fix(files): rewrite viewUrl host to API base on download

resolveAPIURL now rewrites absolute viewUrl hosts to the configured portal
base so downloads stay on the internal network and keep the Authorization
header (a cross-host HTTP->HTTPS redirect would otherwise strip it, failing
large-file reads).
This commit is contained in:
2026-08-20 10:48:38 +01:00
parent ebbd5d5373
commit ecf34ba51a
+12 -2
View File
@@ -319,8 +319,18 @@ func (c *Client) resolveAPIURL(ref string) string {
if ref == "" { if ref == "" {
return ref return ref
} }
if strings.HasPrefix(ref, "http://") || strings.HasPrefix(ref, "https://") { // Rewrite any host to the configured API base so downloads stay on the
return ref // internal network and keep the Authorization header (no cross-host
// redirect that would strip it). Scheme-relative URLs are handled too.
if strings.HasPrefix(ref, "//") {
ref = "http:" + ref
}
if u, err := url.Parse(ref); err == nil && u.IsAbs() {
if base, err2 := url.Parse(c.baseURL()); err2 == nil {
u.Scheme = base.Scheme
u.Host = base.Host
return u.String()
}
} }
base := c.baseURL() base := c.baseURL()
if strings.HasPrefix(ref, "/") { if strings.HasPrefix(ref, "/") {