feat: enhance file upload handling with improved file detection, size limits, and response formatting

This commit is contained in:
MythEclipse
2026-05-21 22:31:55 +07:00
parent 06844f1fa1
commit 52340ee77d
20 changed files with 696 additions and 539 deletions
+97 -181
View File
@@ -1,18 +1,89 @@
import { createReadStream, unlinkSync } from 'node:fs';
import { eq } from 'drizzle-orm';
import { nanoid } from 'nanoid';
import { db, files as fileSchema } from '../db';
import { findFileByHash } from '../db/files';
import type { NewFile } from '../db/schema';
import { config } from '../env';
import {
buildUploadResponse,
checkFileSize,
computeHash,
ensureExtension,
extractMimeType,
getErrorMessage,
getFileType,
} from '../utils/file';
import logger from '../utils/logger';
import { forwardToStorage, getBot } from '../utils/telegram';
type UploadedFile = NewFile & {
createdAt: Date;
updatedAt: Date;
};
type TelegramFileLookup = {
mime_type?: string;
file_size?: number;
};
interface JsonUploadPayload {
file?: unknown;
fileName?: string;
}
const parseBase64File = (file: string): { base64Data: string; mimeType: string } => {
if (!file.startsWith('data:')) {
return { base64Data: file, mimeType: 'application/octet-stream' };
}
const match = file.match(/^data:([^;]+);base64,(.+)$/);
return match
? { base64Data: match[2], mimeType: match[1] }
: { base64Data: file, mimeType: 'application/octet-stream' };
};
const normalizeFileType = (mimeType: string, fileName: string): string => {
const fileType = getFileType(mimeType, fileName);
return fileType === 'application' ? 'document' : fileType;
};
const performUpload = async (
fileBuffer: Buffer,
fileName: string,
mimeType: string,
): Promise<UploadedFile> => {
const tempPath = `/tmp/teleuploader-${nanoid()}`;
try {
await Bun.write(tempPath, fileBuffer);
const fileStream = createReadStream(tempPath);
const result = await forwardToStorage(fileStream, fileName, getFileType(mimeType, fileName));
const bot = getBot();
const fileInfo = (await bot.telegram.getFile(result.telegramFileId)) as TelegramFileLookup;
return {
publicId: nanoid(),
telegramFileId: result.telegramFileId,
telegramFileUniqueId: result.telegramFileUniqueId,
storageChatId: config.storageChatId,
storageMessageId: result.storageMessageId,
fileName,
mimeType: fileInfo.mime_type || mimeType || 'application/octet-stream',
sizeBytes: fileInfo.file_size || fileBuffer.byteLength,
fileType: getFileType(mimeType, fileName),
uploaderId: 0,
fileHash: computeHash(fileBuffer),
createdAt: new Date(),
updatedAt: new Date(),
};
} finally {
setTimeout(() => {
try {
unlinkSync(tempPath);
} catch {}
}, 50);
}
};
export const handleUpload = async (req: Request): Promise<Response> => {
try {
const contentType = req.headers.get('content-type') || '';
@@ -27,14 +98,14 @@ export const handleUpload = async (req: Request): Promise<Response> => {
{ error: 'Unsupported content type. Use multipart/form-data or application/json' },
{ status: 400 },
);
} catch (error: any) {
logger.error('Upload error', { error: error.message });
return Response.json({ error: error.message }, { status: 500 });
} catch (error: unknown) {
const message = getErrorMessage(error);
logger.error('Upload error', { error: message });
return Response.json({ error: message }, { status: 500 });
}
};
const handleMultipartUpload = async (req: Request): Promise<Response> => {
let tempPath = '';
try {
const formData = await req.formData();
const file = formData.get('file');
@@ -49,33 +120,9 @@ const handleMultipartUpload = async (req: Request): Promise<Response> => {
const fileBuffer = Buffer.from(fileBytes);
const hash = computeHash(fileBuffer);
// Check for duplicate in DB
const existing = await db
.select()
.from(fileSchema)
.where(eq(fileSchema.fileHash, hash))
