Files
Gnuboard7/modules/_bundled/sirsoft-board/src/Http/Controllers/Admin/AttachmentController.php
T
HeuJung 71abdeaf60 fix(security): KVE-2026-1914/1915/1919 remediation 전건
위임 관리자(부관리자)가 권한·역할·표현식·비밀 콘텐츠 경계를 우회하던
결함군을 계층 대칭성 원칙으로 전건 차단한다. 약한 경로가 정상 응답을
내보내는 것이 유일한 증상이라, 게이트를 생산 지점 한 곳(SSoT)에 두고
같은 데이터를 내보내는 소비 경로 전부가 그 게이트를 경유하도록 맞췄다.

- 등급 상한(rank ceiling): 슈퍼관리자 보호·역할/사용자 역할 배정(추가·제거
 대칭)·일괄 상태변경·순서변경을 상세 경로와 동일 강도로 재적용. 가드는
 DB 쓰기에 선행하여 거부 시 상태 불변.
- 레이아웃 표현식: new Function/with 실행을 AST 화이트리스트 평가기로 교체.
 비-문자열 computed 키 정규화(normalizeKey)·Object facade(리플렉션 static
 제거)·legacy 접근자 차단. 저장측 검증·정적 검사와 3계층 동형.
- secret 게이트: 비밀글의 댓글·첨부·문의 독립 경로 재적용, hash 파일서빙
 소유권·비밀·발행 상태 검사 통일.
- 신뢰 스크립트 호스트: 확장 선언 기반 + same-origin 브라우저 정규화를
 런타임·저장측·정적검사 3층 동형화.
- 회귀 감지: 단위·Feature·E2E·시나리오 매니페스트 전축 + audit 룰 4종 신설.
2026-08-17 01:45:09 +09:00

