feat: multipart manga + chapter uploads with magic-byte MIME sniff
POST /api/v1/mangas and POST /api/v1/mangas/{id}/chapters now accept
multipart/form-data, gated by CurrentUser:
- /mangas: required `metadata` part (NewManga JSON) + optional `cover`
image part.
- /mangas/{id}/chapters: required `metadata` (NewChapter JSON) + one or
more `page` parts ordered by arrival. Returns 404 if the parent manga
doesn't exist, 409 on duplicate (manga_id, number).
MIME is sniffed via the `infer` crate (magic bytes), not the
client-supplied filename or Content-Type. Whitelist:
jpeg / png / webp / gif / avif. Anything else → 415
unsupported_media_type. The stored key's extension is derived from the
sniffed type so a "page1.png" that's actually a JPEG lands as `.jpg`.
Size cap is two-layer:
- Request body cap (config.max_request_bytes, default 200 MiB) enforced
by axum's DefaultBodyLimit before the handler sees the request.
- Per-image-part cap (config.max_file_bytes, default 20 MiB) enforced
after reading the part, so a single oversized image can't pass even
if the total request fits.
Storage keys follow the layout documented in CLAUDE.md:
- mangas/{manga_id}/cover.{ext}
- mangas/{manga_id}/chapters/{chapter_id}/pages/{nnnn}.{ext} (1-indexed).
AppError grows PayloadTooLarge/UnsupportedMediaType/ValidationFailed
(413 / 415 / 422). ValidationFailed carries a `details` JSON object the
client can use to highlight bad fields (e.g. {"title":"required"}).
Top-level matching in code() stays exhaustive.
Backend coverage in tests/api_uploads.rs (10 cases):
- create_manga_with_cover_stores_image — file is reachable via
/api/v1/files/{key} with the right Content-Type.
- create_manga_without_cover_leaves_path_null.
- create_manga_rejects_non_image_cover_with_415 — PDF claimed as png.
- create_manga_rejects_oversized_cover_with_413.
- create_chapter_with_pages_stores_each — extension derived from
sniffed MIME, files reachable in arrival order.
- create_chapter_rejects_when_no_pages_with_422 — details.page set.
- create_chapter_rejects_renamed_non_image_page → 415.
- create_chapter_returns_409_on_duplicate_number.
- create_chapter_requires_authentication → 401.
- create_chapter_under_unknown_manga_is_404.
Existing tests/api_mangas.rs is migrated to multipart; the create
response is now 201 Created. tests/common::MultipartBuilder builds the
body by hand so the test crate stays free of HTTP-client deps.
Frontend lib/api/mangas.ts: createManga now sends FormData (metadata +
optional cover Blob). Browser fills in the boundary header automatically.
Vitest asserts the FormData structure via FileReader (jsdom doesn't
implement Blob.text()).
E2E tests wait for the post-hydration nav-login link before
interacting with the login form, fixing a flake where pre-hydration
clicks would submit via the browser default and bypass our handler.
Lockstep version bump to 0.5.0.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -15,7 +15,7 @@ use tempfile::TempDir;
|
||||
use tower::ServiceExt;
|
||||
|
||||
use mangalord::app::{router, AppState};
|
||||
use mangalord::config::AuthConfig;
|
||||
use mangalord::config::{AuthConfig, UploadConfig};
|
||||
use mangalord::storage::LocalStorage;
|
||||
|
||||
pub struct Harness {
|
||||
@@ -30,6 +30,12 @@ pub fn harness(pool: PgPool) -> Harness {
|
||||
db: pool,
|
||||
storage: Arc::new(LocalStorage::new(storage_dir.path())),
|
||||
auth: AuthConfig { cookie_secure: false, ..AuthConfig::default() },
|
||||
upload: UploadConfig {
|
||||
// Keep file caps small in tests so the size-cap path is cheap to
|
||||
// exercise without producing tens of MBs of bytes.
|
||||
max_request_bytes: 4 * 1024 * 1024,
|
||||
max_file_bytes: 256 * 1024,
|
||||
},
|
||||
};
|
||||
Harness { app: router(state), _storage_dir: storage_dir }
|
||||
}
|
||||
@@ -124,6 +130,141 @@ pub fn extract_session_cookie(response: &axum::response::Response) -> Option<Str
|
||||
})
|
||||
}
|
||||
|
||||
/// Minimal multipart builder for tests. Real clients would use a real
|
||||
/// library; we hand-roll a small one so the test crate stays free of
|
||||
/// http-client dependencies.
