chore: relocate backend into apps/api ahead of monorepo merge
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,25 @@
|
||||
/***********************************************************************************************************************************************************************
|
||||
* File Name: media.routes.js (client)
|
||||
* Type of Program: Routes
|
||||
* Author: Kenneth Obsequio (@lash0000)
|
||||
* Date Created: Jun. 12, 2026
|
||||
***********************************************************************************************************************************************************************/
|
||||
"use strict";
|
||||
|
||||
const router = require("express").Router();
|
||||
const ctrl = require("../../controllers/client/media.controller");
|
||||
const mediaGuard = require("../../middleware/mediaGuard.middleware");
|
||||
const { authenticate } = require("../../middleware/auth.middleware");
|
||||
|
||||
// ── Stream endpoint — NO mediaGuard, NO authenticate ─────────────────────────
|
||||
// The signed JWT in :token IS the only credential needed.
|
||||
// Browser media/document elements do NOT send Origin/Referer on direct requests
|
||||
// so mediaGuard would always block them.
|
||||
// Supports: video, audio, document (PDF), image
|
||||
router.get("/stream/:token", ctrl.streamAsset);
|
||||
|
||||
// ── All other routes — guarded ────────────────────────────────────────────────
|
||||
router.use(mediaGuard);
|
||||
router.post("/token", authenticate, ctrl.issueToken);
|
||||
|
||||
module.exports = router;
|
||||
Reference in New Issue
Block a user