Add per-user library settings, folder passwords, and a still picker.
Settings manages folders, thumbnail defaults, and passwords for the signed-in account, and choosing an image now browses saved stills instead of only the desktop file dialog. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -35,7 +35,7 @@ export default defineEventHandler(async (event) => {
|
||||
: Math.floor(Math.random() * 2_147_483_647)
|
||||
const length = frameLength(Number(fields.duration || 5))
|
||||
const hideThumbnail = fields.hideThumbnail === 'true'
|
||||
assertLibraryAccess(event)
|
||||
const ownerKey = libraryOwnerKey(event)
|
||||
const library = publicLibrary(event)
|
||||
const folderId = library.folders.some(folder => folder.id === fields.folderId)
|
||||
? fields.folderId
|
||||
@@ -43,11 +43,21 @@ export default defineEventHandler(async (event) => {
|
||||
if (!folderId) {
|
||||
throw createError({ statusCode: 400, statusMessage: 'Create a library folder before generating' })
|
||||
}
|
||||
assertFolderAccess(event, folderId)
|
||||
await saveStill({
|
||||
ownerKey,
|
||||
folderId,
|
||||
filename: image.filename,
|
||||
data: image.data,
|
||||
width,
|
||||
height
|
||||
})
|
||||
|
||||
const job = createJob()
|
||||
job.maxStep = steps
|
||||
job.hideThumbnail = hideThumbnail
|
||||
job.library = {
|
||||
ownerKey,
|
||||
folderId,
|
||||
hideThumbnail,
|
||||
prompt,
|
||||
|
||||
@@ -1,6 +1,8 @@
|
||||
export default defineEventHandler(async (event) => {
|
||||
assertLibraryAccess(event)
|
||||
const id = getRouterParam(event, 'id')
|
||||
await deleteClip(String(id))
|
||||
const { owner } = assertLibraryOwner(event)
|
||||
const id = String(getRouterParam(event, 'id') || '')
|
||||
const clip = getClip(owner, id)
|
||||
assertFolderAccess(event, clip.folderId)
|
||||
await deleteClip(owner, id)
|
||||
return { ok: true }
|
||||
})
|
||||
|
||||
@@ -1,19 +1,19 @@
|
||||
import { existsSync, readFileSync } from 'node:fs'
|
||||
|
||||
export default defineEventHandler((event) => {
|
||||
assertLibraryAccess(event)
|
||||
const { owner } = assertLibraryOwner(event)
|
||||
const id = String(getRouterParam(event, 'id') || '')
|
||||
const clip = getClip(id)
|
||||
const clip = getClip(owner, id)
|
||||
assertFolderAccess(event, clip.folderId)
|
||||
if (clip.hideThumbnail) {
|
||||
throw createError({ statusCode: 404, statusMessage: 'Thumbnail hidden' })
|
||||
}
|
||||
const path = clipThumbPath(clip.id)
|
||||
const path = clipThumbPath(owner, clip.id)
|
||||
if (!existsSync(path)) {
|
||||
throw createError({ statusCode: 404, statusMessage: 'Thumbnail not found' })
|
||||
}
|
||||
const buf = readFileSync(path)
|
||||
const png = buf[0] === 0x89 && buf[1] === 0x50
|
||||
setHeader(event, 'Content-Type', png ? 'image/png' : 'image/jpeg')
|
||||
setHeader(event, 'Content-Type', imageContentType(buf))
|
||||
setHeader(event, 'Cache-Control', 'private, max-age=3600')
|
||||
return buf
|
||||
})
|
||||
|
||||
@@ -1,10 +1,11 @@
|
||||
import { existsSync, readFileSync } from 'node:fs'
|
||||
|
||||
export default defineEventHandler((event) => {
|
||||
assertLibraryAccess(event)
|
||||
const { owner } = assertLibraryOwner(event)
|
||||
const id = String(getRouterParam(event, 'id') || '')
|
||||
const clip = getClip(id)
|
||||
const path = clipVideoPath(clip.id)
|
||||
const clip = getClip(owner, id)
|
||||
assertFolderAccess(event, clip.folderId)
|
||||
const path = clipVideoPath(owner, clip.id)
|
||||
if (!existsSync(path)) {
|
||||
throw createError({ statusCode: 404, statusMessage: 'Video file is missing' })
|
||||
}
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
export default defineEventHandler(async (event) => {
|
||||
assertLibraryAccess(event)
|
||||
const { owner } = assertLibraryOwner(event)
|
||||
const body = await readBody<{ name?: string }>(event)
|
||||
const folder = await createFolder(String(body?.name || ''))
|
||||
return folder
|
||||
const folder = await createFolder(owner, String(body?.name || ''))
|
||||
return publicFolder(event, folder)
|
||||
})
|
||||
|
||||
@@ -1,5 +1,7 @@
|
||||
export default defineEventHandler(async (event) => {
|
||||
assertLibraryAccess(event)
|
||||
const id = getRouterParam(event, 'id')
|
||||
return await deleteFolder(String(id))
|
||||
const { owner } = assertLibraryOwner(event)
|
||||
const id = String(getRouterParam(event, 'id') || '')
|
||||
const result = await deleteFolder(owner, id)
|
||||
clearFolderUnlock(event, id)
|
||||
return { ...result, ...publicLibrary(event) }
|
||||
})
|
||||
|
||||
@@ -1,6 +1,22 @@
|
||||
export default defineEventHandler(async (event) => {
|
||||
assertLibraryAccess(event)
|
||||
