Repository navigation
feat: add S3_PREFIX to store uploads under a folder in the bucket - #500
Open
jordanmiguel wants to merge 1 commit into
Open
jordanmiguel wants to merge 1 commit into
jordanmiguel wants to merge 1 commit into
Conversation
Uploads always landed at the bucket root and startup granted public read on the entire bucket, so Plunk could not share a bucket with another application without exposing that application's objects. S3_PREFIX places uploads under a folder and narrows the public-read policy to that folder only. Unset keeps the current layout and policy.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Uploads are always written to the bucket root as
<projectId>/<timestamp>-<random>.<ext>, and on startupinitializeBucket()grants public read onarn:aws:s3:::<bucket>/*. So Plunk can't share a bucket with another application: that application's objects would become publicly readable too.This adds an optional
S3_PREFIXenv var:<prefix>/<projectId>/<timestamp>-<random>.<ext>, and the returned URL is${S3_PUBLIC_URL}/<prefix>/....arn:aws:s3:::<bucket>/<prefix>/*, so objects outside the prefix stay private./plunk/→plunk), and nested prefixes (tenants/plunk) work.Wiring follows the
MAIL_FROM_SUBDOMAINpattern:validateEnvinconstants.ts, passthrough indocker-compose.yml, the three env lists inturbo.json, and docs inapps/api/.env.example,.env.self-host.example, the self-hosting env-var wiki page, andCLAUDE.md.Note:
PutBucketPolicystill replaces the bucket's entire policy, as it does today. That behaviour is unchanged here and could be a separate follow-up.Type of Change
feat:New feature (MINOR version bump)fix:Bug fix (PATCH version bump)feat!:Breaking change - new feature (MAJOR version bump)fix!:Breaking change - bug fix (MAJOR version bump)docs:Documentation update (no version bump)chore:Maintenance/dependencies (no version bump)refactor:Code refactoring (no version bump)test:Adding tests (no version bump)perf:Performance improvement (PATCH version bump)Testing
apps/api/src/services/__tests__/S3Service.test.ts: object key, public URL and policy resource, both with and without a prefix, plus slash trimming. I wrote it before the implementation; it failed on the three prefix cases and passed on the two unchanged cases.yarn test:run: 52 files, 1280 tests pass (local Postgres 16 + Redis 7, same env as CI).yarn build --filter=apiandyarn lint --filter=apipass (no new warnings).pgsty/minio:RELEASE.2026-08-04T00-00-00Z) withS3_PREFIX=/plunk/:plunk/project-1/<ts>-<rand>.png.Checklist