Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2,229 changes: 918 additions & 1,311 deletions backend/package-lock.json

Large diffs are not rendered by default.

28 changes: 14 additions & 14 deletions backend/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -17,40 +17,40 @@
},
"license": "MIT",
"devDependencies": {
"@eslint/js": "^9.39.2",
"@eslint/js": "^10.0.1",
"@hocuspocus/provider": "^3.4.4",
"@hocuspocus/transformer": "^3.4.4",
"@smithy/util-stream": "^4.5.10",
"@smithy/util-stream": "^4.5.15",
"@types/jsonwebtoken": "^9.0.10",
"@types/node": "^25.0.10",
"@typescript-eslint/eslint-plugin": "^8.53.1",
"@typescript-eslint/parser": "^8.53.1",
"@types/node": "^25.3.3",
"@typescript-eslint/eslint-plugin": "^8.56.1",
"@typescript-eslint/parser": "^8.56.1",
"aws-sdk-client-mock": "^4.1.0",
"eslint": "^9.39.2",
"eslint": "^10.0.2",
"eslint-config-prettier": "^10.1.8",
"globals": "^17.1.0",
"globals": "^17.4.0",
"prettier": "3.8.1",
"ts-node": "^10.9.2",
"tsx": "^4.21.0",
"typescript": "^5.9.3",
"typescript-eslint": "^8.53.1",
"typescript-eslint": "^8.56.1",
"vitest": "^4.0.18",
"vitest-mock-extended": "^3.0.1",
"yjs": "^13.6.29"
},
"dependencies": {
"@aws-sdk/client-s3": "^3.975.0",
"prisma": "^7.3.0",
"@aws-sdk/client-s3": "^3.1000.0",
"prisma": "^7.4.2",
"@hocuspocus/extension-database": "^3.4.4",
"@hocuspocus/extension-logger": "^3.4.4",
"@hocuspocus/server": "^3.1.1",
"@prisma/adapter-pg": "^7.3.0",
"@prisma/client": "^7.3.0",
"@types/formidable": "^3.4.6",
"@prisma/adapter-pg": "^7.4.2",
"@prisma/client": "^7.4.2",
"@types/formidable": "^3.4.7",
"cookie": "^1.1.1",
"cron": "^4.4.0",
"formidable": "^3.5.2",
"jsonwebtoken": "^9.0.3",
"pg": "^8.17.2"
"pg": "^8.19.0"
}
}
98 changes: 90 additions & 8 deletions backend/src/httpHandler.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -114,7 +114,10 @@ describe("handleGetOwnDocumentsRequest", () => {
describe("handleDeleteDocumentRequest", () => {
it("deletes a document", async () => {
const doc = buildFullDocument();
prismaMock.document.findFirst.mockResolvedValue({ id: doc.id } as never);
prismaMock.document.findFirst.mockResolvedValue({
id: doc.id,
modificationSecret: doc.modificationSecret,
} as never);
prismaMock.image.findMany.mockResolvedValue([]);
prismaMock.document.delete.mockResolvedValue(doc);

Expand Down Expand Up @@ -190,13 +193,94 @@ describe("handleUploadImageRequest", () => {

const response = mock<ServerResponse<IncomingMessage>>();
const request = mock<IncomingMessage>();
await expect(
handleUploadImageRequest(doc.id, "wrong", request, response, prismaMock),
).rejects.toBeUndefined();
await handleUploadImageRequest(
doc.id,
"wrong",
request,
response,
prismaMock,
);

expect(response.writeHead.mock.calls[0][0]).toBe(403);
});

it("returns 422 when createImage returns null", async () => {
const doc = buildFullDocument();
prismaMock.document.findFirst.mockResolvedValue({
id: doc.id,
data: doc.data,
modificationSecret: doc.modificationSecret,
} as never);
prismaMock.image.create.mockResolvedValue(null);

const response = mock<ServerResponse<IncomingMessage>>();
const request = mock<IncomingMessage>();
await handleUploadImageRequest(
doc.id,
doc.modificationSecret,
request,
response,
prismaMock,
);

expect(response.writeHead.mock.calls[0][0]).toBe(422);
});

it("returns 400 when file is missing", async () => {
const doc = buildFullDocument();
prismaMock.document.findFirst.mockResolvedValue({
id: doc.id,
data: doc.data,
modificationSecret: doc.modificationSecret,
} as never);

mockFormidableParse.mockResolvedValueOnce([{}, {}]);

const response = mock<ServerResponse<IncomingMessage>>();
const request = mock<IncomingMessage>();
await handleUploadImageRequest(
doc.id,
doc.modificationSecret,
request,
response,
prismaMock,
);

expect(response.writeHead.mock.calls[0][0]).toBe(400);
});

it("rolls back DB entry when S3 upload fails", async () => {
const doc = buildFullDocument();
const image = buildFullExampleImage(doc.id);
prismaMock.document.findFirst.mockResolvedValue({
id: doc.id,
data: doc.data,
modificationSecret: doc.modificationSecret,
} as never);
prismaMock.image.create.mockResolvedValue(image);
prismaMock.image.delete.mockResolvedValue(image);

const { uploadEncryptedImage } = await import("./utils/uploaderDownloader");
vi.mocked(uploadEncryptedImage).mockRejectedValueOnce(
new Error("S3 upload failed"),
);

const response = mock<ServerResponse<IncomingMessage>>();
const request = mock<IncomingMessage>();
await handleUploadImageRequest(
doc.id,
doc.modificationSecret,
request,
response,
prismaMock,
);

