Use stable files API URLs for vendor logo fields

CommonThirdParty.logoUrl and TrustCenterReference.logoUrl were
returning expiring S3 presigned URLs, which break if cached or
shared past their TTL.

Replace with stable /api/files/v1/{id} application URLs.
file.Service now generates these via baseurl; a new filesign
package owns presigning for the files/v1 HTTP handler that
does the internal redirect.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
Ludovic Vielle
2026-06-03 10:21:02 +02:00
parent 383ea5a2d4
commit 6c072a2f7b
14 changed files with 115 additions and 116 deletions

View File

@@ -26,6 +26,7 @@ import (
"go.probo.inc/probo/packages/emails"
"go.probo.inc/probo/pkg/coredata"
"go.probo.inc/probo/pkg/esign"
"go.probo.inc/probo/pkg/file"
"go.probo.inc/probo/pkg/filemanager"
"go.probo.inc/probo/pkg/gid"
"go.probo.inc/probo/pkg/html2pdf"
@@ -46,6 +47,7 @@ type (
esign *esign.Service
html2pdfConverter *html2pdf.Converter
fileManager *filemanager.Service
file *file.Service
logger *log.Logger
slack *slack.Service
TrustCenters *TrustCenterService
@@ -75,6 +77,7 @@ func NewService(
fileManagerService *filemanager.Service,
logger *log.Logger,
slack *slack.Service,
fileService *file.Service,
) *Service {
svc := &Service{
pg: pgClient,
@@ -86,6 +89,7 @@ func NewService(
esign: esignSvc,
html2pdfConverter: html2pdfConverter,
fileManager: fileManagerService,
file: fileService,
logger: logger,
slack: slack,
}

View File

@@ -17,10 +17,7 @@ package trust
import (
"context"
"fmt"
"net/url"
"time"
"github.com/aws/aws-sdk-go-v2/service/s3"
"go.gearno.de/kit/pg"
"go.probo.inc/probo/pkg/coredata"
"go.probo.inc/probo/pkg/gid"
@@ -58,47 +55,17 @@ func (s TrustCenterReferenceService) GenerateLogoURL(
ctx context.Context,
scope coredata.Scoper,
referenceID gid.GID,
duration time.Duration,
) (string, error) {
reference := &coredata.TrustCenterReference{}
file := &coredata.File{}
err := s.svc.pg.WithTx(ctx, func(ctx context.Context, tx pg.Tx) error {
err := reference.LoadByID(ctx, tx, scope, referenceID)
if err != nil {
return fmt.Errorf("cannot load trust center reference: %w", err)
}
err = file.LoadByID(ctx, tx, scope, reference.LogoFileID)
if err != nil {
return fmt.Errorf("cannot load logo file: %w", err)
}
return nil
return reference.LoadByID(ctx, tx, scope, referenceID)
})
if err != nil {
return "", nil
return "", fmt.Errorf("cannot load trust center reference: %w", err)
}
presignClient := s3.NewPresignClient(s.svc.s3)
encodedFilename := url.PathEscape(file.FileName)
contentDisposition := fmt.Sprintf("inline; filename=\"%s\"; filename*=UTF-8''%s",
encodedFilename, encodedFilename)
presignedReq, err := presignClient.PresignGetObject(ctx, &s3.GetObjectInput{
Bucket: new(s.svc.bucket),
Key: new(file.FileKey),
ResponseCacheControl: new("max-age=3600, public"),
ResponseContentDisposition: new(contentDisposition),
}, func(opts *s3.PresignOptions) {
opts.Expires = duration
})
if err != nil {
return "", fmt.Errorf("cannot presign GetObject request: %w", err)
}
return presignedReq.URL, nil
return s.svc.file.GenerateFileURL(ctx, reference.LogoFileID)
}
func (s TrustCenterReferenceService) Get(