fix(api): raise Fastify body size limit for AI menu photo uploads
Default 1 MiB limit rejected base64-encoded camera photos before the
request handler ever ran ("Request body is too large"), unrelated to
the OpenAI model. Also adds the public domains RLS policy needed for
custom-domain resolution on the public menu page (already applied
manually via SQL Editor, committing for history).
This commit is contained in:
@@ -12,7 +12,9 @@ import { qrRoutes } from "./routes/qr.js";
|
|||||||
import { restaurantsRoutes } from "./routes/restaurants.js";
|
import { restaurantsRoutes } from "./routes/restaurants.js";
|
||||||
import { subscriptionRoutes } from "./routes/subscription.js";
|
import { subscriptionRoutes } from "./routes/subscription.js";
|
||||||
|
|
||||||
const app = Fastify({ logger: true });
|
// Default Fastify bodyLimit is 1 MiB — a base64-encoded menu photo from a
|
||||||
|
// phone camera routinely exceeds that, so AI import uploads need real headroom.
|
||||||
|
const app = Fastify({ logger: true, bodyLimit: 20 * 1024 * 1024 });
|
||||||
|
|
||||||
await app.register(cors);
|
await app.register(cors);
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,16 @@
|
|||||||
|
-- Custom domain resolution needs to be readable by anon so the public web
|
||||||
|
-- app (apps/web/src/app/menu/[slug]/page.tsx) can map an arbitrary incoming
|
||||||
|
-- hostname -> restaurant without going through the API. Scoped to verified
|
||||||
|
-- domains on restaurants that actually have a published menu, matching the
|
||||||
|
-- same pattern as the restaurants/locations public policies.
|
||||||
|
|
||||||
|
create policy "anyone can resolve verified custom domains" on domains
|
||||||
|
for select using (
|
||||||
|
status = 'verified'
|
||||||
|
and exists (
|
||||||
|
select 1
|
||||||
|
from locations l
|
||||||
|
join menus m on m.location_id = l.id
|
||||||
|
where l.restaurant_id = domains.restaurant_id and m.is_published = true
|
||||||
|
)
|
||||||
|
);
|
||||||
Reference in New Issue
Block a user