+40









lyzno1
GitHub
-LAN-
GuanMu
Davide Delbianco
NeatGuyCoding
kenwoodjw
Yongtao Huang
Yongtao Huang
Qiang Lee
李强04
autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Asuka Minato
Matri Qi
huayaoyue6
Bowen Liang
znn
crazywoola
crazywoola
Copilot
yihong
Muke Wang
wangmuke
Wu Tianwei
quicksand
非法操作
zxhlyh
Eric Guo
Zhedong Cen
jiangbo721
github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
hjlarry
lxsummer
湛露先生
Guangdong Liu
QuantumGhost
Claude
Yessenia-d
huangzhuo1949
huangzhuo
17hz
Amy
Joel
Nite Knite
Yeuoly
Petrus Han
iamjoel
Kalo Chin
Ujjwal Maurya
Maries
5bbf685035
Signed-off-by: -LAN- <[email protected]> Signed-off-by: kenwoodjw <[email protected]> Signed-off-by: Yongtao Huang <[email protected]> Signed-off-by: yihong0618 <[email protected]> Signed-off-by: zhanluxianshen <[email protected]> Co-authored-by: -LAN- <[email protected]> Co-authored-by: GuanMu <[email protected]> Co-authored-by: Davide Delbianco <[email protected]> Co-authored-by: NeatGuyCoding <[email protected]> Co-authored-by: kenwoodjw <[email protected]> Co-authored-by: Yongtao Huang <[email protected]> Co-authored-by: Yongtao Huang <[email protected]> Co-authored-by: Qiang Lee <[email protected]> Co-authored-by: 李强04 <[email protected]> Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com> Co-authored-by: Asuka Minato <[email protected]> Co-authored-by: Matri Qi <[email protected]> Co-authored-by: huayaoyue6 <[email protected]> Co-authored-by: Bowen Liang <[email protected]> Co-authored-by: znn <[email protected]> Co-authored-by: crazywoola <[email protected]> Co-authored-by: crazywoola <[email protected]> Co-authored-by: Copilot <[email protected]> Co-authored-by: yihong <[email protected]> Co-authored-by: Muke Wang <[email protected]> Co-authored-by: wangmuke <[email protected]> Co-authored-by: Wu Tianwei <[email protected]> Co-authored-by: quicksand <[email protected]> Co-authored-by: 非法操作 <[email protected]> Co-authored-by: zxhlyh <[email protected]> Co-authored-by: Eric Guo <[email protected]> Co-authored-by: Zhedong Cen <[email protected]> Co-authored-by: jiangbo721 <[email protected]> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: hjlarry <[email protected]> Co-authored-by: lxsummer <[email protected]> Co-authored-by: 湛露先生 <[email protected]> Co-authored-by: Guangdong Liu <[email protected]> Co-authored-by: QuantumGhost <[email protected]> Co-authored-by: Claude <[email protected]> Co-authored-by: Yessenia-d <[email protected]> Co-authored-by: huangzhuo1949 <[email protected]> Co-authored-by: huangzhuo <[email protected]> Co-authored-by: 17hz <[email protected]> Co-authored-by: Amy <[email protected]> Co-authored-by: Joel <[email protected]> Co-authored-by: Nite Knite <[email protected]> Co-authored-by: Yeuoly <[email protected]> Co-authored-by: Petrus Han <[email protected]> Co-authored-by: iamjoel <[email protected]> Co-authored-by: Kalo Chin <[email protected]> Co-authored-by: Ujjwal Maurya <[email protected]> Co-authored-by: Maries <[email protected]>
56 lines
2.0 KiB
Python
56 lines
2.0 KiB
Python
from urllib.parse import quote
|
|
|
|
from flask import Response
|
|
from flask_restx import Resource, reqparse
|
|
from werkzeug.exceptions import Forbidden, NotFound
|
|
|
|
from controllers.common.errors import UnsupportedFileTypeError
|
|
from controllers.files import files_ns
|
|
from core.tools.signature import verify_tool_file_signature
|
|
from core.tools.tool_file_manager import ToolFileManager
|
|
from models import db as global_db
|
|
|
|
|
|
@files_ns.route("/tools/<uuid:file_id>.<string:extension>")
|
|
class ToolFileApi(Resource):
|
|
def get(self, file_id, extension):
|
|
file_id = str(file_id)
|
|
|
|
parser = reqparse.RequestParser()
|
|
|
|
parser.add_argument("timestamp", type=str, required=True, location="args")
|
|
parser.add_argument("nonce", type=str, required=True, location="args")
|
|
parser.add_argument("sign", type=str, required=True, location="args")
|
|
parser.add_argument("as_attachment", type=bool, required=False, default=False, location="args")
|
|
|
|
args = parser.parse_args()
|
|
if not verify_tool_file_signature(
|
|
file_id=file_id, timestamp=args["timestamp"], nonce=args["nonce"], sign=args["sign"]
|
|
):
|
|
raise Forbidden("Invalid request.")
|
|
|
|
try:
|
|
tool_file_manager = ToolFileManager(engine=global_db.engine)
|
|
stream, tool_file = tool_file_manager.get_file_generator_by_tool_file_id(
|
|
file_id,
|
|
)
|
|
|
|
if not stream or not tool_file:
|
|
raise NotFound("file is not found")
|
|
except Exception:
|
|
raise UnsupportedFileTypeError()
|
|
|
|
response = Response(
|
|
stream,
|
|
mimetype=tool_file.mimetype,
|
|
direct_passthrough=True,
|
|
headers={},
|
|
)
|
|
if tool_file.size > 0:
|
|
response.headers["Content-Length"] = str(tool_file.size)
|
|
if args["as_attachment"]:
|
|
encoded_filename = quote(tool_file.name)
|
|
response.headers["Content-Disposition"] = f"attachment; filename*=UTF-8''{encoded_filename}"
|
|
|
|
return response
|