This is an automated email from the ASF dual-hosted git repository.
chenli pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/texera.git
The following commit(s) were added to refs/heads/main by this push:
new 31c9e4311e fix: remove /api/dataset/file endpoint (#4137)
31c9e4311e is described below
commit 31c9e4311e4e1994ede67397e3c22c0c0aae5806
Author: Seongjin Yoon <[email protected]>
AuthorDate: Sat Dec 27 22:50:07 2025 -0800
fix: remove /api/dataset/file endpoint (#4137)
<!--
Thanks for sending a pull request (PR)! Here are some tips for you:
1. If this is your first time, please read our contributor guidelines:
[Contributing to
Texera](https://github.com/apache/texera/blob/main/CONTRIBUTING.md)
2. Ensure you have added or run the appropriate tests for your PR
3. If the PR is work in progress, mark it a draft on GitHub.
4. Please write your PR title to summarize what this PR proposes, we
are following Conventional Commits style for PR titles as well.
5. Be sure to keep the PR description updated to reflect all changes.
-->
### What changes were proposed in this PR?
<!--
Please clarify what changes you are proposing. The purpose of this
section
is to outline the changes. Here are some tips for you:
1. If you propose a new API, clarify the use case for a new API.
2. If you fix a bug, you can clarify why it is a bug.
3. If it is a refactoring, clarify what has been changed.
3. It would be helpful to include a before-and-after comparison using
screenshots or GIFs.
4. Please consider writing useful notes for better and faster reviews.
-->
This PR proposes to remove the unused `retrieveDatasetSingleFile()`
endpoint (GET /api/dataset/file) which was allowing unauthenticated
downloads of non-downloadable datasets.
### Any related issues, documentation, discussions?
<!--
Please use this section to link other resources if not mentioned
already.
1. If this PR fixes an issue, please include `Fixes #1234`, `Resolves
#1234`
or `Closes #1234`. If it is only related, simply mention the issue
number.
2. If there is design documentation, please add the link.
3. If there is a discussion in the mailing list, please add the link.
-->
The endpoint is introduced in the PR #2391 which adds dataset APIs to
the webserver. Then it is modified in the PR #2719 which aims to remove
the concept of `Environment`.
### How was this PR tested?
<!--
If tests were added, say they were added here. Or simply mention that if
the PR
is tested with existing test cases. Make sure to include/update test
cases that
check the changes thoroughly including negative and positive cases if
possible.
If it was tested in a way different from regular unit tests, please
clarify how
you tested step by step, ideally copy and paste-able, so that other
reviewers can
test and check, and descendants can verify in the future. If tests were
not added,
please describe why they were not added and/or why it was difficult to
add.
-->
Manually tested:
<img width="690" height="404" alt="Screenshot 2025-12-27 at 1 15 21 AM"
src="https://github.com/user-attachments/assets/91bea787-d447-4abe-ad39-74eb581fa657"
/>
### Was this PR authored or co-authored using generative AI tooling?
<!--
If generative AI tooling has been used in the process of authoring this
PR,
please include the phrase: 'Generated-by: ' followed by the name of the
tool
and its version. If no, write 'No'.
Please refer to the [ASF Generative Tooling
Guidance](https://www.apache.org/legal/generative-tooling.html) for
details.
-->
No.
---
.../texera/service/resource/DatasetResource.scala | 46 ----------------------
1 file changed, 46 deletions(-)
diff --git
a/file-service/src/main/scala/org/apache/texera/service/resource/DatasetResource.scala
b/file-service/src/main/scala/org/apache/texera/service/resource/DatasetResource.scala
index 2a67440cf0..023c4ffc88 100644
---
a/file-service/src/main/scala/org/apache/texera/service/resource/DatasetResource.scala
+++
b/file-service/src/main/scala/org/apache/texera/service/resource/DatasetResource.scala
@@ -1156,52 +1156,6 @@ class DatasetResource {
withTransaction(context)(ctx => getDashboardDataset(ctx, did, None))
}
- @GET
- @Path("/file")
- def retrieveDatasetSingleFile(
- @QueryParam("path") pathStr: String
- ): Response = {
- val decodedPathStr = URLDecoder.decode(pathStr,
StandardCharsets.UTF_8.name())
-
- withTransaction(context)(_ => {
- val fileUri = FileResolver.resolve(decodedPathStr)
- val streamingOutput = new StreamingOutput() {
- override def write(output: OutputStream): Unit = {
- val inputStream =
DocumentFactory.openReadonlyDocument(fileUri).asInputStream()
- try {
- val buffer = new Array[Byte](8192) // buffer size
- var bytesRead = inputStream.read(buffer)
- while (bytesRead != -1) {
- output.write(buffer, 0, bytesRead)
- bytesRead = inputStream.read(buffer)
- }
- } finally {
- inputStream.close()
- }
- }
- }
-
- val contentType =
decodedPathStr.split("\\.").lastOption.map(_.toLowerCase) match {
- case Some("jpg") | Some("jpeg") => "image/jpeg"
- case Some("png") => "image/png"
- case Some("csv") => "text/csv"
- case Some("md") => "text/markdown"
- case Some("txt") => "text/plain"
- case Some("html") | Some("htm") => "text/html"
- case Some("json") => "application/json"
- case Some("pdf") => "application/pdf"
- case Some("doc") | Some("docx") => "application/msword"
- case Some("xls") | Some("xlsx") => "application/vnd.ms-excel"
- case Some("ppt") | Some("pptx") => "application/vnd.ms-powerpoint"
- case Some("mp4") => "video/mp4"
- case Some("mp3") => "audio/mpeg"
- case _ => "application/octet-stream" //
default binary format
- }
-
- Response.ok(streamingOutput).`type`(contentType).build()
- })
- }
-
/**
* This method returns all owner user names of the dataset that the user
has access to
*