feat(media-proxy): sign attachment URLs and gate origins (#2830)

This commit is contained in:
Hampus
2026-09-18 15:57:32 +02:00
committed by GitHub
parent 025c01ab13
commit 522cf08e61
108 changed files with 10148 additions and 441 deletions
+95 -1
View File
@@ -107,6 +107,63 @@
"security": [{"botToken": []}]
}
},
"/attachments/refresh-urls": {
"post": {
"operationId": "refresh_attachment_urls",
"summary": "Refresh attachment URLs",
"tags": ["Messages"],
"responses": {
"200": {
"description": "Success",
"content": {"application/json": {"schema": {"$ref": "#/components/schemas/RefreshAttachmentUrlsResponse"}}}
},
"400": {
"description": "Bad Request - The request was malformed or contained invalid data",
"content": {"application/json": {"schema": {"$ref": "#/components/schemas/Error"}}}
},
"401": {
"description": "Unauthorized - Authentication is required or the token is invalid",
"content": {"application/json": {"schema": {"$ref": "#/components/schemas/Error"}}}
},
"403": {
"description": "Forbidden - You do not have permission to perform this action",
"content": {"application/json": {"schema": {"$ref": "#/components/schemas/Error"}}}
},
"429": {
"description": "Too Many Requests - You are being rate limited",
"content": {"application/json": {"schema": {"$ref": "#/components/schemas/ThrottledError"}}},
"headers": {
"Retry-After": {
"description": "Number of seconds to wait before retrying (only on 429)",
"schema": {"type": "integer"}
},
"X-RateLimit-Limit": {
"description": "The number of requests that can be made in the current window",
"schema": {"type": "integer"}
},
"X-RateLimit-Remaining": {
"description": "The number of remaining requests that can be made",
"schema": {"type": "integer"}
},
"X-RateLimit-Reset": {
"description": "Unix timestamp when the rate limit resets",
"schema": {"type": "integer"}
}
}
},
"500": {
"description": "Internal Server Error - An unexpected error occurred",
"content": {"application/json": {"schema": {"$ref": "#/components/schemas/Error"}}}
}
},
"description": "Reissues the expiring signature on attachment URLs. Returns one entry per requested URL, in the order they were requested, each pairing the URL exactly as it was sent with a freshly signed copy. A URL that is not an attachment URL of this instance is returned unchanged. No membership or existence check is performed.",
"security": [{"botToken": []}, {"sessionToken": []}],
"requestBody": {
"required": true,
"content": {"application/json": {"schema": {"$ref": "#/components/schemas/RefreshAttachmentUrlsRequest"}}}
}
}
},
"/auth/authorize-ip": {
"post": {
"operationId": "authorize_ip_address",
@@ -28845,6 +28902,31 @@
"properties": {"token": {"description": "The IP authorization token from email", "type": "string"}},
"required": ["token"]
},
"RefreshAttachmentUrlsRequest": {
"type": "object",
"properties": {
"attachment_urls": {
"minItems": 1,
"maxItems": 50,
"type": "array",
"items": {"type": "string", "maxLength": 2048},
"description": "Attachment URLs to refresh (1-50 entries, each at most 2048 characters)"
}
},
"required": ["attachment_urls"]
},
"RefreshAttachmentUrlsResponse": {
"type": "object",
"properties": {
"refreshed_urls": {
"type": "array",
"items": {"$ref": "#/components/schemas/RefreshedAttachmentUrl"},
"description": "One entry per requested URL, in the order they were requested"
}
},
"required": ["refreshed_urls"],
"additionalProperties": false
},
"ApplicationsMeResponse": {
"type": "object",
"properties": {
@@ -29351,6 +29433,18 @@
{"name": "SPAMMER", "value": "64", "description": "User is flagged as a spammer"}
]
},
"RefreshedAttachmentUrl": {
"type": "object",
"properties": {
"original": {"type": "string", "description": "The requested URL, echoed back unchanged"},
"refreshed": {
"type": "string",
"description": "The same URL carrying a fresh signature, or the original when it is not an attachment URL of ours"
}
},
"required": ["original", "refreshed"],
"additionalProperties": false
},
"PasswordType": {"type": "string"},
"EmailType": {"type": "string"},
"AuthSessionLocation": {
@@ -34217,8 +34311,8 @@
{"name": "Billing", "description": "Subscription and payment management via Stripe"},
{"name": "Premium", "description": "Premium subscription features and benefits"},
{"name": "Gifts", "description": "Gift codes and redemption"},
{"name": "Connections"},
{"name": "Messages"},
{"name": "Connections"},
{"name": "Donations"},
{"name": "Experiments"},
{"name": "Geolocation"},