From ecf34ba51aae77f1626a60795f7329f25d9344e5 Mon Sep 17 00:00:00 2001 From: Andriy Oblivantsev Date: Thu, 20 Aug 2026 10:48:38 +0100 Subject: [PATCH] fix(files): rewrite viewUrl host to API base on download resolveAPIURL now rewrites absolute viewUrl hosts to the configured portal base so downloads stay on the internal network and keep the Authorization header (a cross-host HTTP->HTTPS redirect would otherwise strip it, failing large-file reads). --- files.go | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/files.go b/files.go index 794821c..c0d0cdd 100644 --- a/files.go +++ b/files.go @@ -319,8 +319,18 @@ func (c *Client) resolveAPIURL(ref string) string { if ref == "" { return ref } - if strings.HasPrefix(ref, "http://") || strings.HasPrefix(ref, "https://") { - return ref + // Rewrite any host to the configured API base so downloads stay on the + // internal network and keep the Authorization header (no cross-host + // redirect that would strip it). Scheme-relative URLs are handled too. + if strings.HasPrefix(ref, "//") { + ref = "http:" + ref + } + if u, err := url.Parse(ref); err == nil && u.IsAbs() { + if base, err2 := url.Parse(c.baseURL()); err2 == nil { + u.Scheme = base.Scheme + u.Host = base.Host + return u.String() + } } base := c.baseURL() if strings.HasPrefix(ref, "/") {