${escape(entry.eyebrow)}
${title}
${description}
// Capability-gated client media landing pages and fresh private downloads. // // Add a release to CLIENT_MEDIA with the SHA-256 of its unguessable access // token. The raw token belongs only in the delivery message; it is never // committed or logged. Assets remain private in Spaces. A successful download // click receives a short-lived signed redirect generated at request time. import { createHash, timingSafeEqual } from "node:crypto"; import { GetObjectCommand, S3Client } from "@aws-sdk/client-s3"; import { getSignedUrl } from "@aws-sdk/s3-request-presigner"; const CLIENT_MEDIA = new Map([ ["fia/jeannette-montgomery-barron", { accessHash: "a3d63ea8a6fe63f3d3b093b46d75adfe451c0de05aa10c5891a1741e965aabb1", title: "Jeannette Montgomery Barron Archive", eyebrow: "Private archive", description: "A private copy of the Instagram archive, including posts, videos, tagged work, captions, and the follower list as it appeared when the archive was made.", version: "1.1.0", platform: "For Mac", size: "151.7 MB", filename: "Jeannette-Montgomery-Barron-Archive-1.1.0.dmg", bucket: "releases-aesthetic-computer", objectKey: "clients/fia/jeannette-montgomery-barron/Jeannette-Montgomery-Barron-Archive-1.1.0.dmg", ogImage: "https://releases.aesthetic.computer/clients/fia/jeannette-montgomery-barron/og-v1.png", }], ]); let s3; function client() { if (s3) return s3; const accessKeyId = process.env.SPACES_KEY || process.env.DO_SPACES_KEY || process.env.ART_KEY; const secretAccessKey = process.env.SPACES_SECRET || process.env.DO_SPACES_SECRET || process.env.ART_SECRET; const rawEndpoint = process.env.SPACES_ENDPOINT || process.env.ART_ENDPOINT || "sfo3.digitaloceanspaces.com"; const endpoint = rawEndpoint.startsWith("http") ? rawEndpoint : `https://${rawEndpoint}`; if (!accessKeyId || !secretAccessKey) throw new Error("client-media storage credentials unavailable"); s3 = new S3Client({ endpoint, region: "us-east-1", credentials: { accessKeyId, secretAccessKey }, requestChecksumCalculation: "WHEN_REQUIRED", responseChecksumValidation: "WHEN_REQUIRED", }); return s3; } function escape(value) { return String(value).replace(/[&<>"']/g, (character) => ({ "&": "&", "<": "<", ">": ">", '"': """, "'": "'", })[character]); } function pathParts(path = "") { const marker = "/client/"; const suffix = path.includes(marker) ? path.slice(path.indexOf(marker) + marker.length) : ""; return suffix.split("/").filter(Boolean).map(decodeURIComponent); } function authorized(token, expectedHash) { if (!token || typeof token !== "string") return false; const actual = Buffer.from(createHash("sha256").update(token).digest("hex")); const expected = Buffer.from(expectedHash); return actual.length === expected.length && timingSafeEqual(actual, expected); } function response(statusCode, body, contentType = "text/plain; charset=utf-8", headers = {}) { return { statusCode, headers: { "Content-Type": contentType, "Cache-Control": "private, no-store", "X-Robots-Tag": "noindex, nofollow, noarchive", "Referrer-Policy": "no-referrer", ...headers, }, body, }; } function landing(entry, token, event, key) { const origin = event.headers?.["x-forwarded-proto"] && event.headers?.host ? `${event.headers["x-forwarded-proto"]}://${event.headers.host}` : "https://aesthetic.computer"; const pagePath = `/client/${key}`; const pageURL = `${origin}${pagePath}?access=${encodeURIComponent(token)}`; const downloadURL = `${pagePath}/download?access=${encodeURIComponent(token)}`; const title = escape(entry.title); const description = escape(entry.description); return response(200, `
${escape(entry.eyebrow)}
${description}