Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
84323ab637 | ||
|
|
40f7f2fb5e |
+2
-2
@@ -37,8 +37,7 @@ tempfile = "3"
|
||||
time = "0.3"
|
||||
tokio = { version = "1", features = ["full"] }
|
||||
tokio-util = { version = "0.7", features = ["io"] }
|
||||
tower = { version = "0.5", features = ["util"] }
|
||||
tower-http = { version = "0.6", features = ["fs", "set-header", "trace"] }
|
||||
tower-http = { version = "0.6", features = ["fs", "trace"] }
|
||||
tracing = "0.1"
|
||||
tracing-subscriber = { version = "0.3", features = ["env-filter"] }
|
||||
urlencoding = "2"
|
||||
@@ -46,6 +45,7 @@ uuid = { version = "1", features = ["v4", "serde"] }
|
||||
|
||||
[dev-dependencies]
|
||||
cookie = { version = "0.18", features = ["signed"] }
|
||||
tower = { version = "0.5", features = ["util"] }
|
||||
|
||||
[profile.release]
|
||||
lto = "thin"
|
||||
|
||||
@@ -2,25 +2,7 @@
|
||||
|
||||
Self-hosted client gallery for photographers. Upload RAWs/JPGs into albums,
|
||||
share them with clients via private (optionally password-protected) links,
|
||||
collect accept/reject votes, ratings and tags, and let clients download
|
||||
originals.
|
||||
|
||||
## Screenshots
|
||||
|
||||
The album view — drag-and-drop upload, justified gallery, and each client's
|
||||
feedback (votes, stars, tags) overlaid on the thumbnails:
|
||||
|
||||

|
||||
|
||||
What clients see on a share link — vote on favorites, filter by verdict,
|
||||
download selects or the whole album as a ZIP:
|
||||
|
||||

|
||||
|
||||
The lightbox — accept/reject, star rating, tags, and keyboard-driven culling
|
||||
(`P`/`X`/`U`, `1`–`5`):
|
||||
|
||||

|
||||
collect ratings and tags, and let clients download originals.
|
||||
|
||||
## Architecture
|
||||
|
||||
@@ -48,19 +30,17 @@ The lightbox — accept/reject, star rating, tags, and keyboard-driven culling
|
||||
`photos/<photo_id>/preview.jpg`, `photos/<photo_id>/thumb.jpg`. The bucket
|
||||
stays fully private; all image traffic is streamed through the API with
|
||||
auth checks (no bucket CORS or public access needed).
|
||||
- **Auth**: photographer signs in via any OIDC provider (authorization-code
|
||||
- **Auth**: photographers sign in via any OIDC provider (authorization-code
|
||||
flow + userinfo); only emails in `ALLOWED_EMAILS` may sign in, and sessions
|
||||
are re-checked against the allowlist on every request, so removing an email
|
||||
revokes access immediately. Clients use unguessable share tokens, optionally
|
||||
revokes access immediately. **Multi-tenant**: each allowed email is its own
|
||||
workspace — albums, photos, and share links are owned per photographer and
|
||||
invisible to the others (enforced via ownership-scoped data access and
|
||||
covered by the tenant-isolation test matrix). Clients use unguessable share tokens, optionally
|
||||
gated by an argon2-hashed password (10 wrong guesses lock the link for
|
||||
15 minutes).
|
||||
- **Frontend**: React + Vite SPA — justified gallery, lightbox with
|
||||
accept/reject thumbs, rating stars and tag chips, keyboard-driven culling
|
||||
(`P`/`X`/`U`, `1`–`5`, `?` shows all shortcuts), drag-and-drop multi-file
|
||||
upload with progress. Touch-first on mobile: swipe sideways to browse,
|
||||
flick a photo up/down to accept/reject (real physics — votes commit
|
||||
instantly, the animation is decoration), pinch to zoom, always-visible
|
||||
selection checkmarks. Voting the last photo fades back to the gallery.
|
||||
- **Frontend**: React + Vite SPA — justified gallery, lightbox with rating
|
||||
stars and tag chips, drag-and-drop multi-file upload with progress.
|
||||
|
||||
## Local development
|
||||
|
||||
@@ -78,6 +58,13 @@ cargo run --bin worker # job worker (separate terminal, same env)
|
||||
cd frontend && npm install && npm run dev # UI on :5173, proxies /api
|
||||
```
|
||||
|
||||
Tests (the tenant-isolation matrix needs a disposable database):
|
||||
|
||||
```sh
|
||||
createdb photos_test # or: docker compose exec postgres createdb -U photos photos_test
|
||||
TEST_DATABASE_URL=postgres://photos:photos@localhost:5432/photos_test cargo test
|
||||
```
|
||||
|
||||
Register the OIDC client with redirect URI `<PUBLIC_URL>/api/auth/callback`
|
||||
(locally: `http://localhost:5173/api/auth/callback`). Any standard OIDC
|
||||
provider works (Authentik, Keycloak, Zitadel, Dex, ...); the app uses
|
||||
@@ -108,20 +95,20 @@ All configuration is via environment variables:
|
||||
|
||||
## Deploying to Kubernetes
|
||||
|
||||
The prebuilt image is at `git.draic.info/nils/photos` (single image contains
|
||||
`server`, `worker`, and the built frontend). To build your own instead:
|
||||
Build and push the image (single image contains `server`, `worker`, and the
|
||||
built frontend):
|
||||
|
||||
```sh
|
||||
docker build -t registry.example.com/you/photos:0.4.3 .
|
||||
docker push registry.example.com/you/photos:0.4.3
|
||||
docker build -t ghcr.io/YOU/photos:0.1.0 .
|
||||
docker push ghcr.io/YOU/photos:0.1.0
|
||||
```
|
||||
|
||||
Install the chart, pointing it at your existing Postgres and S3:
|
||||
|
||||
```sh
|
||||
helm install photos deploy/chart \
|
||||
--set image.repository=git.draic.info/nils/photos \
|
||||
--set image.tag=0.4.3 \
|
||||
--set image.repository=ghcr.io/YOU/photos \
|
||||
--set image.tag=0.1.0 \
|
||||
--set publicUrl=https://photos.example.com \
|
||||
--set ingress.host=photos.example.com \
|
||||
--set config.oidcIssuer=https://auth.example.com \
|
||||
@@ -158,12 +145,9 @@ Notes:
|
||||
- Each album can have any number of share links (`/s/<24-char-token>`), each
|
||||
with its own label (e.g. the client's name), optional password, optional
|
||||
expiry, and a per-link download toggle.
|
||||
- Accept/reject votes (👍/👎), ratings (1–5 stars) and free-form tags are
|
||||
stored **per link**, so create one link per client to keep feedback
|
||||
separate. The album view shows all feedback grouped by link label, and
|
||||
clients can filter their gallery by verdict (e.g. review only what's still
|
||||
undecided, or select-all + download the accepted set). Culling works with
|
||||
keyboard (`P`/`X` auto-advance) on desktop and swipe gestures on mobile.
|
||||
- Ratings (1–5 stars) and free-form tags are stored **per link**, so create
|
||||
one link per client to keep feedback separate. The album view shows all
|
||||
feedback grouped by link label.
|
||||
- Clients (and you) can multi-select photos and download them — or the whole
|
||||
album — as a ZIP. Archives are streamed (each file spools briefly through a
|
||||
temp file for its checksum, then pipelines while the next one prefetches),
|
||||
@@ -176,16 +160,14 @@ Notes:
|
||||
- 10 wrong passwords lock a link for 15 minutes (fresh attempts after the
|
||||
window). A locked link shows in the album's share list with an Unlock
|
||||
button.
|
||||
- Deleting a link removes its votes/ratings/tags; deleting photos or albums
|
||||
cleans up S3 objects via background jobs.
|
||||
- Deleting a link removes its ratings/tags; deleting photos or albums cleans
|
||||
up S3 objects via background jobs.
|
||||
|
||||
## Known limitations / deliberate v1 cuts
|
||||
|
||||
- Full RAW develop fallback for files whose embedded preview is tiny
|
||||
(exceedingly rare on modern cameras; `darktable-cli` in the worker image
|
||||
would cover it).
|
||||
- Multiple photographer accounts with separate libraries (any allowed email
|
||||
sees everything).
|
||||
- No S3 orphan sweeper: a crash in the narrow window between an upload's S3
|
||||
put and its DB commit can leave an unreferenced original in the bucket
|
||||
(never data loss — just unclaimed storage).
|
||||
|
||||
Binary file not shown.
|
Before Width: | Height: | Size: 400 KiB |
Binary file not shown.
|
Before Width: | Height: | Size: 528 KiB |
Binary file not shown.
|
Before Width: | Height: | Size: 389 KiB |
+8
-2
@@ -73,9 +73,15 @@ export function postDownload(url, ids = '') {
|
||||
form.remove()
|
||||
}
|
||||
|
||||
// SHA-256 of a File, matching the server's content hash — used to skip
|
||||
// uploading bytes the album already has.
|
||||
// Above this, hashing whole-file in memory (WebCrypto has no streaming digest)
|
||||
// risks OOM / the ~2GiB ArrayBuffer cap, so we skip the client dedup check and
|
||||
// just upload — the server still dedups on arrival.
|
||||
const CLIENT_HASH_LIMIT = 512 * 1024 * 1024
|
||||
|
||||
// SHA-256 of a File (lowercase hex), matching the server's content hash, or
|
||||
// null when the file is too large to hash safely in the browser.
|
||||
export async function sha256Hex(file) {
|
||||
if (file.size > CLIENT_HASH_LIMIT) return null
|
||||
const digest = await crypto.subtle.digest('SHA-256', await file.arrayBuffer())
|
||||
return [...new Uint8Array(digest)].map((b) => b.toString(16).padStart(2, '0')).join('')
|
||||
}
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
import { useEffect, useRef, useState } from 'react'
|
||||
import { useCallback, useRef, useState } from 'react'
|
||||
import { imgUrl } from '../api'
|
||||
|
||||
// True justified layout: pack photos greedily into rows at their real aspect
|
||||
@@ -32,17 +32,22 @@ function layoutRows(photos, containerWidth, targetHeight, gap) {
|
||||
}
|
||||
|
||||
export default function Gallery({ photos, onOpen, overlay, selected, onToggleSelect }) {
|
||||
const containerRef = useRef(null)
|
||||
const [width, setWidth] = useState(0)
|
||||
const observerRef = useRef(null)
|
||||
|
||||
useEffect(() => {
|
||||
// Callback ref: (re)attaches the observer whenever the container node
|
||||
// mounts. A plain mount-effect misses the case where Gallery first renders
|
||||
// empty (no container) and photos arrive later.
|
||||
const containerRef = useCallback((node) => {
|
||||
observerRef.current?.disconnect()
|
||||
if (!node) return
|
||||
const observer = new ResizeObserver((entries) => setWidth(entries[0].contentRect.width))
|
||||
observer.observe(containerRef.current)
|
||||
return () => observer.disconnect()
|
||||
observer.observe(node)
|
||||
observerRef.current = observer
|
||||
setWidth(node.getBoundingClientRect().width)
|
||||
}, [])
|
||||
|
||||
// The container renders even with zero photos — unmounting it would detach
|
||||
// the observer and leave a later non-empty render stuck at width 0.
|
||||
if (photos.length === 0) return null
|
||||
const gap = 6
|
||||
const targetHeight = width < 700 ? 170 : 240
|
||||
const rows = width > 0 ? layoutRows(photos, width, targetHeight, gap) : []
|
||||
@@ -68,7 +73,7 @@ export default function Gallery({ photos, onOpen, overlay, selected, onToggleSel
|
||||
title={isSelected ? 'Deselect' : 'Select'}
|
||||
onClick={(e) => {
|
||||
e.stopPropagation()
|
||||
onToggleSelect(p.id, e.shiftKey)
|
||||
onToggleSelect(p.id)
|
||||
}}
|
||||
>
|
||||
✓
|
||||
|
||||
@@ -1,87 +1,18 @@
|
||||
import { useEffect, useRef, useState } from 'react'
|
||||
import { useEffect } from 'react'
|
||||
import { imgUrl } from '../api'
|
||||
import useSwipe from '../useSwipe'
|
||||
|
||||
const BASE_SHORTCUTS = [
|
||||
['← / →', 'previous / next photo'],
|
||||
['Space', 'next photo (Shift+Space back)'],
|
||||
['?', 'show / hide shortcuts'],
|
||||
['Esc', 'close'],
|
||||
]
|
||||
|
||||
// `actions` defines the page's shortcuts as one table — display and dispatch
|
||||
// come from the same entry, so the help overlay can't drift from behavior:
|
||||
// { keys: ['p'], help: ['P', 'accept…'], run: (photo, key) => … }.
|
||||
// Keys fire only outside text inputs and while the help overlay is closed.
|
||||
// `gestures` ({ up, down }) maps vertical touch flicks on the photo — the
|
||||
// horizontal axis always navigates, so voting and browsing never collide.
|
||||
// `closing` fades the whole modal out; `onClosed` fires when the fade ends
|
||||
// (the page then actually unmounts the lightbox).
|
||||
export default function Lightbox({
|
||||
photos,
|
||||
index,
|
||||
onClose,
|
||||
onNav,
|
||||
footer,
|
||||
actions,
|
||||
gestures,
|
||||
closing,
|
||||
onClosed,
|
||||
}) {
|
||||
export default function Lightbox({ photos, index, onClose, onNav, footer }) {
|
||||
const photo = photos[index]
|
||||
const [showHelp, setShowHelp] = useState(false)
|
||||
|
||||
// Handlers and view state live in a ref, updated every render, so the
|
||||
// window listener is attached once yet always dispatches against current
|
||||
// values — re-subscribing per render leaves a gap until effects re-run in
|
||||
// which a fast second keystroke hits a stale closure (and e.g. re-votes
|
||||
// the previous photo).
|
||||
const live = useRef({})
|
||||
live.current = { index, count: photos.length, photo, onClose, onNav, actions, showHelp, closing }
|
||||
|
||||
useEffect(() => {
|
||||
// Only text entry captures keys (Escape leaves the field); focus on a
|
||||
// checkbox or button must not disable lightbox navigation.
|
||||
const isTyping = (el) =>
|
||||
el.tagName === 'TEXTAREA' ||
|
||||
el.isContentEditable ||
|
||||
(el.tagName === 'INPUT' && !['checkbox', 'radio', 'button'].includes(el.type))
|
||||
const handler = (e) => {
|
||||
const s = live.current
|
||||
if (s.closing) return
|
||||
if (isTyping(e.target)) {
|
||||
if (e.key === 'Escape') e.target.blur()
|
||||
return
|
||||
}
|
||||
if (e.metaKey || e.ctrlKey || e.altKey) return
|
||||
if (e.key === 'Escape') {
|
||||
if (s.showHelp) setShowHelp(false)
|
||||
else s.onClose()
|
||||
return
|
||||
}
|
||||
if (e.key === '?') {
|
||||
setShowHelp((h) => !h)
|
||||
return
|
||||
}
|
||||
// With the help overlay up, keys must not act on the photo behind it.
|
||||
if (s.showHelp) return
|
||||
if (e.key === 'ArrowRight' || (e.key === ' ' && !e.shiftKey)) {
|
||||
e.preventDefault()
|
||||
if (s.index < s.count - 1) s.onNav(s.index + 1)
|
||||
return
|
||||
}
|
||||
if (e.key === 'ArrowLeft' || (e.key === ' ' && e.shiftKey)) {
|
||||
e.preventDefault()
|
||||
if (s.index > 0) s.onNav(s.index - 1)
|
||||
return
|
||||
}
|
||||
const key = e.key.toLowerCase()
|
||||
const action = s.actions?.find((a) => a.keys.includes(key))
|
||||
if (action && s.photo) action.run(s.photo, key)
|
||||
const onKey = (e) => {
|
||||
if (e.key === 'Escape') onClose()
|
||||
if (e.key === 'ArrowRight' && index < photos.length - 1) onNav(index + 1)
|
||||
if (e.key === 'ArrowLeft' && index > 0) onNav(index - 1)
|
||||
}
|
||||
window.addEventListener('keydown', handler)
|
||||
return () => window.removeEventListener('keydown', handler)
|
||||
}, [])
|
||||
window.addEventListener('keydown', onKey)
|
||||
return () => window.removeEventListener('keydown', onKey)
|
||||
}, [index, photos.length, onClose, onNav])
|
||||
|
||||
useEffect(() => {
|
||||
document.body.style.overflow = 'hidden'
|
||||
@@ -90,53 +21,15 @@ export default function Lightbox({
|
||||
}
|
||||
}, [])
|
||||
|
||||
const preview = (p) => imgUrl(p, 'preview')
|
||||
const prevPhoto = photos[index - 1]
|
||||
const nextPhoto = photos[index + 1]
|
||||
|
||||
const swipe = useSwipe({
|
||||
photo,
|
||||
index,
|
||||
count: photos.length,
|
||||
onNav,
|
||||
gestures,
|
||||
hasNext: index < photos.length - 1,
|
||||
})
|
||||
|
||||
// Immediate neighbors are real DOM slides (loaded by definition); warm the
|
||||
// browser cache a few photos further out so fast swiping never hits the
|
||||
// network.
|
||||
useEffect(() => {
|
||||
for (const i of [index + 2, index + 3, index - 2]) {
|
||||
if (photos[i]) new Image().src = preview(photos[i])
|
||||
}
|
||||
}, [index, photos])
|
||||
|
||||
if (!photo) return null
|
||||
|
||||
// Did the vote fly off the photo we're still showing (no advance target)?
|
||||
const exitSelf = swipe.exit && swipe.exit.photo.id === photo.id
|
||||
|
||||
return (
|
||||
<div
|
||||
className={`lightbox${closing ? ' lb-closing' : ''}`}
|
||||
onClick={onClose}
|
||||
onAnimationEnd={(e) => {
|
||||
if (e.animationName === 'lb-fade-out') onClosed?.()
|
||||
}}
|
||||
>
|
||||
<div className="lightbox" onClick={onClose}>
|
||||
<div className="lb-top" onClick={(e) => e.stopPropagation()}>
|
||||
<span className="lb-name">{photo.filename}</span>
|
||||
<span className="lb-count">
|
||||
{index + 1} / {photos.length}
|
||||
</span>
|
||||
<button
|
||||
className="lb-btn"
|
||||
onClick={() => setShowHelp((h) => !h)}
|
||||
title="Keyboard shortcuts (?)"
