Harden backup and download token flows

This commit is contained in:
shuaiplus
2026-07-06 19:06:24 +08:00
parent c6438747e3
commit cc4a830be8
10 changed files with 58 additions and 41 deletions
+5 -6
View File
@@ -439,17 +439,16 @@ export async function handlePublicDownloadAttachment(
}
const path = getAttachmentObjectKey(cipherId, attachmentId);
const object = await getBlobObject(env, path);
if (!object) {
return errorResponse('Attachment file not found', 404);
}
const firstUse = await storage.consumeAttachmentDownloadToken(claims.jti, claims.exp);
if (!firstUse) {
return errorResponse('Invalid or expired token', 401);
}
const object = await getBlobObject(env, path);
if (!object) {
return errorResponse('Attachment file not found', 404);
}
return new Response(object.body, {
headers: {
'Content-Type': sanitizeDownloadContentType(object.contentType),