mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
Media uploads now carry upload attribution so operators and out-of-band consumers can attribute any stored object without relay internals: - S3 object metadata on the blob and thumbnail PUTs: x-amz-meta-buzz-uploader-id (authenticated Blossom uploader pubkey, hex) and x-amz-meta-buzz-community-id (host-resolved community UUID), readable from a bare HEAD on the object. - The same fields on the BlobMeta sidecar (uploader_id / community_id), nullable with serde defaults so older sidecars still parse. The community always comes from the server-resolved TenantContext (row-zero host binding), never from client input. All three upload paths are covered: image, generic file, and streaming video (the video path attaches metadata via bucket extra_headers so it survives multipart uploads). Note: blobs are shared content-addressed storage across communities, so a re-upload of identical bytes under another tenant overwrites the object metadata with the most recent uploader; the community-scoped sidecar remains the authoritative per-tenant record.