文件下载
通过受控 ID 选择文件,避免请求参数直接决定磁盘路径。示例支持 GET 下载和 HEAD 元数据查询。
准备文件与服务
创建 public/manual.txt,写入 Nova manual。安装 nova-http,保存以下代码为 app.mjs,执行 node app.mjs:
js
import { resolve } from "node:path";
import { createApp } from "nova-http";
import { sendFile } from "nova-http/static";
export function buildApp(root = "./public") {
const app = createApp();
const files = new Map([["manual", resolve(root, "manual.txt")]]);
const download = async (req, res) => {
const file = files.get(req.params.id);
if (!file) {
res.status(404).send("Not Found");
return;
}
res.setHeader("content-disposition", 'attachment; filename="manual.txt"');
await sendFile(req, res, file);
};
app.get("/downloads/:id", download);
app.head("/downloads/:id", download);
return app;
}
if (!process.env.NOVA_DOCS_CHECK) {
await buildApp().listen(3000, "127.0.0.1");
console.log("http://127.0.0.1:3000/downloads/manual");
}验证
sh
curl -i http://127.0.0.1:3000/downloads/manual
curl -I http://127.0.0.1:3000/downloads/manual
curl -i -H "Range: bytes=0-3" http://127.0.0.1:3000/downloads/manualGET 返回文件内容,HEAD 只返回响应头,范围请求返回 206 与 Content-Range。未知 ID 返回 404。受控映射只解决路径选择,私有文件仍需在发送前执行应用的权限校验。
更多选项与条件请求边界见文件适配器。