expect(prismaMock.image.delete).toHaveBeenCalledWith({
where: { id: image.id },
});
expect(response.writeHead.mock.calls[0][0]).toBe(500);
});

it("returns 413 when file size exceeds maximum allowed size", async () => {
const doc = buildFullDocument();
prismaMock.document.findFirst.mockResolvedValue({
Expand Down Expand Up @@ -242,7 +326,7 @@ describe("handleGetImageRequest", () => {
expect(response.writeHead.mock.calls[0][0]).toEqual(200);
expect(response.writeHead.mock.calls[0][1]).toHaveProperty(
"Content-Disposition",
"inline; filename=test.png",
'inline; filename="test.png"',
);
expect(response.writeHead.mock.calls[0][1]).toHaveProperty(
"Content-Type",
Expand Down Expand Up @@ -291,9 +375,7 @@ describe("handleDeleteImageRequest", () => {
);

const response = mock<ServerResponse<IncomingMessage>>();
await expect(
handleDeleteImageRequest(doc.id, "wrong", response, prismaMock),
).rejects.toBeUndefined();
await handleDeleteImageRequest(doc.id, "wrong", response, prismaMock);

expect(response.writeHead.mock.calls[0][0]).toBe(403);
});
Expand Down
75 changes: 51 additions & 24 deletions backend/src/httpHandler.ts
Original file line number Diff line number Diff line change
Expand Up @@ -86,33 +86,50 @@ export const handleUploadImageRequest = async (
response: ServerResponse<IncomingMessage>,
prisma: PrismaClient,
): Promise<void> => {
await checkPermission(prisma, documentId, modificationSecret, response);
const hasPermission = await checkPermission(
prisma,
documentId,
modificationSecret,
);
if (!hasPermission) {
response.writeHead(403);
response.end();
return;
}
try {
const maxFileSize = process.env.UPLOAD_IMAGE_MAX_SIZE_BYTES
? parseInt(process.env.UPLOAD_IMAGE_MAX_SIZE_BYTES, 10)
: DEFAULT_MAX_IMAGE_SIZE_BYTES;
const parsed = parseInt(process.env.UPLOAD_IMAGE_MAX_SIZE_BYTES ?? "", 10);
const maxFileSize = Number.isNaN(parsed)
? DEFAULT_MAX_IMAGE_SIZE_BYTES
: parsed;

const form = formidable({ multiples: false, maxFileSize });
// eslint-disable-next-line @typescript-eslint/no-unused-vars
const [_fields, files] = await form.parse(request);
if (files["file"].length > 0) {
const file = files["file"][0];
const image = await createImage(
prisma,
documentId,
file?.mimetype,
file?.originalFilename,
);
if (!files["file"] || files["file"].length === 0) {
response.writeHead(400);
response.end();
return;
}
const file = files["file"][0];
const image = await createImage(
prisma,
documentId,
file?.mimetype,
file?.originalFilename,
);
if (!image) {
response.writeHead(422);
response.end();
return;
}
try {
await uploadEncryptedImage(image.id, image.mimetype, file?.filepath);

if (image) {
response.writeHead(200, { "Content-Type": "text/json" });
response.end(JSON.stringify({ imageUrl: `images/${image.id}` }));
} else {
response.writeHead(422);
response.end();
}
} catch (uploadError) {
await deleteImage(prisma, image.id);
throw uploadError;
}
response.writeHead(200, { "Content-Type": "text/json" });
response.end(JSON.stringify({ imageUrl: `images/${image.id}` }));
} catch (error) {
if (error instanceof Error && error.message.includes("maxTotalFileSize")) {
response.writeHead(413, { "Content-Type": "text/json" });
Expand All @@ -139,12 +156,18 @@ export const handleGetImageRequest = async (
if (getImageResult && downloadedImage) {
response.writeHead(200, {
"Content-Type": getImageResult.mimetype,
"Content-Disposition": "inline; filename=" + getImageResult.name,
"Content-Disposition": `inline; filename="${getImageResult.name.replace(/["\\\r\n]/g, "_")}"`,
"Content-Length": downloadedImage.length,
"X-Content-Type-Options": "nosniff",
"Cache-Control": "public, max-age=31536000, immutable",
});
try {
await pipeline(Readable.from(downloadedImage), response);
} catch (error) {
if (error instanceof Error && (error as NodeJS.ErrnoException).code === "ERR_STREAM_PREMATURE_CLOSE") {
if (
error instanceof Error &&
(error as NodeJS.ErrnoException).code === "ERR_STREAM_PREMATURE_CLOSE"
) {
return;
}
throw error;
Expand All @@ -163,12 +186,16 @@ export const handleDeleteImageRequest = async (
): Promise<void> => {
const image = await getImage(prisma, imageId);

await checkPermission(
const hasPermission = await checkPermission(
prisma,
image?.documentId,
modificationSecret,
response,
);
if (!hasPermission) {
response.writeHead(403);
response.end();
return;
}
// Delete bucket file first so DB record remains as reference if this fails
const bucketResult = image ? await deleteImageFromBucket(imageId) : null;
const deletedImageResult = bucketResult
Expand Down
3 changes: 3 additions & 0 deletions backend/src/httpRouter.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,9 @@ import {
import jwt from "jsonwebtoken";

vi.mock("./httpHandler");
vi.mock("./utils/rateLimiter", () => ({
checkRateLimit: () => true,
}));

describe("httpRouter", () => {
it("responds with OK to health check", async () => {
Expand Down
Loading