diff --git a/app/api/upload/audio/[filename]/route.ts b/app/api/upload/audio/[filename]/route.ts index 9124286..03e2e29 100644 --- a/app/api/upload/audio/[filename]/route.ts +++ b/app/api/upload/audio/[filename]/route.ts @@ -39,38 +39,50 @@ export async function GET( // Parallelize the DB lookup and session check to narrow the timing delta // between "asset not found" and "asset found, access denied" responses. const voiceUrl = `/api/upload/audio/${filename}`; - const [comment, session] = await Promise.all([ - db.comment.findFirst({ + const projectSelect = { + id: true, + ownerId: true, + workspaceId: true, + visibility: true, + } as const; + const videoSelect = { + id: true, + projectId: true, + project: { select: projectSelect }, + } as const; + const [comments, videoAssets, session] = await Promise.all([ + db.comment.findMany({ where: { voiceUrl }, + take: 2, select: { version: { - select: { - video: { - select: { - id: true, - projectId: true, - project: { - select: { - id: true, - ownerId: true, - workspaceId: true, - visibility: true, - }, - }, - }, - }, - }, + select: { video: { select: videoSelect } }, }, }, }), + db.videoAsset.findMany({ + where: { sourceUrl: voiceUrl }, + take: 2, + select: { video: { select: videoSelect } }, + }), auth(), ]); - if (!comment) { + const uniqueVideos = new Map(); + comments.forEach((comment) => { + if (comment.version?.video) uniqueVideos.set(comment.version.video.id, comment.version.video); + }); + videoAssets.forEach((videoAsset) => uniqueVideos.set(videoAsset.video.id, videoAsset.video)); + + if (uniqueVideos.size > 1) { + return apiErrors.forbidden('Access denied'); + } + + const video = uniqueVideos.values().next().value ?? null; + if (!video) { return apiErrors.forbidden('Access denied'); } - const { video } = comment.version; const access = await checkProjectAccess(video.project, session?.user?.id); if (!access.hasAccess) { diff --git a/scripts/r2-orphan-cleanup.ts b/scripts/r2-orphan-cleanup.ts index 7b2adaf..c92bf0b 100644 --- a/scripts/r2-orphan-cleanup.ts +++ b/scripts/r2-orphan-cleanup.ts @@ -119,8 +119,10 @@ async function findReferencedUrls(urls: string[]): Promise> { }) : Promise.resolve([] as Array<{ url: string }>), db.videoAsset.findMany({ - where: { sourceUrl: { in: group } }, - select: { sourceUrl: true }, + where: { + OR: [{ sourceUrl: { in: group } }, { thumbnailUrl: { in: group } }], + }, + select: { sourceUrl: true, thumbnailUrl: true }, }), db.videoVersion.findMany({ where: { @@ -142,6 +144,7 @@ async function findReferencedUrls(urls: string[]): Promise> { } for (const row of assetRows) { if (row.sourceUrl) referenced.add(row.sourceUrl); + if (row.thumbnailUrl) referenced.add(row.thumbnailUrl); } for (const row of versionRows) { if (row.originalUrl) referenced.add(row.originalUrl);