.limit(1);
if (existing.length > 0) {
const existingFile = existing[0];
const responsePayload = {
public_id: existingFile.publicId,
telegram_file_id: existingFile.telegramFileId,
telegram_file_unique_id: existingFile.telegramFileUniqueId,
storage_chat_id: existingFile.storageChatId,
storage_message_id: existingFile.storageMessageId,
file_name: existingFile.fileName,
mime_type: existingFile.mimeType,
size_bytes: existingFile.sizeBytes,
file_type: existingFile.fileType,
uploader_id: existingFile.uploaderId,
created_at:
existingFile.createdAt instanceof Date
? existingFile.createdAt.toISOString()
: new Date(existingFile.createdAt).toISOString(),
download_url: `${config.baseUrl}/f/${existingFile.publicId}`,
};
return Response.json(responsePayload, { status: 200 });
const existingFile = await findFileByHash(hash);
if (existingFile) {
return Response.json(buildUploadResponse(existingFile, config.baseUrl), { status: 200 });
}
const rawMimeType = file.type || extractMimeType({}, req) || 'application/octet-stream';
@@ -90,68 +137,20 @@ const handleMultipartUpload = async (req: Request): Promise<Response> => {
return Response.json({ error: `File size exceeds ${fileType} limit` }, { status: 400 });
}
// Write file to disk temporarily
tempPath = `/tmp/teleuploader-${nanoid()}`;
await Bun.write(tempPath, fileBuffer);
const fileStream = createReadStream(tempPath);
const result = await forwardToStorage(fileStream, finalFileName, fileType);
const bot = getBot();
const fileInfo = (await bot.telegram.getFile(result.telegramFileId)) as any;
const uploaded = {
publicId: nanoid(),
telegramFileId: result.telegramFileId,
telegramFileUniqueId: result.telegramFileUniqueId,
storageChatId: config.storageChatId,
storageMessageId: result.storageMessageId,
fileName: finalFileName,
mimeType: fileInfo.mime_type || mimeType || 'application/octet-stream',
sizeBytes: fileInfo.file_size || fileBuffer.byteLength,
fileType: fileType,
uploaderId: 0,
fileHash: hash,
createdAt: new Date(),
updatedAt: new Date(),
};
const uploaded = await performUpload(fileBuffer, finalFileName, mimeType);
await db.insert(fileSchema).values(uploaded);
const responsePayload = {
public_id: uploaded.publicId,
telegram_file_id: uploaded.telegramFileId,
telegram_file_unique_id: uploaded.telegramFileUniqueId,
storage_chat_id: uploaded.storageChatId,
storage_message_id: uploaded.storageMessageId,
file_name: uploaded.fileName,
mime_type: uploaded.mimeType,
size_bytes: uploaded.sizeBytes,
file_type: uploaded.fileType,
uploader_id: uploaded.uploaderId,
created_at: uploaded.createdAt.toISOString(),
download_url: `${config.baseUrl}/f/${uploaded.publicId}`,
};
return Response.json(responsePayload, { status: 200 });
} catch (error: any) {
logger.error('Multipart upload error', { error: error.message });
return Response.json({ error: error.message }, { status: 500 });
} finally {
if (tempPath) {
const p = tempPath;
setTimeout(() => {
try {
unlinkSync(p);
} catch {}
}, 50);
}
return Response.json(buildUploadResponse(uploaded, config.baseUrl), { status: 200 });
} catch (error: unknown) {
const message = getErrorMessage(error);
logger.error('Multipart upload error', { error: message });
return Response.json({ error: message }, { status: 500 });
}
};
const handleJSONUpload = async (req: Request): Promise<Response> => {
let tempPath = '';
try {
const { file, fileName = 'file' } = (await req.json()) as any;
const { file, fileName = 'file' } = (await req.json()) as JsonUploadPayload;
if (!file || typeof file !== 'string') {
return Response.json(
@@ -160,112 +159,29 @@ const handleJSONUpload = async (req: Request): Promise<Response> => {
);
}
let base64Data = file;
let rawMimeType = 'application/octet-stream';
if (file.startsWith('data:')) {
