e5b187c575
Backend
- Migration 0010 adds event_branding (one row per event; all fields
nullable so a brand-new event renders with defaults)
- BrandingRepo with COALESCE/NULLIF upsert semantics: nil pointer
preserves the existing value, "" clears the field to NULL
- internal/uploads package: ImageStore interface + LocalFSStore (dev),
pure-stdlib decode + re-encode that strips EXIF and rejects anything
that isn't valid JPEG/PNG. Size cap 2 MB, random 16-byte filenames
- GET /events/{id}/branding (viewer+) returns the row plus the
AllowedFonts list so the frontend picker stays in sync
- PUT /events/{id}/branding (editor+) validates hex colours, font
allowlist, and refuses image URLs whose path doesn't start with
/uploads/ (blocks arbitrary-origin <img> smuggling on guest pages)
- POST /uploads/image (authed) → fresh CDN URL; GET /uploads/{file}
serves with year-long cache (immutable random names)
- GET /access/{token} now embeds the host's branding so the RSVP page
can render in their colours/font with their logo + cover
- docker-compose mounts a named volume for uploads
- Custom-domain sub-block deferred to Tier 3 per the plan
Frontend
- BrandingCard.vue: colour pickers, font dropdown, logo + cover upload
with progressive disclosure, live preview pane that re-renders on
every keystroke
- RSVP page applies branding via CSS vars at the section root, so
primary colour theme + font cascade through every child card. Cover
image renders as a banner above the form; logo lands in the header
- Submit button background switches to var(--brand-primary) when set
- Mounted on the event detail page below the guests block
Plus the small UX fixes from the e2e walkthrough:
- Nav: dropped the top-level "Events" link; the logo doubles as the
home affordance (→ /dashboard when signed in, → / otherwise). Account
+ Billing + Sign out live under a profile dropdown (avatar with
initials, opens on click, closes on outside-click / Esc / route nav)
- Renamed "Back to dashboard" → "Back to events" across event detail,
billing, account, and new-event pages
Tests
- TestBrandingGetReturnsDefaults / TestBrandingPutPersists /
TestBrandingPutRejectsBadInputs / TestUploadAndServeImage /
TestUploadRejectsNonImage — all pass
- Domain tests for IsValidHexColor + IsAllowedFont
- Full integration suite green (176s)
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
94 lines
2.5 KiB
Go
94 lines
2.5 KiB
Go
package uploads
|
|
|
|
import (
|
|
"bytes"
|
|
"image"
|
|
"image/color"
|
|
"image/jpeg"
|
|
"image/png"
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
// makePNG and makeJPEG produce a tiny valid image for the round-trip tests.
|
|
func makePNG(t *testing.T) []byte {
|
|
t.Helper()
|
|
img := image.NewRGBA(image.Rect(0, 0, 4, 4))
|
|
img.Set(0, 0, color.RGBA{34, 197, 94, 255})
|
|
var b bytes.Buffer
|
|
if err := png.Encode(&b, img); err != nil {
|
|
t.Fatalf("encode png: %v", err)
|
|
}
|
|
return b.Bytes()
|
|
}
|
|
|
|
func makeJPEG(t *testing.T) []byte {
|
|
t.Helper()
|
|
img := image.NewRGBA(image.Rect(0, 0, 4, 4))
|
|
img.Set(0, 0, color.RGBA{34, 197, 94, 255})
|
|
var b bytes.Buffer
|
|
if err := jpeg.Encode(&b, img, &jpeg.Options{Quality: 80}); err != nil {
|
|
t.Fatalf("encode jpeg: %v", err)
|
|
}
|
|
return b.Bytes()
|
|
}
|
|
|
|
func TestDecodeAndReencode_PNG(t *testing.T) {
|
|
out, format, err := DecodeAndReencode(makePNG(t))
|
|
if err != nil {
|
|
t.Fatalf("decode png: %v", err)
|
|
}
|
|
if format != FormatPNG {
|
|
t.Errorf("format: got %q want png", format)
|
|
}
|
|
// Output must be valid PNG (round-trip decode).
|
|
if _, _, err := image.Decode(bytes.NewReader(out)); err != nil {
|
|
t.Errorf("re-encoded png is not valid: %v", err)
|
|
}
|
|
}
|
|
|
|
func TestDecodeAndReencode_JPEG(t *testing.T) {
|
|
out, format, err := DecodeAndReencode(makeJPEG(t))
|
|
if err != nil {
|
|
t.Fatalf("decode jpeg: %v", err)
|
|
}
|
|
if format != FormatJPEG {
|
|
t.Errorf("format: got %q want jpeg", format)
|
|
}
|
|
if _, _, err := image.Decode(bytes.NewReader(out)); err != nil {
|
|
t.Errorf("re-encoded jpeg is not valid: %v", err)
|
|
}
|
|
}
|
|
|
|
func TestDecodeAndReencode_RejectsNonImage(t *testing.T) {
|
|
_, _, err := DecodeAndReencode([]byte("hello, world"))
|
|
if err == nil {
|
|
t.Fatal("expected an error decoding a non-image payload")
|
|
}
|
|
if !strings.Contains(err.Error(), "not a recognised image") {
|
|
t.Errorf("error: got %q want 'not a recognised image'", err)
|
|
}
|
|
}
|
|
|
|
func TestDecodeAndReencode_RejectsTooLarge(t *testing.T) {
|
|
big := make([]byte, MaxUploadBytes+1)
|
|
_, _, err := DecodeAndReencode(big)
|
|
if err == nil || !strings.Contains(err.Error(), "exceeds") {
|
|
t.Errorf("expected size-limit error, got %v", err)
|
|
}
|
|
}
|
|
|
|
func TestLocalFSStore_FilePath_RejectsTraversal(t *testing.T) {
|
|
s := &LocalFSStore{Dir: "/tmp/x", PublicBase: "http://localhost/up"}
|
|
cases := []string{"../etc/passwd", "a/b.png", "..", ".env"}
|
|
for _, in := range cases {
|
|
if _, err := s.FilePath(in); err == nil {
|
|
t.Errorf("FilePath(%q) should have refused", in)
|
|
}
|
|
}
|
|
// A bare random filename should be accepted.
|
|
if _, err := s.FilePath("ok.png"); err != nil {
|
|
t.Errorf("FilePath(ok.png) should have accepted: %v", err)
|
|
}
|
|
}
|