const id = getRouterParam(event, 'id')
|
||||
const body = await readBody<{ name?: string }>(event)
|
||||
return await renameFolder(String(id), String(body?.name || ''))
|
||||
const { owner } = assertLibraryOwner(event)
|
||||
const id = String(getRouterParam(event, 'id') || '')
|
||||
const body = await readBody<{
|
||||
name?: string
|
||||
thumbnailDefault?: boolean
|
||||
password?: string | null
|
||||
currentPassword?: string
|
||||
}>(event)
|
||||
const folder = await updateFolder(owner, id, {
|
||||
name: body?.name,
|
||||
thumbnailDefault: body?.thumbnailDefault,
|
||||
password: body?.password,
|
||||
currentPassword: body?.currentPassword
|
||||
})
|
||||
if (body?.password) {
|
||||
setFolderUnlock(event, folder.id, passwordVersion(folder.passwordHash))
|
||||
} else if (body?.password === '') {
|
||||
clearFolderUnlock(event, folder.id)
|
||||
}
|
||||
return publicLibrary(event)
|
||||
})
|
||||
|
||||
@@ -1,4 +1,5 @@
|
||||
export default defineEventHandler((event) => {
|
||||
clearLibraryUnlock(event)
|
||||
export default defineEventHandler(async (event) => {
|
||||
const body = await readBody<{ folderId?: string }>(event).catch(() => ({} as { folderId?: string }))
|
||||
clearFolderUnlock(event, body?.folderId)
|
||||
return publicLibrary(event)
|
||||
})
|
||||
|
||||
@@ -1,14 +1,19 @@
|
||||
export default defineEventHandler(async (event) => {
|
||||
const body = await readBody<{ password?: string; currentPassword?: string }>(event)
|
||||
if (isLibraryLocked() && !(await verifyLibraryPassword(String(body?.currentPassword || '')))) {
|
||||
throw createError({ statusCode: 401, statusMessage: 'Current library password is incorrect' })
|
||||
const { owner } = assertLibraryOwner(event)
|
||||
const body = await readBody<{ folderId?: string; password?: string; currentPassword?: string }>(event)
|
||||
const folderId = String(body?.folderId || '')
|
||||
if (!folderId) {
|
||||
throw createError({ statusCode: 400, statusMessage: 'Choose a folder to protect' })
|
||||
}
|
||||
const next = String(body?.password || '').trim()
|
||||
if (next && next.length < 4) {
|
||||
throw createError({ statusCode: 400, statusMessage: 'Use at least 4 characters, or leave blank to remove the password' })
|
||||
await updateFolder(owner, folderId, {
|
||||
password: body?.password ?? '',
|
||||
currentPassword: body?.currentPassword
|
||||
})
|
||||
const folder = assertLibraryOwner(event).catalog.folders.find(item => item.id === folderId)
|
||||
if (folder?.passwordHash) {
|
||||
setFolderUnlock(event, folder.id, passwordVersion(folder.passwordHash))
|
||||
} else {
|
||||
clearFolderUnlock(event, folderId)
|
||||
}
|
||||
const version = await setLibraryPassword(next || null)
|
||||
if (next) setLibraryUnlock(event, version)
|
||||
else clearLibraryUnlock(event)
|
||||
return publicLibrary(event)
|
||||
})
|
||||
|
||||
@@ -0,0 +1,36 @@
|
||||
export default defineEventHandler(async (event) => {
|
||||
const form = await readMultipartFormData(event)
|
||||
if (!form?.length) {
|
||||
throw createError({ statusCode: 400, statusMessage: 'Expected an image upload' })
|
||||
}
|
||||
const fields: Record<string, string> = {}
|
||||
let image: { filename: string; data: Buffer; type?: string } | null = null
|
||||
for (const part of form) {
|
||||
if (part.name === 'image' && part.filename && part.data?.length) {
|
||||
image = { filename: part.filename, data: part.data, type: part.type }
|
||||
} else if (part.name && part.data) {
|
||||
fields[part.name] = part.data.toString('utf8')
|
||||
}
|
||||
}
|
||||
if (!image) {
|
||||
throw createError({ statusCode: 400, statusMessage: 'An image is required' })
|
||||
}
|
||||
const { owner } = assertLibraryOwner(event)
|
||||
const library = publicLibrary(event)
|
||||
const folderId = library.folders.some(folder => folder.id === fields.folderId)
|
||||
? fields.folderId
|
||||
: library.folders[0]?.id
|
||||
if (!folderId) {
|
||||
throw createError({ statusCode: 400, statusMessage: 'Create a library folder first' })
|
||||
}
|
||||
assertFolderAccess(event, folderId)
|
||||
const still = await saveStill({
|
||||
ownerKey: owner,
|
||||
folderId,
|
||||
filename: image.filename,
|
||||
data: image.data,
|
||||
width: Number(fields.width || 0),
|
||||
height: Number(fields.height || 0)
|
||||
})
|
||||
return { still, ...publicLibrary(event) }
|
||||
})
|
||||
@@ -0,0 +1,8 @@
|
||||
export default defineEventHandler(async (event) => {
|
||||
const { owner } = assertLibraryOwner(event)
|
||||
const id = String(getRouterParam(event, 'id') || '')
|
||||
const still = getStill(owner, id)
|
||||
assertFolderAccess(event, still.folderId)
