Enable nginx X-Accel for original artwork downloads.

Hand originals to nginx after auth so PHP is not in the byte path. Keep DOWNLOAD_ACCEL_ENABLED off until the internal location is verified.
This commit is contained in:
2026-08-29 12:25:37 +02:00
parent fb560fb7dd
commit e9cf754b37
7 changed files with 411 additions and 35 deletions
@@ -48,14 +48,14 @@ final class ArtworkDownloadController extends Controller
$artwork = Artwork::query()->find($id);
if (! $artwork) {
abort(404);
return $this->notFound();
}
$filePath = $this->originalFiles->resolveLocalPath($artwork);
$ext = strtolower(ltrim((string) pathinfo($filePath, PATHINFO_EXTENSION), '.'));
if ($filePath === '' || ! in_array($ext, self::ALLOWED_EXTENSIONS, true)) {
abort(404);
return $this->notFound();
}
if (! File::isFile($filePath)) {
@@ -65,7 +65,7 @@ final class ArtworkDownloadController extends Controller
'resolved_path' => $filePath,
]);
abort(404);
return $this->notFound();
}
$this->recordDownload($request, $artwork->id);
@@ -98,6 +98,14 @@ final class ArtworkDownloadController extends Controller
return response()->download($filePath, $downloadName);
}
private function notFound(): Response
{
return response('', 404, [
'Content-Type' => 'text/plain; charset=UTF-8',
'Cache-Control' => 'no-store',
]);
}
private function resolveAccelUri(string $filePath): ?string
{
if (! config('app.download_accel_enabled')) {