oss请求处理
This commit is contained in:
1 parent
18cb51670c
commit
a9a4cdf125
18 files changed
+450
-29
No files matched your search
@@ -306,7 +306,7 @@ func New(options Options) (*App, error) {
|
||||
}
|
||||
webhookBridge := orchestration.NewWebhookBridge(webhook.NewDeliverer(webhookSender, getenv("ZHINIAN_WEBHOOK_SECRET"), nil))
|
||||
outputs := orchestration.NewAssetOutputRegistrar(assetService, orchestration.ResolveProviderOutputURLs)
|
||||
providerProcessor := jobs.ProviderProcessor{Providers: providerResolver, Store: jobStore}
|
||||
providerProcessor := jobs.ProviderProcessor{Providers: providerResolver, Store: jobStore, AssetURLs: assetService, AssetURLTTL: assets.MaximumSignedURLTTL}
|
||||
settlementProcessor := orchestration.NewSettlementProcessor(providerProcessor, ledger, settlementState, nil)
|
||||
processor := orchestration.NewOutputRegisteringProcessor(settlementProcessor, outputs, jobState)
|
||||
artifacts := orchestration.NewAssetArtifacts(assetService)
|
||||
|
||||
@@ -4,6 +4,7 @@ import (
|
||||
"context"
|
||||
"crypto/rand"
|
||||
"encoding/hex"
|
||||
"errors"
|
||||
"fmt"
|
||||
"io"
|
||||
"net/http"
|
||||
@@ -480,6 +481,14 @@ func (store prefixedBlobStore) Delete(ctx context.Context, key string) error {
|
||||
return store.store.Delete(ctx, path.Join(store.prefix, key))
|
||||
}
|
||||
|
||||
func (store prefixedBlobStore) SignReadURL(key string, ttl time.Duration) (string, error) {
|
||||
signer, ok := store.store.(assets.BlobURLSigner)
|
||||
if !ok {
|
||||
return "", errors.New("blob store does not support signed URLs")
|
||||
}
|
||||
return signer.SignReadURL(path.Join(store.prefix, key), ttl)
|
||||
}
|
||||
|
||||
func configuredOSSBlobStore(getenv postgres.Getenv) (assets.BlobStore, bool, error) {
|
||||
endpoint, bucket := strings.TrimSpace(getenv("ALI_OSS_ENDPOINT")), strings.TrimSpace(getenv("ALI_OSS_BUCKET"))
|
||||
accessKeyID, secret := strings.TrimSpace(getenv("ALI_OSS_ACCESS_KEY_ID")), strings.TrimSpace(getenv("ALI_OSS_ACCESS_KEY_SECRET"))
|
||||
@@ -491,7 +500,7 @@ func configuredOSSBlobStore(getenv postgres.Getenv) (assets.BlobStore, bool, err
|
||||
if err != nil {
|
||||
return nil, false, err
|
||||
}
|
||||
store, err := assets.NewOSS(assets.OSSConfig{Endpoint: endpoint, Bucket: bucket, PublicBaseURL: publicURL, PublicRead: true}, client)
|
||||
store, err := assets.NewOSS(assets.OSSConfig{Endpoint: endpoint, Bucket: bucket, PublicBaseURL: publicURL, PublicRead: false}, client)
|
||||
if err != nil {
|
||||
return nil, false, err
|
||||
}
|
||||
|
||||
@@ -12,6 +12,7 @@ import (
|
||||
"reflect"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"git.nianxx.cn/wangxuming/NianAIGC/backend/internal/assets"
|
||||
"git.nianxx.cn/wangxuming/NianAIGC/backend/internal/billing"
|
||||
@@ -320,9 +321,42 @@ func TestPrefixedBlobStoreKeepsApplicationStoragePathStable(t *testing.T) {
|
||||
if !reflect.DeepEqual([]string{inner.readKey, inner.deleteKey}, []string{"tenant-prefix/uploads/day/file.png", "tenant-prefix/uploads/day/file.png"}) {
|
||||
t.Fatalf("read/delete=%q/%q", inner.readKey, inner.deleteKey)
|
||||
}
|
||||
if _, err := store.SignReadURL(stored.Key, time.Hour); err != nil || inner.signedKey != "tenant-prefix/uploads/day/file.png" || inner.signedTTL != time.Hour {
|
||||
t.Fatalf("signed URL delegation = %q / %s, err=%v", inner.signedKey, inner.signedTTL, err)
|
||||
}
|
||||
}
|
||||
|
||||
type recordingBlobStore struct{ putKey, readKey, deleteKey string }
|
||||
func TestConfiguredOSSBlobStoreDoesNotRequestPublicObjectACL(t *testing.T) {
|
||||
var requests []string
|
||||
server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, request *http.Request) {
|
||||
requests = append(requests, request.Method+" "+request.URL.RequestURI())
|
||||
w.WriteHeader(http.StatusOK)
|
||||
}))
|
||||
defer server.Close()
|
||||
|
||||
values := map[string]string{
|
||||
"ALI_OSS_ENDPOINT": server.URL + "/private-bucket",
|
||||
"ALI_OSS_BUCKET": "private-bucket",
|
||||
"ALI_OSS_ACCESS_KEY_ID": "test-access-key",
|
||||
"ALI_OSS_ACCESS_KEY_SECRET": "test-access-secret",
|
||||
"ALI_OSS_PUBLIC_BASE_URL": server.URL + "/private-bucket",
|
||||
}
|
||||
store, configured, err := configuredOSSBlobStore(func(name string) string { return values[name] })
|
||||
if err != nil || !configured {
|
||||
t.Fatalf("configured store = %T, %v, configured=%v", store, err, configured)
|
||||
}
|
||||
if _, err := store.Put(context.Background(), "uploads/day/private.png", bytes.NewReader([]byte("png")), 3, "image/png"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if !reflect.DeepEqual(requests, []string{"PUT /private-bucket/zhinian/uploads/day/private.png"}) {
|
||||
t.Fatalf("OSS requests = %#v, want one private PutObject request", requests)
|
||||
}
|
||||
}
|
||||
|
||||
type recordingBlobStore struct {
|
||||
putKey, readKey, deleteKey, signedKey string
|
||||
signedTTL time.Duration
|
||||
}
|
||||
|
||||
type applicationRuntimeSettingsRepository struct {
|
||||
values map[string]string
|
||||
@@ -360,3 +394,7 @@ func (s *recordingBlobStore) Delete(_ context.Context, key string) error {
|
||||
s.deleteKey = key
|
||||
return nil
|
||||
}
|
||||
func (s *recordingBlobStore) SignReadURL(key string, ttl time.Duration) (string, error) {
|
||||
s.signedKey, s.signedTTL = key, ttl
|
||||
return "https://signed.example/" + key, nil
|
||||
}
|
||||
Reference in new issue
Block a user