|
||||
await deleteStill(owner, id)
|
||||
return publicLibrary(event)
|
||||
})
|
||||
@@ -0,0 +1,16 @@
|
||||
import { existsSync, readFileSync } from 'node:fs'
|
||||
|
||||
export default defineEventHandler((event) => {
|
||||
const { owner } = assertLibraryOwner(event)
|
||||
const id = String(getRouterParam(event, 'id') || '')
|
||||
const still = getStill(owner, id)
|
||||
assertFolderAccess(event, still.folderId)
|
||||
const path = stillPath(owner, still.id)
|
||||
if (!existsSync(path)) {
|
||||
throw createError({ statusCode: 404, statusMessage: 'Image file is missing' })
|
||||
}
|
||||
const buf = readFileSync(path)
|
||||
setHeader(event, 'Content-Type', imageContentType(buf))
|
||||
setHeader(event, 'Cache-Control', 'private, max-age=3600')
|
||||
return buf
|
||||
})
|
||||
@@ -1,12 +1,11 @@
|
||||
export default defineEventHandler(async (event) => {
|
||||
const body = await readBody<{ password?: string }>(event)
|
||||
const { owner } = assertLibraryOwner(event)
|
||||
const body = await readBody<{ password?: string; folderId?: string }>(event)
|
||||
const password = String(body?.password || '')
|
||||
if (!password) {
|
||||
throw createError({ statusCode: 400, statusMessage: 'Password is required' })
|
||||
}
|
||||
if (!(await verifyLibraryPassword(password))) {
|
||||
throw createError({ statusCode: 401, statusMessage: 'Incorrect library password' })
|
||||
}
|
||||
setLibraryUnlock(event, currentPasswordVersion())
|
||||
const unlocked = await unlockMatchingFolders(owner, password, body?.folderId)
|
||||
setFolderUnlocks(event, Object.fromEntries(unlocked.map(folder => [folder.id, passwordVersion(folder.passwordHash)])))
|
||||
return publicLibrary(event)
|
||||
})
|
||||
|
||||
@@ -30,6 +30,7 @@ export interface Job {
|
||||
clipId?: string
|
||||
hideThumbnail?: boolean
|
||||
library?: {
|
||||
ownerKey: string
|
||||
folderId: string
|
||||
hideThumbnail: boolean
|
||||
prompt: string
|
||||
|
||||
+343
-97
@@ -1,3 +1,4 @@
|
||||
import { createHash } from 'node:crypto'
|
||||
import { existsSync, mkdirSync, readFileSync, renameSync, rmSync, writeFileSync } from 'node:fs'
|
||||
import { join } from 'node:path'
|
||||
import { randomBytes, scrypt, timingSafeEqual } from 'node:crypto'
|
||||
@@ -10,6 +11,8 @@ export interface LibraryFolder {
|
||||
id: string
|
||||
name: string
|
||||
createdAt: number
|
||||
thumbnailDefault: boolean
|
||||
passwordHash: string | null
|
||||
}
|
||||
|
||||
export interface LibraryClip {
|
||||
@@ -26,72 +29,150 @@ export interface LibraryClip {
|
||||
createdAt: number
|
||||
}
|
||||
|
||||
export interface LibraryStill {
|
||||
id: string
|
||||
folderId: string
|
||||
filename: string
|
||||
width: number
|
||||
height: number
|
||||
hash: string
|
||||
createdAt: number
|
||||
}
|
||||
|
||||
export interface PublicFolder {
|
||||
id: string
|
||||
name: string
|
||||
createdAt: number
|
||||
thumbnailDefault: boolean
|
||||
protected: boolean
|
||||
unlocked: boolean
|
||||
}
|
||||
|
||||
interface Catalog {
|
||||
passwordHash: string | null
|
||||
folders: LibraryFolder[]
|
||||
clips: LibraryClip[]
|
||||
stills: LibraryStill[]
|
||||
}
|
||||
|
||||
const writeChains = new Map<string, Promise<unknown>>()
|
||||
|
||||
function libraryRoot() {
|
||||
const config = useRuntimeConfig()
|
||||
return (config.libraryDir || process.env.LIBRARY_DIR || '/data/library').replace(/\/$/, '')
|
||||
}
|
||||
|
||||
function catalogPath() {
|
||||
return join(libraryRoot(), 'catalog.json')
|
||||
export function libraryOwnerKey(event: H3Event) {
|
||||
const user = getSessionUser(event)
|
||||
const raw = user?.sub || user?.email || (!authEnabled() ? 'local' : '')
|
||||
if (!raw) {
|
||||
throw createError({ statusCode: 401, statusMessage: 'Authentication required' })
|
||||
}
|
||||
return createHash('sha256').update(raw).digest('hex').slice(0, 24)
|
||||
}
|
||||
|
||||
function ensureRoot() {
|
||||
const root = libraryRoot()
|
||||
mkdirSync(join(root, 'files'), { recursive: true })
|
||||
return root
|
||||
function ownerRoot(owner: string) {
|
||||
return join(libraryRoot(), 'users', owner)
|
||||
}
|
||||
|
||||
function catalogPath(owner: string) {
|
||||
return join(ownerRoot(owner), 'catalog.json')
|
||||
}
|
||||
|
||||
function emptyCatalog(): Catalog {
|
||||
return {
|
||||
passwordHash: null,
|
||||
folders: [{ id: 'inbox', name: 'Inbox', createdAt: Date.now() }],
|
||||
clips: []
|
||||
folders: [{
|
||||
id: 'inbox',
|
||||
name: 'Inbox',
|
||||
createdAt: Date.now(),
|
||||
thumbnailDefault: true,
|
||||
passwordHash: null
|
||||
}],
|
||||
clips: [],
|
||||
stills: []
|
||||
}
|
||||
}
|
||||
|
