## Summary - Standalone Django 6 shortener: Bearer `/api/links/` (create/list/detail/disable) and public `GET /<code>` 302 - Host split, target-host allowlist, named rotatable tokens; `short_url` from `PUBLIC_SHORT_URL` - Landing page, DEBUG-only `/debug/` mint form, Django admin - Docker/compose (host **8005**), Gitea CI like monica_site (PR tests, beta on merge, prod button) - Caller contract in `API.md` Closes #1. Infra follow-up: [server-infra#22](ai_ml_operations/server-infra#22). ## Test plan - [ ] `cd site && uv run python manage.py test` - [ ] `docker compose up --build` → http://127.0.0.1:8005/ - [ ] `POST /api/links/` with `Bearer monica:dev-only-token` → 201 - [ ] `GET /<code>` → 302 to allowlisted https URL - [ ] No Bearer → 401; non-allowlisted host → 400 - [ ] `/debug/` only when `DEBUG=true` Reviewed-on: #2
32 lines
821 B
Python
32 lines
821 B
Python
"""Public redirect — no auth. SMS recipients tap GET /<code>."""
|
|
|
|
from __future__ import annotations
|
|
|
|
import re
|
|
|
|
from django.http import Http404, HttpResponseRedirect
|
|
from django.views.decorators.http import require_http_methods
|
|
|
|
from links.models import ShortLink
|
|
from links.services import record_click_best_effort
|
|
|
|
CODE_RE = re.compile(r"^[a-z0-9]{4,8}$")
|
|
|
|
|
|
@require_http_methods(["GET", "HEAD"])
|
|
def redirect_view(request, code: str):
|
|
if not CODE_RE.fullmatch(code):
|
|
raise Http404()
|
|
|
|
try:
|
|
link = ShortLink.objects.get(code=code)
|
|
except ShortLink.DoesNotExist as exc:
|
|
raise Http404() from exc
|
|
|
|
if not link.is_available():
|
|
raise Http404()
|
|
|
|
if request.method == "GET":
|
|
record_click_best_effort(request, link)
|
|
return HttpResponseRedirect(link.target_url)
|