|
||||
>
|
||||
?
|
||||
</button>
|
||||
<button className="lb-btn" onClick={onClose} title="Close (Esc)">
|
||||
✕
|
||||
</button>
|
||||
@@ -151,59 +44,13 @@ export default function Lightbox({
|
||||
>
|
||||
‹
|
||||
</button>
|
||||
<div className="lb-stage" {...swipe.handlers}>
|
||||
<div
|
||||
className="lb-track"
|
||||
ref={swipe.trackRef}
|
||||
style={swipe.trackStyle}
|
||||
onTransitionEnd={swipe.onTrackTransitionEnd}
|
||||
>
|
||||
{prevPhoto && (
|
||||
<div key={prevPhoto.id} className="lb-slide" style={{ transform: 'translateX(-100vw)' }}>
|
||||
<img className="lb-img" src={preview(prevPhoto)} alt="" />
|
||||
</div>
|
||||
)}
|
||||
<div key={photo.id} className="lb-slide" style={{ zIndex: 1 }}>
|
||||
<img
|
||||
ref={swipe.imgRef}
|
||||
className={`lb-img${swipe.exit ? (exitSelf ? ' lb-hidden' : ' lb-enter') : ''}`}
|
||||
style={swipe.imgStyle}
|
||||
onTransitionEnd={swipe.onImgTransitionEnd}
|
||||
src={preview(photo)}
|
||||
alt={photo.filename}
|
||||
onClick={(e) => e.stopPropagation()}
|
||||
/>
|
||||
</div>
|
||||
{nextPhoto &&
|
||||
(swipe.showBehind ? (
|
||||
<div
|
||||
key={nextPhoto.id}
|
||||
ref={swipe.behindRef}
|
||||
className="lb-slide lb-behind"
|
||||
style={swipe.behindStyle}
|
||||
>
|
||||
<img className="lb-img" src={preview(nextPhoto)} alt="" />
|
||||
</div>
|
||||
) : (
|
||||
<div key={nextPhoto.id} className="lb-slide" style={{ transform: 'translateX(100vw)' }}>
|
||||
<img className="lb-img" src={preview(nextPhoto)} alt="" />
|
||||
</div>
|
||||
))}
|
||||
</div>
|
||||
{swipe.exit && (
|
||||
<div
|
||||
className="lb-slide lb-ghost"
|
||||
style={{ '--dy': `${swipe.exit.dy}px`, '--rot': `${swipe.exit.dy / 40}deg` }}
|
||||
onAnimationEnd={swipe.clearExit}
|
||||
>
|
||||
<img
|
||||
className={`lb-img lb-exit-${swipe.exit.dir}`}
|
||||
src={preview(swipe.exit.photo)}
|
||||
alt=""
|
||||
/>
|
||||
</div>
|
||||
)}
|
||||
{swipe.showBadge && <div ref={swipe.badgeRef} className="lb-flick" />}
|
||||
<div className="lb-stage">
|
||||
<img
|
||||
className="lb-img"
|
||||
src={imgUrl(photo, 'preview')}
|
||||
alt={photo.filename}
|
||||
onClick={(e) => e.stopPropagation()}
|
||||
/>
|
||||
</div>
|
||||
<button
|
||||
className="lb-nav lb-next"
|
||||
@@ -220,25 +67,6 @@ export default function Lightbox({
|
||||
{footer(photo)}
|
||||
</div>
|
||||
)}
|
||||
{showHelp && (
|
||||
<div
|
||||
className="lb-help"
|
||||
onClick={(e) => {
|
||||
e.stopPropagation()
|
||||
setShowHelp(false)
|
||||
}}
|
||||
>
|
||||
<div className="lb-help-card">
|
||||
<h3>Keyboard shortcuts</h3>
|
||||
{[...(actions?.map((a) => a.help) || []), ...BASE_SHORTCUTS].map(([keys, label]) => (
|
||||
<div key={keys} className="lb-help-row">
|
||||
<kbd>{keys}</kbd>
|
||||
<span className="muted">{label}</span>
|
||||
</div>
|
||||
))}
|
||||
</div>
|
||||
</div>
|
||||
)}
|
||||
</div>
|
||||
)
|
||||
}
|
||||
|
||||
@@ -15,7 +15,6 @@ export default function SelectionBar({
|
||||
onClear,
|
||||
onDownload,
|
||||
onDownloadAll,
|
||||
onDelete,
|
||||
}) {
|
||||
if (total === 0) return null
|
||||
|
||||
@@ -48,11 +47,6 @@ export default function SelectionBar({
|
||||
<button className="btn btn-primary" onClick={onDownload}>
|
||||
Download {count} as ZIP ({fmtBytes(selectedBytes)})
|
||||
</button>
|
||||
{onDelete && (
|
||||
<button className="btn btn-danger" onClick={onDelete}>
|
||||
Delete {count}
|
||||
</button>
|
||||
)}
|
||||
</div>
|
||||
)
|
||||
}
|
||||
|
||||
@@ -1,27 +0,0 @@
|
||||
export const ACCEPT_GLYPH = '👍'
|
||||
export const REJECT_GLYPH = '👎'
|
||||
|
||||
// Accept/reject vote. `value` is 'accept', 'reject' or null; clicking the
|
||||
// active thumb clears it. Without onChange it renders read-only.
|
||||
export default function Thumbs({ value, onChange, small }) {
|
||||
const thumb = (verdict, glyph, label) => (
|
||||
<button
|
||||
type="button"
|
||||
className={`thumb${value === verdict ? ' active' : ''}`}
|
||||
disabled={!onChange}
|
||||
onClick={(e) => {
|
||||
e.stopPropagation()
|
||||
onChange(value === verdict ? null : verdict)
|
||||
}}
|
||||
title={onChange ? label : undefined}
|
||||
>
|
||||
{glyph}
|
||||
</button>
|
||||
)
|
||||
return (
|
||||
<span className={`thumbs${small ? ' thumbs-small' : ''}`}>
|
||||
{thumb('accept', ACCEPT_GLYPH, 'Accept (P)')}
|
||||
{thumb('reject', REJECT_GLYPH, 'Reject (X)')}
|
||||
</span>
|
||||
)
|
||||
}
|
||||
@@ -1,12 +1,10 @@
|
||||
import { useCallback, useEffect, useMemo, useRef, useState } from 'react'
|
||||
import { useCallback, useEffect, useRef, useState } from 'react'
|
||||
import { Link, useNavigate, useParams } from 'react-router-dom'
|
||||
import { api, postDownload, sha256Hex, uploadFile } from '../api'
|
||||
import Gallery from '../components/Gallery'
|
||||
import Lightbox from '../components/Lightbox'
|
||||
import SelectionBar, { fmtBytes } from '../components/SelectionBar'
|
||||
import Stars from '../components/Stars'
|
||||
import Thumbs from '../components/Thumbs'
|
||||
import useLightbox from '../useLightbox'
|
||||
import useSelection from '../useSelection'
|
||||
|
||||
function fmtEta(seconds) {
|
||||
@@ -18,74 +16,6 @@ function fmtEta(seconds) {
|
||||
|
||||
const UPLOAD_CONCURRENCY = 3
|
||||
|
||||
const FEEDBACK_FILTERS = [
|
||||
{ key: 'all', label: 'All' },
|
||||
{ key: 'accept', label: '👍' },
|
||||
{ key: 'reject', label: '👎' },
|
||||
{ key: 'undecided', label: 'Undecided' },
|
||||
]
|
||||
|
||||
// Expiry convention, in one place for the create form and the row editor:
|
||||
// end of the chosen day in the photographer's local timezone — date-only
|
||||
// strings would parse as UTC midnight and expire a day early.
|
||||
const endOfDayIso = (day) => (day ? new Date(`${day}T23:59:59`).toISOString() : null)
|
||||
|
||||
// ISO timestamp -> local yyyy-mm-dd for date inputs.
|
||||
const localDate = (iso) => {
|
||||
const d = new Date(iso)
|
||||
return `${d.getFullYear()}-${String(d.getMonth() + 1).padStart(2, '0')}-${String(d.getDate()).padStart(2, '0')}`
|
||||
}
|
||||
|
||||
// Staged expiry editor: commits on blur/Enter, never per keystroke — typing
|
||||
// a year fires change events with bogus intermediate dates (year 0002) that
|
||||
// must not hit the live link. The ✕ clears explicitly; Safari's date input
|
||||
// has no native clear control.
|
||||
function ExpiryDate({ value, onCommit }) {
|
||||
const current = value ? localDate(value) : ''
|
||||
const [draft, setDraft] = useState(current)
|
||||
useEffect(() => setDraft(current), [current])
|
||||
|
||||
const commit = () => {
|
||||
if (draft === current) return
|
||||
// A half-typed year (e.g. 0002) can survive until blur; don't persist it.
|
||||
if (draft && draft.slice(0, 4) < '2000') {
|
||||
setDraft(current)
|
||||
return
|
||||
}
|
||||
onCommit(endOfDayIso(draft))
|
||||
}
|
||||
|
||||
return (
|
||||
<label className="row field-label" title="Expiry date — empty means the link never expires">
|
||||
<span className="muted">expires</span>
|
||||
<input
|
||||
type="date"
|
||||
value={draft}
|
||||
onChange={(e) => setDraft(e.target.value)}
|
||||
onBlur={commit}
|
||||
onKeyDown={(e) => {
|
||||
if (e.key === 'Enter') e.target.blur()
|
||||
}}
|
||||
/>
|
||||
{draft ? (
|
||||
<button
|
||||
type="button"
|
||||
className="btn btn-ghost"
|
||||
title="Remove expiry — link never expires"
|
||||
onClick={() => {
|
||||
setDraft('')
|
||||
onCommit(null)
|
||||
}}
|
||||
>
|
||||
✕
|
||||
</button>
|
||||
) : (
|
||||
<span className="muted">never</span>
|
||||
)}
|
||||
</label>
|
||||
)
|
||||
}
|
||||
|
||||
function UploadZone({ albumId, onUploaded }) {
|
||||
const [queue, setQueue] = useState([])
|
||||
const [dragging, setDragging] = useState(false)
|
||||
@@ -141,13 +71,16 @@ function UploadZone({ albumId, onUploaded }) {
|
||||
setQueue((q) => q.map((x) => (x.key === item.key ? { ...x, ...patch } : x)))
|
||||
const transfer = async () => {
|
||||
// Hash locally first: content the album already has is skipped
|
||||
// without transferring a single byte.
|
||||
// without transferring a single byte. Files too large to hash in the
|
||||
// browser (null) fall straight through to a normal upload.
|
||||
update({ status: 'checking' })
|
||||
try {
|
||||
const hash = await sha256Hex(item.file)
|
||||
await api(`/api/albums/${albumId}/photos/by-hash/${hash}`)
|
||||
update({ status: 'skipped', progress: 1 })
|
||||
return
|
||||
if (hash) {
|
||||
await api(`/api/albums/${albumId}/photos/by-hash/${hash}`)
|
||||
update({ status: 'skipped', progress: 1 })
|
||||
return
|
||||
}
|
||||
} catch {
|
||||
// 404 (not there yet) or hashing unavailable — upload normally.
|
||||
}
|
||||
@@ -266,7 +199,11 @@ function SharesPanel({ albumId }) {
|
||||
label: form.label,
|
||||
password: form.password || null,
|
||||
allow_download: form.allow_download,
|
||||
expires_at: endOfDayIso(form.expires_at),
|
||||
// End of the chosen day in the photographer's local timezone —
|
||||
// date-only strings would parse as UTC midnight and expire a day early.
|
||||
expires_at: form.expires_at
|
||||
? new Date(`${form.expires_at}T23:59:59`).toISOString()
|
||||
: null,
|
||||
},
|
||||
})
|
||||
setForm({ label: '', password: '', allow_download: true, expires_at: '' })
|
||||
@@ -283,18 +220,6 @@ function SharesPanel({ albumId }) {
|
||||
setTimeout(() => setCopied(null), 1500)
|
||||
}
|
||||
|
||||
const update = async (shareId, patch) => {
|
||||
try {
|
||||
const updated = await api(`/api/shares/${shareId}`, { method: 'PATCH', body: patch })
|
||||
setShares((list) => list.map((s) => (s.id === shareId ? updated : s)))
|
||||
setError(null)
|
||||
} catch (e) {
|
||||
setError(e.message)
|
||||
// Re-sync the controlled inputs with what the server actually has.
|
||||
load()
|
||||
}
|
||||
}
|
||||
|
||||
return (
|
||||
<section className="panel">
|
||||
<h2>Client links</h2>
|
||||
@@ -309,20 +234,15 @@ function SharesPanel({ albumId }) {
|
||||
<span className="muted">
|
||||
{s.has_password ? '🔒 password' : 'no password'}
|
||||
{' · '}
|
||||
{s.rating_count} ratings, {s.tag_count} tags, 👍 {s.accept_count} 👎{' '}
|
||||
{s.reject_count}
|
||||
{s.allow_download ? 'downloads on' : 'downloads off'}
|
||||
{s.expires_at
|
||||
? ` · expires ${new Date(s.expires_at).toLocaleDateString()}`
|
||||
: ' · never expires'}
|
||||
{' · '}
|
||||
{s.rating_count} ratings, {s.tag_count} tags
|
||||
</span>
|
||||
</div>
|
||||
<div className="row">
|
||||
<label className="select-toggle" title="Allow this link to download originals/ZIPs">
|
||||
<input
|
||||
type="checkbox"
|
||||
checked={s.allow_download}
|
||||
onChange={(e) => update(s.id, { allow_download: e.target.checked })}
|
||||
/>
|
||||
downloads
|
||||
</label>
|
||||
<ExpiryDate value={s.expires_at} onCommit={(iso) => update(s.id, { expires_at: iso })} />
|
||||
{s.locked && (
|
||||
<button
|
||||
className="btn"
|
||||
@@ -403,6 +323,9 @@ export default function AlbumPage() {
|
||||
const navigate = useNavigate()
|
||||
const [detail, setDetail] = useState(null)
|
||||
const [error, setError] = useState(null)
|
||||
// Track the open photo by id, not index — the polling refetch can reorder
|
||||
// the array underneath an open lightbox.
|
||||
const [lightboxId, setLightboxId] = useState(null)
|
||||
|
||||
const load = useCallback(
|
||||
() => api(`/api/albums/${id}`).then(setDetail).catch((e) => setError(e.message)),
|
||||
@@ -421,7 +344,21 @@ export default function AlbumPage() {
|
||||
}, [hasPending, load])
|
||||
|
||||
const ready = (detail?.photos ?? []).filter((p) => p.status === 'ready')
|
||||
const feedback = detail?.feedback ?? {}
|
||||
const { selected, toggle, selectAll, clear, selectedBytes, totalBytes } = useSelection(ready)
|
||||
const lightboxIndex = ready.findIndex((p) => p.id === lightboxId)
|
||||
|
||||
// If the open photo leaves the ready list (deleted elsewhere, reprocess),
|
||||
// close for good — otherwise the lightbox would pop back open when the
|
||||
// photo returns to ready.
|
||||
useEffect(() => {
|
||||
if (lightboxId && lightboxIndex < 0) setLightboxId(null)
|
||||
}, [lightboxId, lightboxIndex])
|
||||
|
||||
if (error) return <p className="error">{error}</p>
|
||||
if (!detail) return <p className="muted">Loading…</p>
|
||||
|
||||
const { album, photos, feedback } = detail
|
||||
const notReady = photos.filter((p) => p.status !== 'ready')
|
||||
|
||||
const avgRating = (photoId) => {
|
||||
const ratings = feedback[photoId]?.ratings || []
|
||||
@@ -429,44 +366,6 @@ export default function AlbumPage() {
|
||||
return ratings.reduce((sum, r) => sum + r.rating, 0) / ratings.length
|
||||
}
|
||||
|
||||
// Two combinable filter dimensions over client feedback: verdict chips
|
||||
// plus a minimum-average-stars threshold (0 = off).
|
||||
const [filter, setFilter] = useState('all')
|
||||
const [minStars, setMinStars] = useState(0)
|
||||
const matchesVerdict = (p, key) => {
|
||||
if (key === 'all') return true
|
||||
const verdicts = feedback[p.id]?.verdicts || []
|
||||
if (key === 'accept') return verdicts.some((v) => v.verdict === 'accept')
|
||||
if (key === 'reject') return verdicts.some((v) => v.verdict === 'reject')
|
||||
return verdicts.length === 0
|
||||
}
|
||||
const shown = ready.filter(
|
||||
(p) => matchesVerdict(p, filter) && (minStars === 0 || (avgRating(p.id) ?? 0) >= minStars),
|
||||
)
|
||||
const filterCounts = useMemo(() => {
|
||||
const counts = { all: ready.length, accept: 0, reject: 0, undecided: 0 }
|
||||
for (const p of ready) {
|
||||
const verdicts = feedback[p.id]?.verdicts || []
|
||||
if (verdicts.some((v) => v.verdict === 'accept')) counts.accept += 1
|
||||
if (verdicts.some((v) => v.verdict === 'reject')) counts.reject += 1
|
||||
if (verdicts.length === 0) counts.undecided += 1
|
||||
}
|
||||
return counts
|
||||
}, [detail])
|
||||
|
||||
// Selection spans all ready photos; the bar and bulk actions cover only
|
||||
// the current view, like on the share page.
