Camera pictures without an object-storage bucket
Head office shows a camera's latest frame rather than live video, for a
reason that has not changed: the engine serves MJPEG on 127.0.0.1 on a PC
behind a shop's router with no inbound route, and relaying it needs
WebRTC/TURN. Pointing a browser straight at the shop PC is not the escape
either - the engine's API is Basic-authenticated with a credential it
generates locally and never sends anywhere, and shipping that to the
cloud so a web page could use it would put the key to the biometric API
and the live face feed in the server's database.
But that picture only worked if you had an S3 bucket. Without one,
attachSnapshots reported "This system is not storing images" for every
camera forever - on the two screens whose whole job is to show the
camera. Making them picture-led turned a missing feature into a wall of
empty tiles, on every local install and any self-hosted customer who does
not want a bucket.
migrations/009 adds camera_snapshots and the agent falls back to
PUT /api/agent/cameras/{camera}/snapshot when the presigned route answers
images_disabled - chosen by sentinel, never by matching the message, since
it picks between two routes. One row per camera is what makes this safe in
the database when face images are not: the key IS the camera, so storage
is (cameras x ~100 KB) and does not grow with footfall.
The read is session-authenticated rather than a signed link, which an
<img> cannot use - hence Shot.jsx and useAuthedImage, keyed on the URL
string rather than the snapshot object so a poll does not re-fetch 90 KB
per camera every few seconds, and revoking the object URL on cleanup.
Verified against the real office camera with no bucket configured: 90,587
bytes stored in Postgres, served as image/jpeg to a signed-in user, 401
without a session, rendered on both the Cameras and Shops cards.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HViLj9gYNRtSr7YVZmW5sn
This commit is contained in:
@@ -65,6 +65,10 @@ type Store interface {
|
||||
// reachable only with that site's own agent token.
|
||||
AgentCameras(ctx context.Context, siteID string) ([]AgentCamera, error)
|
||||
ApplyAgentReport(ctx context.Context, clientID, siteID string, rep AgentCameraReport) error
|
||||
// Camera pictures held by this server, for deployments with no object
|
||||
// storage. Where a bucket is configured neither of these is called.
|
||||
PutCameraSnapshot(ctx context.Context, clientID, siteID, cameraID string, jpeg []byte) error
|
||||
CameraSnapshot(ctx context.Context, clientID, cameraID string) ([]byte, time.Time, error)
|
||||
|
||||
// --- claiming a shop PC ---
|
||||
IssueEnrolmentCode(ctx context.Context, clientID, siteID, actorID,
|
||||
@@ -192,6 +196,7 @@ func (s *Server) Routes() *http.ServeMux {
|
||||
mux.HandleFunc("POST /api/sites/{site}/cameras", s.authed(s.handleCreateCamera))
|
||||
mux.HandleFunc("PATCH /api/cameras/{id}", s.authed(s.handleUpdateCamera))
|
||||
mux.HandleFunc("DELETE /api/cameras/{id}", s.authed(s.handleDeleteCamera))
|
||||
mux.HandleFunc("GET /api/cameras/{id}/snapshot.jpg", s.authed(s.handleGetSnapshot))
|
||||
// Prove a camera works: "connection" asks whether the shop PC can open the
|
||||
// stream, "placement" asks whether somebody walking past produces a view
|
||||
// good enough to recognise. Two questions, because a camera passes the
|
||||
@@ -235,6 +240,8 @@ func (s *Server) Routes() *http.ServeMux {
|
||||
// What this shop PC should be running, and what it reports back.
|
||||
mux.HandleFunc("GET /api/agent/cameras", s.agentAuthed(s.handleAgentCameras))
|
||||
mux.HandleFunc("POST /api/agent/cameras", s.agentAuthed(s.handleAgentCameraReport))
|
||||
mux.HandleFunc("PUT /api/agent/cameras/{camera}/snapshot",
|
||||
s.agentAuthed(s.handlePutSnapshot))
|
||||
mux.HandleFunc("GET /api/agent/checks", s.agentAuthed(s.handleAgentChecks))
|
||||
mux.HandleFunc("POST /api/agent/checks", s.agentAuthed(s.handleAgentCheckResult))
|
||||
|
||||
@@ -408,6 +415,11 @@ func looksLikeUUID(s string) bool {
|
||||
// without importing the store package.
