Skip to content

fix(reviews): upload review photos without a public ACL - #112

Merged
roncodes merged 1 commit into
release/v0.4.25from
fix/private-media-bucket
Oct 7, 2026
Merged

roncodes merged 1 commit into
release/v0.4.25from
fix/private-media-bucket

Conversation

@roncodes

@roncodes roncodes commented Oct 6, 2026

Copy link
Copy Markdown
Member

Part of making Fleetbase work with a fully private S3 bucket. Companion to fleetbase/core-api#287 (full write-up there).

Review photos were uploaded with 'public' visibility (a public-read ACL). Buckets with ObjectOwnership=BucketOwnerEnforced reject ACL'd PUTs, and put() returned false without an error, so the photo was never stored. The upload now goes out with no ACL; File::url serves it signed.

The test fake records write options and asserts that none are passed.

The S3 media bucket enforces bucket-owner object ownership and rejects PUTs that
carry an ACL, so put(..., 'public') returned false and no photo was stored.
@codecov

codecov Bot commented Oct 6, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (62af547) to head (5518e67).
⚠️ Report is 3 commits behind head on main.

Additional details and impacted files
@@             Coverage Diff             @@
##                main      #112   +/-   ##
===========================================
  Coverage     100.00%   100.00%           
  Complexity      2282      2282           
===========================================
  Files            182       182           
  Lines           9082      9082           
===========================================
  Hits            9082      9082           
Flag Coverage Δ
backend 100.00% <100.00%> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@roncodes
roncodes changed the base branch from main to release/v0.4.25 October 6, 2026 19:14
@roncodes
roncodes merged commit a4ec476 into release/v0.4.25 Oct 7, 2026
11 checks passed
@roncodes
roncodes deleted the fix/private-media-bucket branch October 7, 2026 05:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant