mirror of
https://github.com/zulip/zulip.git
synced 2025-10-28 10:33:54 +00:00
upload: Use tusd for resumable, larger uploads.
Currently, it handles two hook types: 'pre-create' (to verify that the user is authenticated and the file size is within the limit) and 'pre-finish' (which creates an attachment row). No secret is shared between Django and tusd for authentication of the hooks endpoints, because none is necessary -- tusd forwards the end-user's credentials, and the hook checks them like it would any end-user request. An end-user gaining access to the endpoint would be able to do no more harm than via tusd or the normal file upload API. Regardless, the previous commit has restricted access to the endpoint at the nginx layer. Co-authored-by: Brijmohan Siyag <brijsiyag@gmail.com>
This commit is contained in:
committed by
Tim Abbott
parent
02d3fb7666
commit
818c30372f
@@ -421,6 +421,9 @@ def main(options: argparse.Namespace) -> NoReturn:
|
||||
# Install transifex-cli.
|
||||
run_as_root([*proxy_env, "tools/setup/install-transifex-cli"])
|
||||
|
||||
# Install tusd
|
||||
run_as_root([*proxy_env, "tools/setup/install-tusd"])
|
||||
|
||||
setup_venvs.main()
|
||||
|
||||
run_as_root(["cp", REPO_STOPWORDS_PATH, TSEARCH_STOPWORDS_PATH])
|
||||
|
||||
Reference in New Issue
Block a user