From 56800fbbd4488db20abd4f44f0d39e48599be0ab Mon Sep 17 00:00:00 2001 From: "Somhairle H. Marisol" Date: Mon, 21 Sep 2026 07:37:51 +0800 Subject: Secure artifact serving: manifest/checkpoint membership, hash validation, link rejection --- src/SomhairlesDream.Server/ArtifactRunApi.fs | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) (limited to 'src/SomhairlesDream.Server/ArtifactRunApi.fs') diff --git a/src/SomhairlesDream.Server/ArtifactRunApi.fs b/src/SomhairlesDream.Server/ArtifactRunApi.fs index 8f63b99..48ecc08 100644 --- a/src/SomhairlesDream.Server/ArtifactRunApi.fs +++ b/src/SomhairlesDream.Server/ArtifactRunApi.fs @@ -93,6 +93,7 @@ module ArtifactRunApi = | Error(InvalidManifest message) -> error options 500 message | Error(InvalidArtifactPath message) -> error options 500 message | Error ArtifactNotFound -> error options 500 "manifest not found" + | Error(ArtifactMismatch message) -> error options 500 message let private artifactContentType (path: string) = match Path.GetExtension(path).ToLowerInvariant() with @@ -102,18 +103,26 @@ module ArtifactRunApi = | ".log" -> "text/plain" | _ -> "application/octet-stream" + let private streamArtifact (context: HttpContext) (file: ArtifactFile) = + context.Response.OnCompleted(Func(fun () -> + file.Stream.Dispose() + Task.CompletedTask)) + + Results.Stream(file.Stream, artifactContentType file.RelativePath) + let private artifact options (context: HttpContext) = match selector context, queryValue context "path" with | Error message, _ -> error options 400 message | _, None -> error options 400 "missing query parameter 'path'" | Ok(projectId, runId), Some relativePath -> match options.Coordinator.Artifact(projectId, runId, relativePath) with - | Ok path -> Results.File(path, artifactContentType path) + | Ok file -> streamArtifact context file | Error RunNotFound -> error options 404 "run not found" | Error(RunNotComplete snapshot) -> jsonWithStatus options 409 snapshot | Error(InvalidArtifactPath message) -> error options 400 message | Error ArtifactNotFound -> error options 404 "artifact not found" | Error(InvalidManifest message) -> error options 500 message + | Error(ArtifactMismatch message) -> error options 409 message let private stepArtifact options (context: HttpContext) = match selector context, queryValue context "path" with @@ -121,12 +130,13 @@ module ArtifactRunApi = | _, None -> error options 400 "missing query parameter 'path'" | Ok(projectId, runId), Some relativePath -> match options.Coordinator.StepArtifact(projectId, runId, relativePath) with - | Ok path -> Results.File(path, artifactContentType path) + | Ok file -> streamArtifact context file | Error RunNotFound -> error options 404 "run not found" | Error(RunNotComplete snapshot) -> jsonWithStatus options 409 snapshot | Error(InvalidArtifactPath message) -> error options 400 message | Error ArtifactNotFound -> error options 404 "artifact not found" | Error(InvalidManifest message) -> error options 500 message + | Error(ArtifactMismatch message) -> error options 409 message let private writeError options (context: HttpContext) statusCode message = task { -- cgit v1.2.3