공개 제보 — 파일 스토리지에서 S3 를 선택해 저장해도 실제 파일 저장이 동작하지 않던 결함의 전면 수정. - S3 어댑터(league/flysystem-aws-s3-v3)·predis 를 코어 기본 의존성으로 포함 — 어댑터 부재 즉사, phpredis 확장 없는 서버의 redis 선택 전면 다운 차단 (부트 시 확장 부재 감지 → predis 자동 폴백) - storage_driver=s3 저장 시 코어 첨부 업로드 디스크를 s3 로 전환 (ATTACHMENT_DISK env 명시가 항상 우선, 기존 행은 저장 당시 disk 로 서빙) - 첨부·템플릿 레이아웃 첨부 서빙을 행 disk 를 따르는 스토리지 스트림으로 교체 — 로컬 절대 경로 전제 fileResponse 는 S3 행에서 filemtime stat 500 (streamedFileResponse: 행 메타 기반 ETag/304/Cache-Control) - S3 호환 스토리지(R2/MinIO/NCP) 연결 지원: 엔드포인트 URL·path-style 설정 신설, 리전 목록 선택 → 자유 입력 전환, 연결 테스트를 실제 저장 경로와 동일 설정(endpoint/path-style)으로 정렬 - 사용 불능 드라이버(어댑터·PHP 확장 부재)의 저장/테스트 요청을 사유와 함께 422 로 차단하는 서버 게이트 신설 (DriverRegistryService 능력 판정) - 웹소켓 연결 테스트에 서버(백엔드 발송용) endpoint 검사 추가 — 클라이언트만 검사해 테스트 성공 + 실제 발송 실패가 가능하던 비대칭 해소 - env 빈 값(`KEY=`) 함정 정규화: AWS_URL/AWS_ENDPOINT/ATTACHMENT_DISK 빈 문자열을 미설정으로 취급 (config 정규화 + 예시 파일 주석 처리) - 플러그인 드라이버 폴백의 log 카테고리 죽은 키(logging.default) 정정 및 websocket 유령 설정 키 제거 - 실 AWS S3 종단 검증 완료 (설정 저장 → 업로드 S3 실저장 → 서빙 200/304)
84 lines
3.0 KiB
PHP
84 lines
3.0 KiB
PHP
<?php
|
|
|
|
namespace App\Http\Controllers\Api\Public;
|
|
|
|
use App\Http\Controllers\Api\Base\PublicBaseController;
|
|
use App\Http\Requests\Public\Attachment\DownloadAttachmentRequest;
|
|
use App\Services\AttachmentService;
|
|
use Illuminate\Auth\Access\AuthorizationException;
|
|
use Illuminate\Http\JsonResponse;
|
|
use Illuminate\Http\Response;
|
|
use Symfony\Component\HttpFoundation\BinaryFileResponse;
|
|
use Symfony\Component\HttpFoundation\StreamedResponse;
|
|
|
|
/**
|
|
* 첨부파일 다운로드 컨트롤러
|
|
*
|
|
* 권한 정책에 따라 로그인/비로그인 사용자 모두 접근 가능합니다.
|
|
* 권한 체크는 AttachmentService에서 하이브리드 방식으로 처리합니다.
|
|
*/
|
|
class PublicAttachmentController extends PublicBaseController
|
|
{
|
|
/**
|
|
* PublicAttachmentController 생성자
|
|
*
|
|
* @param AttachmentService $attachmentService 첨부파일 서비스
|
|
*/
|
|
public function __construct(
|
|
private AttachmentService $attachmentService
|
|
) {
|
|
parent::__construct();
|
|
}
|
|
|
|
/**
|
|
* 첨부파일 다운로드
|
|
*
|
|
* 이미지 파일은 캐싱 헤더와 함께 인라인 표시하고,
|
|
* 그 외 파일은 다운로드 방식으로 제공합니다.
|
|
*
|
|
* @param DownloadAttachmentRequest $request 다운로드 요청
|
|
* @param string $hash 첨부파일 해시 (12자)
|
|
* @return BinaryFileResponse|StreamedResponse|Response|JsonResponse 파일 응답 또는 에러 응답
|
|
*/
|
|
public function download(DownloadAttachmentRequest $request, string $hash): BinaryFileResponse|StreamedResponse|Response|JsonResponse
|
|
{
|
|
$user = $request->user();
|
|
|
|
try {
|
|
// 파일 정보 조회 (권한 체크 포함)
|
|
$fileInfo = $this->attachmentService->getFileInfo($hash, $user);
|
|
|
|
if (! $fileInfo) {
|
|
$attachment = $this->attachmentService->findByHash($hash);
|
|
|
|
if (! $attachment) {
|
|
return $this->notFound('attachment.not_found');
|
|
}
|
|
|
|
return $this->forbidden('attachment.access_denied');
|
|
}
|
|
|
|
// 이미지 파일은 캐싱 헤더와 함께 응답 (환경설정 레이아웃 캐시 TTL 사용, 기본 24시간)
|
|
// 행 disk 를 따르는 스토리지 스트림 — 로컬 경로 전제 fileResponse 는 S3 행에서 성립하지 않는다 (#99)
|
|
if (str_starts_with($fileInfo['mime_type'], 'image/')) {
|
|
return $this->streamedFileResponse(
|
|
$fileInfo['response'],
|
|
$fileInfo['etag_source'],
|
|
(int) g7_core_settings('cache.layout_ttl', 86400)
|
|
);
|
|
}
|
|
|
|
// 이미지가 아닌 파일은 기존 다운로드 방식 유지
|
|
$response = $this->attachmentService->download($hash, $user);
|
|
|
|
if (! $response) {
|
|
return $this->forbidden('attachment.access_denied');
|
|
}
|
|
|
|
return $response;
|
|
} catch (AuthorizationException) {
|
|
return $this->forbidden('attachment.access_denied');
|
|
}
|
|
}
|
|
}
|