|
||||
const { selected, toggle, selectAll, clear } = useSelection(ready)
|
||||
const shownSelected = shown.filter((p) => selected.has(p.id))
|
||||
const sumBytes = (list) => list.reduce((sum, p) => sum + p.size_bytes, 0)
|
||||
const lightbox = useLightbox(shown)
|
||||
|
||||
if (error) return <p className="error">{error}</p>
|
||||
if (!detail) return <p className="muted">Loading…</p>
|
||||
|
||||
const { album, photos } = detail
|
||||
const notReady = photos.filter((p) => p.status !== 'ready')
|
||||
|
||||
const rename = async () => {
|
||||
const name = prompt('Album name', album.name)
|
||||
if (name && name.trim()) {
|
||||
@@ -483,24 +382,11 @@ export default function AlbumPage() {
|
||||
|
||||
const removePhoto = async (photoId) => {
|
||||
if (!confirm('Delete this photo?')) return
|
||||
lightbox.close()
|
||||
setLightboxId(null)
|
||||
await api(`/api/photos/${photoId}`, { method: 'DELETE' })
|
||||
load()
|
||||
}
|
||||
|
||||
const removeSelected = async () => {
|
||||
const ids = shownSelected.map((p) => p.id)
|
||||
if (!confirm(`Delete ${ids.length} selected photo${ids.length === 1 ? '' : 's'}? This cannot be undone.`))
|
||||
return
|
||||
try {
|
||||
await api('/api/photos/delete', { method: 'POST', body: { ids } })
|
||||
clear()
|
||||
} catch (e) {
|
||||
alert(`Delete failed: ${e.message}`)
|
||||
}
|
||||
load()
|
||||
}
|
||||
|
||||
return (
|
||||
<>
|
||||
<div className="page-head">
|
||||
@@ -551,43 +437,17 @@ export default function AlbumPage() {
|
||||
</section>
|
||||
)}
|
||||
|
||||
{ready.length > 0 && (
|
||||
<div className="filter-bar filter-bar-admin">
|
||||
{FEEDBACK_FILTERS.map((f) => (
|
||||
<button
|
||||
key={f.key}
|
||||
className={`filter-chip${filter === f.key ? ' active' : ''}`}
|
||||
onClick={() => setFilter(f.key)}
|
||||
>
|
||||
{f.label} {filterCounts[f.key]}
|
||||
</button>
|
||||
))}
|
||||
<span
|
||||
className={`filter-stars${minStars > 0 ? ' active' : ''}`}
|
||||
title="Minimum average rating — click a star to filter, click it again to clear"
|
||||
>
|
||||
<Stars value={minStars} onChange={(n) => setMinStars(n)} small />
|
||||
{minStars > 0 && <span className="muted">≥ {minStars}</span>}
|
||||
</span>
|
||||
</div>
|
||||
)}
|
||||
|
||||
<Gallery
|
||||
photos={shown}
|
||||
onOpen={lightbox.openAt}
|
||||
photos={ready}
|
||||
onOpen={(i) => setLightboxId(ready[i].id)}
|
||||
selected={selected}
|
||||
onToggleSelect={(photoId, shift) => toggle(photoId, shift, shown)}
|
||||
onToggleSelect={toggle}
|
||||
overlay={(p) => {
|
||||
const avg = avgRating(p.id)
|
||||
const tagCount = feedback[p.id]?.tags.length || 0
|
||||
const verdicts = feedback[p.id]?.verdicts || []
|
||||
const accepts = verdicts.filter((v) => v.verdict === 'accept').length
|
||||
const rejects = verdicts.length - accepts
|
||||
if (avg === null && tagCount === 0 && accepts === 0 && rejects === 0) return null
|
||||
if (avg === null && tagCount === 0) return null
|
||||
return (
|
||||
<div className="g-overlay">
|
||||
{accepts > 0 && <span>👍 {accepts}</span>}
|
||||
{rejects > 0 && <span>👎 {rejects}</span>}
|
||||
{avg !== null && <span>★ {avg.toFixed(1)}</span>}
|
||||
{tagCount > 0 && <span># {tagCount}</span>}
|
||||
</div>
|
||||
@@ -597,48 +457,32 @@ export default function AlbumPage() {
|
||||
{ready.length === 0 && notReady.length === 0 && (
|
||||
<p className="muted">No photos yet — drop some above.</p>
|
||||
)}
|
||||
{ready.length > 0 && shown.length === 0 && (
|
||||
<p className="muted">No photos match this filter.</p>
|
||||
)}
|
||||
|
||||
<SelectionBar
|
||||
count={shownSelected.length}
|
||||
total={shown.length}
|
||||
selectedBytes={sumBytes(shownSelected)}
|
||||
totalBytes={sumBytes(shown)}
|
||||
onSelectAll={() => selectAll(shown)}
|
||||
count={selected.size}
|
||||
total={ready.length}
|
||||
selectedBytes={selectedBytes}
|
||||
totalBytes={totalBytes}
|
||||
onSelectAll={selectAll}
|
||||
onClear={clear}
|
||||
onDownload={() =>
|
||||
postDownload(`/api/albums/${id}/zip`, shownSelected.map((p) => p.id).join(','))
|
||||
}
|
||||
onDownloadAll={() =>
|
||||
postDownload(`/api/albums/${id}/zip`, filter === 'all' ? '' : shown.map((p) => p.id).join(','))
|
||||
}
|
||||
onDelete={removeSelected}
|
||||
onDownload={() => postDownload(`/api/albums/${id}/zip`, [...selected].join(','))}
|
||||
onDownloadAll={() => postDownload(`/api/albums/${id}/zip`)}
|
||||
/>
|
||||
|
||||
{lightbox.index >= 0 && (
|
||||
{lightboxIndex >= 0 && (
|
||||
<Lightbox
|
||||
photos={shown}
|
||||
index={lightbox.index}
|
||||
onClose={lightbox.close}
|
||||
onNav={lightbox.openAt}
|
||||
actions={[
|
||||
{ keys: ['s'], help: ['S', 'select for download'], run: (p) => toggle(p.id) },
|
||||
]}
|
||||
photos={ready}
|
||||
index={lightboxIndex}
|
||||
onClose={() => setLightboxId(null)}
|
||||
onNav={(i) => setLightboxId(ready[i].id)}
|
||||
footer={(p) => {
|
||||
const fb = feedback[p.id] || { ratings: [], verdicts: [], tags: [] }
|
||||
const fb = feedback[p.id] || { ratings: [], tags: [] }
|
||||
return (
|
||||
<div className="admin-footer">
|
||||
<div className="feedback">
|
||||
{fb.ratings.length === 0 && fb.verdicts.length === 0 && fb.tags.length === 0 && (
|
||||
{fb.ratings.length === 0 && fb.tags.length === 0 && (
|
||||
<span className="muted">No client feedback yet</span>
|
||||
)}
|
||||
{fb.verdicts.map((v, i) => (
|
||||
<span key={`v${i}`} className="feedback-item">
|
||||
{v.share_label || 'client'}: <Thumbs value={v.verdict} small />
|
||||
</span>
|
||||
))}
|
||||
{fb.ratings.map((r, i) => (
|
||||
<span key={`r${i}`} className="feedback-item">
|
||||
{r.share_label || 'client'}: <Stars value={r.rating} small />
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
import { useCallback, useEffect, useMemo, useRef, useState } from 'react'
|
||||
import { useCallback, useEffect, useState } from 'react'
|
||||
import { useParams } from 'react-router-dom'
|
||||
import { api, postDownload } from '../api'
|
||||
import Gallery from '../components/Gallery'
|
||||
@@ -6,49 +6,18 @@ import Lightbox from '../components/Lightbox'
|
||||
import SelectionBar from '../components/SelectionBar'
|
||||
import Stars from '../components/Stars'
|
||||
import TagEditor from '../components/TagEditor'
|
||||
import Thumbs from '../components/Thumbs'
|
||||
import useLightbox from '../useLightbox'
|
||||
import useSelection from '../useSelection'
|
||||
|
||||
const FILTERS = [
|
||||
{ key: 'all', label: 'All' },
|
||||
{ key: 'accept', label: '👍' },
|
||||
{ key: 'reject', label: '👎' },
|
||||
{ key: 'undecided', label: 'Undecided' },
|
||||
]
|
||||
|
||||
const matchesFilter = (photo, key) =>
|
||||
key === 'all' || (key === 'undecided' ? !photo.my_verdict : photo.my_verdict === key)
|
||||
|
||||
export default function SharePage() {
|
||||
const { token } = useParams()
|
||||
const [view, setView] = useState(null)
|
||||
const [error, setError] = useState(null)
|
||||
const [password, setPassword] = useState('')
|
||||
const [unlockError, setUnlockError] = useState(null)
|
||||
const [filter, setFilter] = useState('all')
|
||||
|
||||
const photos = view?.photos ?? []
|
||||
const visible = useMemo(() => photos.filter((p) => matchesFilter(p, filter)), [photos, filter])
|
||||
const filterCounts = useMemo(() => {
|
||||
const counts = { all: photos.length, accept: 0, reject: 0, undecided: 0 }
|
||||
for (const p of photos) counts[p.my_verdict ?? 'undecided'] += 1
|
||||
return counts
|
||||
}, [photos])
|
||||
|
||||
// Selection spans the whole album (so switching filters keeps it), while
|
||||
// the selection bar describes only the current view: its counts, bytes and
|
||||
// downloads cover the visible photos, and "select all" adds them.
|
||||
const { selected, toggle, selectAll, clear } = useSelection(photos)
|
||||
const visibleSelected = visible.filter((p) => selected.has(p.id))
|
||||
const sumBytes = (list) => list.reduce((sum, p) => sum + p.size_bytes, 0)
|
||||
const lightbox = useLightbox(visible)
|
||||
// Voting the last photo ends the run: fade the modal out over the gallery
|
||||
// instead of cutting hard.
|
||||
const [lightboxFading, setLightboxFading] = useState(false)
|
||||
useEffect(() => {
|
||||
if (lightbox.index < 0) setLightboxFading(false)
|
||||
}, [lightbox.index])
|
||||
const [lightbox, setLightbox] = useState(-1)
|
||||
const { selected, toggle, selectAll, clear, selectedBytes, totalBytes } = useSelection(
|
||||
view?.photos ?? [],
|
||||
)
|
||||
|
||||
const load = useCallback(
|
||||
() => api(`/api/share/${token}`).then(setView).catch((e) => setError(e.message)),
|
||||
@@ -76,77 +45,29 @@ export default function SharePage() {
|
||||
}))
|
||||
}
|
||||
|
||||
// Optimistic write: patch local state, PUT, reload from the server on
|
||||
// failure to undo the patch.
|
||||
const saveFeedback = async (photo, patch, endpoint, body) => {
|
||||
patchPhoto(photo.id, patch)
|
||||
const setRating = async (photo, rating) => {
|
||||
patchPhoto(photo.id, { my_rating: rating || null })
|
||||
try {
|
||||
await api(`/api/share/${token}/photos/${photo.id}/${endpoint}`, { method: 'PUT', body })
|
||||
await api(`/api/share/${token}/photos/${photo.id}/rating`, {
|
||||
method: 'PUT',
|
||||
body: { rating },
|
||||
})
|
||||
} catch {
|
||||
load()
|
||||
}
|
||||
}
|
||||
const setRating = (photo, rating) =>
|
||||
saveFeedback(photo, { my_rating: rating || null }, 'rating', { rating })
|
||||
const setVerdict = (photo, verdict) =>
|
||||
saveFeedback(photo, { my_verdict: verdict }, 'verdict', { verdict })
|
||||
const setTags = (photo, tags) => saveFeedback(photo, { my_tags: tags }, 'tags', { tags })
|
||||
|
||||
// Keyboard votes navigate away from the photo they change, so a transient
|
||||
// toast names what just happened to it — without it the jump reads as
|
||||
// "did that register?".
|
||||
const [flash, setFlash] = useState(null)
|
||||
const flashSeq = useRef(0)
|
||||
const flashTimer = useRef()
|
||||
const showFlash = (text) => {
|
||||
flashSeq.current += 1
|
||||
setFlash({ text, key: flashSeq.current })
|
||||
clearTimeout(flashTimer.current)
|
||||
flashTimer.current = setTimeout(() => setFlash(null), 1400)
|
||||
const setTags = async (photo, tags) => {
|
||||
patchPhoto(photo.id, { my_tags: tags })
|
||||
try {
|
||||
await api(`/api/share/${token}/photos/${photo.id}/tags`, {
|
||||
method: 'PUT',
|
||||
body: { tags },
|
||||
})
|
||||
} catch {
|
||||
load()
|
||||
}
|
||||
}
|
||||
useEffect(() => () => clearTimeout(flashTimer.current), [])
|
||||
|
||||
// Culling flow: vote, then advance to the photo that was next in the
|
||||
// current view. Under a filter that hides the voted photo, the advance
|
||||
// target stays visible, so the run continues seamlessly.
|
||||
const voteAndAdvance = (photo, verdict) => {
|
||||
const next = visible[lightbox.index + 1]
|
||||
setVerdict(photo, verdict)
|
||||
showFlash(
|
||||
verdict === 'accept'
|
||||
? `👍 ${photo.filename}`
|
||||
: verdict === 'reject'
|
||||
? `👎 ${photo.filename}`
|
||||
: `↺ ${photo.filename} cleared`,
|
||||
)
|
||||
if (next) lightbox.show(next.id)
|
||||
// Last photo voted: the run is done — fade back to the gallery.
|
||||
else setLightboxFading(true)
|
||||
}
|
||||
|
||||
const keyActions = [
|
||||
{ keys: ['p'], help: ['P', 'accept and go to next'], run: (p) => voteAndAdvance(p, 'accept') },
|
||||
{ keys: ['x'], help: ['X', 'reject and go to next'], run: (p) => voteAndAdvance(p, 'reject') },
|
||||
{
|
||||
keys: ['u'],
|
||||
help: ['U', 'clear accept / reject'],
|
||||
// When clearing hides the photo from the current filter, advance like
|
||||
// a vote so the lightbox doesn't just close.
|
||||
run: (p) =>
|
||||
matchesFilter({ my_verdict: null }, filter)
|
||||
? setVerdict(p, null)
|
||||
: voteAndAdvance(p, null),
|
||||
},
|
||||
{
|
||||
keys: ['1', '2', '3', '4', '5'],
|
||||
help: ['1–5', 'star rating'],
|
||||
run: (p, key) => setRating(p, Number(key)),
|
||||
},
|
||||
{ keys: ['0'], help: ['0', 'clear star rating'], run: (p) => setRating(p, 0) },
|
||||
...(view?.allow_download
|
||||
? [{ keys: ['s'], help: ['S', 'select for download'], run: (p) => toggle(p.id) }]
|
||||
: []),
|
||||
]
|
||||
|
||||
if (error) return <div className="center-page">{error}</div>
|
||||
if (!view) return <div className="center-page">Loading…</div>
|
||||
@@ -179,89 +100,49 @@ export default function SharePage() {
|
||||
<h1>{view.album_name}</h1>
|
||||
{view.album_description && <p className="muted">{view.album_description}</p>}
|
||||
<p className="muted">
|
||||
{photos.length} photo{photos.length === 1 ? '' : 's'} · tap a photo to view, rate and
|
||||
tag · swipe ↑ to accept, ↓ to reject · <kbd>?</kbd> shows keyboard shortcuts
|
||||
{view.photos.length} photo{view.photos.length === 1 ? '' : 's'} · click a photo to view,
|
||||
rate and tag
|
||||
</p>
|
||||
{photos.length > 0 && (
|
||||
<div className="filter-bar">
|
||||
{FILTERS.map((f) => (
|
||||
<button
|
||||
key={f.key}
|
||||
className={`filter-chip${filter === f.key ? ' active' : ''}`}
|
||||
onClick={() => setFilter(f.key)}
|
||||
>
|
||||
{f.label} {filterCounts[f.key]}
|
||||
</button>
|
||||
))}
|
||||
</div>
|
||||
)}
|
||||
</header>
|
||||
<main className="page">
|
||||
<Gallery
|
||||
photos={visible}
|
||||
onOpen={lightbox.openAt}
|
||||
photos={view.photos}
|
||||
onOpen={setLightbox}
|
||||
selected={view.allow_download ? selected : undefined}
|
||||
// Shift-ranges must walk the filtered view, not the full album —
|
||||
// otherwise hidden photos get swept into the selection.
|
||||
onToggleSelect={
|
||||
view.allow_download ? (id, shift) => toggle(id, shift, visible) : undefined
|
||||
}
|
||||
onToggleSelect={view.allow_download ? toggle : undefined}
|
||||
overlay={(p) =>
|
||||
p.my_verdict || p.my_rating || p.my_tags.length > 0 ? (
|
||||
p.my_rating || p.my_tags.length > 0 ? (
|
||||
<div className="g-overlay">
|
||||
{p.my_verdict && <span>{p.my_verdict === 'accept' ? '👍' : '👎'}</span>}
|
||||
{p.my_rating && <span>★ {p.my_rating}</span>}
|
||||
{p.my_tags.length > 0 && <span># {p.my_tags.length}</span>}
|
||||
</div>
|
||||
) : null
|
||||
}
|
||||
/>
|
||||
{photos.length === 0 && (
|
||||
{view.photos.length === 0 && (
|
||||
<p className="center-page muted">Nothing here yet — check back soon.</p>
|
||||
)}
|
||||
{photos.length > 0 && visible.length === 0 && (
|
||||
<p className="center-page muted">No photos match this filter.</p>
|
||||
)}
|
||||
</main>
|
||||
{view.allow_download && (
|
||||
<SelectionBar
|
||||
count={visibleSelected.length}
|
||||
total={visible.length}
|
||||
selectedBytes={sumBytes(visibleSelected)}
|
||||
totalBytes={sumBytes(visible)}
|
||||
onSelectAll={() => selectAll(visible)}
|
||||
count={selected.size}
|
||||
total={view.photos.length}
|
||||
selectedBytes={selectedBytes}
|
||||
totalBytes={totalBytes}
|
||||
onSelectAll={selectAll}
|
||||
onClear={clear}
|
||||
onDownload={() =>
|
||||
postDownload(`/api/share/${token}/zip`, visibleSelected.map((p) => p.id).join(','))
|
||||
}
|
||||
onDownloadAll={() =>
|
||||
// Under a filter, "download all" means all photos shown.
