Skip to content

fix(files): store signatures without a public ACL; re-sign stored avatar URLs - #353

Merged
roncodes merged 1 commit into
release/v0.6.72from
fix/private-media-bucket
Oct 7, 2026
Merged

roncodes merged 1 commit into
release/v0.6.72from
fix/private-media-bucket

Conversation

@roncodes

@roncodes roncodes commented Oct 6, 2026

Copy link
Copy Markdown
Member

Part of making Fleetbase work with a fully private S3 bucket. Companion to fleetbase/core-api#287 (which has the full write-up).

  • Signatures were not being stored on buckets with ObjectOwnership=BucketOwnerEnforced. ProofController::storeSignature() wrote with 'public' visibility (a public-read ACL). S3 rejects ACL'd PUTs on such buckets, and put() returned false without an error, so the proof and File records were created but no object existed. The write now goes out with no ACL; File::url serves it through a signed URL.
  • avatar_url on Vehicle, Driver and Place: legacy rows that hold an absolute bucket URL are re-signed at read time via core-api File::signStoredUrl(). On core-api releases that predate the helper, the value passes through unchanged.

Tests: the signature-write fakes now assert that no visibility/ACL option is passed, and a pass-through test covers Utils::signStoredFileUrl.

… avatar URLs

- ProofController::storeSignature no longer passes 'public': the media bucket
  enforces bucket-owner ownership, rejects ACL'd PUTs, and put() silently
  returned false (no signature objects written since 2024-11-25).
- Vehicle/Driver/Place avatar_url accessors re-sign legacy absolute bucket URLs
  via core-api File::signStoredUrl when available.
@codecov

codecov Bot commented Oct 6, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (9ba5d0d) to head (413aa47).
⚠️ Report is 11 commits behind head on main.

Additional details and impacted files
@@             Coverage Diff             @@
##                main      #353   +/-   ##
===========================================
  Coverage     100.00%   100.00%           
- Complexity     12379     12381    +2     
===========================================
  Files            600       600           
  Lines          46496     46498    +2     
===========================================
+ Hits           46496     46498    +2     
Flag Coverage Δ
backend 100.00% <100.00%> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@roncodes
roncodes changed the base branch from main to release/v0.6.72 October 7, 2026 05:59
@roncodes roncodes mentioned this pull request Oct 7, 2026
@roncodes
roncodes merged commit 58c87ef into release/v0.6.72 Oct 7, 2026
11 checks passed
@roncodes
roncodes deleted the fix/private-media-bucket branch October 7, 2026 06:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant