Files
Gnuboard7/app/Services/AttachmentService.php
T
HeuJung ea58c606a2 fix(core,admin_basic): S3 스토리지 드라이버 실동작 결함 수정 및 S3 호환 스토리지 연결 지원
공개 제보 — 파일 스토리지에서 S3 를 선택해 저장해도 실제 파일 저장이
동작하지 않던 결함의 전면 수정.

- S3 어댑터(league/flysystem-aws-s3-v3)·predis 를 코어 기본 의존성으로 포함
 — 어댑터 부재 즉사, phpredis 확장 없는 서버의 redis 선택 전면 다운 차단
 (부트 시 확장 부재 감지 → predis 자동 폴백)
- storage_driver=s3 저장 시 코어 첨부 업로드 디스크를 s3 로 전환
 (ATTACHMENT_DISK env 명시가 항상 우선, 기존 행은 저장 당시 disk 로 서빙)
- 첨부·템플릿 레이아웃 첨부 서빙을 행 disk 를 따르는 스토리지 스트림으로 교체
 — 로컬 절대 경로 전제 fileResponse 는 S3 행에서 filemtime stat 500
 (streamedFileResponse: 행 메타 기반 ETag/304/Cache-Control)
- S3 호환 스토리지(R2/MinIO/NCP) 연결 지원: 엔드포인트 URL·path-style 설정
 신설, 리전 목록 선택 → 자유 입력 전환, 연결 테스트를 실제 저장 경로와
 동일 설정(endpoint/path-style)으로 정렬
- 사용 불능 드라이버(어댑터·PHP 확장 부재)의 저장/테스트 요청을 사유와 함께
 422 로 차단하는 서버 게이트 신설 (DriverRegistryService 능력 판정)
- 웹소켓 연결 테스트에 서버(백엔드 발송용) endpoint 검사 추가 — 클라이언트만
 검사해 테스트 성공 + 실제 발송 실패가 가능하던 비대칭 해소
- env 빈 값(`KEY=`) 함정 정규화: AWS_URL/AWS_ENDPOINT/ATTACHMENT_DISK 빈 문자열을
 미설정으로 취급 (config 정규화 + 예시 파일 주석 처리)
- 플러그인 드라이버 폴백의 log 카테고리 죽은 키(logging.default) 정정 및
 websocket 유령 설정 키 제거
- 실 AWS S3 종단 검증 완료 (설정 저장 → 업로드 S3 실저장 → 서빙 200/304)
2026-08-13 15:15:19 +09:00

404 lines
15 KiB
PHP

<?php
namespace App\Services;
use App\Contracts\Extension\StorageInterface;
use App\Contracts\Repositories\AttachmentRepositoryInterface;
use App\Enums\AttachmentSourceType;
use App\Extension\HookManager;
use App\Models\Attachment;
use App\Models\User;
use App\Support\ImageResizer;
use Illuminate\Auth\Access\AuthorizationException;
use Illuminate\Http\UploadedFile;
use Illuminate\Support\Collection;
use Illuminate\Support\Facades\Auth;
use Illuminate\Support\Facades\Log;
use Illuminate\Support\Str;
use Symfony\Component\HttpFoundation\StreamedResponse;
/**
* 첨부파일 서비스
*
* 첨부파일 업로드, 삭제, 다운로드 등의 비즈니스 로직을 처리합니다.