|
||||
postDownload(
|
||||
`/api/share/${token}/zip`,
|
||||
filter === 'all' ? '' : visible.map((p) => p.id).join(','),
|
||||
)
|
||||
}
|
||||
onDownload={() => postDownload(`/api/share/${token}/zip`, [...selected].join(','))}
|
||||
onDownloadAll={() => postDownload(`/api/share/${token}/zip`)}
|
||||
/>
|
||||
)}
|
||||
{lightbox.index >= 0 && (
|
||||
{lightbox >= 0 && (
|
||||
<Lightbox
|
||||
photos={visible}
|
||||
index={lightbox.index}
|
||||
onClose={lightbox.close}
|
||||
onNav={lightbox.openAt}
|
||||
actions={keyActions}
|
||||
closing={lightboxFading}
|
||||
onClosed={() => {
|
||||
setLightboxFading(false)
|
||||
lightbox.close()
|
||||
}}
|
||||
gestures={{
|
||||
up: (p) => voteAndAdvance(p, 'accept'),
|
||||
down: (p) => voteAndAdvance(p, 'reject'),
|
||||
}}
|
||||
photos={view.photos}
|
||||
index={lightbox}
|
||||
onClose={() => setLightbox(-1)}
|
||||
onNav={setLightbox}
|
||||
footer={(p) => (
|
||||
<div className="client-footer">
|
||||
<Thumbs value={p.my_verdict} onChange={(v) => setVerdict(p, v)} />
|
||||
<Stars value={p.my_rating || 0} onChange={(r) => setRating(p, r)} />
|
||||
<TagEditor tags={p.my_tags} onChange={(tags) => setTags(p, tags)} />
|
||||
{view.allow_download && (
|
||||
@@ -283,11 +164,6 @@ export default function SharePage() {
|
||||
)}
|
||||
/>
|
||||
)}
|
||||
{flash && (
|
||||
<div key={flash.key} className="action-flash">
|
||||
{flash.text}
|
||||
</div>
|
||||
)}
|
||||
</>
|
||||
)
|
||||
}
|
||||
|
||||
+1
-286
@@ -451,18 +451,6 @@ progress {
|
||||
.lb-stage {
|
||||
flex: 1;
|
||||
min-height: 0;
|
||||
position: relative;
|
||||
overflow: hidden;
|
||||
/* Swipes are handled in JS; stop the browser from panning/zooming. */
|
||||
touch-action: none;
|
||||
}
|
||||
.lb-track {
|
||||
position: absolute;
|
||||
inset: 0;
|
||||
}
|
||||
.lb-slide {
|
||||
position: absolute;
|
||||
inset: 0;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
@@ -474,79 +462,6 @@ progress {
|
||||
object-fit: contain;
|
||||
cursor: default;
|
||||
}
|
||||
.lb-flick {
|
||||
z-index: 2;
|
||||
position: absolute;
|
||||
inset: 0;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
font-size: 5rem;
|
||||
opacity: 0;
|
||||
pointer-events: none;
|
||||
text-shadow: 0 2px 24px rgba(0, 0, 0, 0.6);
|
||||
}
|
||||
/* Next photo waiting behind a vote drag, before its zoom-in. */
|
||||
.lb-behind {
|
||||
transform: scale(0.22);
|
||||
opacity: 0;
|
||||
}
|
||||
/* Ghost of a just-voted photo flying off; the vote itself is already saved. */
|
||||
.lb-ghost {
|
||||
z-index: 3;
|
||||
pointer-events: none;
|
||||
}
|
||||
.lb-exit-up {
|
||||
animation: lb-exit-up 0.26s ease-in forwards;
|
||||
}
|
||||
.lb-exit-down {
|
||||
animation: lb-exit-down 0.26s ease-in forwards;
|
||||
}
|
||||
@keyframes lb-exit-up {
|
||||
from {
|
||||
transform: translateY(var(--dy)) rotate(var(--rot));
|
||||
}
|
||||
to {
|
||||
transform: translateY(-120vh) rotate(var(--rot));
|
||||
opacity: 0;
|
||||
}
|
||||
}
|
||||
@keyframes lb-exit-down {
|
||||
from {
|
||||
transform: translateY(var(--dy)) rotate(var(--rot));
|
||||
}
|
||||
to {
|
||||
transform: translateY(120vh) rotate(var(--rot));
|
||||
opacity: 0;
|
||||
}
|
||||
}
|
||||
.lb-hidden {
|
||||
opacity: 0;
|
||||
}
|
||||
/* Whole-modal fade after voting the last photo — the gallery is behind it. */
|
||||
.lightbox.lb-closing {
|
||||
animation: lb-fade-out 0.26s ease forwards;
|
||||
pointer-events: none;
|
||||
}
|
||||
@keyframes lb-fade-out {
|
||||
to {
|
||||
opacity: 0;
|
||||
}
|
||||
}
|
||||
/* The photo taking over after a vote zooms in organically. */
|
||||
.lb-enter {
|
||||
animation: lb-enter 0.26s ease-out;
|
||||
}
|
||||
@keyframes lb-enter {
|
||||
from {
|
||||
transform: scale(0.3);
|
||||
opacity: 0.2;
|
||||
}
|
||||
to {
|
||||
transform: scale(1);
|
||||
opacity: 1;
|
||||
}
|
||||
}
|
||||
.lb-nav {
|
||||
position: absolute;
|
||||
top: 50%;
|
||||
@@ -619,150 +534,6 @@ progress {
|
||||
cursor: default;
|
||||
}
|
||||
|
||||
/* thumbs (accept / reject) */
|
||||
.thumbs {
|
||||
display: inline-flex;
|
||||
gap: 0.15rem;
|
||||
}
|
||||
.thumb {
|
||||
background: none;
|
||||
border: none;
|
||||
font-size: 1.35rem;
|
||||
line-height: 1;
|
||||
padding: 0 0.15rem;
|
||||
cursor: pointer;
|
||||
filter: grayscale(1);
|
||||
opacity: 0.4;
|
||||
transition: opacity 0.12s;
|
||||
}
|
||||
.thumb:hover:enabled {
|
||||
opacity: 0.8;
|
||||
}
|
||||
.thumb.active {
|
||||
filter: none;
|
||||
opacity: 1;
|
||||
}
|
||||
.thumb:disabled {
|
||||
cursor: default;
|
||||
}
|
||||
.thumbs-small .thumb {
|
||||
font-size: 0.95rem;
|
||||
}
|
||||
|
||||
/* verdict filter */
|
||||
.filter-bar {
|
||||
display: flex;
|
||||
justify-content: center;
|
||||
flex-wrap: wrap;
|
||||
gap: 0.5rem;
|
||||
margin-top: 0.9rem;
|
||||
}
|
||||
.filter-chip {
|
||||
background: var(--panel);
|
||||
border: 1px solid var(--panel-2);
|
||||
border-radius: 999px;
|
||||
color: var(--muted);
|
||||
padding: 0.25rem 0.8rem;
|
||||
font-size: 0.85rem;
|
||||
cursor: pointer;
|
||||
}
|
||||
.filter-chip.active {
|
||||
background: var(--panel-2);
|
||||
color: var(--text);
|
||||
border-color: var(--accent);
|
||||
}
|
||||
.filter-bar-admin {
|
||||
justify-content: flex-start;
|
||||
margin: 0 0 0.75rem;
|
||||
}
|
||||
.filter-stars {
|
||||
display: inline-flex;
|
||||
align-items: center;
|
||||
gap: 0.35rem;
|
||||
background: var(--panel);
|
||||
border: 1px solid var(--panel-2);
|
||||
border-radius: 999px;
|
||||
padding: 0.1rem 0.7rem;
|
||||
font-size: 0.85rem;
|
||||
}
|
||||
.filter-stars.active {
|
||||
border-color: var(--accent);
|
||||
}
|
||||
.filter-stars .star {
|
||||
cursor: pointer;
|
||||
}
|
||||
|
||||
/* transient action feedback (keyboard votes that navigate away) */
|
||||
.action-flash {
|
||||
position: fixed;
|
||||
top: 3rem;
|
||||
left: 50%;
|
||||
transform: translateX(-50%);
|
||||
z-index: 110;
|
||||
background: var(--panel);
|
||||
border: 1px solid var(--panel-2);
|
||||
border-radius: 999px;
|
||||
padding: 0.35rem 1rem;
|
||||
font-size: 0.9rem;
|
||||
white-space: nowrap;
|
||||
pointer-events: none;
|
||||
animation: flash-fade 1.4s ease forwards;
|
||||
}
|
||||
@keyframes flash-fade {
|
||||
0% {
|
||||
opacity: 0;
|
||||
transform: translate(-50%, -6px);
|
||||
}
|
||||
8%,
|
||||
70% {
|
||||
opacity: 1;
|
||||
transform: translate(-50%, 0);
|
||||
}
|
||||
100% {
|
||||
opacity: 0;
|
||||
transform: translate(-50%, 0);
|
||||
}
|
||||
}
|
||||
|
||||
/* lightbox shortcut help */
|
||||
.lb-help {
|
||||
position: absolute;
|
||||
inset: 0;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
background: rgba(8, 9, 11, 0.6);
|
||||
z-index: 102;
|
||||
}
|
||||
.lb-help-card {
|
||||
background: var(--panel);
|
||||
border: 1px solid var(--panel-2);
|
||||
border-radius: 12px;
|
||||
padding: 1.1rem 1.5rem 1.25rem;
|
||||
min-width: 280px;
|
||||
cursor: default;
|
||||
}
|
||||
.lb-help-card h3 {
|
||||
font-size: 0.95rem;
|
||||
margin: 0 0 0.6rem;
|
||||
}
|
||||
.lb-help-row {
|
||||
display: flex;
|
||||
align-items: baseline;
|
||||
justify-content: space-between;
|
||||
gap: 1.5rem;
|
||||
padding: 0.18rem 0;
|
||||
font-size: 0.88rem;
|
||||
}
|
||||
kbd {
|
||||
background: var(--panel-2);
|
||||
border-radius: 4px;
|
||||
padding: 0.08rem 0.45rem;
|
||||
font-family: ui-monospace, SFMono-Regular, Menlo, monospace;
|
||||
font-size: 0.8rem;
|
||||
white-space: nowrap;
|
||||
}
|
||||
|
||||
/* tags */
|
||||
.tag-editor {
|
||||
display: inline-flex;
|
||||
@@ -793,68 +564,12 @@ kbd {
|
||||
padding: 0;
|
||||
}
|
||||
|
||||
/* Touch devices: no hover — selection checkmarks must always be visible,
|
||||
and the overlay nav arrows give way to swiping. */
|
||||
@media (hover: none) {
|
||||
.g-check {
|
||||
opacity: 1;
|
||||
}
|
||||
.lb-nav {
|
||||
display: none;
|
||||
}
|
||||
/* No visible arrows to keep clear of — give the photo the width. */
|
||||
.lb-slide {
|
||||
padding: 0 0.75rem;
|
||||
}
|
||||
}
|
||||
|
||||
@media (max-width: 700px) {
|
||||
.lb-slide {
|
||||
.lb-stage {
|
||||
padding: 0 0.5rem;
|
||||
}
|
||||
.login-card {
|
||||
padding: 2rem 1.5rem;
|
||||
margin: 0 1rem;
|
||||
}
|
||||
.share-head {
|
||||
padding: 1.25rem 0.75rem 0.25rem;
|
||||
}
|
||||
.lb-footer {
|
||||
padding: 0.5rem 0.6rem calc(0.8rem + env(safe-area-inset-bottom));
|
||||
}
|
||||
.client-footer {
|
||||
gap: 0.8rem;
|
||||
}
|
||||
/* Finger-sized vote and rating targets in the client lightbox. */
|
||||
.client-footer .thumb {
|
||||
font-size: 1.7rem;
|
||||
}
|
||||
.client-footer .star {
|
||||
font-size: 1.8rem;
|
||||
}
|
||||
.select-bar {
|
||||
flex-wrap: wrap;
|
||||
justify-content: center;
|
||||
max-width: calc(100vw - 1.5rem);
|
||||
padding: 0.5rem 0.75rem;
|
||||
bottom: calc(0.75rem + env(safe-area-inset-bottom));
|
||||
}
|
||||
/* Share rows: info and controls stack instead of fighting for one line. */
|
||||
.share-row {
|
||||
flex-direction: column;
|
||||
align-items: stretch;
|
||||
gap: 0.5rem;
|
||||
padding: 0.75rem 0;
|
||||
}
|
||||
.share-row .row {
|
||||
flex-wrap: wrap;
|
||||
row-gap: 0.5rem;
|
||||
}
|
||||
.share-form {
|
||||
flex-direction: column;
|
||||
align-items: stretch;
|
||||
}
|
||||
.share-form > input {
|
||||
width: 100%;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,23 +0,0 @@
|
||||
import { useEffect, useState } from 'react'
|
||||
|
||||
// Lightbox state tracked by photo id, not index — the list can reorder
|
||||
// (polling refetch) or shrink (filter change, delete) underneath an open
|
||||
// lightbox. When the open photo leaves the list, close for good — otherwise
|
||||
// the lightbox would pop back open when the photo returns to the list.
|
||||
export default function useLightbox(photos) {
|
||||
const [openId, setOpenId] = useState(null)
|
||||
const index = openId ? photos.findIndex((p) => p.id === openId) : -1
|
||||
|
||||
useEffect(() => {
|
||||
if (openId && index < 0) setOpenId(null)
|
||||
}, [openId, index])
|
||||
|
||||
return {
|
||||
index,
|
||||
// Bounds-safe: callers may hold a stale index (the list can shrink
|
||||
// between render and dispatch).
|
||||
openAt: (i) => photos[i] && setOpenId(photos[i].id),
|
||||
show: (id) => setOpenId(id),
|
||||
close: () => setOpenId(null),
|
||||
}
|
||||
}
|
||||
@@ -1,12 +1,10 @@
|
||||
import { useEffect, useRef, useState } from 'react'
|
||||
import { useEffect, useState } from 'react'
|
||||
|
||||
// Multi-select over a photo list. Selection lives here (not in the gallery)
|
||||
// so it survives lightbox open/close, and is pruned automatically when
|
||||
// photos disappear from the list (deletes, polling refreshes).
|
||||
export default function useSelection(photos) {
|
||||
const [selected, setSelected] = useState(() => new Set())
|
||||
// Anchor for shift-click range selection: the photo last toggled.
|
||||
const lastToggled = useRef(null)
|
||||
|
||||
useEffect(() => {
|
||||
setSelected((prev) => {
|
||||
@@ -17,43 +15,16 @@ export default function useSelection(photos) {
|
||||
})
|
||||
}, [photos])
|
||||
|
||||
// Shift-toggle selects the whole range from the previously toggled photo
|
||||
// (both directions), so contiguous runs don't need per-photo clicks. The
|
||||
// range walks `list` — the photo order the user is actually looking at —
|
||||
// which callers with a filtered view must pass explicitly, so hidden
|
||||
// photos are never swept into the selection. Anchor updates and range
|
||||
// computation stay out of the setSelected updater: React may re-invoke
|
||||
// updaters (StrictMode does), so they must be pure.
|
||||
const toggle = (photoId, shift = false, list = photos) => {
|
||||
const anchor = lastToggled.current
|
||||
lastToggled.current = photoId
|
||||
if (shift && anchor) {
|
||||
const a = list.findIndex((p) => p.id === anchor)
|
||||
const b = list.findIndex((p) => p.id === photoId)
|
||||
if (a >= 0 && b >= 0) {
|
||||
const range = list.slice(Math.min(a, b), Math.max(a, b) + 1).map((p) => p.id)
|
||||
setSelected((prev) => new Set([...prev, ...range]))
|
||||
return
|
||||
}
|
||||
}
|
||||
const toggle = (photoId) =>
|
||||
setSelected((prev) => {
|
||||
const next = new Set(prev)
|
||||
if (next.has(photoId)) next.delete(photoId)
|
||||
else next.add(photoId)
|
||||
return next
|
||||
})
|
||||
}
|
||||
|
||||
// Adds `list` (the caller's currently visible photos) to the selection —
|
||||
// additive, so selecting all of one filtered view keeps picks from another.
|
||||
const selectAll = (list) =>
|
||||
setSelected((prev) => new Set([...prev, ...list.map((p) => p.id)]))
|
||||
const clear = () => {
|
||||
// Reset the anchor too — a shift-click after Clear must start fresh, not
|
||||
// extend a range from a photo selected before the wipe.
|
||||
lastToggled.current = null
|
||||
setSelected(new Set())
|
||||
}
|
||||
const selectAll = () => setSelected(new Set(photos.map((p) => p.id)))
|
||||
const clear = () => setSelected(new Set())
|
||||
const selectedBytes = photos.reduce((sum, p) => sum + (selected.has(p.id) ? p.size_bytes : 0), 0)
|
||||
const totalBytes = photos.reduce((sum, p) => sum + p.size_bytes, 0)
|
||||
|
||||
|
||||
@@ -1,230 +0,0 @@
|
||||
import { useLayoutEffect, useRef, useState } from 'react'
|
||||
import { ACCEPT_GLYPH, REJECT_GLYPH } from './components/Thumbs'
|
||||
|
||||
const COMMIT_MS = 260
|
||||
const CANCEL_MS = 180
|
||||
const DEAD_ZONE = 12 // px of travel before the axis locks
|
||||
const FLICK_MS = 250 // releases faster than this commit at the lower threshold
|
||||
const H_THRESHOLD = { slow: 70, fast: 30 }
|
||||
const V_THRESHOLD = { slow: 90, fast: 40 }
|
||||
const V_SATURATE = 160 // px of vertical drag for full badge/preview intensity
|
||||
const ZOOM_MAX = 4
|
||||
|
||||
// Touch engine for the lightbox: horizontal swipes navigate, vertical flicks
|
||||
// dispatch gestures.up/down (when provided), two fingers pinch-zoom the
|
||||
// current photo (springs back on release, never votes).
|
||||
//
|
||||
// Navigation and votes are dispatched SYNCHRONOUSLY on release; every
|
||||
// animation afterwards is pure decoration (a ghost flying off, the track
|
||||
// settling). Closing the lightbox, key presses or list changes during an
|
||||
// animation therefore can't drop, duplicate or misdirect an action.
|
||||
//
|
||||
// Per-move motion is written straight to the DOM via refs — dragging costs
|
||||
// no React renders; state changes happen only at axis lock and release.
|
||||
export default function useSwipe({ photo, index, count, onNav, gestures, hasNext }) {
|
||||
const [dragAxis, setDragAxis] = useState(null) // 'h' | 'v' | 'z' while a finger is down
|
||||
const [spring, setSpring] = useState(null) // 'h' | 'v' | 'z': sub-threshold release gliding back
|
||||
const [settleFrom, setSettleFrom] = useState(null) // px the track settles from after a nav commit
|
||||
const [settleRun, setSettleRun] = useState(false)
|
||||
const [exit, setExit] = useState(null) // { photo, dir, dy }: ghost flying off after a vote
|
||||
|
||||
const trackRef = useRef(null)
|
||||
const imgRef = useRef(null)
|
||||
const behindRef = useRef(null)
|
||||
const badgeRef = useRef(null)
|
||||
const g = useRef(null)
|
||||
|
||||
// FLIP: paint the track at the release offset around the NEW index first,
|
||||
// force a style flush, then let it transition to center.
