feat(backend): user + library admin API, atomic sanitized upload

This commit is contained in:
2026-09-05 00:16:33 +08:00
parent 51735680e0
commit ed4ee2458f
9 changed files with 514 additions and 3 deletions
+42
View File
@@ -0,0 +1,42 @@
package bookfile
import (
"path/filepath"
"strings"
"unicode"
)
func FormatFromExt(name string) string {
switch strings.ToLower(filepath.Ext(name)) {
case ".cbz", ".zip":
return "cbz"
case ".pdf":
return "pdf"
case ".epub":
return "epub"
case ".txt":
return "txt"
case ".md":
return "md"
}
return ""
}
func SafeName(s string) string {
s = strings.Map(func(r rune) rune {
if unicode.IsControl(r) {
return -1
}
return r
}, s)
s = strings.ReplaceAll(s, "\\", "/")
s = filepath.Base(filepath.ToSlash(s))
if s == "." || s == "/" {
return ""
}
s = strings.TrimSpace(s)
if len(s) > 200 {
s = strings.TrimSpace(s[:200])
}
return s
}
@@ -0,0 +1,32 @@
package bookfile
import "testing"
func TestFormatFromExt(t *testing.T) {
cases := map[string]string{
"a.cbz": "cbz", "B.PDF": "pdf", "x.epub": "epub", "y.txt": "txt", "z.md": "md",
"w.rar": "", "noext": "", "cbr.cbZ": "cbz", "tar.gz": "",
}
for in, want := range cases {
if got := FormatFromExt(in); got != want {
t.Errorf("FormatFromExt(%q)=%q want %q", in, got, want)
}
}
}
func TestSafeName(t *testing.T) {
cases := map[string]string{
"my book.cbz": "my book.cbz",
"../../etc/passwd": "passwd",
"/abs/name.pdf": "name.pdf",
"a\\b\\c.epub": "c.epub",
" spaced .txt ": "spaced .txt",
"con\ntl.bin": "contl.bin",
"": "",
}
for in, want := range cases {
if got := SafeName(in); got != want {
t.Errorf("SafeName(%q)=%q want %q", in, got, want)
}
}
}