*/
class AttachmentService
{
/**
* AttachmentService 생성자
*
* @param AttachmentRepositoryInterface $repository 첨부파일 리포지토리
* @param StorageInterface $storage 스토리지 드라이버
* @param ImageResizer $imageResizer 업로드 이미지 축소기
*/
public function __construct(
private AttachmentRepositoryInterface $repository,
private StorageInterface $storage,
private ImageResizer $imageResizer
) {}
/**
* 단일 파일 업로드
*
* @param UploadedFile $file 업로드된 파일
* @param string|null $attachmentableType 첨부 대상 타입
* @param int|null $attachmentableId 첨부 대상 ID
* @param string $collection 컬렉션명
* @param AttachmentSourceType $sourceType 소스 타입
* @param string|null $sourceIdentifier 소스 식별자
* @return Attachment 생성된 첨부파일
*/
public function upload(
UploadedFile $file,
?string $attachmentableType = null,
?int $attachmentableId = null,
string $collection = 'default',
AttachmentSourceType $sourceType = AttachmentSourceType::Core,
?string $sourceIdentifier = null,
): Attachment {
// Before 훅
HookManager::doAction('core.attachment.before_upload', $file, $attachmentableType, $attachmentableId);
// 필터 훅 - 파일 데이터 변형 (압축, 리사이즈 등 확장 포인트)
$file = HookManager::applyFilters('core.attachment.filter_upload_file', $file);
// 환경설정 > 업로드의 최대 가로/세로·품질을 실제로 적용한다.
// 임시 파일을 제자리에서 줄이므로 아래의 저장·크기·메타 계산이 모두 축소본을 본다.
$this->imageResizer->resizeInPlace($file->getRealPath(), $file->getMimeType());
// 저장 경로 생성 (날짜별 디렉토리).
// 확장자는 클라이언트가 보낸 파일명이 아니라 MIME 추론값을 우선 사용한다 —
// 파일명 확장자는 사용자가 임의로 바꿀 수 있어 저장 확장자의 근거가 될 수 없다.
$extension = strtolower($file->extension() ?: $file->getClientOriginalExtension());
$storedFilename = Str::uuid().($extension !== '' ? '.'.$extension : '');
$datePath = date('Y/m/d');
$path = "{$datePath}/{$storedFilename}";
// 스토리지에 파일 저장
$disk = config('attachment.disk');
$this->storage->withDisk($disk)->put('', $path, file_get_contents($file->getRealPath()));
// 현재 컬렉션의 최대 order 조회
if ($attachmentableType && $attachmentableId) {
$maxOrder = $this->repository->getMaxOrder($attachmentableType, $attachmentableId, $collection);
} else {
$maxOrder = $this->repository->getMaxOrderByCollection($collection);
}
// 메타데이터 준비 (이미지인 경우 크기 정보)
$meta = [];
if (str_starts_with($file->getMimeType(), 'image/')) {
$imageSize = @getimagesize($file->getRealPath());
if ($imageSize) {
$meta['width'] = $imageSize[0];
$meta['height'] = $imageSize[1];
}
}
// DB에 저장
$attachment = $this->repository->create([
'attachmentable_type' => $attachmentableType,
'attachmentable_id' => $attachmentableId,
'source_type' => $sourceType,
'source_identifier' => $sourceIdentifier,
'original_filename' => $file->getClientOriginalName(),
'stored_filename' => $storedFilename,
'disk' => $disk,
'path' => $path,
'mime_type' => $file->getMimeType(),
'size' => $file->getSize(),
'collection' => $collection,
'order' => $maxOrder + 1,
'meta' => ! empty($meta) ? $meta : null,
'created_by' => Auth::id(),
]);
Log::info('첨부파일 업로드 완료', [
'attachment_id' => $attachment->id,
'hash' => $attachment->hash,
'original_filename' => $attachment->original_filename,
'size' => $attachment->size,
]);
// After 훅
HookManager::doAction('core.attachment.after_upload', $attachment);
return $attachment;
}
/**
* 여러 파일 일괄 업로드
*
* @param array<UploadedFile> $files 업로드할 파일 배열
* @param string|null $attachmentableType 첨부 대상 타입
* @param int|null $attachmentableId 첨부 대상 ID
* @param string $collection 컬렉션명
* @param AttachmentSourceType $sourceType 소스 타입
