Files
SnapOtter/apps/api/src/routes/branding.ts
T
Siddharth Kumar Sah cc8a27239b fix: complete RBAC implementation lost during merge
Several RBAC features from feat/rbac-permissions were silently lost
during the merge into main. This restores and completes them:

- Add permissions and teamName to login/session API responses
- Export Permission and Role types from shared package
- Filter settings tabs by user permissions in frontend
- Extend useAuth hook with role, permissions, and hasPermission
- Restrict teams listing to admin only
- Add admin override for API keys, files, and pipelines listing
- Add ownership scoping to file access, download, and delete routes
- Register userFileRoutes in integration test server
- Mock auth import in unit permissions test to avoid SQLite lock
2026-04-10 21:25:30 +08:00

103 lines
3.3 KiB
TypeScript

/**
* Branding routes — custom logo upload, serving, and deletion.
*
* POST /api/v1/settings/logo — Upload logo (admin only)
* GET /api/v1/settings/logo — Serve custom logo as PNG (public)
* DELETE /api/v1/settings/logo — Remove custom logo (admin only)
*/
import { existsSync, mkdirSync, readFileSync, unlinkSync, writeFileSync } from "node:fs";
import { join } from "node:path";
import { eq } from "drizzle-orm";
import type { FastifyInstance, FastifyReply, FastifyRequest } from "fastify";
import sharp from "sharp";
import { db, schema } from "../db/index.js";
import { requireAdmin } from "../plugins/auth.js";
const BRANDING_DIR = join(process.cwd(), "data", "branding");
const LOGO_PATH = join(BRANDING_DIR, "logo.png");
const MAX_LOGO_SIZE = 500 * 1024; // 500 KB
function upsertSetting(key: string, value: string): void {
const existing = db.select().from(schema.settings).where(eq(schema.settings.key, key)).get();
if (existing) {
db.update(schema.settings)
.set({ value, updatedAt: new Date() })
.where(eq(schema.settings.key, key))
.run();
} else {
db.insert(schema.settings).values({ key, value }).run();
}
}
export async function brandingRoutes(app: FastifyInstance): Promise<void> {
// POST /api/v1/settings/logo — Upload logo (admin only)
app.post("/api/v1/settings/logo", async (request: FastifyRequest, reply: FastifyReply) => {
const admin = requireAdmin(request, reply);
if (!admin) return;
const file = await request.file();
if (!file) {
return reply.status(400).send({ error: "No file uploaded", code: "VALIDATION_ERROR" });
}
// Validate mimetype
if (!file.mimetype.startsWith("image/")) {
return reply.status(400).send({ error: "File must be an image", code: "VALIDATION_ERROR" });
}
// Read file buffer
const buffer = await file.toBuffer();
// Validate size
if (buffer.length > MAX_LOGO_SIZE) {
return reply
.status(400)
.send({ error: "Logo must be 500KB or smaller", code: "VALIDATION_ERROR" });
}
// Convert to PNG, resize to max 128x128
const pngBuffer = await sharp(buffer)
.resize(128, 128, { fit: "inside", withoutEnlargement: true })
.png()
.toBuffer();
// Ensure branding directory exists
mkdirSync(BRANDING_DIR, { recursive: true });
// Write file
writeFileSync(LOGO_PATH, pngBuffer);
// Upsert setting
upsertSetting("customLogo", "true");
return reply.send({ ok: true });
});
// GET /api/v1/settings/logo — Serve logo (public, no auth required)
app.get("/api/v1/settings/logo", async (_request: FastifyRequest, reply: FastifyReply) => {
if (!existsSync(LOGO_PATH)) {
return reply.status(404).send({ error: "No custom logo set", code: "NOT_FOUND" });
}
const logoBuffer = readFileSync(LOGO_PATH);
return reply.type("image/png").send(logoBuffer);
});
// DELETE /api/v1/settings/logo — Remove logo (admin only)
app.delete("/api/v1/settings/logo", async (request: FastifyRequest, reply: FastifyReply) => {
const admin = requireAdmin(request, reply);
if (!admin) return;
if (existsSync(LOGO_PATH)) {
unlinkSync(LOGO_PATH);
}
upsertSetting("customLogo", "false");
return reply.send({ ok: true });
});
app.log.info("Branding routes registered");
}