31 lines
1.0 KiB
PHP
31 lines
1.0 KiB
PHP
<?php
|
|
|
|
namespace App\Http\Controllers\Hooks;
|
|
|
|
use App\Http\Controllers\Controller;
|
|
use App\Models\Photo;
|
|
use App\Services\PhotoOrigin;
|
|
use Illuminate\Http\Request;
|
|
use Illuminate\Support\Facades\Storage;
|
|
use Symfony\Component\HttpFoundation\Response;
|
|
|
|
class PhotoOriginController extends Controller
|
|
{
|
|
public function __invoke(Request $request, Photo $photo, PhotoOrigin $origin): Response
|
|
{
|
|
$token = $request->header('X-Photo-Origin-Token', $request->query('token'));
|
|
abort_unless($origin->serveEnabled() && $origin->tokenMatches(is_string($token) ? $token : null), 401);
|
|
|
|
$path = trim((string) $photo->path);
|
|
abort_unless($origin->isSafeRelPath($path), 404);
|
|
abort_unless(Storage::disk('local')->exists($path), 404);
|
|
|
|
$abs = Storage::disk('local')->path($path);
|
|
$mime = @mime_content_type($abs) ?: 'application/octet-stream';
|
|
|
|
return response((string) file_get_contents($abs), 200)
|
|
->header('Content-Type', $mime)
|
|
->header('X-Photo-Origin', 'local');
|
|
}
|
|
}
|