mirror of
https://github.com/saltbo/zpan.git
synced 2026-09-24 23:22:31 +08:00
feat(avatars): host avatars + team logos on Cloud via SDK 2.4.0; remove public-bucket mode (#467)
* feat(avatars): host avatars + team logos on Cloud via SDK 2.4.0; remove public-bucket mode Host user avatars and org logos on the ZPan Cloud avatar service (zpan-cloud-sdk ^2.4.0) instead of a public S3/R2 bucket, then remove the now-dead storages.mode / public-bucket concept entirely (#456 parts 2-3). - image-upload gateway: upload/delete via SDK uploadAvatar/deleteAvatar against a bound Cloud client; validate mime (AVATAR_CONTENT_TYPES) + size (MAX_AVATAR_BYTES) before the call; map cloud error codes to 400/403/413/500; unbound instance returns 503 cloud_required (delete is a best-effort no-op). - licensing-cloud: createAvatarUploadClient builds the client with a plain-object bearer header so both the image content-type and Authorization survive hono's per-request header merge (a Headers instance would be dropped). - drop storages.mode (migration via drizzle-kit), StorageRepo.select() no longer takes a mode, remove StorageMode / Storage.mode / mode schema+audit+UI+i18n and the PUBLIC_IMAGES bucket + PUBLIC_IMAGES_URL wiring. Agent-Profile: https://agent-kanban.dev/agents/f759c704c282d88a * ci(deploy): drop dead PUBLIC_IMAGES R2 provisioning from CF deploy The Cloud avatar migration removed the PUBLIC_IMAGES binding from wrangler.toml, so the deploy workflow's R2 public-images steps are dead and must go too — otherwise every CF deploy keeps re-provisioning a public-read zpan-public-images bucket (the footgun #456 eliminates) and sets an unused PUBLIC_IMAGES_URL secret. Removes the bucket-create, managed-public-URL, and secret steps (steps.r2 was only consumed by the secret step). Also drops a stale storage-modes line from the v2.0 roadmap. Agent-Profile: https://agent-kanban.dev/agents/f759c704c282d88a --------- Co-authored-by: Alex Chen <alex-chen@mails.agent-kanban.dev>
This commit is contained in:
co-authored by
Alex Chen
parent
0138e7779e
commit
00f48cf355
@@ -91,52 +91,6 @@ jobs:
|
||||
fi
|
||||
echo "id=$DB_ID" >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: Ensure R2 public-images bucket exists
|
||||
env:
|
||||
CF_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
|
||||
CF_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
|
||||
run: |
|
||||
# Use CF REST API — `wrangler r2 bucket list` has no --json flag.
|
||||
EXISTS=$(curl -sf \
|
||||
"https://api.cloudflare.com/client/v4/accounts/$CF_ACCOUNT_ID/r2/buckets" \
|
||||
-H "Authorization: Bearer $CF_API_TOKEN" \
|
||||
| jq -r '.result.buckets[]? | select(.name == "zpan-public-images") | .name')
|
||||
if [ -z "$EXISTS" ]; then
|
||||
curl -sf -X POST \
|
||||
"https://api.cloudflare.com/client/v4/accounts/$CF_ACCOUNT_ID/r2/buckets" \
|
||||
-H "Authorization: Bearer $CF_API_TOKEN" \
|
||||
-H "Content-Type: application/json" \
|
||||
-d '{"name": "zpan-public-images"}' > /dev/null
|
||||
echo "Created R2 bucket: zpan-public-images"
|
||||
else
|
||||
echo "Reusing R2 bucket: zpan-public-images"
|
||||
fi
|
||||
|
||||
- name: Enable R2 managed public URL + capture
|
||||
id: r2
|
||||
env:
|
||||
CF_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
|
||||
CF_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
|
||||
run: |
|
||||
# Idempotent: PUT enabled=true — CF returns the same pub-<hash>.r2.dev
|
||||
# on every call once enabled.
|
||||
curl -sf -X PUT \
|
||||
"https://api.cloudflare.com/client/v4/accounts/$CF_ACCOUNT_ID/r2/buckets/zpan-public-images/domains/managed" \
|
||||
-H "Authorization: Bearer $CF_API_TOKEN" \
|
||||
-H "Content-Type: application/json" \
|
||||
-d '{"enabled": true}' > /dev/null
|
||||
|
||||
DOMAIN=$(curl -sf \
|
||||
"https://api.cloudflare.com/client/v4/accounts/$CF_ACCOUNT_ID/r2/buckets/zpan-public-images/domains/managed" \
|
||||
-H "Authorization: Bearer $CF_API_TOKEN" | jq -r '.result.domain')
|
||||
|
||||
if [ -z "$DOMAIN" ] || [ "$DOMAIN" = "null" ]; then
|
||||
echo "::error::Failed to retrieve R2 managed public domain. Make sure CLOUDFLARE_API_TOKEN has 'R2 Storage: Edit' scope."
|
||||
exit 1
|
||||
fi
|
||||
echo "url=https://$DOMAIN" >> "$GITHUB_OUTPUT"
|
||||
echo "R2 public URL: https://$DOMAIN"
|
||||
|
||||
- name: Ensure Queue exists
|
||||
env:
|
||||
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
|
||||
@@ -172,14 +126,6 @@ jobs:
|
||||
echo "BETTER_AUTH_SECRET already set, skipping"
|
||||
fi
|
||||
|
||||
- name: Set PUBLIC_IMAGES_URL (always upsert — R2 domain is stable)
|
||||
env:
|
||||
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
|
||||
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
|
||||
run: |
|
||||
echo "${{ steps.r2.outputs.url }}" | pnpm exec wrangler secret put PUBLIC_IMAGES_URL
|
||||
echo "Set PUBLIC_IMAGES_URL = ${{ steps.r2.outputs.url }}"
|
||||
|
||||
# vite build runs the @cloudflare/vite-plugin, which writes the deploy
|
||||
# config (dist/zpan/wrangler.json) that the subsequent wrangler deploy
|
||||
# consumes: it resolves the assets directory to dist/client and inlines
|
||||
|
||||
Reference in New Issue
Block a user