Revert "Merge pull request 'Complete Housekeeping migration and /ase cutover' (#52) from codex/housekeeping-complete into main"
This reverts commit488b6e57c4, reversing changes made tob506b4499a.
This commit is contained in:
1 parent
488b6e57c4
commit
b1ddda66ff
802 files changed
+61370
-76659
No files matched your search
@@ -1,36 +0,0 @@
|
||||
import { existsSync } from "node:fs";
|
||||
import { readFile } from "node:fs/promises";
|
||||
import { beforeEach, describe, expect, it, vi } from "vitest";
|
||||
import { GET } from "./route";
|
||||
|
||||
vi.mock("node:fs", () => ({ existsSync: vi.fn() }));
|
||||
vi.mock("node:fs/promises", () => ({ readFile: vi.fn() }));
|
||||
vi.mock("@/lib/media-storage", async () => {
|
||||
const path = await import("node:path");
|
||||
const mediaRoot = path.resolve("media-fixture");
|
||||
return {
|
||||
MEDIA_ROOT: mediaRoot,
|
||||
resolveMediaPath: vi.fn((name: string) => path.join(mediaRoot, name)),
|
||||
};
|
||||
});
|
||||
|
||||
describe("GET /api/media/[...path]", () => {
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks();
|
||||
vi.mocked(existsSync).mockReturnValue(true);
|
||||
vi.mocked(readFile).mockResolvedValue(Buffer.from([0, 0, 1, 0]));
|
||||
});
|
||||
|
||||
it("serves a stored genuine ICO with the canonical MIME and nosniff", async () => {
|
||||
const response = await GET(
|
||||
new Request("http://localhost/api/media/favicon/site.ico"),
|
||||
{
|
||||
params: Promise.resolve({ path: ["favicon", "site.ico"] }),
|
||||
},
|
||||
);
|
||||
expect(response.status).toBe(200);
|
||||
expect(response.headers.get("content-type")).toBe("image/x-icon");
|
||||
expect(response.headers.get("x-content-type-options")).toBe("nosniff");
|
||||
expect(readFile).toHaveBeenCalledOnce();
|
||||
});
|
||||
});
|
||||
@@ -4,16 +4,7 @@ import path from "node:path";
|
||||
import { NextResponse } from "next/server";
|
||||
import { MEDIA_ROOT, resolveMediaPath } from "@/lib/media-storage";
|
||||
|
||||
const ALLOWED_EXT = [
|
||||
".png",
|
||||
".jpg",
|
||||
".jpeg",
|
||||
".gif",
|
||||
".webp",
|
||||
".svg",
|
||||
".bmp",
|
||||
".ico",
|
||||
];
|
||||
const ALLOWED_EXT = [".png", ".jpg", ".jpeg", ".gif", ".webp", ".svg", ".bmp"];
|
||||
|
||||
export async function GET(
|
||||
_request: Request,
|
||||
@@ -50,20 +41,12 @@ export async function GET(
|
||||
".webp": "image/webp",
|
||||
".svg": "image/svg+xml",
|
||||
".bmp": "image/bmp",
|
||||
".ico": "image/x-icon",
|
||||
};
|
||||
|
||||
return new NextResponse(bytes, {
|
||||
headers: {
|
||||
// eslint-disable-next-line security/detect-object-injection -- ext validated against ALLOWED_EXT
|
||||
"Content-Type": mime[ext] ?? "application/octet-stream",
|
||||
"X-Content-Type-Options": "nosniff",
|
||||
...(ext === ".svg"
|
||||
? {
|
||||
"Content-Security-Policy":
|
||||
"sandbox; default-src 'none'; style-src 'unsafe-inline'",
|
||||
}
|
||||
: {}),
|
||||
"Cache-Control": "public, max-age=3600, must-revalidate",
|
||||
},
|
||||
});
|
||||
|
||||
Reference in new issue
Block a user