* @param string|null $sourceIdentifier 소스 식별자
* @return Collection<int, Attachment>
*/
public function uploadBatch(
array $files,
?string $attachmentableType = null,
?int $attachmentableId = null,
string $collection = 'default',
AttachmentSourceType $sourceType = AttachmentSourceType::Core,
?string $sourceIdentifier = null,
): Collection {
$attachments = collect();
foreach ($files as $file) {
$attachment = $this->upload(
$file,
$attachmentableType,
$attachmentableId,
$collection,
$sourceType,
$sourceIdentifier,
);
$attachments->push($attachment);
}
return $attachments;
}
/**
* 첨부파일 삭제
*
* @param int $id 첨부파일 ID
* @return bool 삭제 성공 여부
*/
public function delete(int $id): bool
{
$attachment = $this->repository->findById($id);
if (! $attachment) {
return false;
}
// 삭제 후 재정렬을 위해 정보 저장
$attachmentableType = $attachment->attachmentable_type;
$attachmentableId = $attachment->attachmentable_id;
$collection = $attachment->collection;
// Before 훅
HookManager::doAction('core.attachment.before_delete', $attachment);
// 스토리지에서 파일 삭제
$this->storage->withDisk($attachment->disk)->delete('', $attachment->path);
// DB에서 영구 삭제
$result = $this->repository->forceDelete($id);
Log::info('첨부파일 삭제 완료', [
'attachment_id' => $id,
'hash' => $attachment->hash,
]);
// 삭제 후 남은 파일들의 순서 재정렬
if ($result && $attachmentableType && $attachmentableId) {
$this->repository->reorderAfterDelete($attachmentableType, $attachmentableId, $collection);
}
// After 훅
HookManager::doAction('core.attachment.after_delete', $attachment);
return $result;
}
/**
* 순서 변경
*
* @param array<int, array{id: int, order: int}> $orderData 순서 데이터
*/
public function reorder(array $orderData): void
{
// Before 훅
HookManager::doAction('core.attachment.before_reorder', $orderData);
$this->repository->reorder($orderData);
// After 훅
HookManager::doAction('core.attachment.after_reorder', $orderData);
}
/**
* 다운로드 응답 생성
*
* 기능 레벨 권한 체크 (permission_hooks) - 다운로드 기능 자체에 대한 접근 권한
*
* @param string $hash 첨부파일 해시
* @param User|null $user 요청한 사용자 (null이면 비로그인)
* @return StreamedResponse|null 다운로드 응답 또는 null
*
* @throws AuthorizationException 기능 레벨 권한이 없는 경우
*/
public function download(string $hash, mixed $user = null): ?StreamedResponse
{
$attachment = $this->repository->findByHash($hash);
if (! $attachment) {
return null;
}
// 기능 레벨 권한 체크 (permission_hooks)
// → 'core.attachment.download' 훅에 권한이 매핑되어 있으면 체크
// → 미매핑 시 모든 사용자 허용
HookManager::checkHookPermission('core.attachment.download', $user);
// 액션 훅 - IDV 정책 가드 지점 (filter 훅과 병행)
HookManager::doAction('core.attachment.before_download_action', $attachment, $user);
// 필터 훅 - 다운로드 전 처리 (다운로드 카운트 증가 등)
$attachment = HookManager::applyFilters('core.attachment.before_download', $attachment, $user);
// 파일 존재 확인
$diskStorage = $this->storage->withDisk($attachment->disk);
if (! $diskStorage->exists('', $attachment->path)) {
Log::error('첨부파일 스토리지에 없음', [
'attachment_id' => $attachment->id,
'path' => $attachment->path,
]);
return null;
}
// 다운로드 응답 생성 (원본 파일명으로)
return $diskStorage->download('', $attachment->path, $attachment->original_filename);
}
/**
* 이미지 파일 정보 조회 (캐싱 응답용)
*
* 권한 체크 후 인라인 스트림 응답과 캐싱용 메타를 반환합니다.
* 로컬 절대 경로 조립(getBasePath) 방식은 S3 등 원격 디스크 행에서 성립하지
* 않으므로(#99 — filemtime stat 실패 500), 행 disk 를 그대로 따르는
* StorageInterface::response() 스트림으로 서빙합니다. 컨트롤러는
* streamedFileResponse() 로 캐싱 헤더(ETag/304)를 입혀 응답합니다.