|
||||
useLayoutEffect(() => {
|
||||
if (settleFrom == null) {
|
||||
setSettleRun(false)
|
||||
return
|
||||
}
|
||||
trackRef.current?.getBoundingClientRect()
|
||||
setSettleRun(true)
|
||||
}, [settleFrom])
|
||||
|
||||
const clearManual = () => {
|
||||
for (const ref of [trackRef, imgRef, behindRef, badgeRef]) {
|
||||
if (ref.current) {
|
||||
ref.current.style.transform = ''
|
||||
ref.current.style.opacity = ''
|
||||
ref.current.style.transition = ''
|
||||
ref.current.style.transformOrigin = ''
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
const onTouchStart = (e) => {
|
||||
// Fresh input takes over: decorative animations yield immediately.
|
||||
setSpring(null)
|
||||
setSettleFrom(null)
|
||||
if (e.touches.length === 2 && imgRef.current) {
|
||||
// Second finger at any point turns the gesture into a pinch — a pinch
|
||||
// never navigates and never votes.
|
||||
clearManual()
|
||||
const [a, b] = e.touches
|
||||
const rect = imgRef.current.getBoundingClientRect()
|
||||
const cx = (a.clientX + b.clientX) / 2
|
||||
const cy = (a.clientY + b.clientY) / 2
|
||||
imgRef.current.style.transformOrigin = `${cx - rect.left}px ${cy - rect.top}px`
|
||||
g.current = {
|
||||
mode: 'pinch',
|
||||
d0: Math.hypot(a.clientX - b.clientX, a.clientY - b.clientY),
|
||||
cx,
|
||||
cy,
|
||||
}
|
||||
setDragAxis('z')
|
||||
return
|
||||
}
|
||||
if (e.touches.length !== 1) {
|
||||
g.current = null
|
||||
setDragAxis(null)
|
||||
clearManual()
|
||||
return
|
||||
}
|
||||
const t = e.touches[0]
|
||||
g.current = { mode: 'swipe', x0: t.clientX, y0: t.clientY, t0: e.timeStamp, axis: null, dx: 0, dy: 0 }
|
||||
}
|
||||
|
||||
const onTouchMove = (e) => {
|
||||
const s = g.current
|
||||
if (!s) return
|
||||
if (s.mode === 'pinch') {
|
||||
if (e.touches.length < 2 || !imgRef.current) return
|
||||
const [a, b] = e.touches
|
||||
const scale = Math.min(
|
||||
ZOOM_MAX,
|
||||
Math.max(1, Math.hypot(a.clientX - b.clientX, a.clientY - b.clientY) / s.d0),
|
||||
)
|
||||
const mx = (a.clientX + b.clientX) / 2 - s.cx
|
||||
const my = (a.clientY + b.clientY) / 2 - s.cy
|
||||
imgRef.current.style.transition = 'none'
|
||||
imgRef.current.style.transform = `translate(${mx}px, ${my}px) scale(${scale})`
|
||||
return
|
||||
}
|
||||
if (e.touches.length !== 1) return
|
||||
const t = e.touches[0]
|
||||
s.dx = t.clientX - s.x0
|
||||
s.dy = t.clientY - s.y0
|
||||
if (!s.axis) {
|
||||
if (Math.hypot(s.dx, s.dy) < DEAD_ZONE) return
|
||||
s.axis = Math.abs(s.dx) >= Math.abs(s.dy) || !gestures ? 'h' : 'v'
|
||||
setDragAxis(s.axis)
|
||||
}
|
||||
if (s.axis === 'h') {
|
||||
if (trackRef.current) {
|
||||
trackRef.current.style.transition = 'none'
|
||||
trackRef.current.style.transform = `translateX(${s.dx}px)`
|
||||
}
|
||||
} else {
|
||||
if (imgRef.current) {
|
||||
imgRef.current.style.transition = 'none'
|
||||
imgRef.current.style.transform = `translateY(${s.dy}px) rotate(${s.dy / 40}deg)`
|
||||
}
|
||||
const p = Math.min(1, Math.abs(s.dy) / V_SATURATE)
|
||||
if (behindRef.current) {
|
||||
behindRef.current.style.transition = 'none'
|
||||
behindRef.current.style.transform = `scale(${0.22 + 0.15 * p})`
|
||||
behindRef.current.style.opacity = p
|
||||
}
|
||||
if (badgeRef.current) {
|
||||
badgeRef.current.style.opacity = p
|
||||
badgeRef.current.textContent = s.dy < 0 ? ACCEPT_GLYPH : REJECT_GLYPH
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
const onTouchEnd = (e) => {
|
||||
const s = g.current
|
||||
if (!s) return
|
||||
if (s.mode === 'pinch') {
|
||||
if (e.touches.length > 0) return
|
||||
g.current = null
|
||||
setDragAxis(null)
|
||||
setSpring('z')
|
||||
return
|
||||
}
|
||||
g.current = null
|
||||
setDragAxis(null)
|
||||
if (!s.axis) {
|
||||
clearManual()
|
||||
return
|
||||
}
|
||||
const quick = e.timeStamp - s.t0 < FLICK_MS
|
||||
const past = (v, th) => Math.abs(v) > th.slow || (quick && Math.abs(v) > th.fast)
|
||||
if (s.axis === 'h') {
|
||||
if (s.dx < 0 && past(s.dx, H_THRESHOLD) && index < count - 1) {
|
||||
onNav(index + 1)
|
||||
setSettleFrom(s.dx + window.innerWidth)
|
||||
} else if (s.dx > 0 && past(s.dx, H_THRESHOLD) && index > 0) {
|
||||
onNav(index - 1)
|
||||
setSettleFrom(s.dx - window.innerWidth)
|
||||
} else {
|
||||
setSpring('h')
|
||||
}
|
||||
} else if (past(s.dy, V_THRESHOLD)) {
|
||||
const dir = s.dy < 0 ? 'up' : 'down'
|
||||
gestures?.[dir]?.(photo)
|
||||
clearManual()
|
||||
setExit({ photo, dir, dy: s.dy })
|
||||
} else {
|
||||
setSpring('v')
|
||||
}
|
||||
}
|
||||
|
||||
const onTouchCancel = () => {
|
||||
g.current = null
|
||||
setDragAxis(null)
|
||||
clearManual()
|
||||
}
|
||||
|
||||
const trackStyle =
|
||||
settleFrom != null
|
||||
? settleRun
|
||||
? { transform: 'translateX(0)', transition: `transform ${COMMIT_MS}ms ease-out` }
|
||||
: { transform: `translateX(${settleFrom}px)`, transition: 'none' }
|
||||
: spring === 'h'
|
||||
? { transform: 'translateX(0)', transition: `transform ${CANCEL_MS}ms ease-out` }
|
||||
: undefined
|
||||
|
||||
const imgStyle =
|
||||
spring === 'v'
|
||||
? { transform: 'translateY(0) rotate(0deg)', transition: `transform ${CANCEL_MS}ms ease-out` }
|
||||
: spring === 'z'
|
||||
? { transform: 'none', transition: `transform ${CANCEL_MS}ms ease-out` }
|
||||
: undefined
|
||||
|
||||
const behindStyle =
|
||||
spring === 'v'
|
||||
? { transform: 'scale(0.22)', opacity: 0, transition: `all ${CANCEL_MS}ms ease-out` }
|
||||
: undefined
|
||||
|
||||
return {
|
||||
handlers: { onTouchStart, onTouchMove, onTouchEnd, onTouchCancel },
|
||||
trackRef,
|
||||
imgRef,
|
||||
behindRef,
|
||||
badgeRef,
|
||||
trackStyle,
|
||||
imgStyle,
|
||||
behindStyle,
|
||||
showBehind: (dragAxis === 'v' || spring === 'v') && hasNext,
|
||||
showBadge: dragAxis === 'v',
|
||||
exit,
|
||||
clearExit: () => setExit(null),
|
||||
onTrackTransitionEnd: (e) => {
|
||||
if (e.target !== trackRef.current) return
|
||||
setSettleFrom(null)
|
||||
if (spring === 'h') setSpring(null)
|
||||
},
|
||||
onImgTransitionEnd: (e) => {
|
||||
if (e.target !== imgRef.current) return
|
||||
if (spring === 'v' || spring === 'z') {
|
||||
setSpring(null)
|
||||
clearManual()
|
||||
}
|
||||
},
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,27 @@
|
||||
-- Albums gain an owner: the tenancy root. Photos, shares, ratings and tags
|
||||
-- all hang off albums, so this single column scopes everything.
|
||||
alter table albums add column owner_id uuid references users(id);
|
||||
|
||||
-- Backfill: pre-tenancy albums had no owner. Assigning them to "the" original
|
||||
-- photographer is only unambiguous when exactly one user exists. With several
|
||||
-- (v0.1.0 let every allowed email share all albums) the correct owner is
|
||||
-- unknowable, so refuse rather than silently transfer everyone's work to one
|
||||
-- account — the operator must assign ownership manually before migrating.
|
||||
do $$
|
||||
declare
|
||||
n_users int;
|
||||
n_albums int;
|
||||
begin
|
||||
select count(*) into n_users from users;
|
||||
select count(*) into n_albums from albums;
|
||||
if n_albums > 0 and n_users <> 1 then
|
||||
raise exception
|
||||
'multi-tenant migration: % albums exist but there are % users (need exactly 1 to auto-assign ownership); set albums.owner_id manually first',
|
||||
n_albums, n_users;
|
||||
end if;
|
||||
update albums set owner_id = (select id from users order by created_at limit 1);
|
||||
end $$;
|
||||
|
||||
alter table albums alter column owner_id set not null;
|
||||
|
||||
create index albums_owner_idx on albums (owner_id);
|
||||
@@ -1,13 +0,0 @@
|
||||
-- Client accept/reject votes, one per (link, photo) — a separate axis from
|
||||
-- the 1-5 star rating so a photo can be e.g. accepted but unrated.
|
||||
create table verdicts (
|
||||
share_id uuid not null references shares(id) on delete cascade,
|
||||
photo_id uuid not null references photos(id) on delete cascade,
|
||||
verdict text not null check (verdict in ('accept', 'reject')),
|
||||
updated_at timestamptz not null default now(),
|
||||
primary key (share_id, photo_id)
|
||||
);
|
||||
|
||||
-- Cascaded photo deletes fire per-row FK triggers; without this each one
|
||||
-- sequential-scans the table.
|
||||
create index verdicts_photo_idx on verdicts (photo_id);
|
||||
+7
-1
@@ -114,11 +114,17 @@ pub(crate) fn base_cookie(name: &'static str, value: String, secure: bool) -> Co
|
||||
.build()
|
||||
}
|
||||
|
||||
/// The signed session-cookie payload, in one place so tests and the
|
||||
/// mint_session dev tool can't drift from what user_from_jar parses.
|
||||
pub fn session_payload(user_id: Uuid, email: &str, exp: i64) -> String {
|
||||
format!("{user_id}|{exp}|{email}")
|
||||
}
|
||||
|
||||
fn session_cookie(state: &AppState, user_id: Uuid, email: &str) -> Cookie<'static> {
|
||||
let exp = Utc::now().timestamp() + SESSION_DAYS * 86400;
|
||||
let mut cookie = base_cookie(
|
||||
SESSION_COOKIE,
|
||||
format!("{user_id}|{exp}|{email}"),
|
||||
session_payload(user_id, email, exp),
|
||||
state.config.cookie_secure(),
|
||||
);
|
||||
cookie.set_max_age(time::Duration::days(SESSION_DAYS));
|
||||
|
||||
+3
-26
@@ -1,8 +1,4 @@
|
||||
use axum::http::{header, HeaderValue};
|
||||
use tower::ServiceBuilder;
|
||||
use tower_http::services::fs::ServeFileSystemResponseBody;
|
||||
use tower_http::services::{ServeDir, ServeFile};
|
||||
use tower_http::set_header::SetResponseHeaderLayer;
|
||||
use tower_http::trace::TraceLayer;
|
||||
use tracing_subscriber::EnvFilter;
|
||||
|
||||
@@ -21,30 +17,11 @@ async fn main() -> anyhow::Result<()> {
|
||||
let state = AppState::new(config).await?;
|
||||
|
||||
let static_dir = state.config.static_dir.clone();
|
||||
let static_root = std::path::Path::new(&static_dir);
|
||||
// Hashed assets cache forever — except 404s, which would outlive the next deploy.
|
||||
let assets = ServiceBuilder::new()
|
||||
.map_response(|mut response: axum::http::Response<ServeFileSystemResponseBody>| {
|
||||
if response.status().is_success() {
|
||||
response.headers_mut().insert(
|
||||
header::CACHE_CONTROL,
|
||||
HeaderValue::from_static("public, max-age=31536000, immutable"),
|
||||
);
|
||||
}
|
||||
response
|
||||
})
|
||||
.service(ServeDir::new(static_root.join("assets")));
|
||||
// index.html revalidates every load (it names the asset hashes);
|
||||
// .fallback (not .not_found_service) so SPA routes get it with a 200.
|
||||
let spa = ServiceBuilder::new()
|
||||
.layer(SetResponseHeaderLayer::overriding(
|
||||
header::CACHE_CONTROL,
|
||||
HeaderValue::from_static("no-cache"),
|
||||
))
|
||||
.service(ServeDir::new(static_root).fallback(ServeFile::new(static_root.join("index.html"))));
|
||||
let index = std::path::Path::new(&static_dir).join("index.html");
|
||||
// .fallback (not .not_found_service) so SPA routes get index.html with a 200
|
||||
let spa = ServeDir::new(&static_dir).fallback(ServeFile::new(index));
|
||||
|
||||
let app = photos::routes::router(&state)
|
||||
.nest_service("/assets", assets)
|
||||
.fallback_service(spa)
|
||||
.layer(TraceLayer::new_for_http())
|
||||
.with_state(state.clone());
|
||||
|
||||
@@ -4,6 +4,7 @@ pub mod error;
|
||||
pub mod imaging;
|
||||
pub mod jobs;
|
||||
pub mod models;
|
||||
pub mod owned;
|
||||
pub mod routes;
|
||||
pub mod s3;
|
||||
pub mod state;
|
||||
|
||||
+3
-20
@@ -1,5 +1,5 @@
|
||||
use chrono::{DateTime, Utc};
|
||||
use serde::{Deserialize, Serialize};
|
||||
use serde::Serialize;
|
||||
use uuid::Uuid;
|
||||
|
||||
/// Stored as text in Postgres; decoded via TryFrom so an unknown value is a
|
||||
@@ -47,25 +47,6 @@ impl TryFrom<String> for PhotoStatus {
|
||||
}
|
||||
}
|
||||
|
||||
/// Client accept/reject vote. Same convention as PhotoStatus: text in
|
||||
/// Postgres (check-constrained), this enum everywhere Rust touches the value
|
||||
/// — serde rejects anything but "accept"/"reject" at the API boundary.
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)]
|
||||
#[serde(rename_all = "lowercase")]
|
||||
pub enum Verdict {
|
||||
Accept,
|
||||
Reject,
|
||||
}
|
||||
|
||||
impl Verdict {
|
||||
pub fn as_str(self) -> &'static str {
|
||||
match self {
|
||||
Self::Accept => "accept",
|
||||
Self::Reject => "reject",
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||
pub enum JobKind {
|
||||
ProcessPhoto,
|
||||
@@ -115,6 +96,8 @@ impl JobStatus {
|
||||
#[derive(Debug, Clone, sqlx::FromRow, Serialize)]
|
||||
pub struct Album {
|
||||
pub id: Uuid,
|
||||
#[serde(skip_serializing)]
|
||||
pub owner_id: Uuid,
|
||||
pub name: String,
|
||||
pub description: String,
|
||||
pub created_at: DateTime<Utc>,
|
||||
|
||||
@@ -0,0 +1,46 @@
|
||||
//! Tenant-scoped data access. These are the ONLY functions admin handlers may
|
||||
//! use to fetch albums, photos, or shares — every one joins ownership, so a
|
||||
//! handler cannot accidentally reach across tenants. Another user's resource
|
||||
//! is indistinguishable from a nonexistent one (404).
