Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Bind scoped blob URLs to an exact record CID

Aperta
#2 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
64/100
Tipo di issue
Funzionalità
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
typescript

Direzione di ricerca

Inizia dagli handler delle route blob e image soggette a scope e dalla logica di admission, quindi confrontali con la gestione dei CID dell’entrypoint Record. Traccia la costruzione delle route canoniche e delle chiavi di cache ed esegui i test HTTP deployati, verificando al contempo gli esempi nel README. Il lavoro è completato quando entrambi i controlli CID, gli URL raw e image consapevoli della revisione, il comportamento di purge e la documentazione delle route soddisfano i criteri di accettazione.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Problem

Scoped blob URLs currently identify a record by DID, collection, and rkey:

/r/{did}/{collection}/{rkey}/{blobCid}
/img/{preset}/r/{did}/{collection}/{rkey}/{blobCid}[@format]

Admission fetches the current record and checks that it references blobCid. The Record entrypoint already returns the current record CID, but scoped admission does not compare it with a caller-selected revision.

This makes the route describe “whatever record is current at this key” rather than the exact record revision that authorized the blob. A client holding an aggregator view for record CID A cannot bind its cache request to A after the rkey has moved to record CID B. Jetstream purging narrows the cache window, but the URL and admission contract remain revision-ambiguous.

Proposed change

Include the repository record CID in scoped blob and image routes:

/r/{did}/{collection}/{rkey}/{recordCid}/{blobCid}
/img/{preset}/r/{did}/{collection}/{rkey}/{recordCid}/{blobCid}[@format]

During admission:

  1. Fetch the record as today.
  2. Require RecordInfo.cid === recordCid.
  3. Require RecordInfo.blobs to contain blobCid.
  4. Admit and cache only when both checks pass.

The record CID needs its own validation because repository record CIDs use DAG-CBOR, while blob CIDs use the raw codec.

Acceptance criteria

  • Scoped raw and image routes include recordCid in their canonical path and cache key.
  • A matching record CID and referenced blob CID are admitted.
  • A mismatched record CID is denied even when the current record references the requested blob.
  • A matching record CID is denied when the record does not reference the blob.
  • Record update/delete purges continue to clear every revision URL via the existing record tag.
  • The README and deployed HTTP tests document the new route.

Backward compatibility for the old scoped route is not required. Returning 404 for the revision-ambiguous form is preferable to redirecting it to whichever revision happens to be current.

Lingua principale
TypeScript
Stelle
18
Fork
1
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Preparare l'ambiente

Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.