fix: align upload-asset URL contract end-to-end

- ImageUploadService::store() now returns /assets/uploads/<token>/<file>
  so the URL the upload handler emits matches the new GET route.
- public/index.php registers a dedicated GET /assets/uploads/{userToken}/{filename}
  route; the legacy /assets/{kind}/{filename} is kept as a fallback.
- GetAssets reads the upload token from $request->server['__uploads_token']
  (the front controller threads it that way) instead of the cookies bag.
- Adds GetAssets unit tests for the upload-token happy path and a
  token-mismatch 404, plus a FullFlowTest step that uploads and re-fetches
  the asset through the front controller.
This commit is contained in:
Keith Solomon
2026-07-06 23:21:33 -05:00
parent 5d9af7a4fd
commit 61abb93e59
6 changed files with 136 additions and 8 deletions
+57
View File
@@ -67,4 +67,61 @@ final class GetAssetsTest extends TestCase
self::assertSame(404, $response->status);
}
public function testItServesAnUploadedAssetWhenTheServerTokenMatches(): void
{
$userToken = str_repeat('a', 64);
$namespace = $this->uploadsDir . '/' . $userToken;
mkdir($namespace, 0700, true);
$payload = base64_decode(
'iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAADUlEQVR4nGNgYGBgAAAABQABh6FO1AAAAABJRU5ErkJggg==',
true,
);
file_put_contents($namespace . '/demo.png', $payload);
$handler = new GetAssets($this->placeholderDir, $this->uploadsDir);
$request = new Request(
[],
[],
[],
[],
['__uploads_token' => $userToken],
'',
'GET',
'/assets/uploads/' . $userToken . '/demo.png',
null,
'',
);
$response = $handler->handle(
$request,
['kind' => 'uploads', 'userToken' => $userToken, 'filename' => 'demo.png'],
);
self::assertSame(200, $response->status);
self::assertSame('image/png', $response->headers['Content-Type'] ?? '');
self::assertSame($payload, $response->body);
}
public function testItRefusesAnUploadedAssetWhenTheServerTokenDiffers(): void
{
$handler = new GetAssets($this->placeholderDir, $this->uploadsDir);
$request = new Request(
[],
[],
[],
[],
['__uploads_token' => str_repeat('a', 64)],
'',
'GET',
'/assets/uploads/abc/def.png',
null,
'',
);
$response = $handler->handle(
$request,
['kind' => 'uploads', 'userToken' => str_repeat('b', 64), 'filename' => 'def.png'],
);
self::assertSame(404, $response->status);
}
}