unit PM.Handler.Attachments; (* Encrypted file attachments per entry. GET /entries/{id}/attachments -> [{id, filename, mime, size_bytes, created_at}, ...] POST /entries/{id}/attachments body {filename, mime, encrypted_blob, iv, size_bytes} -> {id, filename, mime, size_bytes, created_at} GET /attachments/{id} -> {id, filename, mime, size_bytes, encrypted_blob, iv} DELETE /attachments/{id} -> {message} encrypted_blob is the base64-encoded AES-GCM ciphertext of the raw file bytes, produced by the JS client with the per-user vault key. Server never sees plaintext. Per-attachment cap: ~10 MB of ciphertext-as-base64 (≈ 7.5 MB raw file). Heavier attachments aren't appropriate for SQLite TEXT storage anyway. *) interface implementation uses System.SysUtils, System.JSON, FireDAC.Comp.Client, FireDAC.Stan.Param, IdCustomHTTPServer, PM.Router, PM.JSON, PM.Database, PM.Session, PM.Audit; const MAX_ATTACHMENT_B64 = 10 * 1024 * 1024; // 10 MB of base64 text function GetClientIP(ARequest: TIdHTTPRequestInfo): string; begin Result := ARequest.RemoteIP; if Result = '' then Result := '127.0.0.1'; end; // Ownership check: returns True iff the entry exists and belongs to LUserId. function EntryBelongsToUser(LEntryId, LUserId: Integer): Boolean; var LQ: TFDQuery; begin LQ := TFDQuery.Create(nil); try LQ.Connection := DB.Connection; LQ.SQL.Text := 'SELECT 1 FROM vault_entries WHERE id = :id AND user_id = :uid'; LQ.ParamByName('id').AsInteger := LEntryId; LQ.ParamByName('uid').AsInteger := LUserId; LQ.Open; Result := not LQ.Eof; finally LQ.Free; end; end; // ===== GET /entries/{id}/attachments ========================================= procedure HandleListAttachments(ARequest: TIdHTTPRequestInfo; AResponse: TIdHTTPResponseInfo; const AParams: TArray); var LUserId, LEntryId: Integer; LQ: TFDQuery; LArr: TJSONArray; LObj: TJSONObject; begin try LUserId := Authenticate(ARequest, AResponse); except on ESessionRejected do Exit; end; LEntryId := StrToIntDef(AParams[0], 0); if LEntryId = 0 then begin TJSONHelper.SendError(AResponse, 400, 'Invalid entry id'); Exit; end; LArr := TJSONArray.Create; DB.Lock; try if not EntryBelongsToUser(LEntryId, LUserId) then begin TJSONHelper.SendError(AResponse, 404, 'Entry not found'); LArr.Free; Exit; end; LQ := TFDQuery.Create(nil); try LQ.Connection := DB.Connection; LQ.SQL.Text := 'SELECT id, filename, mime, size_bytes, created_at ' + 'FROM entry_attachments WHERE entry_id = :eid AND user_id = :uid ' + 'ORDER BY created_at DESC'; LQ.ParamByName('eid').AsInteger := LEntryId; LQ.ParamByName('uid').AsInteger := LUserId; LQ.Open; while not LQ.Eof do begin LObj := TJSONObject.Create; LObj.AddPair('id', TJSONNumber.Create(LQ.FieldByName('id').AsInteger)); LObj.AddPair('filename', LQ.FieldByName('filename').AsString); LObj.AddPair('mime', LQ.FieldByName('mime').AsString); LObj.AddPair('size_bytes', TJSONNumber.Create(LQ.FieldByName('size_bytes').AsInteger)); LObj.AddPair('created_at', FormatDateTime('yyyy-mm-dd"T"hh:nn:ss', LQ.FieldByName('created_at').AsDateTime)); LArr.Add(LObj); LQ.Next; end; finally LQ.Free; end; finally DB.Unlock; end; TJSONHelper.SendJSON(AResponse, LArr); end; // ===== POST /entries/{id}/attachments ======================================== procedure HandleCreateAttachment(ARequest: TIdHTTPRequestInfo; AResponse: TIdHTTPResponseInfo; const AParams: TArray); var LUserId, LEntryId, LNewId: Integer; LBody: TJSONObject; LFilename, LMime, LBlob, LIv: string; LSize: Integer; LQ: TFDQuery; LObj: TJSONObject; begin try LUserId := Authenticate(ARequest, AResponse); RequireCSRF(ARequest, AResponse, LUserId); except on ESessionRejected do Exit; end; LEntryId := StrToIntDef(AParams[0], 0); if LEntryId = 0 then begin TJSONHelper.SendError(AResponse, 400, 'Invalid entry id'); Exit; end; LBody := TJSONHelper.ReadBody(ARequest); try LFilename := Trim(LBody.GetValue('filename', '')); LMime := LBody.GetValue('mime', ''); LBlob := LBody.GetValue('encrypted_blob', ''); LIv := LBody.GetValue('iv', ''); LSize := LBody.GetValue('size_bytes', 0); finally LBody.Free; end; if (LFilename = '') or (LBlob = '') or (LIv = '') then begin