|
||||
pub struct MultipartBuilder {
|
||||
boundary: String,
|
||||
body: Vec<u8>,
|
||||
}
|
||||
|
||||
impl Default for MultipartBuilder {
|
||||
fn default() -> Self {
|
||||
Self::new()
|
||||
}
|
||||
}
|
||||
|
||||
impl MultipartBuilder {
|
||||
pub fn new() -> Self {
|
||||
Self {
|
||||
boundary: format!("----mangalord-test-{}", uuid::Uuid::new_v4().simple()),
|
||||
body: Vec::new(),
|
||||
}
|
||||
}
|
||||
|
||||
pub fn add_json(mut self, name: &str, value: serde_json::Value) -> Self {
|
||||
self.write_part_header(name, None, Some("application/json"));
|
||||
self.body.extend(value.to_string().as_bytes());
|
||||
self.body.extend(b"\r\n");
|
||||
self
|
||||
}
|
||||
|
||||
pub fn add_file(
|
||||
mut self,
|
||||
name: &str,
|
||||
filename: &str,
|
||||
content_type: &str,
|
||||
bytes: &[u8],
|
||||
) -> Self {
|
||||
self.write_part_header(name, Some(filename), Some(content_type));
|
||||
self.body.extend(bytes);
|
||||
self.body.extend(b"\r\n");
|
||||
self
|
||||
}
|
||||
|
||||
fn write_part_header(
|
||||
&mut self,
|
||||
name: &str,
|
||||
filename: Option<&str>,
|
||||
ct: Option<&str>,
|
||||
) {
|
||||
self.body
|
||||
.extend(format!("--{}\r\n", self.boundary).as_bytes());
|
||||
let disposition = if let Some(fname) = filename {
|
||||
format!(
|
||||
"Content-Disposition: form-data; name=\"{name}\"; filename=\"{fname}\"\r\n"
|
||||
)
|
||||
} else {
|
||||
format!("Content-Disposition: form-data; name=\"{name}\"\r\n")
|
||||
};
|
||||
self.body.extend(disposition.as_bytes());
|
||||
if let Some(ct) = ct {
|
||||
self.body.extend(format!("Content-Type: {ct}\r\n").as_bytes());
|
||||
}
|
||||
self.body.extend(b"\r\n");
|
||||
}
|
||||
|
||||
fn finalize(self) -> (String, Vec<u8>) {
|
||||
let mut body = self.body;
|
||||
body.extend(format!("--{}--\r\n", self.boundary).as_bytes());
|
||||
(self.boundary, body)
|
||||
}
|
||||
}
|
||||
|
||||
pub fn post_multipart(uri: &str, builder: MultipartBuilder) -> Request<Body> {
|
||||
let (boundary, body) = builder.finalize();
|
||||
Request::builder()
|
||||
.method("POST")
|
||||
.uri(uri)
|
||||
.header(
|
||||
header::CONTENT_TYPE,
|
||||
format!("multipart/form-data; boundary={boundary}"),
|
||||
)
|
||||
.body(Body::from(body))
|
||||
.unwrap()
|
||||
}
|
||||
|
||||
pub fn post_multipart_with_cookie(
|
||||
uri: &str,
|
||||
builder: MultipartBuilder,
|
||||
cookie: &str,
|
||||
) -> Request<Body> {
|
||||
let (boundary, body) = builder.finalize();
|
||||
Request::builder()
|
||||
.method("POST")
|
||||
.uri(uri)
|
||||
.header(
|
||||
header::CONTENT_TYPE,
|
||||
format!("multipart/form-data; boundary={boundary}"),
|
||||
)
|
||||
.header(header::COOKIE, cookie)
|
||||
.body(Body::from(body))
|
||||
.unwrap()
|
||||
}
|
||||
|
||||
/// Realistic PNG file header bytes — enough for `infer` to identify.
|
||||
pub fn fake_png_bytes() -> Vec<u8> {
|
||||
vec![0x89, 0x50, 0x4e, 0x47, 0x0d, 0x0a, 0x1a, 0x0a, 0, 0, 0, 0]
|
||||
}
|
||||
|
||||
/// Realistic JPEG file header bytes — enough for `infer` to identify.
|
||||
pub fn fake_jpeg_bytes() -> Vec<u8> {
|
||||
vec![
|
||||
0xff, 0xd8, 0xff, 0xe0, 0, 0x10, b'J', b'F', b'I', b'F', 0, 0,
|
||||
]
|
||||
}
|
||||
|
||||
/// Create a manga via the upload API and return its id. Used by tests
|
||||
/// that need a manga to exist before they exercise chapters / etc.
|
||||
pub async fn seed_manga_via_api(app: &Router, cookie: &str, title: &str) -> uuid::Uuid {
|
||||
let resp = app
|
||||
.clone()
|
||||
.oneshot(post_multipart_with_cookie(
|
||||
"/api/v1/mangas",
|
||||
MultipartBuilder::new().add_json("metadata", serde_json::json!({ "title": title })),
|
||||
cookie,
|
||||
))
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(
|
||||
resp.status(),
|
||||
axum::http::StatusCode::CREATED,
|
||||
"seed_manga_via_api failed"
|
||||
);
|
||||
let body = body_json(resp).await;
|
||||
uuid::Uuid::parse_str(body["id"].as_str().unwrap()).unwrap()
|
||||
}
|
||||
|
||||
/// Register a brand-new user and return (username, session cookie value).
|
||||
/// The username is unique per call so tests can run in parallel against a
|
||||
/// single DB without colliding.
|
||||
|
||||
Reference in New Issue
Block a user