oss请求处理

This commit is contained in:
andy committed 2026-08-19 10:52:55 +08:00
1 parent 18cb51670c
commit a9a4cdf125
18 files changed
+450 -29

No files matched your search

+1 -1
View File
@@ -306,7 +306,7 @@ func New(options Options) (*App, error) {
}
webhookBridge := orchestration.NewWebhookBridge(webhook.NewDeliverer(webhookSender, getenv("ZHINIAN_WEBHOOK_SECRET"), nil))
outputs := orchestration.NewAssetOutputRegistrar(assetService, orchestration.ResolveProviderOutputURLs)
providerProcessor := jobs.ProviderProcessor{Providers: providerResolver, Store: jobStore}
providerProcessor := jobs.ProviderProcessor{Providers: providerResolver, Store: jobStore, AssetURLs: assetService, AssetURLTTL: assets.MaximumSignedURLTTL}
settlementProcessor := orchestration.NewSettlementProcessor(providerProcessor, ledger, settlementState, nil)
processor := orchestration.NewOutputRegisteringProcessor(settlementProcessor, outputs, jobState)
artifacts := orchestration.NewAssetArtifacts(assetService)
+10 -1
View File
@@ -4,6 +4,7 @@ import (
"context"
"crypto/rand"
"encoding/hex"
"errors"
"fmt"
"io"
"net/http"
@@ -480,6 +481,14 @@ func (store prefixedBlobStore) Delete(ctx context.Context, key string) error {
return store.store.Delete(ctx, path.Join(store.prefix, key))
}
func (store prefixedBlobStore) SignReadURL(key string, ttl time.Duration) (string, error) {
signer, ok := store.store.(assets.BlobURLSigner)
if !ok {
return "", errors.New("blob store does not support signed URLs")
}
return signer.SignReadURL(path.Join(store.prefix, key), ttl)
}
func configuredOSSBlobStore(getenv postgres.Getenv) (assets.BlobStore, bool, error) {
endpoint, bucket := strings.TrimSpace(getenv("ALI_OSS_ENDPOINT")), strings.TrimSpace(getenv("ALI_OSS_BUCKET"))
accessKeyID, secret := strings.TrimSpace(getenv("ALI_OSS_ACCESS_KEY_ID")), strings.TrimSpace(getenv("ALI_OSS_ACCESS_KEY_SECRET"))
@@ -491,7 +500,7 @@ func configuredOSSBlobStore(getenv postgres.Getenv) (assets.BlobStore, bool, err
if err != nil {
return nil, false, err
}
store, err := assets.NewOSS(assets.OSSConfig{Endpoint: endpoint, Bucket: bucket, PublicBaseURL: publicURL, PublicRead: true}, client)
store, err := assets.NewOSS(assets.OSSConfig{Endpoint: endpoint, Bucket: bucket, PublicBaseURL: publicURL, PublicRead: false}, client)
if err != nil {
return nil, false, err
}
+39 -1
View File
@@ -12,6 +12,7 @@ import (
"reflect"
"strings"
"testing"
"time"
"git.nianxx.cn/wangxuming/NianAIGC/backend/internal/assets"
"git.nianxx.cn/wangxuming/NianAIGC/backend/internal/billing"
@@ -320,9 +321,42 @@ func TestPrefixedBlobStoreKeepsApplicationStoragePathStable(t *testing.T) {
if !reflect.DeepEqual([]string{inner.readKey, inner.deleteKey}, []string{"tenant-prefix/uploads/day/file.png", "tenant-prefix/uploads/day/file.png"}) {
t.Fatalf("read/delete=%q/%q", inner.readKey, inner.deleteKey)
}
if _, err := store.SignReadURL(stored.Key, time.Hour); err != nil || inner.signedKey != "tenant-prefix/uploads/day/file.png" || inner.signedTTL != time.Hour {
t.Fatalf("signed URL delegation = %q / %s, err=%v", inner.signedKey, inner.signedTTL, err)
}
}
type recordingBlobStore struct{ putKey, readKey, deleteKey string }
func TestConfiguredOSSBlobStoreDoesNotRequestPublicObjectACL(t *testing.T) {
var requests []string
server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, request *http.Request) {
requests = append(requests, request.Method+" "+request.URL.RequestURI())
w.WriteHeader(http.StatusOK)
}))
defer server.Close()
values := map[string]string{
"ALI_OSS_ENDPOINT": server.URL + "/private-bucket",
"ALI_OSS_BUCKET": "private-bucket",
"ALI_OSS_ACCESS_KEY_ID": "test-access-key",
"ALI_OSS_ACCESS_KEY_SECRET": "test-access-secret",
"ALI_OSS_PUBLIC_BASE_URL": server.URL + "/private-bucket",
}
store, configured, err := configuredOSSBlobStore(func(name string) string { return values[name] })
if err != nil || !configured {
t.Fatalf("configured store = %T, %v, configured=%v", store, err, configured)
}
if _, err := store.Put(context.Background(), "uploads/day/private.png", bytes.NewReader([]byte("png")), 3, "image/png"); err != nil {
t.Fatal(err)
}
if !reflect.DeepEqual(requests, []string{"PUT /private-bucket/zhinian/uploads/day/private.png"}) {
t.Fatalf("OSS requests = %#v, want one private PutObject request", requests)
}
}
type recordingBlobStore struct {
putKey, readKey, deleteKey, signedKey string
signedTTL time.Duration
}
type applicationRuntimeSettingsRepository struct {
values map[string]string
@@ -360,3 +394,7 @@ func (s *recordingBlobStore) Delete(_ context.Context, key string) error {
s.deleteKey = key
return nil
}
func (s *recordingBlobStore) SignReadURL(key string, ttl time.Duration) (string, error) {
s.signedKey, s.signedTTL = key, ttl
return "https://signed.example/" + key, nil
}