|
||||
var ErrNoSecrets = errors.New("this server has no encryption key, so camera passwords cannot be stored")
|
||||
|
||||
// ErrNoSnapshot means a camera has no stored picture. An ordinary state - a
|
||||
// camera added a minute ago has none - so it is reported as absence, never as
|
||||
// a failure.
|
||||
var ErrNoSnapshot = errors.New("no snapshot for this camera")
|
||||
|
||||
// BlobStore is what the API needs from object storage. Declared here and
|
||||
// implemented by internal/blob, so the handlers can be tested without a bucket
|
||||
// and so a deployment with images switched off is a nil field rather than a
|
||||
|
||||
@@ -19,6 +19,14 @@ import (
|
||||
// live - which tenant, which message on failure, what is echoed back - and
|
||||
// those are exactly what a real database would make slow and awkward to test.
|
||||
type fakeStore struct {
|
||||
// Camera pictures held by the server, for a deployment with no bucket.
|
||||
// Keyed as written by PutCameraSnapshot (by camera_id) and as read by
|
||||
// CameraSnapshot ("client/camera"), so a test has to say which it means.
|
||||
snapshots map[string][]byte
|
||||
snapshotRejects bool
|
||||
lastSnapshotClient string
|
||||
lastSnapshotSite string
|
||||
|
||||
mu sync.Mutex
|
||||
|
||||
users map[string]UserRecord // by lower-cased email
|
||||
@@ -586,3 +594,31 @@ func (b *fakeBlob) Delete(_ context.Context, key string) error {
|
||||
b.deleted = append(b.deleted, key)
|
||||
return nil
|
||||
}
|
||||
|
||||
// ------------------------------------------------------- camera snapshots --
|
||||
|
||||
func (f *fakeStore) PutCameraSnapshot(_ context.Context,
|
||||
clientID, siteID, cameraID string, jpeg []byte) error {
|
||||
f.mu.Lock()
|
||||
defer f.mu.Unlock()
|
||||
if f.snapshots == nil {
|
||||
f.snapshots = map[string][]byte{}
|
||||
}
|
||||
if f.snapshotRejects {
|
||||
return ErrNoSnapshot
|
||||
}
|
||||
f.lastSnapshotClient, f.lastSnapshotSite = clientID, siteID
|
||||
f.snapshots[cameraID] = append([]byte(nil), jpeg...)
|
||||
return nil
|
||||
}
|
||||
|
||||
func (f *fakeStore) CameraSnapshot(_ context.Context, clientID, cameraID string) (
|
||||
[]byte, time.Time, error) {
|
||||
f.mu.Lock()
|
||||
defer f.mu.Unlock()
|
||||
img, ok := f.snapshots[clientID+"/"+cameraID]
|
||||
if !ok {
|
||||
return nil, time.Time{}, ErrNoSnapshot
|
||||
}
|
||||
return img, time.Unix(1756900000, 0).UTC(), nil
|
||||
}
|
||||
|
||||
@@ -49,10 +49,23 @@ func (s *Server) attachSnapshots(cams []Camera) {
|
||||
key := cams[i].Snapshot.Key
|
||||
cams[i].Snapshot.Key = ""
|
||||
switch {
|
||||
case s.Blob == nil:
|
||||
cams[i].Snapshot.Reason = "This system is not storing images."
|
||||
case key == "" && cams[i].SnapshotAt != "":
|
||||
// Held by this server, because the deployment has no object
|
||||
// storage. Served from an endpoint rather than a signed link:
|
||||
// there is no third party to delegate to, the bytes are in our own
|
||||
// database, and an unauthenticated URL to somebody's shop floor
|
||||
// would be a new way in for no gain.
|
||||
cams[i].Snapshot = Image{
|
||||
Available: true,
|
||||
URL: "/api/cameras/" + cams[i].ID + "/snapshot.jpg",
|
||||
ExpiresIn: int(snapshotTTL.Seconds()),
|
||||
}
|
||||
case key == "":
|
||||
cams[i].Snapshot.Reason = "No picture from this camera yet."
