mirror of
https://github.com/bewcloud/bewcloud.git
synced 2026-03-11 08:54:49 +00:00
This allows not enabling Dashboard and Files. It also sorts the apps in the menu according to the order in the `config.core.enabledApps` array. Since this will require a major version upgrade (`v3.0.0`), I also took the opportunity to upgrade PostgreSQL. You can [follow this guide on how to upgrade PostgreSQL on Docker containers](https://news.onbrn.com/step-by-step-guide-upgrading-postgresql-docker-containers/). Finally, this has some minor security improvements (confirming API endpoints won't work if their app is disabled in the config). Closes #114 Closes #108
53 lines
1.9 KiB
TypeScript
53 lines
1.9 KiB
TypeScript
import { Handlers } from 'fresh/server.ts';
|
|
|
|
import { Directory, DirectoryFile, FreshContextState } from '/lib/types.ts';
|
|
import { DirectoryModel, FileModel } from '/lib/models/files.ts';
|
|
import { AppConfig } from '/lib/config.ts';
|
|
|
|
interface Data {}
|
|
|
|
export interface ResponseBody {
|
|
success: boolean;
|
|
newFiles: DirectoryFile[];
|
|
newDirectories: Directory[];
|
|
}
|
|
|
|
export const handler: Handlers<Data, FreshContextState> = {
|
|
async POST(request, context) {
|
|
if (!context.state.user) {
|
|
return new Response('Unauthorized', { status: 401 });
|
|
}
|
|
|
|
if (
|
|
!(await AppConfig.isAppEnabled('files')) && !(await AppConfig.isAppEnabled('photos')) &&
|
|
!(await AppConfig.isAppEnabled('notes'))
|
|
) {
|
|
return new Response('Forbidden', { status: 403 });
|
|
}
|
|
|
|
const requestBody = await request.clone().formData();
|
|
|
|
const pathInView = requestBody.get('path_in_view') as string;
|
|
const parentPath = requestBody.get('parent_path') as string;
|
|
const name = requestBody.get('name') as string;
|
|
const contents = requestBody.get('contents') as File | string;
|
|
|
|
if (
|
|
!parentPath || !pathInView || !name.trim() || !contents || !parentPath.startsWith('/') ||
|
|
parentPath.includes('../') || !pathInView.startsWith('/') || pathInView.includes('../')
|
|
) {
|
|
return new Response('Bad Request', { status: 400 });
|
|
}
|
|
|
|
const fileContents = typeof contents === 'string' ? contents : await contents.arrayBuffer();
|
|
|
|
const createdFile = await FileModel.create(context.state.user.id, parentPath, name.trim(), fileContents);
|
|
|
|
const newFiles = await FileModel.list(context.state.user.id, pathInView);
|
|
const newDirectories = await DirectoryModel.list(context.state.user.id, pathInView);
|
|
|
|
const responseBody: ResponseBody = { success: createdFile, newFiles, newDirectories };
|
|
|
|
return new Response(JSON.stringify(responseBody));
|
|
},
|
|
};
|