||||
let writeChain = Promise.resolve()
|
||||
function normalizeFolder(folder: LibraryFolder): LibraryFolder {
|
||||
return {
|
||||
id: folder.id,
|
||||
name: folder.name,
|
||||
createdAt: folder.createdAt || Date.now(),
|
||||
thumbnailDefault: folder.thumbnailDefault !== false,
|
||||
passwordHash: folder.passwordHash || null
|
||||
}
|
||||
}
|
||||
|
||||
function readCatalog(): Catalog {
|
||||
ensureRoot()
|
||||
if (!existsSync(catalogPath())) {
|
||||
const created = emptyCatalog()
|
||||
writeFileSync(catalogPath(), JSON.stringify(created, null, 2))
|
||||
return created
|
||||
function normalizeCatalog(parsed: Partial<Catalog> & { passwordHash?: string | null }): Catalog {
|
||||
const folders = Array.isArray(parsed.folders) && parsed.folders.length
|
||||
? parsed.folders.map(normalizeFolder)
|
||||
: emptyCatalog().folders
|
||||
if (parsed.passwordHash) {
|
||||
for (const folder of folders) {
|
||||
if (!folder.passwordHash) folder.passwordHash = parsed.passwordHash
|
||||
}
|
||||
}
|
||||
return {
|
||||
folders,
|
||||
clips: Array.isArray(parsed.clips) ? parsed.clips : [],
|
||||
stills: Array.isArray(parsed.stills) ? parsed.stills : []
|
||||
}
|
||||
}
|
||||
|
||||
function migrateLegacy(owner: string) {
|
||||
const dest = catalogPath(owner)
|
||||
if (existsSync(dest)) return
|
||||
mkdirSync(ownerRoot(owner), { recursive: true })
|
||||
const legacyCatalog = join(libraryRoot(), 'catalog.json')
|
||||
const legacyFiles = join(libraryRoot(), 'files')
|
||||
if (!existsSync(legacyCatalog)) {
|
||||
writeFileSync(dest, JSON.stringify(emptyCatalog(), null, 2))
|
||||
return
|
||||
}
|
||||
try {
|
||||
const parsed = JSON.parse(readFileSync(catalogPath(), 'utf8')) as Catalog
|
||||
if (!Array.isArray(parsed.folders) || !parsed.folders.length) {
|
||||
parsed.folders = emptyCatalog().folders
|
||||
const catalog = normalizeCatalog(JSON.parse(readFileSync(legacyCatalog, 'utf8')))
|
||||
writeFileSync(dest, JSON.stringify(catalog, null, 2))
|
||||
if (existsSync(legacyFiles) && !existsSync(join(ownerRoot(owner), 'files'))) {
|
||||
renameSync(legacyFiles, join(ownerRoot(owner), 'files'))
|
||||
}
|
||||
parsed.clips = Array.isArray(parsed.clips) ? parsed.clips : []
|
||||
parsed.passwordHash = parsed.passwordHash || null
|
||||
return parsed
|
||||
renameSync(legacyCatalog, `${legacyCatalog}.migrated`)
|
||||
} catch {
|
||||
return emptyCatalog()
|
||||
writeFileSync(dest, JSON.stringify(emptyCatalog(), null, 2))
|
||||
}
|
||||
}
|
||||
|
||||
function writeCatalog(catalog: Catalog) {
|
||||
ensureRoot()
|
||||
const tmp = catalogPath() + '.tmp'
|
||||
writeFileSync(tmp, JSON.stringify(catalog, null, 2))
|
||||
renameSync(tmp, catalogPath())
|
||||
function ensureOwner(owner: string) {
|
||||
mkdirSync(join(ownerRoot(owner), 'files'), { recursive: true })
|
||||
mkdirSync(join(ownerRoot(owner), 'stills'), { recursive: true })
|
||||
migrateLegacy(owner)
|
||||
}
|
||||
|
||||
function mutate<T>(fn: (catalog: Catalog) => T): Promise<T> {
|
||||
const run = writeChain.then(() => {
|
||||
const catalog = readCatalog()
|
||||
function readCatalog(owner: string): Catalog {
|
||||
ensureOwner(owner)
|
||||
try {
|
||||
return normalizeCatalog(JSON.parse(readFileSync(catalogPath(owner), 'utf8')))
|
||||
} catch {
|
||||
const created = emptyCatalog()
|
||||
writeFileSync(catalogPath(owner), JSON.stringify(created, null, 2))
|
||||
return created
|
||||
}
|
||||
}
|
||||
|
||||
function writeCatalog(owner: string, catalog: Catalog) {
|
||||
ensureOwner(owner)
|
||||
const tmp = catalogPath(owner) + '.tmp'
|
||||
writeFileSync(tmp, JSON.stringify(catalog, null, 2))
|
||||
renameSync(tmp, catalogPath(owner))
|
||||
}
|
||||
|
||||
function mutate<T>(owner: string, fn: (catalog: Catalog) => T): Promise<T> {
|
||||
const prev = writeChains.get(owner) || Promise.resolve()
|
||||
const run = prev.then(() => {
|
||||
const catalog = readCatalog(owner)
|
||||
const result = fn(catalog)
|
||||
writeCatalog(catalog)
|
||||
writeCatalog(owner, catalog)
|
||||
return result
|
||||
})
|
||||
writeChain = run.then(() => undefined, () => undefined)
|
||||
writeChains.set(owner, run.then(() => undefined, () => undefined))
|
||||
return run
|
||||
}
|
||||
|
||||
@@ -99,33 +180,13 @@ export function passwordVersion(hash: string | null) {
|
||||
return hash ? hash.slice(-24) : 'open'
|
||||
}
|
||||
|
||||
export function currentPasswordVersion() {
|
||||
return passwordVersion(readCatalog().passwordHash)
|
||||
}
|
||||
|
||||
export function isLibraryLocked() {
|
||||
return Boolean(readCatalog().passwordHash)
|
||||
}
|
||||
|
||||
export function libraryUnlocked(event: H3Event) {