203 lines
7.7 KiB
PHP

<?php
namespace Modules\Sirsoft\Board\Http\Controllers\Admin;
use App\Http\Controllers\Api\Base\AdminBaseController;
use Illuminate\Http\JsonResponse;
use Modules\Sirsoft\Board\Exceptions\AttachmentLimitExceededException;
use Modules\Sirsoft\Board\Exceptions\BoardNotFoundException;
use Modules\Sirsoft\Board\Http\Requests\ReorderAttachmentsRequest;
use Modules\Sirsoft\Board\Http\Requests\UploadAttachmentRequest;
use Modules\Sirsoft\Board\Services\AttachmentService;
use Modules\Sirsoft\Board\Services\BoardService;
use Modules\Sirsoft\Board\Traits\ChecksBoardPermission;
use Symfony\Component\HttpFoundation\StreamedResponse;
use Symfony\Component\HttpKernel\Exception\AccessDeniedHttpException;
/**
* 관리자용 게시판 첨부파일 컨트롤러
*
* 게시판별 동적 테이블을 사용하는 첨부파일 업로드, 삭제, 순서 변경 등을 처리합니다.
*/
class AttachmentController extends AdminBaseController
{
use ChecksBoardPermission;
/**
* AttachmentController 생성자
*
* @param AttachmentService $attachmentService 첨부파일 서비스
* @param BoardService $boardService 게시판 서비스
*/
public function __construct(
private AttachmentService $attachmentService,
private BoardService $boardService
) {
parent::__construct();
}
/**
* 단일 파일 업로드
*
* @param UploadAttachmentRequest $request 업로드 요청
* @param string $slug 게시판 슬러그
* @return JsonResponse 업로드된 첨부파일 정보 응답
*/
public function upload(UploadAttachmentRequest $request, string $slug): JsonResponse
{
try {
// 게시판 존재 여부 확인
$this->boardService->getBoardBySlug($slug);
$validated = $request->validated();
// post_id가 없으면 임시 업로드 (temp_key 필수)
$postId = $validated['post_id'] ?? null;
$tempKey = $validated['temp_key'] ?? null;
$attachment = $this->attachmentService->upload(
slug: $slug,
file: $request->file('file'),
postId: $postId,
collection: $validated['collection'] ?? 'attachments',
tempKey: $tempKey
);
// FileUploader 컴포넌트가 response.data?.data 형식을 기대하므로
// data 키 안에 한 번 더 감싸서 반환
return $this->success(
'sirsoft-board::messages.attachment.upload_success',
[
'data' => [
'id' => $attachment->id,
'hash' => $attachment->hash,
'original_filename' => $attachment->original_filename,
'stored_filename' => $attachment->stored_filename,
'mime_type' => $attachment->mime_type,
'size' => $attachment->size,
'url' => $this->attachmentService->getUrl($slug, $attachment->id),
'order' => $attachment->order,
'created_at' => $attachment->created_at,
],
],
201
);
} catch (AttachmentLimitExceededException $e) {
// 게시판 첨부 개수 상한 초과 — generic 500 이 아닌 422 명시 차단
return $this->error(
$e->getMessageKey(),
422,
['code' => 'attachment_limit_exceeded'],
$e->getMessageParams()
);
} catch (BoardNotFoundException $e) {
return $this->error('sirsoft-board::messages.boards.not_found', 404);
} catch (\Exception $e) {
return $this->error('sirsoft-board::messages.attachment.upload_failed', 500, $e->getMessage());
}
}
/**
* 첨부파일 삭제
*
* @param string $slug 게시판 슬러그
* @param int $id 첨부파일 ID
* @return JsonResponse 삭제 결과 응답
*/
public function destroy(string $slug, int $id): JsonResponse
{
try {
// 게시판 존재 여부 확인
$this->boardService->getBoardBySlug($slug);
// 첨부파일 조회 (Service를 통해)
$attachment = $this->attachmentService->getById($slug, $id);
if (! $attachment) {
return $this->error('sirsoft-board::messages.attachment.not_found', 404);
}
// 삭제 (Service에서 처리)
$result = $this->attachmentService->delete($slug, $id, 'admin');
if (! $result) {
return $this->error('sirsoft-board::messages.attachment.delete_failed', 500);
}
return $this->success('sirsoft-board::messages.attachment.delete_success');
} catch (BoardNotFoundException $e) {
return $this->error('sirsoft-board::messages.boards.not_found', 404);
} catch (\Exception $e) {
return $this->error('sirsoft-board::messages.attachment.delete_failed', 500, $e->getMessage());
}
}
/**
* 첨부파일 순서 변경
*
* @param ReorderAttachmentsRequest $request 순서 변경 요청
* @param string $slug 게시판 슬러그
* @return JsonResponse 순서 변경 결과 응답
*/
public function reorder(ReorderAttachmentsRequest $request, string $slug): JsonResponse
{
try {
// 게시판 존재 여부 확인
$this->boardService->getBoardBySlug($slug);
$validated = $request->validated();
// FileUploader가 [{id, order}] 형태로 전송 → [ID => order] 매핑으로 변환
$orders = collect($validated['order'])->pluck('order', 'id')->all();
$result = $this->attachmentService->reorder($slug, $orders, 'admin');
if (! $result) {
return $this->error('sirsoft-board::messages.attachment.reorder_failed', 500);
}
return $this->success('sirsoft-board::messages.attachment.reorder_success');
} catch (BoardNotFoundException $e) {
return $this->error('sirsoft-board::messages.boards.not_found', 404);
} catch (\Exception $e) {
return $this->error('sirsoft-board::messages.attachment.reorder_failed', 500, $e->getMessage());
}
}
/**
* 첨부파일 다운로드 (해시 기반)
*
* @param string $slug 게시판 슬러그
* @param string $hash 첨부파일 해시
* @return StreamedResponse|JsonResponse 파일 스트림 또는 오류 응답
*/
public function download(string $slug, string $hash): StreamedResponse|JsonResponse
{
try {
// 게시판 존재 여부 확인
$this->boardService->getBoardBySlug($slug);
// 해시로 첨부파일 조회
$attachment = $this->attachmentService->getByHash($slug, $hash);
if (! $attachment) {
return $this->error('sirsoft-board::messages.attachment.not_found', 404);
}
// 다운로드 응답 생성
$response = $this->attachmentService->download($slug, $attachment->id);
if (! $response) {
return $this->error('sirsoft-board::messages.attachment.file_not_found', 404);
}
return $response;
} catch (AccessDeniedHttpException $e) {
return $this->error('auth.scope_denied', 403);
} catch (BoardNotFoundException $e) {
return $this->error('sirsoft-board::messages.boards.not_found', 404);
} catch (\Exception $e) {
return $this->error('sirsoft-board::messages.attachment.download_failed', 500, $e->getMessage());
}
}
}