*
* @param string $hash 첨부파일 해시
* @param User|null $user 요청한 사용자 (null이면 비로그인)
* @return array{response: StreamedResponse, etag_source: string, mime_type: string, filename: string}|null 서빙 정보 또는 null
*
* @throws AuthorizationException 기능 레벨 권한이 없는 경우
*/
public function getFileInfo(string $hash, mixed $user = null): ?array
{
$attachment = $this->repository->findByHash($hash);
if (! $attachment) {
return null;
}
// 기능 레벨 권한 체크 (permission_hooks)
HookManager::checkHookPermission('core.attachment.download', $user);
// 필터 훅 - 다운로드 전 처리
$attachment = HookManager::applyFilters('core.attachment.before_download', $attachment, $user);
// 행 disk 기준 인라인 스트림 (존재 검사는 response() 내부에서 수행)
// Content-Type/Length 를 행 메타로 선지정해 원격 디스크의 추가 메타 조회를 생략한다.
$response = $this->storage->withDisk($attachment->disk)->response(
'',
$attachment->path,
$attachment->original_filename,
[
'Content-Type' => $attachment->mime_type,
'Content-Length' => (string) $attachment->size,
]
);
if (! $response) {
Log::error('첨부파일 스토리지에 없음', [
'attachment_id' => $attachment->id,
'path' => $attachment->path,
]);
return null;
}
return [
'response' => $response,
// 파일 stat 없이 결정적인 ETag 소스 (업로드 파일은 경로당 불변)
'etag_source' => implode('|', [
$attachment->disk,
$attachment->path,
(string) $attachment->updated_at?->getTimestamp(),
(string) $attachment->size,
]),
'mime_type' => $attachment->mime_type,
'filename' => $attachment->original_filename,
];
}
/**
* 해시로 첨부파일 조회
*
* @param string $hash 첨부파일 해시
* @return Attachment|null 첨부파일 또는 null
*/
public function findByHash(string $hash): ?Attachment
{
return $this->repository->findByHash($hash);
}
/**
* ID로 첨부파일 조회
*
* @param int $id 첨부파일 ID
* @return Attachment|null 첨부파일 또는 null
*/
public function findById(int $id): ?Attachment
{
return $this->repository->findById($id);
}
/**
* 첨부 대상의 첨부파일 목록 조회
*
* @param string $type attachmentable_type
* @param int $id attachmentable_id
* @param string|null $collection 컬렉션명 (null이면 전체)
* @return Collection<int, Attachment>
*/
public function getByAttachmentable(string $type, int $id, ?string $collection = null): Collection
{
return $this->repository->getByAttachmentable($type, $id, $collection);
}
/**
* 특정 소스 식별자의 첨부파일 일괄 삭제
* (모듈/플러그인 제거 시 사용)
*
* @param string $identifier 소스 식별자
* @return int 삭제된 개수
*/
public function deleteBySourceIdentifier(string $identifier): int
{
// Before 훅
HookManager::doAction('core.attachment.before_bulk_delete', $identifier);
// 해당 첨부파일들의 스토리지 파일 삭제
$attachments = $this->repository->getBySourceIdentifier($identifier);
$attachmentIds = $attachments->pluck('id')->toArray();
$snapshots = $attachments->keyBy('id')->map(fn ($a) => $a->toArray())->toArray();
foreach ($attachments as $attachment) {
$this->storage->withDisk($attachment->disk)->delete('', $attachment->path);
}
// DB에서 삭제
$count = $this->repository->deleteBySourceIdentifier($identifier);
Log::info('소스 식별자 기준 첨부파일 일괄 삭제', [
'source_identifier' => $identifier,
'deleted_count' => $count,
]);
// After 훅
HookManager::doAction('core.attachment.after_bulk_delete', $identifier, $count, $attachmentIds, $snapshots);
return $count;
}
}