oss请求处理

This commit is contained in:
andy committed 2026-08-19 10:52:55 +08:00
1 parent 18cb51670c
commit a9a4cdf125
18 files changed
+450 -29

No files matched your search

+49
View File
@@ -126,6 +126,9 @@ type BlobStore interface {
Read(context.Context, string) (Blob, error)
Delete(context.Context, string) error
}
type BlobURLSigner interface {
SignReadURL(string, time.Duration) (string, error)
}
type RemoteFetcher interface {
Fetch(context.Context, string) (Blob, error)
}
@@ -364,6 +367,52 @@ func (s *Service) Download(ctx context.Context, scope Scope, id string) (Blob, e
return s.remote.Fetch(ctx, a.URL)
}
// SignedDownloadURL returns a short-lived direct URL only when the configured
// blob store supports it. Callers can otherwise fall back to Download without
// exposing storage credentials or assuming that every backend is OSS.
func (s *Service) SignedDownloadURL(ctx context.Context, scope Scope, id string, ttl time.Duration) (string, bool, error) {
a, err := s.Get(ctx, scope, id)
if err != nil {
return "", false, err
}
return s.signedDownloadURL(a, ttl)
}
func (s *Service) signedDownloadURL(a Asset, ttl time.Duration) (string, bool, error) {
if a.StoragePath == "" || s.blobs == nil {
return "", false, nil
}
signer, ok := s.blobs.(BlobURLSigner)
if !ok {
return "", false, nil
}
signed, err := signer.SignReadURL(a.StoragePath, ttl)
if err != nil {
return "", false, err
}
return signed, true, nil
}
// ResolveProviderAssetURL implements the jobs package's narrow resolver seam
// without importing jobs. The stable source URL is used only to replace the
// matching value in a transient provider request; the signed URL is never
// persisted in the asset catalog or job payload.
func (s *Service) ResolveProviderAssetURL(ctx context.Context, ownerID, id string, ttl time.Duration) (string, string, error) {
scope := PlatformScope(ownerID)
a, err := s.Get(ctx, scope, id)
if err != nil {
return "", "", err
}
signed, ok, err := s.signedDownloadURL(a, ttl)
if err != nil {
return "", "", err
}
if ok {
return a.URL, signed, nil
}
return a.URL, a.URL, nil
}
// DownloadPath serves a stored object only after its metadata has been found
// in the requesting owner's catalog. Catalogs that support HTTP file serving
// implement the optional storage-path lookup without widening other callers.