mirror of https://github.com/zulip/zulip.git
818c30372f
Currently, it handles two hook types: 'pre-create' (to verify that the user is authenticated and the file size is within the limit) and 'pre-finish' (which creates an attachment row). No secret is shared between Django and tusd for authentication of the hooks endpoints, because none is necessary -- tusd forwards the end-user's credentials, and the hook checks them like it would any end-user request. An end-user gaining access to the endpoint would be able to do no more harm than via tusd or the normal file upload API. Regardless, the previous commit has restricted access to the endpoint at the nginx layer. Co-authored-by: Brijmohan Siyag <brijsiyag@gmail.com> |
||
---|---|---|
.. | ||
apns | ||
dev-vagrant-docker | ||
emoji | ||
__init__.py | ||
bootstrap-aws-installer | ||
build_pygments_data | ||
build_timezone_values | ||
dev-motd | ||
generate-fixtures | ||
generate-test-credentials | ||
generate_integration_bots_avatars.py | ||
generate_landing_page_images.py | ||
generate_zulip_bots_static_files.py | ||
install-aws-server | ||
install-shellcheck | ||
install-shfmt | ||
install-transifex-cli | ||
install-tusd | ||
lang.json | ||
optimize-svg | ||
pack-local-script | ||
postgresql-init-dev-db | ||
postgresql-init-test-db | ||
setup_venvs.py | ||
vagrant-provision |