|
||||
|
||||
use uuid::Uuid;
|
||||
|
||||
use crate::error::ApiError;
|
||||
use crate::models::{Album, Photo, Share};
|
||||
use crate::state::AppState;
|
||||
|
||||
pub async fn album(state: &AppState, album_id: Uuid, owner: Uuid) -> Result<Album, ApiError> {
|
||||
let album: Option<Album> =
|
||||
sqlx::query_as("select * from albums where id = $1 and owner_id = $2")
|
||||
.bind(album_id)
|
||||
.bind(owner)
|
||||
.fetch_optional(&state.db)
|
||||
.await?;
|
||||
album.ok_or_else(ApiError::not_found)
|
||||
}
|
||||
|
||||
pub async fn photo(state: &AppState, photo_id: Uuid, owner: Uuid) -> Result<Photo, ApiError> {
|
||||
let photo: Option<Photo> = sqlx::query_as(
|
||||
"select p.* from photos p
|
||||
join albums a on a.id = p.album_id
|
||||
where p.id = $1 and a.owner_id = $2",
|
||||
)
|
||||
.bind(photo_id)
|
||||
.bind(owner)
|
||||
.fetch_optional(&state.db)
|
||||
.await?;
|
||||
photo.ok_or_else(ApiError::not_found)
|
||||
}
|
||||
|
||||
pub async fn share(state: &AppState, share_id: Uuid, owner: Uuid) -> Result<Share, ApiError> {
|
||||
let share: Option<Share> = sqlx::query_as(
|
||||
"select s.* from shares s
|
||||
join albums a on a.id = s.album_id
|
||||
where s.id = $1 and a.owner_id = $2",
|
||||
)
|
||||
.bind(share_id)
|
||||
.bind(owner)
|
||||
.fetch_optional(&state.db)
|
||||
.await?;
|
||||
share.ok_or_else(ApiError::not_found)
|
||||
}
|
||||
+72
-93
@@ -6,8 +6,10 @@ use chrono::{DateTime, Utc};
|
||||
use serde::{Deserialize, Serialize};
|
||||
use uuid::Uuid;
|
||||
|
||||
use crate::auth::AuthUser;
|
||||
use crate::error::{ApiError, ApiResult};
|
||||
use crate::models::{Album, Photo, PhotoStatus};
|
||||
use crate::models::{Album, JobKind, Photo, PhotoStatus};
|
||||
use crate::owned;
|
||||
use crate::state::AppState;
|
||||
|
||||
#[derive(Serialize, sqlx::FromRow)]
|
||||
@@ -23,6 +25,7 @@ pub struct AlbumListItem {
|
||||
|
||||
pub async fn list(
|
||||
State(state): State<AppState>,
|
||||
user: AuthUser,
|
||||
) -> ApiResult<Json<Vec<AlbumListItem>>> {
|
||||
let albums: Vec<AlbumListItem> = sqlx::query_as(
|
||||
"select a.id, a.name, a.description, a.created_at,
|
||||
@@ -35,9 +38,11 @@ pub async fn list(
|
||||
order by coalesce(p.taken_at, p.created_at), p.filename
|
||||
limit 1
|
||||
) c on true
|
||||
where a.owner_id = $2
|
||||
order by a.created_at desc",
|
||||
)
|
||||
.bind(PhotoStatus::Ready.as_str())
|
||||
.bind(user.id)
|
||||
.fetch_all(&state.db)
|
||||
.await?;
|
||||
Ok(Json(albums))
|
||||
@@ -52,18 +57,21 @@ pub struct CreateAlbum {
|
||||
|
||||
pub async fn create(
|
||||
State(state): State<AppState>,
|
||||
user: AuthUser,
|
||||
Json(body): Json<CreateAlbum>,
|
||||
) -> ApiResult<Json<Album>> {
|
||||
let name = body.name.trim();
|
||||
if name.is_empty() {
|
||||
return Err(ApiError::bad_request("album name is required"));
|
||||
}
|
||||
let album: Album =
|
||||
sqlx::query_as("insert into albums (name, description) values ($1, $2) returning *")
|
||||
.bind(name)
|
||||
.bind(body.description.trim())
|
||||
.fetch_one(&state.db)
|
||||
.await?;
|
||||
let album: Album = sqlx::query_as(
|
||||
"insert into albums (owner_id, name, description) values ($1, $2, $3) returning *",
|
||||
)
|
||||
.bind(user.id)
|
||||
.bind(name)
|
||||
.bind(body.description.trim())
|
||||
.fetch_one(&state.db)
|
||||
.await?;
|
||||
Ok(Json(album))
|
||||
}
|
||||
|
||||
@@ -79,40 +87,12 @@ pub struct ShareTag {
|
||||
pub tag: String,
|
||||
}
|
||||
|
||||
#[derive(Serialize)]
|
||||
pub struct ShareVerdict {
|
||||
pub share_label: String,
|
||||
pub verdict: String,
|
||||
}
|
||||
|
||||
#[derive(Serialize, Default)]
|
||||
pub struct PhotoFeedback {
|
||||
pub ratings: Vec<ShareRating>,
|
||||
pub verdicts: Vec<ShareVerdict>,
|
||||
pub tags: Vec<ShareTag>,
|
||||
}
|
||||
|
||||
async fn feedback_rows<T>(
|
||||
db: &sqlx::PgPool,
|
||||
sql: &str,
|
||||
album_id: Uuid,
|
||||
) -> Result<Vec<(Uuid, String, T)>, sqlx::Error>
|
||||
where
|
||||
(Uuid, String, T): for<'r> sqlx::FromRow<'r, sqlx::postgres::PgRow> + Send + Unpin,
|
||||
{
|
||||
sqlx::query_as(sql).bind(album_id).fetch_all(db).await
|
||||
}
|
||||
|
||||
fn fold_feedback<T>(
|
||||
feedback: &mut HashMap<Uuid, PhotoFeedback>,
|
||||
rows: Vec<(Uuid, String, T)>,
|
||||
push: impl Fn(&mut PhotoFeedback, String, T),
|
||||
) {
|
||||
for (photo_id, share_label, value) in rows {
|
||||
push(feedback.entry(photo_id).or_default(), share_label, value);
|
||||
}
|
||||
}
|
||||
|
||||
#[derive(Serialize)]
|
||||
pub struct AlbumDetail {
|
||||
pub album: Album,
|
||||
@@ -122,12 +102,10 @@ pub struct AlbumDetail {
|
||||
|
||||
pub async fn get_one(
|
||||
State(state): State<AppState>,
|
||||
user: AuthUser,
|
||||
Path(album_id): Path<Uuid>,
|
||||
) -> ApiResult<Json<AlbumDetail>> {
|
||||
let album: Album = sqlx::query_as("select * from albums where id = $1")
|
||||
.bind(album_id)
|
||||
.fetch_one(&state.db)
|
||||
.await?;
|
||||
let album = owned::album(&state, album_id, user.id).await?;
|
||||
let photos: Vec<Photo> = sqlx::query_as(
|
||||
"select * from photos where album_id = $1
|
||||
order by coalesce(taken_at, created_at), filename",
|
||||
@@ -136,49 +114,41 @@ pub async fn get_one(
|
||||
.fetch_all(&state.db)
|
||||
.await?;
|
||||
|
||||
// The three feedback kinds are independent (photo_id, share label, value)
|
||||
// queries — run them concurrently and fold with one shared shape.
|
||||
let (ratings, verdicts, tags) = tokio::try_join!(
|
||||
feedback_rows::<i32>(
|
||||
&state.db,
|
||||
"select r.photo_id, s.label, r.rating
|
||||
from ratings r join shares s on s.id = r.share_id
|
||||
where s.album_id = $1",
|
||||
album_id,
|
||||
),
|
||||
feedback_rows::<String>(
|
||||
&state.db,
|
||||
"select v.photo_id, s.label, v.verdict
|
||||
from verdicts v join shares s on s.id = v.share_id
|
||||
where s.album_id = $1",
|
||||
album_id,
|
||||
),
|
||||
feedback_rows::<String>(
|
||||
&state.db,
|
||||
"select t.photo_id, s.label, t.tag
|
||||
from tags t join shares s on s.id = t.share_id
|
||||
where s.album_id = $1
|
||||
order by t.created_at",
|
||||
album_id,
|
||||
),
|
||||
)?;
|
||||
|
||||
let mut feedback: HashMap<Uuid, PhotoFeedback> = HashMap::new();
|
||||
fold_feedback(&mut feedback, ratings, |f, share_label, rating| {
|
||||
f.ratings.push(ShareRating {
|
||||
share_label,
|
||||
rating,
|
||||
})
|
||||
});
|
||||
fold_feedback(&mut feedback, verdicts, |f, share_label, verdict| {
|
||||
f.verdicts.push(ShareVerdict {
|
||||
share_label,
|
||||
verdict,
|
||||
})
|
||||
});
|
||||
fold_feedback(&mut feedback, tags, |f, share_label, tag| {
|
||||
f.tags.push(ShareTag { share_label, tag })
|
||||
});
|
||||
let ratings: Vec<(Uuid, String, i32)> = sqlx::query_as(
|
||||
"select r.photo_id, s.label, r.rating
|
||||
from ratings r join shares s on s.id = r.share_id
|
||||
where s.album_id = $1",
|
||||
)
|
||||
.bind(album_id)
|
||||
.fetch_all(&state.db)
|
||||
.await?;
|
||||
for (photo_id, share_label, rating) in ratings {
|
||||
feedback
|
||||
.entry(photo_id)
|
||||
.or_default()
|
||||
.ratings
|
||||
.push(ShareRating {
|
||||
share_label,
|
||||
rating,
|
||||
});
|
||||
}
|
||||
let tags: Vec<(Uuid, String, String)> = sqlx::query_as(
|
||||
"select t.photo_id, s.label, t.tag
|
||||
from tags t join shares s on s.id = t.share_id
|
||||
where s.album_id = $1
|
||||
order by t.created_at",
|
||||
)
|
||||
.bind(album_id)
|
||||
.fetch_all(&state.db)
|
||||
.await?;
|
||||
for (photo_id, share_label, tag) in tags {
|
||||
feedback
|
||||
.entry(photo_id)
|
||||
.or_default()
|
||||
.tags
|
||||
.push(ShareTag { share_label, tag });
|
||||
}
|
||||
|
||||
Ok(Json(AlbumDetail {
|
||||
album,
|
||||
@@ -195,6 +165,7 @@ pub struct UpdateAlbum {
|
||||
|
||||
pub async fn update(
|
||||
State(state): State<AppState>,
|
||||
user: AuthUser,
|
||||
Path(album_id): Path<Uuid>,
|
||||
Json(body): Json<UpdateAlbum>,
|
||||
) -> ApiResult<Json<Album>> {
|
||||
@@ -206,12 +177,13 @@ pub async fn update(
|
||||
let album: Album = sqlx::query_as(
|
||||
"update albums
|
||||
set name = coalesce($2, name), description = coalesce($3, description)
|
||||
where id = $1
|
||||
where id = $1 and owner_id = $4
|
||||
returning *",
|
||||
)
|
||||
.bind(album_id)
|
||||
.bind(body.name.as_deref().map(str::trim))
|
||||
.bind(body.description.as_deref().map(str::trim))
|
||||
.bind(user.id)
|
||||
.fetch_one(&state.db)
|
||||
.await?;
|
||||
Ok(Json(album))
|
||||
@@ -219,26 +191,33 @@ pub async fn update(
|
||||
|
||||
pub async fn delete(
|
||||
State(state): State<AppState>,
|
||||
user: AuthUser,
|
||||
Path(album_id): Path<Uuid>,
|
||||
) -> ApiResult<Json<serde_json::Value>> {
|
||||
let mut tx = state.db.begin().await?;
|
||||
// Lock the album row: concurrent uploads block on their FK check against
|
||||
// it, then fail once it's gone and clean up their own S3 objects — so no
|
||||
// photo can slip in between the cleanup enqueue and the cascade delete.
|
||||
let locked: Option<(Uuid,)> = sqlx::query_as("select id from albums where id = $1 for update")
|
||||
.bind(album_id)
|
||||
.fetch_optional(&mut *tx)
|
||||
.await?;
|
||||
let locked: Option<(Uuid,)> =
|
||||
sqlx::query_as("select id from albums where id = $1 and owner_id = $2 for update")
|
||||
.bind(album_id)
|
||||
.bind(user.id)
|
||||
.fetch_optional(&mut *tx)
|
||||
.await?;
|
||||
if locked.is_none() {
|
||||
return Err(ApiError::not_found());
|
||||
}
|
||||
// Delete photos through the shared path so the S3 cleanup convention
|
||||
// lives in one place; the album lock above keeps this set complete.
|
||||
let photo_ids: Vec<Uuid> = sqlx::query_scalar("select id from photos where album_id = $1")
|
||||
.bind(album_id)
|
||||
.fetch_all(&mut *tx)
|
||||
.await?;
|
||||
super::photos::delete_with_cleanup(&mut tx, &photo_ids).await?;
|
||||
// Delete photos and enqueue their S3 cleanup atomically, in one statement.
|
||||
sqlx::query(
|
||||
"with deleted as (delete from photos where album_id = $1 returning id)
|
||||
insert into jobs (kind, payload)
|
||||
select $2, jsonb_build_object('prefix', 'photos/' || id || '/')
|
||||
from deleted",
|
||||
)
|
||||
.bind(album_id)
|
||||
.bind(JobKind::DeleteS3Prefix.as_str())
|
||||
.execute(&mut *tx)
|
||||
.await?;
|
||||
sqlx::query("delete from albums where id = $1")
|
||||
.bind(album_id)
|
||||
.execute(&mut *tx)
|
||||
|
||||
+2
-40
@@ -10,7 +10,7 @@ use serde::{Deserialize, Serialize};
|
||||
use uuid::Uuid;
|
||||
|
||||
use crate::error::{ApiError, ApiResult};
|
||||
use crate::models::{PhotoStatus, Share, Verdict};
|
||||
use crate::models::{PhotoStatus, Share};
|
||||
use crate::state::AppState;
|
||||
|
||||
pub async fn load_share(state: &AppState, token: &str) -> Result<Share, ApiError> {
|
||||
@@ -137,7 +137,6 @@ struct ClientPhotoRow {
|
||||
taken_at: Option<DateTime<Utc>>,
|
||||
processed_at: Option<DateTime<Utc>>,
|
||||
my_rating: Option<i32>,
|
||||
my_verdict: Option<String>,
|
||||
}
|
||||
|
||||
#[derive(Serialize)]
|
||||
@@ -186,10 +185,9 @@ pub async fn get_share(
|
||||
let jar = grant_access(&state, jar, share.id);
|
||||
|
||||
let rows: Vec<ClientPhotoRow> = sqlx::query_as(
|
||||
"select p.id, p.filename, p.size_bytes, p.width, p.height, p.taken_at, p.processed_at, r.rating as my_rating, v.verdict as my_verdict
|
||||
"select p.id, p.filename, p.size_bytes, p.width, p.height, p.taken_at, p.processed_at, r.rating as my_rating
|
||||
from photos p
|
||||
left join ratings r on r.photo_id = p.id and r.share_id = $2
|
||||
left join verdicts v on v.photo_id = p.id and v.share_id = $2
|
||||
where p.album_id = $1 and p.status = $3
|
||||
order by coalesce(p.taken_at, p.created_at), p.filename",
|
||||
)
|
||||
@@ -354,42 +352,6 @@ pub async fn set_rating(
|
||||
Ok(Json(serde_json::json!({ "ok": true })))
|
||||
}
|
||||
|
||||
#[derive(Deserialize)]
|
||||
pub struct VerdictBody {
|
||||
verdict: Option<Verdict>,
|
||||
}
|
||||
|
||||
pub async fn set_verdict(
|
||||
State(state): State<AppState>,
|
||||
Path((token, photo_id)): Path<(String, Uuid)>,
|
||||
jar: SignedCookieJar,
|
||||
Json(body): Json<VerdictBody>,
|
||||
) -> ApiResult<Json<serde_json::Value>> {
|
||||
let share = share_photo(&state, &jar, &token, photo_id).await?;
|
||||
match body.verdict {
|
||||
None => {
|
||||
sqlx::query("delete from verdicts where share_id = $1 and photo_id = $2")
|
||||
.bind(share.id)
|
||||
.bind(photo_id)
|
||||
.execute(&state.db)
|
||||
.await?;
|
||||
}
|
||||
Some(verdict) => {
|
||||
sqlx::query(
|
||||
"insert into verdicts (share_id, photo_id, verdict) values ($1, $2, $3)
|
||||
on conflict (share_id, photo_id)
|
||||
do update set verdict = excluded.verdict, updated_at = now()",
|
||||
)
|
||||
.bind(share.id)
|
||||
.bind(photo_id)
|
||||
.bind(verdict.as_str())
|
||||
.execute(&state.db)
|
||||
.await?;
|
||||
}
|
||||
}
|
||||
Ok(Json(serde_json::json!({ "ok": true })))
|
||||
}
|
||||
|
||||
#[derive(Deserialize)]
|
||||
pub struct TagsBody {
|
||||
tags: Vec<String>,
|
||||
|
||||
+13
-2
@@ -28,8 +28,19 @@ async fn authorize_photo(
|
||||
.await?;
|
||||
let photo = photo.ok_or_else(ApiError::not_found)?;
|
||||
|
||||
if user_from_jar(state, jar).is_some() {
|
||||
return Ok(photo);
|
||||
// Photographers may only reach their OWN photos (scoped by album owner);
|
||||
// otherwise fall through to share-cookie access.
|
||||
if let Some(user) = user_from_jar(state, jar) {
|
||||
let owns: Option<(Uuid,)> = sqlx::query_as(
|
||||
"select a.id from albums a where a.id = $1 and a.owner_id = $2",
|
||||
)
|
||||
.bind(photo.album_id)
|
||||
.bind(user.id)
|
||||
.fetch_optional(&state.db)
|
||||
.await?;
|
||||
if owns.is_some() {
|
||||
return Ok(photo);
|
||||
}
|
||||
}
|
||||
authorize_album_via_cookie(state, jar, photo.album_id, need_download).await?;
|
||||
// Clients may only reach photos the share listing exposes.
|
||||
|
||||
+1
-9
@@ -78,13 +78,9 @@ pub fn router(state: &AppState) -> Router<AppState> {
|
||||
)
|
||||
.route("/api/albums/{id}/zip", post(zip::album_zip))
|
||||
.route("/api/albums/{id}/photos/by-hash/{sha256}", get(photos::by_hash))
|
||||
.route("/api/photos/delete", post(photos::delete_many))
|
||||
.route("/api/photos/{id}", delete(photos::delete))
|
||||
.route("/api/photos/{id}/reprocess", post(photos::reprocess))
|
||||
.route(
|
||||
"/api/shares/{id}",
|
||||
delete(shares::delete).patch(shares::update),
|
||||
)
|
||||
.route("/api/shares/{id}", delete(shares::delete))
|
||||
.route("/api/shares/{id}/reset-lock", post(shares::reset_lock))
|
||||
.route_layer(middleware::from_fn_with_state(
|
||||
state.clone(),
|
||||
@@ -104,10 +100,6 @@ pub fn router(state: &AppState) -> Router<AppState> {
|
||||
"/api/share/{token}/photos/{photo_id}/rating",
|
||||
put(client::set_rating),
|
||||
)
|
||||
.route(
|
||||
"/api/share/{token}/photos/{photo_id}/verdict",
|
||||
put(client::set_verdict),
|
||||
)
|
||||
.route(
|
||||
"/api/share/{token}/photos/{photo_id}/tags",
|
||||
put(client::set_tags),
|
||||
|
||||
+42
-61
@@ -9,9 +9,11 @@ use sha2::Digest;
|
||||
use tokio::io::AsyncWriteExt;
|
||||
use uuid::Uuid;
|
||||
|
||||
use crate::auth::AuthUser;
|
||||
use crate::error::{ApiError, ApiResult};
|
||||
use crate::jobs;
|
||||
use crate::models::{JobKind, Photo, PhotoStatus};
|
||||
use crate::owned;
|
||||
use crate::s3;
|
||||
use crate::state::AppState;
|
||||
|
||||
@@ -39,20 +41,34 @@ fn sanitize_filename(raw: &str) -> Result<String, ApiError> {
|
||||
Ok(cleaned.chars().take(150).collect())
|
||||
}
|
||||
|
||||
/// A dedup hit on a photo that previously failed processing means the user is
|
||||
/// re-uploading to fix it — reset it and re-enqueue instead of handing back a
|
||||
/// broken row that the UI would report as "already uploaded".
