Server: faster releases (cache hashes), per-version skip, longer signed-URL TTL
- gate.php : ETag now derived from size+mtime instead of md5_file($zip). Previously the gate hashed the entire 14 GB ZIP on every HEAD/GET call (including each of 8 parallel segments) → 30s-5min preparation lag for clients before the first byte. Now <1ms per request. - SignManifest : disk-backed cache for SHA-256 keyed by (path,size,mtime). Re-signing 5×14 GB versions used to take ~25 min, now ~1s when nothing changed. New "Force re-hash" toggle in admin to ignore the cache. - versions.php : per-row "🔁 Hash" button to sign a single version, plus a "⚙ Hash" dropdown to toggle hashAlgorithm:none for builds where the user accepts skipping client-side verification (manifest stays signed Ed25519, only the per-ZIP SHA-256 verification is bypassed). - DownloadUrl.php : signed-URL TTL bumped 1h → 6h to cover slow ADSL users who need >1h to finish a 14 GB download. - .gitignore : track server/builds/.htaccess + gate.php (still ignore the actual ZIP/exe binaries). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -96,9 +96,14 @@ final class DownloadUrl
|
||||
}
|
||||
|
||||
// Génère l'URL HMAC-signée
|
||||
// TTL : 6 h. Compromis entre :
|
||||
// - sécurité (limite la fenêtre de replay si une URL fuit)
|
||||
// - utilisabilité (un user en ADSL 8 Mbps mettra ~4 h pour DL 14 Go)
|
||||
// Pour une connexion plus lente, le client sait auto-refresher l'URL
|
||||
// pendant le DL (cf DownloadManager → 403 retry avec nouvelle URL).
|
||||
$baseUrl = rtrim($config['base_url'], '/');
|
||||
$relPath = '/builds/proserve-' . $version . '.zip';
|
||||
$exp = time() + 3600; // 1 h
|
||||
$exp = time() + 21600; // 6 h
|
||||
$secret = $config['hmac_secret'] ?? '';
|
||||
if ($secret === '') {
|
||||
Response::error('config_error', 'hmac_secret non configuré', 500);
|
||||
|
||||
Reference in New Issue
Block a user