|
||||
const catalog = readCatalog()
|
||||
if (!catalog.passwordHash) return true
|
||||
return getLibraryUnlockVersion(event) === passwordVersion(catalog.passwordHash)
|
||||
}
|
||||
|
||||
export function assertLibraryAccess(event: H3Event) {
|
||||
if (libraryUnlocked(event)) return readCatalog()
|
||||
throw createError({ statusCode: 403, statusMessage: 'Library is locked' })
|
||||
}
|
||||
|
||||
export async function hashLibraryPassword(password: string) {
|
||||
const salt = randomBytes(16)
|
||||
const hash = await scryptAsync(password, salt, 64) as Buffer
|
||||
return `scrypt:${salt.toString('hex')}:${hash.toString('hex')}`
|
||||
}
|
||||
|
||||
export async function verifyLibraryPassword(password: string) {
|
||||
const stored = readCatalog().passwordHash
|
||||
async function verifyStoredPassword(stored: string | null, password: string) {
|
||||
if (!stored) return true
|
||||
const parts = stored.split(':')
|
||||
if (parts.length !== 3 || parts[0] !== 'scrypt') return false
|
||||
@@ -135,84 +196,259 @@ export async function verifyLibraryPassword(password: string) {
|
||||
return actual.length === expected.length && timingSafeEqual(actual, expected)
|
||||
}
|
||||
|
||||
export function publicLibrary(event: H3Event) {
|
||||
const catalog = readCatalog()
|
||||
const locked = Boolean(catalog.passwordHash)
|
||||
const unlocked = libraryUnlocked(event)
|
||||
if (locked && !unlocked) {
|
||||
return { locked: true, unlocked: false, folders: [] as LibraryFolder[], clips: [] as LibraryClip[] }
|
||||
}
|
||||
function folderUnlocks(event: H3Event) {
|
||||
return getFolderUnlocks(event)
|
||||
}
|
||||
|
||||
export function folderUnlocked(event: H3Event, folder: LibraryFolder) {
|
||||
if (!folder.passwordHash) return true
|
||||
return folderUnlocks(event)[folder.id] === passwordVersion(folder.passwordHash)
|
||||
}
|
||||
|
||||
export function publicFolder(event: H3Event, folder: LibraryFolder): PublicFolder {
|
||||
return {
|
||||
locked,
|
||||
unlocked: true,
|
||||
folders: catalog.folders,
|
||||
clips: catalog.clips
|
||||
id: folder.id,
|
||||
name: folder.name,
|
||||
createdAt: folder.createdAt,
|
||||
thumbnailDefault: folder.thumbnailDefault,
|
||||
protected: Boolean(folder.passwordHash),
|
||||
unlocked: folderUnlocked(event, folder)
|
||||
}
|
||||
}
|
||||
|
||||
export function createFolder(name: string) {
|
||||
export function publicLibrary(event: H3Event) {
|
||||
const owner = libraryOwnerKey(event)
|
||||
const catalog = readCatalog(owner)
|
||||
const folders = catalog.folders.map(folder => publicFolder(event, folder))
|
||||
const unlockedIds = new Set(folders.filter(folder => folder.unlocked).map(folder => folder.id))
|
||||
return {
|
||||
folders,
|
||||
clips: catalog.clips.filter(clip => unlockedIds.has(clip.folderId)),
|
||||
stills: catalog.stills.filter(still => unlockedIds.has(still.folderId))
|
||||
}
|
||||
}
|
||||
|
||||
export function assertLibraryOwner(event: H3Event) {
|
||||
const owner = libraryOwnerKey(event)
|
||||
return { owner, catalog: readCatalog(owner) }
|
||||
}
|
||||
|
||||
export function assertFolderAccess(event: H3Event, folderId: string) {
|
||||
const { owner, catalog } = assertLibraryOwner(event)
|
||||
const folder = catalog.folders.find(item => item.id === folderId)
|
||||
if (!folder) throw createError({ statusCode: 404, statusMessage: 'Folder not found' })
|
||||
if (!folderUnlocked(event, folder)) {
|
||||
throw createError({ statusCode: 403, statusMessage: 'Folder is locked' })
|
||||
}
|
||||
return { owner, catalog, folder }
|
||||
}
|
||||
|
||||
export function assertLibraryAccess(event: H3Event) {
|
||||
return assertLibraryOwner(event).catalog
|
||||
}
|
||||
|
||||
export function createFolder(owner: string, name: string) {
|
||||
const trimmed = name.trim().slice(0, 80)
|
||||
if (!trimmed) throw createError({ statusCode: 400, statusMessage: 'Folder name is required' })
|
||||
return mutate((catalog) => {
|
||||
return mutate(owner, (catalog) => {
|
||||
if (catalog.folders.some(folder => folder.name.toLowerCase() === trimmed.toLowerCase())) {
|
||||
throw createError({ statusCode: 409, statusMessage: 'A folder with that name already exists' })
|
||||
}
|
||||
const folder: LibraryFolder = { id: crypto.randomUUID(), name: trimmed, createdAt: Date.now() }
|
||||
const folder: LibraryFolder = {
|
||||
id: crypto.randomUUID(),
|
||||
name: trimmed,
|
||||
createdAt: Date.now(),
|
||||
thumbnailDefault: true,
|
||||
passwordHash: null
|
||||
}
|
||||
catalog.folders.push(folder)
|
||||
return folder
|
||||
})
|
||||
}
|
||||
|
||||
export function renameFolder(id: string, name: string) {
