Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Bind scoped blob URLs to an exact record CID

オープン
#2 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
64/100
issue の種類
機能追加
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
typescript

調査の方向性

スコープされた blob および image のルートハンドラーと admission ロジックから着手し、その後、Record エントリポイントの CID 処理と比較する。canonical なルートと cache-key の構築を追跡し、README の例を確認しながら、デプロイ済みの HTTP テストを実行する。両方の CID チェック、リビジョン対応の raw および image URL、purge の動作、ルートのドキュメントが受け入れ基準を満たせば完了とする。

索引モデルが issue の本文から書いたものです。

説明

Problem

Scoped blob URLs currently identify a record by DID, collection, and rkey:

/r/{did}/{collection}/{rkey}/{blobCid}
/img/{preset}/r/{did}/{collection}/{rkey}/{blobCid}[@format]

Admission fetches the current record and checks that it references blobCid. The Record entrypoint already returns the current record CID, but scoped admission does not compare it with a caller-selected revision.

This makes the route describe “whatever record is current at this key” rather than the exact record revision that authorized the blob. A client holding an aggregator view for record CID A cannot bind its cache request to A after the rkey has moved to record CID B. Jetstream purging narrows the cache window, but the URL and admission contract remain revision-ambiguous.

Proposed change

Include the repository record CID in scoped blob and image routes:

/r/{did}/{collection}/{rkey}/{recordCid}/{blobCid}
/img/{preset}/r/{did}/{collection}/{rkey}/{recordCid}/{blobCid}[@format]

During admission:

  1. Fetch the record as today.
  2. Require RecordInfo.cid === recordCid.
  3. Require RecordInfo.blobs to contain blobCid.
  4. Admit and cache only when both checks pass.

The record CID needs its own validation because repository record CIDs use DAG-CBOR, while blob CIDs use the raw codec.

Acceptance criteria

  • Scoped raw and image routes include recordCid in their canonical path and cache key.
  • A matching record CID and referenced blob CID are admitted.
  • A mismatched record CID is denied even when the current record references the requested blob.
  • A matching record CID is denied when the record does not reference the blob.
  • Record update/delete purges continue to clear every revision URL via the existing record tag.
  • The README and deployed HTTP tests document the new route.

Backward compatibility for the old scoped route is not required. Returning 404 for the revision-ambiguous form is preferable to redirecting it to whichever revision happens to be current.

主要言語
TypeScript
スター
18
フォーク
1
PR マージ指標
30日以内にマージされた PR はありません

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。