TJSONHelper.SendError(AResponse, 400, 'Missing required fields'); Exit; end; if Length(LBlob) > MAX_ATTACHMENT_B64 then begin TJSONHelper.SendError(AResponse, 413, 'Attachment too large (max ~7.5 MB raw)'); Exit; end; DB.Lock; try if not EntryBelongsToUser(LEntryId, LUserId) then begin TJSONHelper.SendError(AResponse, 404, 'Entry not found'); Exit; end; LQ := TFDQuery.Create(nil); try LQ.Connection := DB.Connection; LQ.SQL.Text := 'INSERT INTO entry_attachments ' + '(user_id, entry_id, filename, mime, size_bytes, encrypted_blob, iv) ' + 'VALUES (:uid, :eid, :name, :mime, :sz, :blob, :iv)'; LQ.ParamByName('uid').AsInteger := LUserId; LQ.ParamByName('eid').AsInteger := LEntryId; LQ.ParamByName('name').AsString := LFilename; LQ.ParamByName('mime').AsString := LMime; LQ.ParamByName('sz').AsInteger := LSize; LQ.ParamByName('blob').AsString := LBlob; LQ.ParamByName('iv').AsString := LIv; LQ.ExecSQL; LNewId := DB.Connection.GetLastAutoGenValue('entry_attachments'); finally LQ.Free; end; finally DB.Unlock; end; LogAudit(LUserId, 'add_attachment', GetClientIP(ARequest)); LObj := TJSONObject.Create; LObj.AddPair('id', TJSONNumber.Create(LNewId)); LObj.AddPair('filename', LFilename); LObj.AddPair('mime', LMime); LObj.AddPair('size_bytes', TJSONNumber.Create(LSize)); LObj.AddPair('created_at', FormatDateTime('yyyy-mm-dd"T"hh:nn:ss', Now)); TJSONHelper.SendJSON(AResponse, LObj); end; // ===== GET /attachments/{id} ================================================= procedure HandleGetAttachment(ARequest: TIdHTTPRequestInfo; AResponse: TIdHTTPResponseInfo; const AParams: TArray); var LUserId, LId: Integer; LQ: TFDQuery; LObj: TJSONObject; begin try LUserId := Authenticate(ARequest, AResponse); except on ESessionRejected do Exit; end; LId := StrToIntDef(AParams[0], 0); if LId = 0 then begin TJSONHelper.SendError(AResponse, 400, 'Invalid id'); Exit; end; DB.Lock; try LQ := TFDQuery.Create(nil); try LQ.Connection := DB.Connection; LQ.SQL.Text := 'SELECT id, filename, mime, size_bytes, encrypted_blob, iv ' + 'FROM entry_attachments WHERE id = :id AND user_id = :uid'; LQ.ParamByName('id').AsInteger := LId; LQ.ParamByName('uid').AsInteger := LUserId; LQ.Open; if LQ.Eof then begin TJSONHelper.SendError(AResponse, 404, 'Not found'); Exit; end; LObj := TJSONObject.Create; LObj.AddPair('id', TJSONNumber.Create(LQ.FieldByName('id').AsInteger)); LObj.AddPair('filename', LQ.FieldByName('filename').AsString); LObj.AddPair('mime', LQ.FieldByName('mime').AsString); LObj.AddPair('size_bytes', TJSONNumber.Create(LQ.FieldByName('size_bytes').AsInteger)); LObj.AddPair('encrypted_blob', LQ.FieldByName('encrypted_blob').AsString); LObj.AddPair('iv', LQ.FieldByName('iv').AsString); TJSONHelper.SendJSON(AResponse, LObj); finally LQ.Free; end; finally DB.Unlock; end; end; // ===== DELETE /attachments/{id} ============================================== procedure HandleDeleteAttachment(ARequest: TIdHTTPRequestInfo; AResponse: TIdHTTPResponseInfo; const AParams: TArray); var LUserId, LId: Integer; LQ: TFDQuery; begin try LUserId := Authenticate(ARequest, AResponse); RequireCSRF(ARequest, AResponse, LUserId); except on ESessionRejected do Exit; end; LId := StrToIntDef(AParams[0], 0); if LId = 0 then begin TJSONHelper.SendError(AResponse, 400, 'Invalid id'); Exit; end; DB.Lock; try LQ := TFDQuery.Create(nil); try LQ.Connection := DB.Connection; LQ.SQL.Text := 'DELETE FROM entry_attachments WHERE id = :id AND user_id = :uid'; LQ.ParamByName('id').AsInteger := LId; LQ.ParamByName('uid').AsInteger := LUserId; LQ.ExecSQL; if LQ.RowsAffected = 0 then begin TJSONHelper.SendError(AResponse, 404, 'Not found'); Exit; end; finally LQ.Free; end; finally DB.Unlock; end; LogAudit(LUserId, 'delete_attachment', GetClientIP(ARequest)); TJSONHelper.SendOK(AResponse, 'Deleted'); end; initialization Router.Register('GET', '/entries/(\d+)/attachments', HandleListAttachments); Router.Register('POST', '/entries/(\d+)/attachments', HandleCreateAttachment); Router.Register('GET', '/attachments/(\d+)', HandleGetAttachment); Router.Register('DELETE', '/attachments/(\d+)', HandleDeleteAttachment); end.