29c9014a33
Replaces the multipart-via-API path for image uploads with a three-step
direct-to-storage flow:
1. Client POSTs /api/uploads/presign with content_length + content_type;
server validates size (10 MB cap), mime allow-list per category, rate
limit (50/hour/user via Redis sliding window), and concurrent unclaimed
cap (10 in-flight per user). On success it persists a pending_uploads
row, signs an S3 POST policy with content-length-range bound to the
claimed length ±256 bytes, and returns the URL+fields.
2. Client POSTs the bytes directly to B2 using the signed policy. B2
enforces size, content-type, and key match before accepting.
3. Client passes upload_ids[] to /api/task-completions/ or /api/documents/.
Service HEADs each B2 object, verifies size matches expected_bytes
within slack, marks pending_uploads claimed_at, and creates the
associated TaskCompletionImage / DocumentImage rows.
Bytes never traverse our API server. The 1 MB Echo BodyLimit middleware
that was rejecting all task-completion image uploads becomes irrelevant
for this path. Existing multipart endpoints stay functional alongside,
soak-testing the new path before legacy removal.
Cleanup:
- cmd/worker registers a new hourly cron (TypeUploadCleanup, "30 * * * *")
that reaps pending_uploads where claimed_at IS NULL AND expires_at < NOW().
Reaps both the B2 object and the row.
- B2 bucket lifecycle rule on `uploads/` prefix (7 days hide → 1 day delete)
documented in deploy-k3s/manifests/b2-lifecycle.md as a backstop.
Schema:
- migrations/000002_pending_uploads.sql adds the table + partial index for
cleanup + nullable pending_upload_id FKs on task_taskcompletionimage and
task_documentimage.
Policy (single tier, no free/pro split):
- 10 MB cap per upload
- 50 presigns/hour/user
- 10 concurrent unclaimed uploads/user
- allow-list: jpeg/png/heic/heif/webp for image categories;
+ pdf for document_file
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
54 lines
3.1 KiB
Go
54 lines
3.1 KiB
Go
package requests
|
|
|
|
import (
|
|
"time"
|
|
|
|
"github.com/shopspring/decimal"
|
|
|
|
"github.com/treytartt/honeydue-api/internal/models"
|
|
)
|
|
|
|
// CreateDocumentRequest represents the request to create a document
|
|
type CreateDocumentRequest struct {
|
|
ResidenceID uint `json:"residence_id" validate:"required"`
|
|
Title string `json:"title" validate:"required,min=1,max=200"`
|
|
Description string `json:"description" validate:"max=10000"`
|
|
DocumentType models.DocumentType `json:"document_type" validate:"omitempty,oneof=general warranty receipt contract insurance manual"`
|
|
FileURL string `json:"file_url" validate:"max=500"`
|
|
FileName string `json:"file_name" validate:"max=255"`
|
|
FileSize *int64 `json:"file_size" validate:"omitempty,min=0"`
|
|
MimeType string `json:"mime_type" validate:"max=100"`
|
|
PurchaseDate *time.Time `json:"purchase_date"`
|
|
ExpiryDate *time.Time `json:"expiry_date"`
|
|
PurchasePrice *decimal.Decimal `json:"purchase_price"`
|
|
Vendor string `json:"vendor" validate:"max=200"`
|
|
SerialNumber string `json:"serial_number" validate:"max=100"`
|
|
ModelNumber string `json:"model_number" validate:"max=100"`
|
|
TaskID *uint `json:"task_id"`
|
|
ImageURLs []string `json:"image_urls" validate:"omitempty,max=20,dive,max=500"` // Legacy multipart upload path
|
|
// UploadIDs claims pending_uploads rows produced by the presigned-URL
|
|
// upload flow and turns them into document_image rows. May be combined
|
|
// with ImageURLs during the rollout window. UploadIDs of category
|
|
// "document_file" attach to the document's main FileURL/FileName fields
|
|
// instead — the service infers placement from the row's category.
|
|
UploadIDs []uint `json:"upload_ids" validate:"omitempty,max=20"`
|
|
}
|
|
|
|
// UpdateDocumentRequest represents the request to update a document
|
|
type UpdateDocumentRequest struct {
|
|
Title *string `json:"title" validate:"omitempty,min=1,max=200"`
|
|
Description *string `json:"description" validate:"omitempty,max=10000"`
|
|
DocumentType *models.DocumentType `json:"document_type" validate:"omitempty,oneof=general warranty receipt contract insurance manual"`
|
|
FileURL *string `json:"file_url" validate:"omitempty,max=500"`
|
|
FileName *string `json:"file_name" validate:"omitempty,max=255"`
|
|
FileSize *int64 `json:"file_size" validate:"omitempty,min=0"`
|
|
MimeType *string `json:"mime_type" validate:"omitempty,max=100"`
|
|
PurchaseDate *time.Time `json:"purchase_date"`
|
|
ExpiryDate *time.Time `json:"expiry_date"`
|
|
PurchasePrice *decimal.Decimal `json:"purchase_price"`
|
|
Vendor *string `json:"vendor" validate:"omitempty,max=200"`
|
|
SerialNumber *string `json:"serial_number" validate:"omitempty,max=100"`
|
|
ModelNumber *string `json:"model_number" validate:"omitempty,max=100"`
|
|
TaskID *uint `json:"task_id"`
|
|
}
|