Files
docuseal/app/controllers/api/active_storage_blobs_proxy_controller.rb
T

70 lines
2.1 KiB
Ruby
Raw Normal View History

2024-02-18 11:26:30 +02:00
# frozen_string_literal: true
module Api
class ActiveStorageBlobsProxyController < ApiBaseController
include ActiveStorage::Streaming
skip_before_action :authenticate_user!
skip_authorization_check
2024-02-20 18:24:57 +02:00
before_action :set_cors_headers
2024-04-20 15:47:48 +03:00
before_action :set_noindex_headers
2024-02-20 18:24:57 +02:00
2024-02-18 11:26:30 +02:00
def show
2024-02-25 02:00:18 +02:00
blob_uuid, purp, exp = ApplicationRecord.signed_id_verifier.verified(params[:signed_uuid])
2024-02-18 11:26:30 +02:00
2025-08-31 16:40:18 +03:00
if blob_uuid.blank? || purp != 'blob'
2024-02-19 17:07:37 +02:00
Rollbar.error('Blob not found') if defined?(Rollbar)
return head :not_found
end
2024-02-18 11:26:30 +02:00
blob = ActiveStorage::Blob.find_by!(uuid: blob_uuid)
2025-05-03 13:59:15 +03:00
attachment = blob.attachments.take
@record = attachment.record
2025-08-31 16:40:18 +03:00
@record = @record.record if @record.is_a?(ActiveStorage::Attachment)
2025-05-03 13:59:15 +03:00
2025-08-31 16:40:18 +03:00
authorization_check!(attachment, @record, exp)
2024-04-15 19:58:24 +03:00
2024-02-18 11:26:30 +02:00
if request.headers['Range'].present?
send_blob_byte_range_data blob, request.headers['Range']
else
http_cache_forever public: true do
response.headers['Accept-Ranges'] = 'bytes'
2026-04-30 17:43:42 +03:00
if request.head?
response.headers['Content-Type'] = blob.content_type_for_serving
head :ok
else
send_blob_stream blob, disposition: params[:disposition]
end
response.headers['Content-Length'] = blob.byte_size.to_s
2024-02-18 11:26:30 +02:00
end
end
end
2024-04-15 19:58:24 +03:00
private
2025-08-31 16:40:18 +03:00
def authorization_check!(attachment, record, exp)
return if attachment.name == 'logo'
return if exp.to_i >= Time.current.to_i
return if current_user && current_ability.can?(:read, record)
2025-09-01 13:36:55 +03:00
if exp.blank?
configs = record.account.account_configs.where(key: [AccountConfig::DOWNLOAD_LINKS_AUTH_KEY,
AccountConfig::DOWNLOAD_LINKS_EXPIRE_KEY])
2025-08-31 16:40:18 +03:00
2025-09-01 13:36:55 +03:00
require_auth = configs.any? { |c| c.key == AccountConfig::DOWNLOAD_LINKS_AUTH_KEY && c.value }
require_ttl = configs.none? { |c| c.key == AccountConfig::DOWNLOAD_LINKS_EXPIRE_KEY && c.value == false }
2025-08-31 16:40:18 +03:00
2025-09-01 13:36:55 +03:00
return if !require_ttl && !require_auth
end
2024-04-15 19:58:24 +03:00
raise CanCan::AccessDenied
end
2024-02-18 11:26:30 +02:00
end
end