feat: add wildcard token support for allowed extensions and access token CLI commands
Introduce WILDCARD_TOKENS set in attachments.py to treat "*", ".*", "*.*" as wildcards that fall back to ALLOWED_UPLOAD_TYPES. Add cmd_token_issue and cmd_token_list CLI commands for issuing and listing DevPlace access tokens. Register access_tokens table in SOFT_DELETE_TABLES and initialize its columns and indexes in init_db. Replace Form() with Depends(json_or_form(...)) in admin backup, container, notification, settings, and user routers to support both JSON and form data.
This commit is contained in:
@@ -196,15 +196,17 @@ def _get_max_upload_bytes():
|
||||
return int(get_setting("max_upload_size_mb", "10")) * 1024 * 1024
|
||||
|
||||
|
||||
WILDCARD_TOKENS = {"*", ".*", "*.*"}
|
||||
|
||||
|
||||
def allowed_extensions():
|
||||
raw = get_setting("allowed_file_types", "").strip()
|
||||
if raw:
|
||||
return {
|
||||
ext if ext.startswith(".") else f".{ext}"
|
||||
for ext in (part.strip().lower() for part in raw.split(","))
|
||||
if ext
|
||||
}
|
||||
return set(ALLOWED_UPLOAD_TYPES)
|
||||
if not raw:
|
||||
return set(ALLOWED_UPLOAD_TYPES)
|
||||
tokens = {part.strip().lower() for part in raw.split(",") if part.strip()}
|
||||
if tokens & WILDCARD_TOKENS:
|
||||
return set(ALLOWED_UPLOAD_TYPES)
|
||||
return {token if token.startswith(".") else f".{token}" for token in tokens}
|
||||
|
||||
|
||||
def is_extension_allowed(ext):
|
||||
|
||||
Reference in New Issue
Block a user