Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
18 commits
Select commit Hold shift + click to select a range
fbb5b1d
docs: implementation-ready plan for firearm photo management (#9)
unclesp1d3r Jul 10, 2026
956d086
feat(storage): reusable storage service with local-filesystem adapter…
unclesp1d3r Jul 10, 2026
bd99571
feat(db): firearm_photo child table + migration (#9)
unclesp1d3r Jul 10, 2026
d3b0ba1
feat(photos): image upload pipeline with sharp (#9)
unclesp1d3r Jul 10, 2026
26ccd27
feat(photos): firearm-photo domain service (#9)
unclesp1d3r Jul 10, 2026
2a6c757
feat(photos): firearm-delete blob cleanup + orphan sweep (#9)
unclesp1d3r Jul 10, 2026
0c4c68d
feat(photos): upload/manage server actions + authenticated serving ro…
unclesp1d3r Jul 10, 2026
6b65efe
feat(photos): firearm detail-view photo gallery (#9)
unclesp1d3r Jul 10, 2026
b944a98
feat(photos): primary thumbnail in firearm list/table (#9)
unclesp1d3r Jul 10, 2026
c13345f
test(e2e): enable photo specs — UPLOAD_DIR in harness, exact badge ma…
unclesp1d3r Jul 10, 2026
b7e9c07
refactor(photos): dedup blob cleanup, parallelize encodes, trim hot-p…
unclesp1d3r Jul 10, 2026
2c49074
fix(review): block SVG SSRF, cap reorder, delete blobs post-commit (#9)
unclesp1d3r Jul 10, 2026
2cd9ec1
fix(review): DB-enforce single primary, authz+route tests, error logg…
unclesp1d3r Jul 10, 2026
e6d9c38
fix(security): keep user-controlled mime out of log format string (#9)
unclesp1d3r Jul 10, 2026
cb1d076
fix(photos): unblock real uploads and harden delete/quota (#9)
unclesp1d3r Jul 11, 2026
27cecbc
refactor(photos): harden schema, error types, and variant vocab (#9)
unclesp1d3r Jul 11, 2026
7633946
fix(photos): resolve PR review feedback (#62)
unclesp1d3r Jul 11, 2026
8505d1b
refactor(photos): eliminate the deferred upload/sweep residuals (#9)
unclesp1d3r Jul 11, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,12 @@ BETTER_AUTH_URL=http://localhost:3000
ADMIN_EMAIL=admin@example.com
ADMIN_PASSWORD=change-me-strong-admin-password

# --- Storage ------------------------------------------------------------------
# Directory the app reads/writes blobs (photo originals + derivatives) under.
# In docker-compose this is a mounted named volume (magstacker-uploads); for
# local tooling outside Docker, point it at any writable local directory.
UPLOAD_DIR=/data/uploads

# --- App --------------------------------------------------------------------
APP_HOST_PORT=3000

Expand Down
8 changes: 8 additions & 0 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,14 @@ COPY --from=builder /app/auth.ts ./auth.ts
COPY --from=builder /app/src ./src
COPY --from=builder /app/scripts ./scripts

# Create the upload root owned by the unprivileged runtime user BEFORE dropping
# privileges. docker-compose mounts a NAMED volume at /data/uploads (UPLOAD_DIR);
# Docker seeds an empty named volume from the image directory's contents AND
# ownership on first use, so creating it bun-owned here makes the mounted volume
# writable by uid `bun`. Without this the fresh volume mounts root-owned and the
# first upload fails EACCES.
RUN mkdir -p /data/uploads && chown bun:bun /data/uploads

# Run as the unprivileged user shipped in the bun image.
USER bun

Expand Down
Loading