위임 관리자(부관리자)가 권한·역할·표현식·비밀 콘텐츠 경계를 우회하던 결함군을 계층 대칭성 원칙으로 전건 차단한다. 약한 경로가 정상 응답을 내보내는 것이 유일한 증상이라, 게이트를 생산 지점 한 곳(SSoT)에 두고 같은 데이터를 내보내는 소비 경로 전부가 그 게이트를 경유하도록 맞췄다. - 등급 상한(rank ceiling): 슈퍼관리자 보호·역할/사용자 역할 배정(추가·제거 대칭)·일괄 상태변경·순서변경을 상세 경로와 동일 강도로 재적용. 가드는 DB 쓰기에 선행하여 거부 시 상태 불변. - 레이아웃 표현식: new Function/with 실행을 AST 화이트리스트 평가기로 교체. 비-문자열 computed 키 정규화(normalizeKey)·Object facade(리플렉션 static 제거)·legacy 접근자 차단. 저장측 검증·정적 검사와 3계층 동형. - secret 게이트: 비밀글의 댓글·첨부·문의 독립 경로 재적용, hash 파일서빙 소유권·비밀·발행 상태 검사 통일. - 신뢰 스크립트 호스트: 확장 선언 기반 + same-origin 브라우저 정규화를 런타임·저장측·정적검사 3층 동형화. - 회귀 감지: 단위·Feature·E2E·시나리오 매니페스트 전축 + audit 룰 4종 신설.
139 lines
4.8 KiB
PHP
139 lines
4.8 KiB
PHP
<?php
|
|
|
|
namespace App\Http\Controllers\Api\Admin;
|
|
|
|
use App\Enums\AttachmentSourceType;
|
|
use App\Http\Controllers\Api\Base\AdminBaseController;
|
|
use App\Http\Requests\Attachment\ReorderAttachmentsRequest;
|
|
use App\Http\Requests\Attachment\UploadAttachmentRequest;
|
|
use App\Http\Requests\Attachment\UploadBatchAttachmentRequest;
|
|
use App\Http\Resources\AttachmentResource;
|
|
use App\Models\Attachment;
|
|
use App\Services\AttachmentService;
|
|
use Exception;
|
|
use Illuminate\Auth\Access\AuthorizationException;
|
|
use Illuminate\Http\JsonResponse;
|
|
|
|
/**
|
|
* 관리자용 첨부파일 컨트롤러
|
|
*/
|
|
class AttachmentController extends AdminBaseController
|
|
{
|
|
/**
|
|
* AttachmentController 생성자
|
|
*
|
|
* @param AttachmentService $attachmentService 첨부파일 서비스
|
|
*/
|
|
public function __construct(
|
|
private AttachmentService $attachmentService
|
|
) {
|
|
parent::__construct();
|
|
}
|
|
|
|
/**
|
|
* 단일 파일 업로드
|
|
*
|
|
* @param UploadAttachmentRequest $request 업로드 요청
|
|
* @return JsonResponse
|
|
*/
|
|
public function upload(UploadAttachmentRequest $request): JsonResponse
|
|
{
|
|
try {
|
|
$validated = $request->validated();
|
|
|
|
$attachment = $this->attachmentService->upload(
|
|
file: $request->file('file'),
|
|
attachmentableType: $validated['attachmentable_type'] ?? null,
|
|
attachmentableId: $validated['attachmentable_id'] ?? null,
|
|
collection: $validated['collection'] ?? 'default',
|
|
sourceType: isset($validated['source_type'])
|
|
? AttachmentSourceType::from($validated['source_type'])
|
|
: AttachmentSourceType::Core,
|
|
sourceIdentifier: $validated['source_identifier'] ?? null,
|
|
);
|
|
|
|
return $this->successWithResource(
|
|
'attachment.upload_success',
|
|
new AttachmentResource($attachment),
|
|
201
|
|
);
|
|
} catch (Exception $e) {
|
|
return $this->error('attachment.upload_failed', 500, $e->getMessage());
|
|
}
|
|
}
|
|
|
|
/**
|
|
* 여러 파일 일괄 업로드
|
|
*
|
|
* @param UploadBatchAttachmentRequest $request 일괄 업로드 요청
|
|
* @return JsonResponse
|
|
*/
|
|
public function uploadBatch(UploadBatchAttachmentRequest $request): JsonResponse
|
|
{
|
|
try {
|
|
$validated = $request->validated();
|
|
|
|
$attachments = $this->attachmentService->uploadBatch(
|
|
files: $request->file('files'),
|
|
attachmentableType: $validated['attachmentable_type'] ?? null,
|
|
attachmentableId: $validated['attachmentable_id'] ?? null,
|
|
collection: $validated['collection'] ?? 'default',
|
|
sourceType: isset($validated['source_type'])
|
|
? AttachmentSourceType::from($validated['source_type'])
|
|
: AttachmentSourceType::Core,
|
|
sourceIdentifier: $validated['source_identifier'] ?? null,
|
|
);
|
|
|
|
return $this->successWithResource(
|
|
'attachment.upload_batch_success',
|
|
AttachmentResource::collection($attachments),
|
|
201
|
|
);
|
|
} catch (Exception $e) {
|
|
return $this->error('attachment.upload_failed', 500, $e->getMessage());
|
|
}
|
|
}
|
|
|
|
/**
|
|
* 첨부파일 삭제
|
|
*
|
|
* @param Attachment $attachment 첨부파일 (라우트 모델 바인딩)
|
|
* @return JsonResponse
|
|
*/
|
|
public function destroy(Attachment $attachment): JsonResponse
|
|
{
|
|
try {
|
|
$result = $this->attachmentService->delete($attachment->id);
|
|
|
|
if (! $result) {
|
|
return $this->error('attachment.delete_failed');
|
|
}
|
|
|
|
return $this->success('attachment.delete_success');
|
|
} catch (Exception $e) {
|
|
return $this->error('attachment.delete_failed', 500, $e->getMessage());
|
|
}
|
|
}
|
|
|
|
/**
|
|
* 순서 변경
|
|
*
|
|
* @param ReorderAttachmentsRequest $request 순서 변경 요청
|
|
* @return JsonResponse
|
|
*/
|
|
public function reorder(ReorderAttachmentsRequest $request): JsonResponse
|
|
{
|
|
try {
|
|
$this->attachmentService->reorder($request->input('order'));
|
|
|
|
return $this->success('attachment.reorder_success');
|
|
} catch (AuthorizationException $e) {
|
|
// 스코프 밖 첨부가 포함된 경우. 아래 제네릭 catch 보다 앞에 둬야 한다 —
|
|
// 뒤에 두면 인가 거부가 500 으로 뭉개져 상세 경로(403)와 응답이 갈린다.
|
|
return $this->error('auth.scope_denied', 403, $e->getMessage());
|
|
} catch (Exception $e) {
|
|
return $this->error('attachment.reorder_failed', 500, $e->getMessage());
|
|
}
|
|
}
|
|
}
|