- update, files and the 6 /api catalog controllers now live in the engine on a new WarpEngine::ApiController base (same rescue/mime behavior as host) - engine routes serve /update, /file/*path, /api/software*, /api/builds*, /api/image/:id, /api/download at unchanged public paths via the root mount; host routes keep only TTG endpoints (events, members, wiki, rss, swagger) - /update secret comes from WarpEngine.config.update_secret and an unconfigured secret now rejects every request (previously an empty UPDATE_SECRET env accepted empty secrets) - apipie-rails is an engine dependency (DSL in engine controllers); dummy app configures apipie with validation off, mirroring the host - engine request specs: catalog controller specs moved from host plus new /update auth contract spec Verified: engine suite 53 green, host suite 6 green, /api/software and /api/builds byte-identical to baselines, /update 401/400 behavior intact, admin and TTG endpoints OK. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
18 lines
562 B
Ruby
18 lines
562 B
Ruby
module WarpEngine
|
|
class Api::ImagesController < ApiController
|
|
resource_description do
|
|
short "Images"
|
|
formats [ "binary" ]
|
|
end
|
|
|
|
api :GET, "/api/image/:id", "Get image by ID"
|
|
param :id, :number, required: true, desc: "Image ID"
|
|
returns code: 200, desc: "Image binary data"
|
|
error code: 404, desc: "Image not found"
|
|
def show
|
|
image = WarpEngine::ImageService.new.show(WarpEngine::ImageShowInputDto.new(id: params[:id]))
|
|
send_file image.file_path, type: image.content_type, disposition: "inline"
|
|
end
|
|
end
|
|
end
|