|
||||
export function renameFolder(owner: string, id: string, name: string) {
|
||||
const trimmed = name.trim().slice(0, 80)
|
||||
if (!trimmed) throw createError({ statusCode: 400, statusMessage: 'Folder name is required' })
|
||||
return mutate((catalog) => {
|
||||
return mutate(owner, (catalog) => {
|
||||
const folder = catalog.folders.find(item => item.id === id)
|
||||
if (!folder) throw createError({ statusCode: 404, statusMessage: 'Folder not found' })
|
||||
if (catalog.folders.some(item => item.id !== id && item.name.toLowerCase() === trimmed.toLowerCase())) {
|
||||
throw createError({ statusCode: 409, statusMessage: 'A folder with that name already exists' })
|
||||
}
|
||||
folder.name = trimmed
|
||||
return folder
|
||||
})
|
||||
}
|
||||
|
||||
export function deleteFolder(id: string) {
|
||||
return mutate((catalog) => {
|
||||
export function deleteFolder(owner: string, id: string) {
|
||||
return mutate(owner, (catalog) => {
|
||||
if (catalog.folders.length <= 1) {
|
||||
throw createError({ statusCode: 400, statusMessage: 'Keep at least one library folder' })
|
||||
}
|
||||
const folder = catalog.folders.find(item => item.id === id)
|
||||
if (!folder) throw createError({ statusCode: 404, statusMessage: 'Folder not found' })
|
||||
const clips = catalog.clips.filter(clip => clip.folderId === id)
|
||||
const stills = catalog.stills.filter(still => still.folderId === id)
|
||||
catalog.folders = catalog.folders.filter(item => item.id !== id)
|
||||
catalog.clips = catalog.clips.filter(clip => clip.folderId !== id)
|
||||
const fallback = catalog.folders[0].id
|
||||
catalog.stills = catalog.stills.filter(still => still.folderId !== id)
|
||||
for (const clip of clips) {
|
||||
rmSync(clipDir(clip.id), { recursive: true, force: true })
|
||||
rmSync(clipDir(owner, clip.id), { recursive: true, force: true })
|
||||
}
|
||||
return { fallbackFolderId: fallback }
|
||||
for (const still of stills) {
|
||||
rmSync(stillPath(owner, still.id), { force: true })
|
||||
}
|
||||
return { fallbackFolderId: catalog.folders[0].id }
|
||||
})
|
||||
}
|
||||
|
||||
export async function setLibraryPassword(password: string | null) {
|
||||
const hash = password && password.length ? await hashLibraryPassword(password) : null
|
||||
return mutate((catalog) => {
|
||||
catalog.passwordHash = hash
|
||||
return passwordVersion(hash)
|
||||
export async function updateFolder(owner: string, id: string, patch: {
|
||||
name?: string
|
||||
thumbnailDefault?: boolean
|
||||
password?: string | null
|
||||
currentPassword?: string
|
||||
}) {
|
||||
const catalog = readCatalog(owner)
|
||||
const folder = catalog.folders.find(item => item.id === id)
|
||||
if (!folder) throw createError({ statusCode: 404, statusMessage: 'Folder not found' })
|
||||
|
||||
let nextName = folder.name
|
||||
if (patch.name !== undefined) {
|
||||
nextName = patch.name.trim().slice(0, 80)
|
||||
if (!nextName) throw createError({ statusCode: 400, statusMessage: 'Folder name is required' })
|
||||
if (catalog.folders.some(item => item.id !== id && item.name.toLowerCase() === nextName.toLowerCase())) {
|
||||
throw createError({ statusCode: 409, statusMessage: 'A folder with that name already exists' })
|
||||
}
|
||||
}
|
||||
|
||||
let nextHash: string | null | undefined
|
||||
if (patch.password !== undefined) {
|
||||
const next = String(patch.password || '').trim()
|
||||
if (folder.passwordHash && !(await verifyStoredPassword(folder.passwordHash, String(patch.currentPassword || '')))) {
|
||||
throw createError({ statusCode: 401, statusMessage: 'Current folder password is incorrect' })
|
||||
}
|
||||
if (next && next.length < 4) {
|
||||
throw createError({ statusCode: 400, statusMessage: 'Use at least 4 characters, or leave blank to remove the password' })
|
||||
}
|
||||
nextHash = next ? await hashLibraryPassword(next) : null
|
||||
}
|
||||
|
||||
return mutate(owner, (nextCatalog) => {
|
||||
const item = nextCatalog.folders.find(entry => entry.id === id)
|
||||
if (!item) throw createError({ statusCode: 404, statusMessage: 'Folder not found' })
|
||||
item.name = nextName
|
||||
if (typeof patch.thumbnailDefault === 'boolean') item.thumbnailDefault = patch.thumbnailDefault
|
||||
if (nextHash !== undefined) item.passwordHash = nextHash
|
||||
return item
|
||||
})
|
||||
}
|
||||
|
||||
function clipDir(id: string) {
|
||||
return join(libraryRoot(), 'files', id)
|
||||
export async function verifyFolderPassword(owner: string, folderId: string, password: string) {
|
||||
const folder = readCatalog(owner).folders.find(item => item.id === folderId)
|
||||
