feat: update image upload API with user authentication and validation
This commit is contained in:
@@ -2,8 +2,12 @@ import type { NextApiRequest, NextApiResponse } from "next";
|
|||||||
import { PutObjectCommand, S3Client } from "@aws-sdk/client-s3";
|
import { PutObjectCommand, S3Client } from "@aws-sdk/client-s3";
|
||||||
import { getSignedUrl } from "@aws-sdk/s3-request-presigner";
|
import { getSignedUrl } from "@aws-sdk/s3-request-presigner";
|
||||||
|
|
||||||
|
import { createNextApiContext } from "@kan/api/trpc";
|
||||||
|
|
||||||
import { env } from "~/env";
|
import { env } from "~/env";
|
||||||
|
|
||||||
|
const allowedContentTypes = ["image/jpeg", "image/png"];
|
||||||
|
|
||||||
export default async function handler(
|
export default async function handler(
|
||||||
req: NextApiRequest,
|
req: NextApiRequest,
|
||||||
res: NextApiResponse,
|
res: NextApiResponse,
|
||||||
@@ -13,14 +17,37 @@ export default async function handler(
|
|||||||
}
|
}
|
||||||
|
|
||||||
try {
|
try {
|
||||||
const { filename, contentType } = req.body;
|
const { user } = await createNextApiContext(req);
|
||||||
|
|
||||||
|
if (!user) {
|
||||||
|
return res.status(401).json({ error: "Unauthorized" });
|
||||||
|
}
|
||||||
|
|
||||||
|
const { filename, contentType } = req.body as {
|
||||||
|
filename: string;
|
||||||
|
contentType: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
// Specific to avatar uploads for now
|
||||||
|
const filenameRegex = /^[a-f0-9\-]+\/[a-zA-Z0-9_\-]+(\.jpg|\.jpeg|\.png)$/;
|
||||||
|
|
||||||
|
if (!filenameRegex.test(filename)) {
|
||||||
|
return res.status(400).json({ error: "Invalid filename" });
|
||||||
|
}
|
||||||
|
|
||||||
|
if (
|
||||||
|
typeof contentType !== "string" ||
|
||||||
|
!allowedContentTypes.includes(contentType)
|
||||||
|
) {
|
||||||
|
return res.status(400).json({ error: "Invalid content type" });
|
||||||
|
}
|
||||||
|
|
||||||
const client = new S3Client({
|
const client = new S3Client({
|
||||||
region: env.S3_REGION,
|
region: env.S3_REGION ?? "",
|
||||||
endpoint: env.S3_ENDPOINT,
|
endpoint: env.S3_ENDPOINT ?? "",
|
||||||
credentials: {
|
credentials: {
|
||||||
accessKeyId: env.S3_ACCESS_KEY_ID,
|
accessKeyId: env.S3_ACCESS_KEY_ID ?? "",
|
||||||
secretAccessKey: env.S3_SECRET_ACCESS_KEY,
|
secretAccessKey: env.S3_SECRET_ACCESS_KEY ?? "",
|
||||||
},
|
},
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user