fix: link old
This commit is contained in:
@@ -0,0 +1,30 @@
|
||||
<?php
|
||||
|
||||
namespace App\Http\Controllers\Hooks;
|
||||
|
||||
use App\Http\Controllers\Controller;
|
||||
use App\Models\Photo;
|
||||
use App\Services\PhotoOrigin;
|
||||
use Illuminate\Http\Request;
|
||||
use Illuminate\Support\Facades\Storage;
|
||||
use Symfony\Component\HttpFoundation\Response;
|
||||
|
||||
class PhotoOriginController extends Controller
|
||||
{
|
||||
public function __invoke(Request $request, Photo $photo, PhotoOrigin $origin): Response
|
||||
{
|
||||
$token = $request->header('X-Photo-Origin-Token', $request->query('token'));
|
||||
abort_unless($origin->serveEnabled() && $origin->tokenMatches(is_string($token) ? $token : null), 401);
|
||||
|
||||
$path = trim((string) $photo->path);
|
||||
abort_unless($origin->isSafeRelPath($path), 404);
|
||||
abort_unless(Storage::disk('local')->exists($path), 404);
|
||||
|
||||
$abs = Storage::disk('local')->path($path);
|
||||
$mime = @mime_content_type($abs) ?: 'application/octet-stream';
|
||||
|
||||
return response((string) file_get_contents($abs), 200)
|
||||
->header('Content-Type', $mime)
|
||||
->header('X-Photo-Origin', 'local');
|
||||
}
|
||||
}
|
||||
@@ -7,47 +7,80 @@ use App\Services\Tokenview\TokenviewMonitorService;
|
||||
use Illuminate\Http\Request;
|
||||
use Illuminate\Http\Response;
|
||||
use Illuminate\Support\Facades\Log;
|
||||
use Throwable;
|
||||
|
||||
class TokenviewWebhookController extends Controller
|
||||
{
|
||||
public function __invoke(Request $request, TokenviewMonitorService $monitor): Response
|
||||
{
|
||||
$log = Log::channel('tokenview');
|
||||
$raw = $request->getContent();
|
||||
$signature = $request->header('X-Tokenview-Signature');
|
||||
try {
|
||||
$raw = $request->getContent();
|
||||
$signature = $request->header('X-Tokenview-Signature');
|
||||
$payload = $this->decodePayload($request, $raw);
|
||||
|
||||
$payload = $request->json()->all();
|
||||
if (! is_array($payload) || $payload === []) {
|
||||
$decoded = json_decode($raw, true);
|
||||
$payload = is_array($decoded) ? $decoded : [];
|
||||
}
|
||||
|
||||
$log->info('tokenview webhook received', [
|
||||
'ip' => $request->ip(),
|
||||
'method' => $request->method(),
|
||||
'has_signature' => is_string($signature) && $signature !== '',
|
||||
'body_bytes' => strlen($raw),
|
||||
'payload' => $payload !== [] ? $payload : $raw,
|
||||
]);
|
||||
|
||||
// Tokenview probes the webhook (often unsigned GET/POST) before a
|
||||
// sign key exists. Always 200 + non-empty body; only skip ingest.
|
||||
$signed = $monitor->verifySignature($raw, $signature);
|
||||
if (! $signed) {
|
||||
$log->warning('tokenview webhook bad signature (acked 200, skipped ingest)', [
|
||||
$this->tvLog('info', 'tokenview webhook received', [
|
||||
'ip' => $request->ip(),
|
||||
'method' => $request->method(),
|
||||
'has_signature' => is_string($signature) && $signature !== '',
|
||||
'body_bytes' => strlen($raw),
|
||||
'payload' => $payload !== [] ? $payload : $raw,
|
||||
]);
|
||||
} elseif ($payload !== []) {
|
||||
try {
|
||||
$monitor->handleWebhook($payload);
|
||||
} catch (\Throwable $e) {
|
||||
$log->warning('tokenview webhook handle failed: '.$e->getMessage(), [
|
||||
'exception' => $e::class,
|
||||
|
||||
// Tokenview probes the webhook (often unsigned GET/POST) before a
|
||||
// sign key exists. Always 200 + non-empty body; only skip ingest.
|
||||
$signed = $monitor->verifySignature($raw, $signature);
|
||||
if (! $signed) {
|
||||
$this->tvLog('warning', 'tokenview webhook bad signature (acked 200, skipped ingest)', [
|
||||
'ip' => $request->ip(),
|
||||
'body_bytes' => strlen($raw),
|
||||
]);
|
||||
} elseif ($payload !== []) {
|
||||
try {
|
||||
$monitor->handleWebhook($payload);
|
||||
} catch (Throwable $e) {
|
||||
$this->tvLog('warning', 'tokenview webhook handle failed: '.$e->getMessage(), [
|
||||
'exception' => $e::class,
|
||||
]);
|
||||
}
|
||||
}
|
||||
} catch (Throwable $e) {
|
||||
$this->tvLog('warning', 'tokenview webhook crashed: '.$e->getMessage(), [
|
||||
'exception' => $e::class,
|
||||
]);
|
||||
}
|
||||
|
||||
return response('ok', 200)->header('Content-Type', 'text/plain; charset=UTF-8');
|
||||
}
|
||||
|
||||
/**
|
||||
* @return array<string, mixed>
|
||||
*/
|
||||
private function decodePayload(Request $request, string $raw): array
|
||||
{
|
||||
try {
|
||||
$payload = $request->json()->all();
|
||||
if (is_array($payload) && $payload !== []) {
|
||||
return $payload;
|
||||
}
|
||||
} catch (Throwable) {
|
||||
}
|
||||
|
||||
$decoded = json_decode($raw, true);
|
||||
|
||||
return is_array($decoded) ? $decoded : [];
|
||||
}
|
||||
|
||||
/** @param array<string, mixed> $context */
|
||||
private function tvLog(string $level, string $message, array $context = []): void
|
||||
{
|
||||
try {
|
||||
$dir = storage_path('logs/tokenview');
|
||||
if (! is_dir($dir)) {
|
||||
@mkdir($dir, 0775, true);
|
||||
}
|
||||
Log::channel('tokenview')->{$level}($message, $context);
|
||||
} catch (Throwable $e) {
|
||||
Log::warning($message, $context + ['tokenview_channel_error' => $e->getMessage()]);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user