const match = file.match(/^data:([^;]+);base64,(.+)$/);
if (match) {
rawMimeType = match[1];
base64Data = match[2];
}
}
const { base64Data, mimeType: rawMimeType } = parseBase64File(file);
const fileBytes = Buffer.from(base64Data, 'base64');
const hash = computeHash(fileBytes);
// Check for duplicate in DB
const existing = await db
.select()
.from(fileSchema)
.where(eq(fileSchema.fileHash, hash))
.limit(1);
if (existing.length > 0) {
const existingFile = existing[0];
const responsePayload = {
public_id: existingFile.publicId,
telegram_file_id: existingFile.telegramFileId,
telegram_file_unique_id: existingFile.telegramFileUniqueId,
storage_chat_id: existingFile.storageChatId,
storage_message_id: existingFile.storageMessageId,
file_name: existingFile.fileName,
mime_type: existingFile.mimeType,
size_bytes: existingFile.sizeBytes,
file_type: existingFile.fileType,
uploader_id: existingFile.uploaderId,
created_at:
existingFile.createdAt instanceof Date
? existingFile.createdAt.toISOString()
: new Date(existingFile.createdAt).toISOString(),
download_url: `${config.baseUrl}/f/${existingFile.publicId}`,
};
return Response.json(responsePayload, { status: 200 });
const existingFile = await findFileByHash(hash);
if (existingFile) {
return Response.json(buildUploadResponse(existingFile, config.baseUrl), { status: 200 });
}
const { fileName: finalFileName, mimeType } = ensureExtension(fileName, fileBytes, rawMimeType);
const fileType =
getFileType(mimeType, finalFileName) === 'application'
? 'document'
: getFileType(mimeType, finalFileName);
const fileType = normalizeFileType(mimeType, finalFileName);
if (!checkFileSize(fileBytes.byteLength, fileType)) {
return Response.json({ error: `File size exceeds ${fileType} limit` }, { status: 400 });
}
// Write file to disk temporarily
tempPath = `/tmp/teleuploader-${nanoid()}`;
await Bun.write(tempPath, fileBytes);
const fileStream = createReadStream(tempPath);
const result = await forwardToStorage(fileStream, finalFileName, fileType);
const bot = getBot();
const fileInfo = (await bot.telegram.getFile(result.telegramFileId)) as any;
const uploaded = {
publicId: nanoid(),
telegramFileId: result.telegramFileId,
telegramFileUniqueId: result.telegramFileUniqueId,
storageChatId: config.storageChatId,
storageMessageId: result.storageMessageId,
fileName: finalFileName,
mimeType: fileInfo.mime_type || mimeType || 'application/octet-stream',
sizeBytes: fileInfo.file_size || fileBytes.byteLength,
fileType: fileType,
uploaderId: 0,
fileHash: hash,
createdAt: new Date(),
updatedAt: new Date(),
};
const uploaded = await performUpload(fileBytes, finalFileName, mimeType);
await db.insert(fileSchema).values(uploaded);
const responsePayload = {
public_id: uploaded.publicId,
telegram_file_id: uploaded.telegramFileId,
telegram_file_unique_id: uploaded.telegramFileUniqueId,
storage_chat_id: uploaded.storageChatId,
storage_message_id: uploaded.storageMessageId,
file_name: uploaded.fileName,
mime_type: uploaded.mimeType,
size_bytes: uploaded.sizeBytes,
file_type: uploaded.fileType,
uploader_id: uploaded.uploaderId,
created_at: uploaded.createdAt.toISOString(),
download_url: `${config.baseUrl}/f/${uploaded.publicId}`,
};
return Response.json(responsePayload, { status: 200 });
} catch (error: any) {
logger.error('JSON upload error', { error: error.message });
return Response.json({ error: error.message }, { status: 500 });
} finally {
if (tempPath) {
const p = tempPath;
setTimeout(() => {
try {
unlinkSync(p);
} catch {}
}, 50);
}
return Response.json(buildUploadResponse(uploaded, config.baseUrl), { status: 200 });
} catch (error: unknown) {
const message = getErrorMessage(error);
logger.error('JSON upload error', { error: message });
return Response.json({ error: message }, { status: 500 });
}
};