// HealthPath answers 200 without touching the bucket.
	HealthPath = "/healthz"
)

Variables

This section is empty.

Functions

This section is empty.

Types

type Config

type Config struct {
	Endpoint        string // path-style S3 endpoint, e.g. http://rook-ceph-rgw-external-rgw.rook-ceph.svc:7480
	Bucket          string
	Region          string // default us-east-1
	AccessKeyID     string
	SecretAccessKey string
	Ring            token.Ring
	// Hosts limits the Host header (without port); empty accepts any
	// (not recommended in production).
	Hosts []string
	// Origins are exact CORS origins ("https://example.com", no path or
	// wildcard) allowed with credentials: the sites whose hls.js reads blobs.
	Origins []string
	// ResourcePolicy is the Cross-Origin-Resource-Policy on every object:
	// "same-site" (default: only the site's own domain and subdomains may
	// embed media), "same-origin", or "cross-origin" for a deployment whose
	// pages are on another site than its media.
	ResourcePolicy string
	// Client reaches the bucket; default a transport without compression.
	Client *http.Client
	Logger *slog.Logger
}

Config configures a Handler. The S3 key should only be able to read */private/*, */public/* and */temp/e-*.

type Handler

type Handler struct {
	// contains filtered or unexported fields
}

Handler serves media objects.

func New

func New(cfg Config) (*Handler, error)

New validates cfg.

func (*Handler) ServeHTTP

func (h *Handler) ServeHTTP(w http.ResponseWriter, r *http.Request)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL