mirror of
https://github.com/abhinavxd/libredesk.git
synced 2026-10-03 12:10:28 +00:00
Sign all avatar URLs in widget endpoints and WS broadcasts
This commit is contained in:
@@ -467,6 +467,7 @@ func handleChatSendMessage(r *fastglue.Request) error {
|
||||
for i := range message.Attachments {
|
||||
message.Attachments[i].URL = app.media.GetSignedURL(message.Attachments[i].UUID)
|
||||
}
|
||||
app.conversation.SignAvatarURL(&message.Author.AvatarURL)
|
||||
|
||||
return r.SendEnvelope(cmodels.ChatMessage{
|
||||
UUID: message.UUID,
|
||||
@@ -602,6 +603,7 @@ func handleWidgetMediaUpload(r *fastglue.Request) error {
|
||||
for i := range insertedMessage.Attachments {
|
||||
insertedMessage.Attachments[i].URL = app.media.GetSignedURL(insertedMessage.Attachments[i].UUID)
|
||||
}
|
||||
app.conversation.SignAvatarURL(&insertedMessage.Author.AvatarURL)
|
||||
|
||||
return r.SendEnvelope(insertedMessage)
|
||||
}
|
||||
|
||||
@@ -416,7 +416,10 @@ func (c *Manager) GetContactChatConversations(contactID, inboxID int) ([]models.
|
||||
if conversations[i].Assignee.ID == 0 {
|
||||
conversations[i].Assignee = nil
|
||||
}
|
||||
c.signChatAssigneeAvatar(conversations[i].Assignee)
|
||||
if conversations[i].Assignee != nil {
|
||||
c.SignAvatarURL(&conversations[i].Assignee.AvatarURL)
|
||||
}
|
||||
c.SignAvatarURL(&conversations[i].LastChatMessage.Author.AvatarURL)
|
||||
}
|
||||
return conversations, nil
|
||||
}
|
||||
@@ -431,18 +434,20 @@ func (c *Manager) GetChatConversation(conversationUUID string) (models.ChatConve
|
||||
if conversation.Assignee.ID == 0 {
|
||||
conversation.Assignee = nil
|
||||
}
|
||||
c.signChatAssigneeAvatar(conversation.Assignee)
|
||||
if conversation.Assignee != nil {
|
||||
c.SignAvatarURL(&conversation.Assignee.AvatarURL)
|
||||
}
|
||||
c.SignAvatarURL(&conversation.LastChatMessage.Author.AvatarURL)
|
||||
return conversation, nil
|
||||
}
|
||||
|
||||
// signChatAssigneeAvatar converts a raw /uploads/ avatar path to a signed URL.
|
||||
func (c *Manager) signChatAssigneeAvatar(assignee *umodels.ChatUser) {
|
||||
if assignee == nil || !assignee.AvatarURL.Valid || assignee.AvatarURL.String == "" {
|
||||
// SignAvatarURL converts a raw /uploads/ avatar path to a signed URL.
|
||||
func (c *Manager) SignAvatarURL(avatarURL *null.String) {
|
||||
if avatarURL == nil || !avatarURL.Valid || avatarURL.String == "" {
|
||||
return
|
||||
}
|
||||
if strings.HasPrefix(assignee.AvatarURL.String, "/uploads/") {
|
||||
avatarUUID := strings.TrimPrefix(assignee.AvatarURL.String, "/uploads/")
|
||||
assignee.AvatarURL = null.StringFrom(c.mediaStore.GetSignedURL(avatarUUID))
|
||||
if strings.HasPrefix(avatarURL.String, "/uploads/") {
|
||||
*avatarURL = null.StringFrom(c.mediaStore.GetSignedURL(strings.TrimPrefix(avatarURL.String, "/uploads/")))
|
||||
}
|
||||
}
|
||||
|
||||
@@ -697,6 +702,7 @@ func (c *Manager) UpdateConversationUserAssignee(uuid string, assigneeID int, ac
|
||||
// Broadcast conversation update to widget clients with assignee info.
|
||||
agent, err := c.userStore.GetAgent(assigneeID, "")
|
||||
if err == nil {
|
||||
c.SignAvatarURL(&agent.AvatarURL)
|
||||
c.BroadcastConversationToWidget(uuid, conversation.ContactID, conversation.InboxID, map[string]any{
|
||||
"assignee": map[string]any{
|
||||
"id": agent.ID,
|
||||
|
||||
Reference in New Issue
Block a user