Bind scoped blob URLs to an exact record CID
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 64/100
- issue の種類
- 機能追加
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- typescript
- 領域
- api, backend, documentation, testing
調査の方向性
スコープされた blob および image のルートハンドラーと admission ロジックから着手し、その後、Record エントリポイントの CID 処理と比較する。canonical なルートと cache-key の構築を追跡し、README の例を確認しながら、デプロイ済みの HTTP テストを実行する。両方の CID チェック、リビジョン対応の raw および image URL、purge の動作、ルートのドキュメントが受け入れ基準を満たせば完了とする。
索引モデルが issue の本文から書いたものです。
説明
Problem
Scoped blob URLs currently identify a record by DID, collection, and rkey:
/r/{did}/{collection}/{rkey}/{blobCid}
/img/{preset}/r/{did}/{collection}/{rkey}/{blobCid}[@format]
Admission fetches the current record and checks that it references blobCid. The Record entrypoint already returns the current record CID, but scoped admission does not compare it with a caller-selected revision.
This makes the route describe “whatever record is current at this key” rather than the exact record revision that authorized the blob. A client holding an aggregator view for record CID A cannot bind its cache request to A after the rkey has moved to record CID B. Jetstream purging narrows the cache window, but the URL and admission contract remain revision-ambiguous.
Proposed change
Include the repository record CID in scoped blob and image routes:
/r/{did}/{collection}/{rkey}/{recordCid}/{blobCid}
/img/{preset}/r/{did}/{collection}/{rkey}/{recordCid}/{blobCid}[@format]
During admission:
- Fetch the record as today.
- Require
RecordInfo.cid === recordCid. - Require
RecordInfo.blobsto containblobCid. - Admit and cache only when both checks pass.
The record CID needs its own validation because repository record CIDs use DAG-CBOR, while blob CIDs use the raw codec.
Acceptance criteria
- Scoped raw and image routes include
recordCidin their canonical path and cache key. - A matching record CID and referenced blob CID are admitted.
- A mismatched record CID is denied even when the current record references the requested blob.
- A matching record CID is denied when the record does not reference the blob.
- Record update/delete purges continue to clear every revision URL via the existing record tag.
- The README and deployed HTTP tests document the new route.
Backward compatibility for the old scoped route is not required. Returning 404 for the revision-ambiguous form is preferable to redirecting it to whichever revision happens to be current.
- 主要言語
- TypeScript
- スター
- 18
- フォーク
- 1
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
bug:new
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
callstackincubator/simlock#350 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
openwatersio/maritime-zones#33 ·
メンテナーはふだん 1 日以内に返信
-
Booking email verification fails for plus aliases with impersonation protection enabled対応中かも @kankadev が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
calcom/cal.diy#30293 · コメント 1 件 ·
メンテナーはふだん 5 日以内に返信
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
AOSSIE-Org/DebateAI#611 ·
メンテナーはふだん 3 日以内に返信