if (!folder) throw createError({ statusCode: 404, statusMessage: 'Folder not found' })
|
||||
if (!folder.passwordHash) return folder
|
||||
if (!(await verifyStoredPassword(folder.passwordHash, password))) {
|
||||
throw createError({ statusCode: 401, statusMessage: 'Incorrect folder password' })
|
||||
}
|
||||
return folder
|
||||
}
|
||||
|
||||
export function clipVideoPath(id: string) {
|
||||
return join(clipDir(id), 'video.mp4')
|
||||
export async function unlockMatchingFolders(owner: string, password: string, folderId?: string) {
|
||||
const catalog = readCatalog(owner)
|
||||
const targets = folderId
|
||||
? catalog.folders.filter(folder => folder.id === folderId)
|
||||
: catalog.folders.filter(folder => folder.passwordHash)
|
||||
if (folderId && !targets.length) {
|
||||
throw createError({ statusCode: 404, statusMessage: 'Folder not found' })
|
||||
}
|
||||
const unlocked: LibraryFolder[] = []
|
||||
for (const folder of targets) {
|
||||
if (!folder.passwordHash || await verifyStoredPassword(folder.passwordHash, password)) {
|
||||
unlocked.push(folder)
|
||||
}
|
||||
}
|
||||
if (!unlocked.length) {
|
||||
throw createError({ statusCode: 401, statusMessage: 'Incorrect folder password' })
|
||||
}
|
||||
return unlocked
|
||||
}
|
||||
|
||||
export function clipThumbPath(id: string) {
|
||||
return join(clipDir(id), 'thumb')
|
||||
function clipDir(owner: string, id: string) {
|
||||
return join(ownerRoot(owner), 'files', id)
|
||||
}
|
||||
|
||||
export function clipVideoPath(owner: string, id: string) {
|
||||
return join(clipDir(owner, id), 'video.mp4')
|
||||
}
|
||||
|
||||
export function clipThumbPath(owner: string, id: string) {
|
||||
return join(clipDir(owner, id), 'thumb')
|
||||
}
|
||||
|
||||
export function stillPath(owner: string, id: string) {
|
||||
return join(ownerRoot(owner), 'stills', id)
|
||||
}
|
||||
|
||||
function bytesHash(data: Buffer) {
|
||||
return createHash('sha256').update(data).digest('hex')
|
||||
}
|
||||
|
||||
export async function saveStill(params: {
|
||||
ownerKey: string
|
||||
folderId: string
|
||||
filename: string
|
||||
data: Buffer
|
||||
width?: number
|
||||
height?: number
|
||||
}) {
|
||||
const catalog = readCatalog(params.ownerKey)
|
||||
const folder = catalog.folders.find(item => item.id === params.folderId) || catalog.folders[0]
|
||||
if (!folder) throw createError({ statusCode: 400, statusMessage: 'No library folder available' })
|
||||
const hash = bytesHash(params.data)
|
||||
const existing = catalog.stills.find(item => item.folderId === folder.id && item.hash === hash)
|
||||
if (existing) return existing
|
||||
const still: LibraryStill = {
|
||||
id: crypto.randomUUID(),
|
||||
folderId: folder.id,
|
||||
filename: params.filename.slice(0, 120) || 'still.png',
|
||||
width: params.width || 0,
|
||||
height: params.height || 0,
|
||||
hash,
|
||||
createdAt: Date.now()
|
||||
}
|
||||
mkdirSync(join(ownerRoot(params.ownerKey), 'stills'), { recursive: true })
|
||||
writeFileSync(stillPath(params.ownerKey, still.id), params.data)
|
||||
await mutate(params.ownerKey, (next) => {
|
||||
next.stills.unshift(still)
|
||||
})
|
||||
return still
|
||||
}
|
||||
|
||||
export function getStill(owner: string, id: string) {
|
||||
const still = readCatalog(owner).stills.find(item => item.id === id)
|
||||
if (!still) throw createError({ statusCode: 404, statusMessage: 'Image not found' })
|
||||
return still
|
||||
}
|
||||
|
||||
export function deleteStill(owner: string, id: string) {
|
||||
return mutate(owner, (catalog) => {
|
||||
const still = catalog.stills.find(item => item.id === id)
|
||||
if (!still) throw createError({ statusCode: 404, statusMessage: 'Image not found' })
|
||||
catalog.stills = catalog.stills.filter(item => item.id !== id)
|
||||
rmSync(stillPath(owner, id), { force: true })
|
||||
return still
|
||||
})
|
||||
}
|
||||
|
||||
export function imageContentType(buf: Buffer) {
|
||||
if (buf[0] === 0x89 && buf[1] === 0x50) return 'image/png'
|
||||
if (buf[0] === 0xff && buf[1] === 0xd8) return 'image/jpeg'
|
||||
if (buf[0] === 0x52 && buf[1] === 0x49) return 'image/webp'
|
||||
return 'application/octet-stream'
|
||||
}
|
||||
|
||||
export async function saveClip(params: {
|
||||
ownerKey: string
|
||||
folderId: string
|
||||
prompt: string
|
||||
aspect: string
|
||||
@@ -225,7 +461,7 @@ export async function saveClip(params: {
|
||||
video: Buffer
|
||||
thumb?: Buffer | null
|
||||
}) {
|
||||
const catalog = readCatalog()
|
||||
const catalog = readCatalog(params.ownerKey)
|
||||
const folder = catalog.folders.find(item => item.id === params.folderId) || catalog.folders[0]
|
