diff options
| author | Christian Cleberg <[email protected]> | 2026-07-16 01:06:46 -0500 |
|---|---|---|
| committer | Christian Cleberg <[email protected]> | 2026-07-16 01:06:46 -0500 |
| commit | 871b04159aa47c0b0e62e2520c2f30e81f0f024b (patch) | |
| tree | 5dcc31ad97b094f52a59a539ae3950ae0dc2ab4c /Shared | |
| parent | d32ad837ac9eb153598c10c3cf47fbdb4e51e3ba (diff) | |
| download | hutch-871b04159aa47c0b0e62e2520c2f30e81f0f024b.tar.gz hutch-871b04159aa47c0b0e62e2520c2f30e81f0f024b.tar.bz2 hutch-871b04159aa47c0b0e62e2520c2f30e81f0f024b.zip | |
fix: download artifacts through the API instead of handing them to Safari
Tapping download opened Artifact.url in the browser, which answered with
"Authorization header is required". That URL is not a web page: git.sr.ht
resolves it to <api origin>/query/artifact/<checksum>/<filename>, which demands
a bearer token. Safari has none and no way to get one, so the download could
never have worked — this predates the upload work.
Fetch it with the client that already holds the token and hand the user the file
through a share sheet. fetchData mirrors fetchText, including its host guard, so
an authenticated request still cannot be aimed anywhere but *.sr.ht over https.
Also guards zero-byte uploads. sr.ht streams into S3, which rejects a zero-part
multipart completion with "MalformedXML: UnknownError" — an error that says
nothing about the cause and cost a round of testing to identify. Empty files are
now refused by name before the request is made.
Diffstat (limited to 'Shared')
0 files changed, 0 insertions, 0 deletions
