Expand ecash explorer capabilities

Add Fedimint discovery, dual SQLite/Postgres storage, richer review handling, and generated social imagery.
This commit is contained in:
michilis
2026-08-21 02:10:48 +02:00
parent aa1771ea20
commit 6f17b572b1
80 changed files with 7580 additions and 704 deletions
+57 -15
View File
@@ -1,6 +1,8 @@
import fs from 'node:fs/promises';
import path from 'node:path';
import { isFetchableUrl } from '@cashumints/shared';
import { config } from './config.ts';
import { readBodyBounded } from './http.ts';
import { log } from './log.ts';
import type { MintRow } from './mints.ts';
@@ -8,13 +10,54 @@ const EXT_BY_TYPE: Record<string, string> = {
'image/png': '.png',
'image/jpeg': '.jpg',
'image/webp': '.webp',
'image/svg+xml': '.svg',
'image/gif': '.gif',
'image/x-icon': '.ico',
'image/vnd.microsoft.icon': '.ico',
// No SVG on purpose: SVG is markup that can carry script, and these files are
// re-served from the site's own origin, so a cached one opened directly would run a
// mint operator's script there. The sandbox header in server.ts covers files cached
// before this rule existed.
};
const MAX_ICON_BYTES = 512 * 1024;
/** Redirect hops followed, each hop re-checked before it is fetched. */
const MAX_REDIRECTS = 3;
/**
* Fetch an icon with redirects validated hop by hop.
*
* `icon_url` is whatever the mint's /v1/info says it is, so every address on the way —
* the first one and each Location after it — has to pass `isFetchableUrl`, or a public
* URL that 302s to a metadata endpoint walks straight around a check done only once.
*/
async function fetchIconResponse(startUrl: string, signal: AbortSignal): Promise<Response | null> {
let target = startUrl;
for (let hop = 0; hop <= MAX_REDIRECTS; hop++) {
if (!isFetchableUrl(target)) return null;
const res = await fetch(target, {
signal,
redirect: 'manual',
headers: { 'User-Agent': config.userAgent },
});
if (res.status >= 300 && res.status < 400) {
const location = res.headers.get('location');
if (!location) return null;
try {
target = new URL(location, target).toString();
} catch {
return null;
}
continue;
}
return res.ok ? res : null;
}
return null;
}
/**
* Cache a mint's icon to disk so offline mints keep theirs.
@@ -30,27 +73,26 @@ export async function cacheIcon(row: MintRow, iconUrl: string | null): Promise<s
try {
const absolute = new URL(iconUrl, `${row.url}/`).toString();
if (!absolute.startsWith('https://') && !absolute.startsWith('http://')) return row.icon_file;
const controller = new AbortController();
const timer = setTimeout(() => controller.abort(), config.probeTimeoutMs);
let res: Response;
let buf: Buffer | null = null;
let ext: string | undefined;
try {
res = await fetch(absolute, {
signal: controller.signal,
headers: { 'User-Agent': config.userAgent },
});
const res = await fetchIconResponse(absolute, controller.signal);
if (!res) return row.icon_file;
const type = (res.headers.get('content-type') ?? '').split(';')[0]?.trim() ?? '';
ext = EXT_BY_TYPE[type];
if (!ext) return row.icon_file;
// The timer stays armed through the body read: the abort is what stops a server
// that sends its headers quickly and then never finishes the body.
buf = await readBodyBounded(res, MAX_ICON_BYTES);
} finally {
clearTimeout(timer);
}
if (!res.ok) return row.icon_file;
const type = (res.headers.get('content-type') ?? '').split(';')[0]?.trim() ?? '';
const ext = EXT_BY_TYPE[type];
if (!ext) return row.icon_file;
const buf = Buffer.from(await res.arrayBuffer());
if (buf.byteLength === 0 || buf.byteLength > MAX_ICON_BYTES) return row.icon_file;
if (!buf || buf.byteLength === 0) return row.icon_file;
const filename = `${row.host}${ext}`;
await fs.writeFile(path.join(config.iconDir, filename), buf);