|
||||
async fn heal_if_errored(state: &AppState, photo: Photo) -> ApiResult<Photo> {
|
||||
if photo.status != PhotoStatus::Error {
|
||||
return Ok(photo);
|
||||
}
|
||||
let mut tx = state.db.begin().await?;
|
||||
let healed: Photo =
|
||||
sqlx::query_as("update photos set status = $2, error = null where id = $1 returning *")
|
||||
.bind(photo.id)
|
||||
.bind(PhotoStatus::Uploaded.as_str())
|
||||
.fetch_one(&mut *tx)
|
||||
.await?;
|
||||
jobs::ensure_process_photo(&mut tx, photo.id).await?;
|
||||
tx.commit().await?;
|
||||
Ok(healed)
|
||||
}
|
||||
|
||||
pub async fn upload(
|
||||
State(state): State<AppState>,
|
||||
user: AuthUser,
|
||||
Path(album_id): Path<Uuid>,
|
||||
Query(query): Query<UploadQuery>,
|
||||
headers: HeaderMap,
|
||||
body: Body,
|
||||
) -> ApiResult<Json<Photo>> {
|
||||
let album_exists: Option<(Uuid,)> = sqlx::query_as("select id from albums where id = $1")
|
||||
.bind(album_id)
|
||||
.fetch_optional(&state.db)
|
||||
.await?;
|
||||
if album_exists.is_none() {
|
||||
return Err(ApiError::not_found());
|
||||
}
|
||||
owned::album(&state, album_id, user.id).await?;
|
||||
|
||||
let filename = sanitize_filename(&query.filename)?;
|
||||
let content_type = headers
|
||||
@@ -97,7 +113,7 @@ pub async fn upload(
|
||||
.fetch_optional(&state.db)
|
||||
.await?;
|
||||
if let Some(existing) = existing {
|
||||
return Ok(Json(existing));
|
||||
return Ok(Json(heal_if_errored(&state, existing).await?));
|
||||
}
|
||||
|
||||
// Upload to S3 first, then create the row and enqueue processing in one
|
||||
@@ -156,7 +172,7 @@ pub async fn upload(
|
||||
.fetch_optional(&state.db)
|
||||
.await?;
|
||||
if let Some(winner) = winner {
|
||||
return Ok(Json(winner));
|
||||
return Ok(Json(heal_if_errored(&state, winner).await?));
|
||||
}
|
||||
}
|
||||
return Err(e.into());
|
||||
@@ -178,8 +194,10 @@ pub async fn upload(
|
||||
/// content already exists in the album.
|
||||
pub async fn by_hash(
|
||||
State(state): State<AppState>,
|
||||
user: AuthUser,
|
||||
Path((album_id, sha256)): Path<(Uuid, String)>,
|
||||
) -> ApiResult<Json<Photo>> {
|
||||
owned::album(&state, album_id, user.id).await?;
|
||||
let photo: Option<Photo> =
|
||||
sqlx::query_as("select * from photos where album_id = $1 and sha256 = $2")
|
||||
.bind(album_id)
|
||||
@@ -189,73 +207,36 @@ pub async fn by_hash(
|
||||
photo.map(Json).ok_or_else(ApiError::not_found)
|
||||
}
|
||||
|
||||
/// The one deletion path: delete the given photos and enqueue their S3
|
||||
/// cleanup jobs in the same transaction. Prefixes come from s3::photo_prefix
|
||||
/// so the key layout has a single source of truth. Returns how many photos
|
||||
/// were actually deleted.
|
||||
pub(super) async fn delete_with_cleanup(
|
||||
tx: &mut sqlx::PgConnection,
|
||||
ids: &[Uuid],
|
||||
) -> Result<u64, sqlx::Error> {
|
||||
let deleted: Vec<Uuid> = sqlx::query_scalar("delete from photos where id = any($1) returning id")
|
||||
.bind(ids)
|
||||
.fetch_all(&mut *tx)
|
||||
.await?;
|
||||
if deleted.is_empty() {
|
||||
return Ok(0);
|
||||
}
|
||||
let prefixes: Vec<String> = deleted.iter().map(|id| s3::photo_prefix(*id)).collect();
|
||||
sqlx::query(
|
||||
"insert into jobs (kind, payload)
|
||||
select $1, jsonb_build_object('prefix', p)
|
||||
from unnest($2::text[]) as p",
|
||||
)
|
||||
.bind(JobKind::DeleteS3Prefix.as_str())
|
||||
.bind(&prefixes)
|
||||
.execute(&mut *tx)
|
||||
.await?;
|
||||
Ok(deleted.len() as u64)
|
||||
}
|
||||
|
||||
pub async fn delete(
|
||||
State(state): State<AppState>,
|
||||
user: AuthUser,
|
||||
Path(photo_id): Path<Uuid>,
|
||||
) -> ApiResult<Json<serde_json::Value>> {
|
||||
owned::photo(&state, photo_id, user.id).await?;
|
||||
let mut tx = state.db.begin().await?;
|
||||
if delete_with_cleanup(&mut tx, &[photo_id]).await? == 0 {
|
||||
let deleted = sqlx::query("delete from photos where id = $1")
|
||||
.bind(photo_id)
|
||||
.execute(&mut *tx)
|
||||
.await?;
|
||||
if deleted.rows_affected() == 0 {
|
||||
return Err(ApiError::not_found());
|
||||
}
|
||||
jobs::enqueue(
|
||||
&mut *tx,
|
||||
JobKind::DeleteS3Prefix,
|
||||
serde_json::json!({ "prefix": s3::photo_prefix(photo_id) }),
|
||||
)
|
||||
.await?;
|
||||
tx.commit().await?;
|
||||
Ok(Json(serde_json::json!({ "ok": true })))
|
||||
}
|
||||
|
||||
#[derive(Deserialize)]
|
||||
pub struct DeleteManyBody {
|
||||
ids: Vec<Uuid>,
|
||||
}
|
||||
|
||||
pub async fn delete_many(
|
||||
State(state): State<AppState>,
|
||||
Json(body): Json<DeleteManyBody>,
|
||||
) -> ApiResult<Json<serde_json::Value>> {
|
||||
if body.ids.is_empty() {
|
||||
return Err(ApiError::bad_request("ids must not be empty"));
|
||||
}
|
||||
let mut tx = state.db.begin().await?;
|
||||
let deleted = delete_with_cleanup(&mut tx, &body.ids).await?;
|
||||
// Consistent with the single-photo route: deleting nothing is an error,
|
||||
// not a silent success (e.g. a stale tab re-deleting already-gone photos).
|
||||
if deleted == 0 {
|
||||
return Err(ApiError::not_found());
|
||||
}
|
||||
tx.commit().await?;
|
||||
Ok(Json(serde_json::json!({ "ok": true, "deleted": deleted })))
|
||||
}
|
||||
|
||||
pub async fn reprocess(
|
||||
State(state): State<AppState>,
|
||||
user: AuthUser,
|
||||
Path(photo_id): Path<Uuid>,
|
||||
) -> ApiResult<Json<serde_json::Value>> {
|
||||
owned::photo(&state, photo_id, user.id).await?;
|
||||
let mut tx = state.db.begin().await?;
|
||||
let updated = sqlx::query("update photos set status = $2, error = null where id = $1")
|
||||
.bind(photo_id)
|
||||
|
||||
+19
-71
@@ -7,8 +7,9 @@ use chrono::{DateTime, Utc};
|
||||
use serde::Deserialize;
|
||||
use uuid::Uuid;
|
||||
|
||||
use crate::auth::random_token;
|
||||
use crate::auth::{random_token, AuthUser};
|
||||
use crate::error::{ApiError, ApiResult};
|
||||
use crate::owned;
|
||||
use crate::state::AppState;
|
||||
|
||||
#[derive(sqlx::FromRow)]
|
||||
@@ -23,8 +24,6 @@ struct ShareAdminRow {
|
||||
created_at: DateTime<Utc>,
|
||||
rating_count: i64,
|
||||
tag_count: i64,
|
||||
accept_count: i64,
|
||||
reject_count: i64,
|
||||
}
|
||||
|
||||
fn share_json(state: &AppState, row: &ShareAdminRow) -> serde_json::Value {
|
||||
@@ -40,30 +39,22 @@ fn share_json(state: &AppState, row: &ShareAdminRow) -> serde_json::Value {
|
||||
"created_at": row.created_at,
|
||||
"rating_count": row.rating_count,
|
||||
"tag_count": row.tag_count,
|
||||
"accept_count": row.accept_count,
|
||||
"reject_count": row.reject_count,
|
||||
})
|
||||
}
|
||||
|
||||
// Aggregates run as laterals so each feedback table is scanned once per
|
||||
// share (the verdict lateral yields both counts from a single pass).
|
||||
const SHARE_SELECT: &str = "select s.id, s.token, s.label, s.password_hash, s.allow_download,
|
||||
const SHARE_COLUMNS: &str = "s.id, s.token, s.label, s.password_hash, s.allow_download,
|
||||
s.expires_at, s.locked_until, s.created_at,
|
||||
rc.rating_count, tc.tag_count, vc.accept_count, vc.reject_count
|
||||
from shares s
|
||||
cross join lateral (select count(*) as rating_count from ratings r where r.share_id = s.id) rc
|
||||
cross join lateral (select count(*) as tag_count from tags t where t.share_id = s.id) tc
|
||||
cross join lateral (
|
||||
select count(*) filter (where v.verdict = 'accept') as accept_count,
|
||||
count(*) filter (where v.verdict = 'reject') as reject_count
|
||||
from verdicts v where v.share_id = s.id) vc";
|
||||
(select count(*) from ratings r where r.share_id = s.id) as rating_count,
|
||||
(select count(*) from tags t where t.share_id = s.id) as tag_count";
|
||||
|
||||
pub async fn list(
|
||||
State(state): State<AppState>,
|
||||
user: AuthUser,
|
||||
Path(album_id): Path<Uuid>,
|
||||
) -> ApiResult<Json<Vec<serde_json::Value>>> {
|
||||
owned::album(&state, album_id, user.id).await?;
|
||||
let rows: Vec<ShareAdminRow> = sqlx::query_as(&format!(
|
||||
"{SHARE_SELECT} where s.album_id = $1 order by s.created_at desc"
|
||||
"select {SHARE_COLUMNS} from shares s where s.album_id = $1 order by s.created_at desc"
|
||||
))
|
||||
.bind(album_id)
|
||||
.fetch_all(&state.db)
|
||||
@@ -87,16 +78,11 @@ fn default_true() -> bool {
|
||||
|
||||
pub async fn create(
|
||||
State(state): State<AppState>,
|
||||
user: AuthUser,
|
||||
Path(album_id): Path<Uuid>,
|
||||
Json(body): Json<CreateShare>,
|
||||
) -> ApiResult<Json<serde_json::Value>> {
|
||||
let album_exists: Option<(Uuid,)> = sqlx::query_as("select id from albums where id = $1")
|
||||
.bind(album_id)
|
||||
.fetch_optional(&state.db)
|
||||
.await?;
|
||||
if album_exists.is_none() {
|
||||
return Err(ApiError::not_found());
|
||||
}
|
||||
owned::album(&state, album_id, user.id).await?;
|
||||
|
||||
let password_hash = match body.password.as_deref().map(str::trim) {
|
||||
Some(pw) if !pw.is_empty() => {
|
||||
@@ -131,53 +117,11 @@ pub async fn create(
|
||||
.fetch_one(&state.db)
|
||||
.await?;
|
||||
|
||||
let row: ShareAdminRow = sqlx::query_as(&format!("{SHARE_SELECT} where s.id = $1"))
|
||||
.bind(share_id)
|
||||
.fetch_one(&state.db)
|
||||
.await?;
|
||||
Ok(Json(share_json(&state, &row)))
|
||||
}
|
||||
|
||||
/// Distinguishes an absent JSON field (keep current value) from an explicit
|
||||
/// null (clear the expiry): absent → None, present → Some(inner).
|
||||
fn double_option<'de, D>(de: D) -> Result<Option<Option<DateTime<Utc>>>, D::Error>
|
||||
where
|
||||
D: serde::Deserializer<'de>,
|
||||
{
|
||||
serde::Deserialize::deserialize(de).map(Some)
|
||||
}
|
||||
|
||||
#[derive(Deserialize)]
|
||||
pub struct UpdateShare {
|
||||
allow_download: Option<bool>,
|
||||
#[serde(default, deserialize_with = "double_option")]
|
||||
expires_at: Option<Option<DateTime<Utc>>>,
|
||||
}
|
||||
|
||||
pub async fn update(
|
||||
State(state): State<AppState>,
|
||||
Path(share_id): Path<Uuid>,
|
||||
Json(body): Json<UpdateShare>,
|
||||
) -> ApiResult<Json<serde_json::Value>> {
|
||||
let updated = sqlx::query(
|
||||
"update shares set
|
||||
allow_download = coalesce($2, allow_download),
|
||||
expires_at = case when $3 then $4 else expires_at end
|
||||
where id = $1",
|
||||
)
|
||||
.bind(share_id)
|
||||
.bind(body.allow_download)
|
||||
.bind(body.expires_at.is_some())
|
||||
.bind(body.expires_at.flatten())
|
||||
.execute(&state.db)
|
||||
.await?;
|
||||
if updated.rows_affected() == 0 {
|
||||
return Err(ApiError::not_found());
|
||||
}
|
||||
let row: ShareAdminRow = sqlx::query_as(&format!("{SHARE_SELECT} where s.id = $1"))
|
||||
.bind(share_id)
|
||||
.fetch_one(&state.db)
|
||||
.await?;
|
||||
let row: ShareAdminRow =
|
||||
sqlx::query_as(&format!("select {SHARE_COLUMNS} from shares s where s.id = $1"))
|
||||
.bind(share_id)
|
||||
.fetch_one(&state.db)
|
||||
.await?;
|
||||
Ok(Json(share_json(&state, &row)))
|
||||
}
|
||||
|
||||
@@ -185,8 +129,10 @@ pub async fn update(
|
||||
/// their way into the 15-minute lock).
|
||||
pub async fn reset_lock(
|
||||
State(state): State<AppState>,
|
||||
user: AuthUser,
|
||||
Path(share_id): Path<Uuid>,
|
||||
) -> ApiResult<Json<serde_json::Value>> {
|
||||
owned::share(&state, share_id, user.id).await?;
|
||||
let updated =
|
||||
sqlx::query("update shares set failed_attempts = 0, locked_until = null where id = $1")
|
||||
.bind(share_id)
|
||||
@@ -200,8 +146,10 @@ pub async fn reset_lock(
|
||||
|
||||
pub async fn delete(
|
||||
State(state): State<AppState>,
|
||||
user: AuthUser,
|
||||
Path(share_id): Path<Uuid>,
|
||||
) -> ApiResult<Json<serde_json::Value>> {
|
||||
owned::share(&state, share_id, user.id).await?;
|
||||
let deleted = sqlx::query("delete from shares where id = $1")
|
||||
.bind(share_id)
|
||||
.execute(&state.db)
|
||||
|
||||
+46
-59
@@ -81,12 +81,13 @@ async fn album_name(state: &AppState, album_id: Uuid) -> Result<String, ApiError
|
||||
|
||||
pub async fn album_zip(
|
||||
State(state): State<AppState>,
|
||||
user: crate::auth::AuthUser,
|
||||
Path(album_id): Path<Uuid>,
|
||||
Form(request): Form<ZipRequest>,
|
||||
) -> ApiResult<Response> {
|
||||
let name = album_name(&state, album_id).await?;
|
||||
let album = crate::owned::album(&state, album_id, user.id).await?;
|
||||
let photos = ready_photos(&state, album_id, &parse_ids(&request.ids)?).await?;
|
||||
stream_zip(state, photos, &name)
|
||||
stream_zip(state, photos, &album.name)
|
||||
}
|
||||
|
||||
pub async fn share_zip(
|
||||
@@ -136,9 +137,6 @@ struct Entry {
|
||||
offset: u64,
|
||||
dos_time: u16,
|
||||
dos_date: u16,
|
||||
/// Stored at upload/processing time; photos from before hashes existed
|
||||
/// have None and take the slower spool path (which backfills it).
|
||||
crc: Option<u32>,
|
||||
}
|
||||
|
||||
struct ZipPlan {
|
||||
@@ -179,7 +177,6 @@ fn plan_zip(photos: &[Photo]) -> Result<ZipPlan, ApiError> {
|
||||
offset: entry_offset,
|
||||
dos_time,
|
||||
dos_date,
|
||||
crc: photo.crc32.map(|v| v as u32),
|
||||
});
|
||||
}
|
||||
let cd_offset = offset;
|
||||
@@ -281,23 +278,26 @@ fn stream_zip(state: AppState, photos: Vec<Photo>, album_name: &str) -> ApiResul
|
||||
.map_err(|e| anyhow::anyhow!("building response: {e}").into())
|
||||
}
|
||||
|
||||
enum Fetched {
|
||||
/// CRC already known — the body streams straight into the response.
|
||||
Direct(Box<aws_sdk_s3::operation::get_object::GetObjectOutput>),
|
||||
/// Pre-hash photo: spooled to a temp file to compute the CRC first.
|
||||
Spooled(tokio::fs::File, u32),
|
||||
struct Fetched {
|
||||
file: tokio::fs::File,
|
||||
crc: u32,
|
||||
/// sha256 hex — always computed so legacy photos (crc-only) get their
|
||||
/// content hash backfilled, restoring upload dedup for them.
|
||||
sha256: String,
|
||||
}
|
||||
|
||||
/// Start fetching an original. With a known CRC this only opens the S3
|
||||
/// response (the body is consumed later, straight into the zip stream);
|
||||
/// otherwise the object is spooled to an anonymous temp file to compute the
|
||||
/// CRC, verifying the byte count the zip plan promised.
|
||||
/// Fetch an original and spool it to an anonymous temp file, computing crc32
|
||||
/// and sha256 and verifying the byte count the zip plan promised. Spooling
|
||||
/// (rather than streaming the live S3 body straight through) is deliberate:
|
||||
/// the prefetched entry is fully read immediately, so no S3 connection sits
|
||||
/// idle across the previous entry's (possibly slow) client stream — which S3
|
||||
/// idle-timeouts would otherwise reset mid-download.
