mirror of
https://github.com/yusufipk/OpenFrame.git
synced 2026-09-11 09:36:08 +00:00
feat: enable S3 video uploads and update related configurations
- Added support for self-hosted S3 video uploads with new environment variables: OPENFRAME_ENABLE_S3_VIDEO_UPLOADS and OPENFRAME_MAX_VIDEO_UPLOAD_BYTES. - Updated .env.example and .env.docker.example to reflect new configuration options. - Enhanced Content Security Policy to include origins for S3-compatible storage. - Updated dependencies for AWS SDK to support new features. - Refactored upload logic to accommodate both Bunny and S3 upload providers. - Updated documentation to clarify the usage of direct uploads and S3 configurations. - Closes #11
This commit is contained in:
@@ -91,3 +91,32 @@ export function validateOptionalUrl(
|
||||
|
||||
return validateUrl(urlString, fieldName);
|
||||
}
|
||||
|
||||
const SAFE_APP_RELATIVE_PATH =
|
||||
/^\/(?:api\/upload\/(?:image|audio|video)\/[0-9a-f-]{36}\.[a-z0-9]+|placeholder-video-thumbnail\.png)$/i;
|
||||
|
||||
export function isSafeAppRelativePath(path: string): boolean {
|
||||
if (!path.startsWith('/') || path.includes('..')) {
|
||||
return false;
|
||||
}
|
||||
|
||||
return SAFE_APP_RELATIVE_PATH.test(path);
|
||||
}
|
||||
|
||||
/**
|
||||
* Accepts optional absolute http(s) URLs or safe same-origin app paths (upload proxy, placeholders).
|
||||
*/
|
||||
export function validateOptionalUrlOrAppPath(
|
||||
urlString: string | null | undefined,
|
||||
fieldName: string = 'URL'
|
||||
): string | null {
|
||||
if (!urlString) {
|
||||
return null;
|
||||
}
|
||||
|
||||
if (isSafeAppRelativePath(urlString)) {
|
||||
return null;
|
||||
}
|
||||
|
||||
return validateOptionalUrl(urlString, fieldName);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user