feat(settings,index): per-user index sub-path, strip dead PP settings, scope duplicates
Lets a user pick a sub-folder under their library as a working index root, stored server-side (new sidecar user_prefs table). The Library tree, reindex, and both duplicate views (stacks + cross-folder scan) now re-root to it via a single userLibraryBase() helper. Also fixes the cross-folder scan/archive endpoints, which previously walked/touched the whole originals root instead of being scoped per-user (archive now rejects out-of-scope paths, 403). Removes PhotoPrism settings (Search/Maps/Server-UI/Features/Import) that only steered PhotoPrism's own bundled SPA and were never read by mulimage's UI. Also fixes the Library tree occasionally getting stuck on "Loading folders…" by dropping gcTime:0 and gating the spinner on isLoading instead of isPending. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -9,10 +9,12 @@ import (
|
||||
"os"
|
||||
"path/filepath"
|
||||
"sort"
|
||||
"strings"
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"github.com/gin-gonic/gin"
|
||||
"gorm.io/gorm"
|
||||
)
|
||||
|
||||
const quarantineDir = ".duplicates"
|
||||
@@ -36,17 +38,41 @@ type dupListPhoto struct {
|
||||
Files []ppFile `json:"Files"`
|
||||
}
|
||||
|
||||
func handleDupScan(cfg *Config, pp *ppClient) gin.HandlerFunc {
|
||||
func handleDupScan(cfg *Config, pp *ppClient, db *gorm.DB) gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
token := ctxToken(c)
|
||||
start := time.Now()
|
||||
slog.Info("dup.scan starting", "root", cfg.OriginalsRoot)
|
||||
|
||||
all, err := walkFiles(cfg.OriginalsRoot)
|
||||
// Scope the walk to the user's effective library root (BasePath +
|
||||
// chosen index sub-path), same as the folders/timeline/reindex scope —
|
||||
// otherwise a narrowed root would still surface every other user's
|
||||
// files in the cross-folder duplicate scan. "" means whole library
|
||||
// (today's admin-without-BasePath default).
|
||||
root := effectiveLibraryRoot(c, db)
|
||||
scanRoot := cfg.OriginalsRoot
|
||||
if root != "" {
|
||||
abs, err := resolveUnderRoot(cfg.OriginalsRoot, root, true)
|
||||
if err != nil {
|
||||
c.JSON(http.StatusBadRequest, gin.H{"error": "invalid library root"})
|
||||
return
|
||||
}
|
||||
scanRoot = abs
|
||||
}
|
||||
slog.Info("dup.scan starting", "root", scanRoot)
|
||||
|
||||
all, err := walkFiles(scanRoot)
|
||||
if err != nil {
|
||||
c.JSON(http.StatusInternalServerError, gin.H{"error": err.Error()})
|
||||
return
|
||||
}
|
||||
// walkFiles computes RelPath relative to scanRoot; re-prefix with the
|
||||
// scoped sub-path so RelPath stays originals-root-relative, matching
|
||||
// what handleDupArchive (and the rest of the API) expects.
|
||||
if root != "" {
|
||||
for i := range all {
|
||||
all[i].RelPath = root + "/" + all[i].RelPath
|
||||
}
|
||||
}
|
||||
|
||||
// Group by size first: byte-identical files necessarily share size,
|
||||
// so size-collision is a cheap O(N) prefilter that lets us skip
|
||||
@@ -149,7 +175,7 @@ type dupArchiveErr struct {
|
||||
Error string `json:"error"`
|
||||
}
|
||||
|
||||
func handleDupArchive(cfg *Config, pp *ppClient) gin.HandlerFunc {
|
||||
func handleDupArchive(cfg *Config, pp *ppClient, db *gorm.DB) gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
token := ctxToken(c)
|
||||
var body dupArchiveBody
|
||||
@@ -158,6 +184,23 @@ func handleDupArchive(cfg *Config, pp *ppClient) gin.HandlerFunc {
|
||||
return
|
||||
}
|
||||
|
||||
// Authz: every path must live under the caller's effective library
|
||||
// root. The scan above already only ever returns paths from there,
|
||||
// but this endpoint takes paths straight from the request body, so a
|
||||
// scoped (non-admin, or admin-with-sub-path) user could otherwise
|
||||
// pass an arbitrary originals-relative path and archive (move) files
|
||||
// outside their own folder.
|
||||
root := effectiveLibraryRoot(c, db)
|
||||
if root != "" {
|
||||
for _, p := range body.Paths {
|
||||
clean := strings.Trim(p, "/")
|
||||
if clean != root && !strings.HasPrefix(clean, root+"/") {
|
||||
c.JSON(http.StatusForbidden, gin.H{"error": "path outside your library root"})
|
||||
return
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Each archive batch lands in its own timestamped subdir so the
|
||||
// user can browse what was quarantined when (and recover by hand
|
||||
// if they change their mind).
|
||||
|
||||
Reference in New Issue
Block a user