|
||||
fn fetch_entry(
|
||||
state: &AppState,
|
||||
key: String,
|
||||
expected_size: u64,
|
||||
crc_known: bool,
|
||||
) -> JoinHandle<anyhow::Result<Fetched>> {
|
||||
use sha2::Digest;
|
||||
let state = state.clone();
|
||||
tokio::spawn(async move {
|
||||
let object = state
|
||||
@@ -308,12 +308,10 @@ fn fetch_entry(
|
||||
.send()
|
||||
.await
|
||||
.map_err(|e| anyhow::anyhow!("fetching {key}: {e}"))?;
|
||||
if crc_known {
|
||||
return Ok(Fetched::Direct(Box::new(object)));
|
||||
}
|
||||
let mut file = tokio::fs::File::from_std(tempfile::tempfile()?);
|
||||
let mut reader = object.body.into_async_read();
|
||||
let mut hasher = crc32fast::Hasher::new();
|
||||
let mut crc = crc32fast::Hasher::new();
|
||||
let mut sha = sha2::Sha256::new();
|
||||
let mut written: u64 = 0;
|
||||
let mut buf = vec![0u8; 128 * 1024];
|
||||
loop {
|
||||
@@ -321,7 +319,8 @@ fn fetch_entry(
|
||||
if n == 0 {
|
||||
break;
|
||||
}
|
||||
hasher.update(&buf[..n]);
|
||||
crc.update(&buf[..n]);
|
||||
sha.update(&buf[..n]);
|
||||
file.write_all(&buf[..n]).await?;
|
||||
written += n as u64;
|
||||
}
|
||||
@@ -331,7 +330,11 @@ fn fetch_entry(
|
||||
);
|
||||
file.flush().await?;
|
||||
file.seek(std::io::SeekFrom::Start(0)).await?;
|
||||
Ok(Fetched::Spooled(file, hasher.finalize()))
|
||||
Ok(Fetched {
|
||||
file,
|
||||
crc: crc.finalize(),
|
||||
sha256: hex::encode(sha.finalize()),
|
||||
})
|
||||
})
|
||||
}
|
||||
|
||||
@@ -344,30 +347,23 @@ async fn write_zip(
|
||||
const FLAGS: u16 = 0x0800;
|
||||
let mut crcs = Vec::with_capacity(plan.entries.len());
|
||||
|
||||
// Prefetch: start fetching the next object while streaming the current one.
|
||||
// Prefetch: spool the next object to a temp file while streaming the
|
||||
// current one — the prefetched body is drained immediately, never held
|
||||
// open across the current entry's client stream.
|
||||
let mut pending: Option<JoinHandle<anyhow::Result<Fetched>>> = None;
|
||||
for (i, entry) in plan.entries.iter().enumerate() {
|
||||
let current = match pending.take() {
|
||||
Some(handle) => handle,
|
||||
None => fetch_entry(state, entry.s3_key.clone(), entry.size, entry.crc.is_some()),
|
||||
None => fetch_entry(state, entry.s3_key.clone(), entry.size),
|
||||
};
|
||||
if let Some(next) = plan.entries.get(i + 1) {
|
||||
pending = Some(fetch_entry(
|
||||
state,
|
||||
next.s3_key.clone(),
|
||||
next.size,
|
||||
next.crc.is_some(),
|
||||
));
|
||||
pending = Some(fetch_entry(state, next.s3_key.clone(), next.size));
|
||||
}
|
||||
let fetched = current
|
||||
let mut fetched = current
|
||||
.await
|
||||
.map_err(|e| anyhow::anyhow!("fetch task failed: {e}"))?
|
||||
.map_err(|e| anyhow::anyhow!("photo {}: {e:#}", entry.photo_id))?;
|
||||
let crc = match &fetched {
|
||||
Fetched::Direct(_) => entry.crc.expect("direct fetch implies known crc"),
|
||||
Fetched::Spooled(_, crc) => *crc,
|
||||
};
|
||||
crcs.push(crc);
|
||||
crcs.push(fetched.crc);
|
||||
|
||||
let mut lfh = Vec::with_capacity(30 + entry.name.len());
|
||||
lfh.extend_from_slice(&0x04034b50u32.to_le_bytes());
|
||||
@@ -376,35 +372,26 @@ async fn write_zip(
|
||||
lfh.extend_from_slice(&0u16.to_le_bytes()); // method: stored
|
||||
lfh.extend_from_slice(&entry.dos_time.to_le_bytes());
|
||||
lfh.extend_from_slice(&entry.dos_date.to_le_bytes());
|
||||
lfh.extend_from_slice(&crc.to_le_bytes());
|
||||
lfh.extend_from_slice(&fetched.crc.to_le_bytes());
|
||||
lfh.extend_from_slice(&(entry.size as u32).to_le_bytes()); // compressed
|
||||
lfh.extend_from_slice(&(entry.size as u32).to_le_bytes()); // uncompressed
|
||||
lfh.extend_from_slice(&(entry.name.len() as u16).to_le_bytes());
|
||||
lfh.extend_from_slice(&0u16.to_le_bytes()); // extra len
|
||||
lfh.extend_from_slice(&entry.name);
|
||||
out.write_all(&lfh).await?;
|
||||
match fetched {
|
||||
Fetched::Direct(object) => {
|
||||
let mut reader = object.body.into_async_read();
|
||||
let copied = tokio::io::copy(&mut reader, &mut out).await?;
|
||||
anyhow::ensure!(
|
||||
copied == entry.size,
|
||||
"{} is {copied} bytes in s3 but {} in the database",
|
||||
entry.s3_key,
|
||||
entry.size
|
||||
);
|
||||
}
|
||||
Fetched::Spooled(mut file, crc) => {
|
||||
tokio::io::copy(&mut file, &mut out).await?;
|
||||
// Self-heal: store the freshly computed crc so the next
|
||||
// download of this photo streams directly.
|
||||
let _ = sqlx::query("update photos set crc32 = coalesce(crc32, $2) where id = $1")
|
||||
.bind(entry.photo_id)
|
||||
.bind(i64::from(crc))
|
||||
.execute(&state.db)
|
||||
.await;
|
||||
}
|
||||
}
|
||||
tokio::io::copy(&mut fetched.file, &mut out).await?;
|
||||
|
||||
// Self-heal legacy photos: backfill both hashes so future zips and
|
||||
// upload dedup both work for them.
|
||||
let _ = sqlx::query(
|
||||
"update photos set crc32 = coalesce(crc32, $2), sha256 = coalesce(sha256, $3)
|
||||
where id = $1",
|
||||
)
|
||||
.bind(entry.photo_id)
|
||||
.bind(i64::from(fetched.crc))
|
||||
.bind(&fetched.sha256)
|
||||
.execute(&state.db)
|
||||
.await;
|
||||
}
|
||||
|
||||
// Central directory.
|
||||
|
||||
@@ -0,0 +1,254 @@
|
||||
//! Tenant-isolation matrix: every admin endpoint must treat another user's
|
||||
//! resources as nonexistent (404), and unauthenticated requests as 401.
|
||||
//!
|
||||
//! Needs a disposable Postgres database:
|
||||
//! TEST_DATABASE_URL=postgres://photos:photos@localhost:5432/photos_test cargo test
|
||||
//! Skips silently when TEST_DATABASE_URL is unset. S3 is never contacted —
|
||||
//! the matrix stops at the ownership checks by construction.
|
||||
|
||||
use axum::body::Body;
|
||||
use axum::http::{header, Request, StatusCode};
|
||||
use cookie::{Cookie, CookieJar, Key};
|
||||
use sha2::{Digest, Sha512};
|
||||
use tower::ServiceExt;
|
||||
use uuid::Uuid;
|
||||
|
||||
use photos::config::Config;
|
||||
use photos::state::AppState;
|
||||
|
||||
const SECRET: &str = "test-secret-test-secret-test-secret-1234";
|
||||
|
||||
fn test_config(database_url: String) -> Config {
|
||||
Config {
|
||||
database_url,
|
||||
bind_addr: "127.0.0.1:0".into(),
|
||||
public_url: "http://localhost:8080".into(),
|
||||
session_secret: SECRET.into(),
|
||||
s3_bucket: "photos".into(),
|
||||
// Unroutable on purpose: no test may reach S3.
|
||||
s3_endpoint: Some("http://127.0.0.1:9".into()),
|
||||
s3_region: "us-east-1".into(),
|
||||
s3_access_key: "test".into(),
|
||||
s3_secret_key: "test".into(),
|
||||
s3_force_path_style: true,
|
||||
oidc_issuer: "https://auth.invalid".into(),
|
||||
oidc_client_id: "x".into(),
|
||||
oidc_client_secret: "x".into(),
|
||||
allowed_emails: vec!["a@test".into(), "b@test".into()],
|
||||
static_dir: "frontend/dist".into(),
|
||||
worker_concurrency: 1,
|
||||
dev_autologin_email: None,
|
||||
}
|
||||
}
|
||||
|
||||
fn session_for(user_id: Uuid, email: &str) -> String {
|
||||
let key = Key::from(&Sha512::digest(SECRET.as_bytes()));
|
||||
let exp = chrono::Utc::now().timestamp() + 3600;
|
||||
// Use the production payload builder so the test can't drift from what
|
||||
// user_from_jar parses.
|
||||
let mut jar = CookieJar::new();
|
||||
jar.signed_mut(&key).add(Cookie::new(
|
||||
"photos_session",
|
||||
photos::auth::session_payload(user_id, email, exp),
|
||||
));
|
||||
format!("photos_session={}", jar.get("photos_session").unwrap().value())
|
||||
}
|
||||
|
||||
async fn request(
|
||||
router: &axum::Router,
|
||||
method: &str,
|
||||
path: &str,
|
||||
cookie: Option<&str>,
|
||||
json: Option<serde_json::Value>,
|
||||
) -> (StatusCode, serde_json::Value) {
|
||||
let mut builder = Request::builder().method(method).uri(path);
|
||||
if let Some(cookie) = cookie {
|
||||
builder = builder.header(header::COOKIE, cookie);
|
||||
}
|
||||
let body = match json {
|
||||
Some(value) => {
|
||||
builder = builder.header(header::CONTENT_TYPE, "application/json");
|
||||
Body::from(value.to_string())
|
||||
}
|
||||
// Zip endpoints take a form; everything else ignores the body.
|
||||
None if path.ends_with("/zip") => {
|
||||
builder = builder.header(header::CONTENT_TYPE, "application/x-www-form-urlencoded");
|
||||
Body::from("ids=")
|
||||
}
|
||||
None => Body::empty(),
|
||||
};
|
||||
let response = router
|
||||
.clone()
|
||||
.oneshot(builder.body(body).unwrap())
|
||||
.await
|
||||
.unwrap();
|
||||
let status = response.status();
|
||||
let bytes = axum::body::to_bytes(response.into_body(), 1 << 20)
|
||||
.await
|
||||
.unwrap();
|
||||
let value = serde_json::from_slice(&bytes).unwrap_or(serde_json::Value::Null);
|
||||
(status, value)
|
||||
}
|
||||
|
||||
async fn seed_user(state: &AppState, email: &str) -> Uuid {
|
||||
let (id,): (Uuid,) = sqlx::query_as(
|
||||
"insert into users (oidc_subject, email) values ($1, $2) returning id",
|
||||
)
|
||||
.bind(format!("test:{email}"))
|
||||
.bind(email)
|
||||
.fetch_one(&state.db)
|
||||
.await
|
||||
.unwrap();
|
||||
id
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn tenant_isolation_matrix() {
|
||||
let Ok(database_url) = std::env::var("TEST_DATABASE_URL") else {
|
||||
eprintln!("TEST_DATABASE_URL not set — skipping tenancy matrix");
|
||||
return;
|
||||
};
|
||||
let state = AppState::new(test_config(database_url)).await.unwrap();
|
||||
sqlx::query("truncate users, albums, photos, shares, ratings, tags, jobs cascade")
|
||||
.execute(&state.db)
|
||||
.await
|
||||
.unwrap();
|
||||
|
||||
let alice = seed_user(&state, "a@test").await;
|
||||
let bob = seed_user(&state, "b@test").await;
|
||||
let cookie_a = session_for(alice, "a@test");
|
||||
let cookie_b = session_for(bob, "b@test");
|
||||
let router = photos::routes::router(&state).with_state(state.clone());
|
||||
|
||||
// Alice creates an album through the real API.
|
||||
let (status, album) = request(
|
||||
&router,
|
||||
"POST",
|
||||
"/api/albums",
|
||||
Some(&cookie_a),
|
||||
Some(serde_json::json!({ "name": "Alice's Wedding" })),
|
||||
)
|
||||
.await;
|
||||
assert_eq!(status, StatusCode::OK);
|
||||
let album_id = album["id"].as_str().unwrap().to_string();
|
||||
|
||||
// Seed a photo (kept non-ready so no code path reaches S3) and a share.
|
||||
let photo_id = Uuid::new_v4();
|
||||
sqlx::query(
|
||||
"insert into photos (id, album_id, filename, content_type, size_bytes, sha256)
|
||||
values ($1, $2::uuid, 'a.jpg', 'image/jpeg', 3, 'hash-a')",
|
||||
)
|
||||
.bind(photo_id)
|
||||
.bind(&album_id)
|
||||
.execute(&state.db)
|
||||
.await
|
||||
.unwrap();
|
||||
let share_id = Uuid::new_v4();
|
||||
sqlx::query("insert into shares (id, album_id, token) values ($1, $2::uuid, 'tenanttesttoken123456789')")
|
||||
.bind(share_id)
|
||||
.bind(&album_id)
|
||||
.execute(&state.db)
|
||||
.await
|
||||
.unwrap();
|
||||
|
||||
// ---- Bob vs Alice's resources: everything must be a 404 (or absent). ----
|
||||
let bob_hits: &[(&str, String, Option<serde_json::Value>)] = &[
|
||||
("GET", format!("/api/albums/{album_id}"), None),
|
||||
(
|
||||
"PATCH",
|
||||
format!("/api/albums/{album_id}"),
|
||||
Some(serde_json::json!({ "name": "stolen" })),
|
||||
),
|
||||
("DELETE", format!("/api/albums/{album_id}"), None),
|
||||
("POST", format!("/api/albums/{album_id}/photos?filename=x.jpg"), None),
|
||||
("GET", format!("/api/albums/{album_id}/shares"), None),
|
||||
(
|
||||
"POST",
|
||||
format!("/api/albums/{album_id}/shares"),
|
||||
Some(serde_json::json!({ "label": "x" })),
|
||||
),
|
||||
("POST", format!("/api/albums/{album_id}/zip"), None),
|
||||
("GET", format!("/api/albums/{album_id}/photos/by-hash/hash-a"), None),
|
||||
("DELETE", format!("/api/photos/{photo_id}"), None),
|
||||
("POST", format!("/api/photos/{photo_id}/reprocess"), None),
|
||||
("DELETE", format!("/api/shares/{share_id}"), None),
|
||||
("POST", format!("/api/shares/{share_id}/reset-lock"), None),
|
||||
];
|
||||
for (method, path, body) in bob_hits {
|
||||
let (status, _) = request(&router, method, path, Some(&cookie_b), body.clone()).await;
|
||||
assert_eq!(
|
||||
status,
|
||||
StatusCode::NOT_FOUND,
|
||||
"cross-tenant {method} {path} must 404"
|
||||
);
|
||||
}
|
||||
let (status, list) = request(&router, "GET", "/api/albums", Some(&cookie_b), None).await;
|
||||
assert_eq!(status, StatusCode::OK);
|
||||
assert_eq!(list.as_array().unwrap().len(), 0, "bob must see no albums");
|
||||
|
||||
// ---- Dual-auth image routes must ALSO reject a non-owning photographer.
|
||||
// Bob owns no share and doesn't own the album, so authorize_photo falls
|
||||
// through to the share-cookie path and 401s BEFORE any S3 access — the
|
||||
// cross-tenant original leak these routes previously allowed. ----
|
||||
for path in [
|
||||
format!("/api/img/{photo_id}/thumb"),
|
||||
format!("/api/img/{photo_id}/preview"),
|
||||
format!("/api/photos/{photo_id}/original"),
|
||||
] {
|
||||
let (status, _) = request(&router, "GET", &path, Some(&cookie_b), None).await;
|
||||
assert_eq!(
|
||||
status,
|
||||
StatusCode::UNAUTHORIZED,
|
||||
"cross-tenant image GET {path} must not authorize"
|
||||
);
|
||||
}
|
||||
|
||||
// ---- Alice keeps full access to her own resources. ----
|
||||
let (status, list) = request(&router, "GET", "/api/albums", Some(&cookie_a), None).await;
|
||||
assert_eq!(status, StatusCode::OK);
|
||||
assert_eq!(list.as_array().unwrap().len(), 1);
|
||||
let (status, _) = request(
|
||||
&router,
|
||||
"GET",
|
||||
&format!("/api/albums/{album_id}"),
|
||||
Some(&cookie_a),
|
||||
None,
|
||||
)
|
||||
.await;
|
||||
assert_eq!(status, StatusCode::OK);
|
||||
let (status, _) = request(
|
||||
&router,
|
||||
"GET",
|
||||
&format!("/api/albums/{album_id}/photos/by-hash/hash-a"),
|
||||
Some(&cookie_a),
|
||||
None,
|
||||
)
|
||||
.await;
|
||||
assert_eq!(status, StatusCode::OK);
|
||||
// Ownership check runs before the body is read: empty upload = 400, not 404.
|
||||
let (status, _) = request(
|
||||
&router,
|
||||
"POST",
|
||||
&format!("/api/albums/{album_id}/photos?filename=x.jpg"),
|
||||
Some(&cookie_a),
|
||||
None,
|
||||
)
|
||||
.await;
|
||||
assert_eq!(status, StatusCode::BAD_REQUEST);
|
||||
// No ready photos yet: zip is a 400 for the owner, never an S3 call.
|
||||
let (status, _) = request(
|
||||
&router,
|
||||
"POST",
|
||||
&format!("/api/albums/{album_id}/zip"),
|
||||
Some(&cookie_a),
|
||||
None,
|
||||
)
|
||||
.await;
|
||||
assert_eq!(status, StatusCode::BAD_REQUEST);
|
||||
|
||||
// ---- No session at all: 401 on the admin surface. ----
|
||||
for path in ["/api/albums", "/api/me"] {
|
||||
let (status, _) = request(&router, "GET", path, None, None).await;
|
||||
assert_eq!(status, StatusCode::UNAUTHORIZED, "{path} without session");
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user