||||
if (!folder) throw createError({ statusCode: 400, statusMessage: 'No library folder available' })
|
||||
const clip: LibraryClip = {
|
||||
@@ -241,29 +477,39 @@ export async function saveClip(params: {
|
||||
hideThumbnail: params.hideThumbnail,
|
||||
createdAt: Date.now()
|
||||
}
|
||||
mkdirSync(clipDir(clip.id), { recursive: true })
|
||||
writeFileSync(clipVideoPath(clip.id), params.video)
|
||||
mkdirSync(clipDir(params.ownerKey, clip.id), { recursive: true })
|
||||
writeFileSync(clipVideoPath(params.ownerKey, clip.id), params.video)
|
||||
if (!params.hideThumbnail && params.thumb?.length) {
|
||||
writeFileSync(clipThumbPath(clip.id), params.thumb)
|
||||
writeFileSync(clipThumbPath(params.ownerKey, clip.id), params.thumb)
|
||||
}
|
||||
await mutate((next) => {
|
||||
if (params.thumb?.length) {
|
||||
await saveStill({
|
||||
ownerKey: params.ownerKey,
|
||||
folderId: folder.id,
|
||||
filename: `${clip.id}.png`,
|
||||
data: params.thumb,
|
||||
width: params.width,
|
||||
height: params.height
|
||||
})
|
||||
}
|
||||
await mutate(params.ownerKey, (next) => {
|
||||
next.clips.unshift(clip)
|
||||
})
|
||||
return clip
|
||||
}
|
||||
|
||||
export function getClip(id: string) {
|
||||
const clip = readCatalog().clips.find(item => item.id === id)
|
||||
export function getClip(owner: string, id: string) {
|
||||
const clip = readCatalog(owner).clips.find(item => item.id === id)
|
||||
if (!clip) throw createError({ statusCode: 404, statusMessage: 'Clip not found' })
|
||||
return clip
|
||||
}
|
||||
|
||||
export function deleteClip(id: string) {
|
||||
return mutate((catalog) => {
|
||||
export function deleteClip(owner: string, id: string) {
|
||||
return mutate(owner, (catalog) => {
|
||||
const clip = catalog.clips.find(item => item.id === id)
|
||||
if (!clip) throw createError({ statusCode: 404, statusMessage: 'Clip not found' })
|
||||
catalog.clips = catalog.clips.filter(item => item.id !== id)
|
||||
rmSync(clipDir(id), { recursive: true, force: true })
|
||||
rmSync(clipDir(owner, id), { recursive: true, force: true })
|
||||
return clip
|
||||
})
|
||||
}
|
||||
|
||||
+37
-3
@@ -79,16 +79,50 @@ export function authEnabled() {
|
||||
return Boolean(config.public.authEnabled && config.oidcClientId && config.oidcClientSecret)
|
||||
}
|
||||
|
||||
interface LibraryUnlock {
|
||||
version?: string
|
||||
folders?: Record<string, string>
|
||||
}
|
||||
|
||||
function readUnlock(event: H3Event): LibraryUnlock {
|
||||
return unseal<LibraryUnlock>(getCookie(event, LIBRARY_COOKIE)) || {}
|
||||
}
|
||||
|
||||
export function getFolderUnlocks(event: H3Event) {
|
||||
return { ...(readUnlock(event).folders || {}) }
|
||||
}
|
||||
|
||||
export function setFolderUnlock(event: H3Event, folderId: string, version: string) {
|
||||
const folders = getFolderUnlocks(event)
|
||||
folders[folderId] = version
|
||||
setCookie(event, LIBRARY_COOKIE, seal({ folders }), cookieOpts(event))
|
||||
}
|
||||
|
||||
export function setFolderUnlocks(event: H3Event, entries: Record<string, string>) {
|
||||
const folders = { ...getFolderUnlocks(event), ...entries }
|
||||
setCookie(event, LIBRARY_COOKIE, seal({ folders }), cookieOpts(event))
|
||||
}
|
||||
|
||||
export function clearFolderUnlock(event: H3Event, folderId?: string) {
|
||||
if (!folderId) {
|
||||
deleteCookie(event, LIBRARY_COOKIE, { path: '/' })
|
||||
return
|
||||
}
|
||||
const folders = getFolderUnlocks(event)
|
||||
delete folders[folderId]
|
||||
setCookie(event, LIBRARY_COOKIE, seal({ folders }), cookieOpts(event))
|
||||
}
|
||||
|
||||
export function setLibraryUnlock(event: H3Event, version: string) {
|
||||
setCookie(event, LIBRARY_COOKIE, seal({ version }), cookieOpts(event))
|
||||
setFolderUnlock(event, '*', version)
|
||||
}
|
||||
|
||||
export function getLibraryUnlockVersion(event: H3Event) {
|
||||
return unseal<{ version?: string }>(getCookie(event, LIBRARY_COOKIE))?.version || null
|
||||
return getFolderUnlocks(event)['*'] || readUnlock(event).version || null
|
||||
}
|
||||
|
||||
export function clearLibraryUnlock(event: H3Event) {
|
||||
deleteCookie(event, LIBRARY_COOKIE, { path: '/' })
|
||||
clearFolderUnlock(event)
|
||||
}
|
||||
|
||||
export function publicBaseUrl(event: H3Event) {
|
||||
|
||||
@@ -60,6 +60,7 @@ export function watchComfyJob(job: Job): Promise<void> {
|
||||
try {
|
||||
const buffer = await downloadComfyVideo(video)
|
||||
const clip = await saveClip({
|
||||
ownerKey: job.library.ownerKey,
|
||||
folderId: job.library.folderId,
|
||||
prompt: job.library.prompt,
|
||||
aspect: job.library.aspect,
|
||||
|
||||
Reference in New Issue
Block a user