Revert "Merge pull request 'Complete Housekeeping migration and /ase cutover' (#52) from codex/housekeeping-complete into main"
CI / check (push) Successful in 27s
CI / release (push) Skipped
CI / deploy (push) Successful in 43s

This reverts commit 488b6e57c4, reversing
changes made to b506b4499a.
This commit is contained in:
Simo committed 2026-08-30 21:31:34 +02:00
1 parent 488b6e57c4
commit b1ddda66ff
802 files changed
+61370 -76659

No files matched your search

-36
View File
@@ -1,36 +0,0 @@
import { existsSync } from "node:fs";
import { readFile } from "node:fs/promises";
import { beforeEach, describe, expect, it, vi } from "vitest";
import { GET } from "./route";
vi.mock("node:fs", () => ({ existsSync: vi.fn() }));
vi.mock("node:fs/promises", () => ({ readFile: vi.fn() }));
vi.mock("@/lib/media-storage", async () => {
const path = await import("node:path");
const mediaRoot = path.resolve("media-fixture");
return {
MEDIA_ROOT: mediaRoot,
resolveMediaPath: vi.fn((name: string) => path.join(mediaRoot, name)),
};
});
describe("GET /api/media/[...path]", () => {
beforeEach(() => {
vi.clearAllMocks();
vi.mocked(existsSync).mockReturnValue(true);
vi.mocked(readFile).mockResolvedValue(Buffer.from([0, 0, 1, 0]));
});
it("serves a stored genuine ICO with the canonical MIME and nosniff", async () => {
const response = await GET(
new Request("http://localhost/api/media/favicon/site.ico"),
{
params: Promise.resolve({ path: ["favicon", "site.ico"] }),
},
);
expect(response.status).toBe(200);
expect(response.headers.get("content-type")).toBe("image/x-icon");
expect(response.headers.get("x-content-type-options")).toBe("nosniff");
expect(readFile).toHaveBeenCalledOnce();
});
});
+1 -18
View File
@@ -4,16 +4,7 @@ import path from "node:path";
import { NextResponse } from "next/server";
import { MEDIA_ROOT, resolveMediaPath } from "@/lib/media-storage";
const ALLOWED_EXT = [
".png",
".jpg",
".jpeg",
".gif",
".webp",
".svg",
".bmp",
".ico",
];
const ALLOWED_EXT = [".png", ".jpg", ".jpeg", ".gif", ".webp", ".svg", ".bmp"];
export async function GET(
_request: Request,
@@ -50,20 +41,12 @@ export async function GET(
".webp": "image/webp",
".svg": "image/svg+xml",
".bmp": "image/bmp",
".ico": "image/x-icon",
};
return new NextResponse(bytes, {
headers: {
// eslint-disable-next-line security/detect-object-injection -- ext validated against ALLOWED_EXT
"Content-Type": mime[ext] ?? "application/octet-stream",
"X-Content-Type-Options": "nosniff",
...(ext === ".svg"
? {
"Content-Security-Policy":
"sandbox; default-src 'none'; style-src 'unsafe-inline'",
}
: {}),
"Cache-Control": "public, max-age=3600, must-revalidate",
},
});