fix(imaging): keep avatars rendering, cacheable and reliably timed
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m40s
CI / tests-unit (push) Successful in 1m51s
CI / tests-ui (push) Successful in 2m43s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m10s
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m40s
CI / tests-unit (push) Successful in 1m51s
CI / tests-ui (push) Successful in 2m43s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m10s
Effect renders need a little over 4s, which the 4s primary timeout cut off, so every avatar with the default effect fell through to an unreachable public fallback and rendered as a placeholder. Raise the primary budget above the observed render cost and shorten the fallback budget. Also stop the proxy from stamping no-store over the avatar and media responses, so browsers keep the long-lived Cache-Control the route already sends, and recreate the imaging cache directories with the container user on every deploy, since root ownership made those cache writes fail silently.
This commit is contained in:
1 parent
8486ac4053
commit
fe5a7a6185
6 files changed
+66
-8
No files matched your search
+12
-5
@@ -3,7 +3,10 @@ import { getToken } from "next-auth/jwt";
|
||||
import { env } from "@/env";
|
||||
import { buildContentSecurityPolicy, createCspNonce } from "@/lib/csp";
|
||||
import { ddosReject, enforceDdosRateLimit } from "@/lib/ddos-guard";
|
||||
import { shouldRedirectAdminRequest } from "@/lib/proxy-access";
|
||||
import {
|
||||
isCacheableAssetPath,
|
||||
shouldRedirectAdminRequest,
|
||||
} from "@/lib/proxy-access";
|
||||
|
||||
const SECURITY_HEADERS: Record<string, string> = {
|
||||
"X-Content-Type-Options": "nosniff",
|
||||
@@ -56,10 +59,14 @@ export const proxy = async (req: import("next/server").NextRequest) => {
|
||||
// always references the current build's chunks. Static assets are
|
||||
// content-hashed + immutable and can be cached aggressively; a stale HTML
|
||||
// document would reference chunk URLs that no longer exist after a rebuild.
|
||||
response.headers.set(
|
||||
"Cache-Control",
|
||||
"private, no-cache, no-store, max-age=0, must-revalidate",
|
||||
);
|
||||
// Rendered avatars and uploaded media are immutable per key and already
|
||||
// carry their own long-lived Cache-Control, so they keep it here.
|
||||
if (!isCacheableAssetPath(pathname)) {
|
||||
response.headers.set(
|
||||
"Cache-Control",
|
||||
"private, no-cache, no-store, max-age=0, must-revalidate",
|
||||
);
|
||||
}
|
||||
|
||||
for (const [key, value] of Object.entries(SECURITY_HEADERS)) {
|
||||
response.headers.set(key, value);
|
||||
|
||||
Reference in new issue
Block a user