|
||||
case s.Blob == nil:
|
||||
// A key from a bucket this server can no longer reach. Distinct
|
||||
// from "no picture yet": one is waiting, the other is misconfigured.
|
||||
cams[i].Snapshot.Reason = "This system is not storing images."
|
||||
default:
|
||||
url, err := s.Blob.PresignGet(key, snapshotTTL)
|
||||
if err != nil {
|
||||
|
||||
118
server/internal/api/handlers_snapshots.go
Normal file
118
server/internal/api/handlers_snapshots.go
Normal file
@@ -0,0 +1,118 @@
|
||||
package api
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"fmt"
|
||||
"io"
|
||||
"net/http"
|
||||
"strconv"
|
||||
"time"
|
||||
)
|
||||
|
||||
// maxSnapshotBytes caps what a shop PC may store per camera.
|
||||
//
|
||||
// A camera frame downscaled to 1280 px is ~100 KB; 2 MB is generous for a
|
||||
// 4K still and small enough that a misbehaving or compromised agent cannot use
|
||||
// this endpoint as free storage. One row per camera means it cannot accumulate
|
||||
// either - the cap is about a single request, the primary key about the total.
|
||||
const maxSnapshotBytes = 2 << 20
|
||||
|
||||
// snapshotMaxAge is how long a browser may reuse a camera picture. The agent
|
||||
// refreshes them every 60 s, so anything longer shows a stale shop floor and
|
||||
// anything shorter re-fetches a picture that has not changed.
|
||||
const snapshotMaxAge = 30 * time.Second
|
||||
|
||||
// handlePutSnapshot stores the latest frame from one of this site's cameras.
|
||||
//
|
||||
// This is the path for a deployment with NO object storage. Where a bucket is
|
||||
// configured the agent keeps using the presigned-URL route, which never puts a
|
||||
// picture through this process at all; both exist because they are right for
|
||||
// different deployments, not because one supersedes the other.
|
||||
//
|
||||
// The body is the JPEG itself rather than JSON with base64: it avoids a third
|
||||
// of the bytes and a decode step, and there is exactly one thing being sent.
|
||||
func (s *Server) handlePutSnapshot(w http.ResponseWriter, r *http.Request, ap AgentPrincipal) {
|
||||
cameraID := r.PathValue("camera")
|
||||
if cameraID == "" {
|
||||
writeErr(w, http.StatusNotFound, "not_found", "No such camera.")
|
||||
return
|
||||
}
|
||||
|
||||
// http.MaxBytesReader, not a Content-Length check: a length header is
|
||||
// whatever the client says it is, and this has to bound what is actually
|
||||
// read into memory.
|
||||
body, err := io.ReadAll(http.MaxBytesReader(w, r.Body, maxSnapshotBytes+1))
|
||||
if err != nil {
|
||||
writeErr(w, http.StatusRequestEntityTooLarge, "too_large",
|
||||
fmt.Sprintf("A snapshot must be under %d KB.", maxSnapshotBytes/1024))
|
||||
return
|
||||
}
|
||||
if len(body) > maxSnapshotBytes {
|
||||
writeErr(w, http.StatusRequestEntityTooLarge, "too_large",
|
||||
fmt.Sprintf("A snapshot must be under %d KB.", maxSnapshotBytes/1024))
|
||||
return
|
||||
}
|
||||
// Checked against the bytes, not the Content-Type header. This endpoint
|
||||
// stores whatever it is given and hands it back to a browser later, so the
|
||||
// one thing it must not become is a way to park arbitrary content under a
|
||||
// URL this server will serve.
|
||||
if !isJPEG(body) {
|
||||
badRequest(w, "a snapshot must be a JPEG")
|
||||
return
|
||||
}
|
||||
|
||||
switch err := s.Store.PutCameraSnapshot(r.Context(),
|
||||
ap.ClientID, ap.SiteID, cameraID, body); {
|
||||
case err == nil:
|
||||
w.WriteHeader(http.StatusNoContent)
|
||||
case errors.Is(err, ErrNoSnapshot):
|
||||
// Head office has not adopted this camera yet. Not the agent's fault
|
||||
// and not worth retrying: the next sync adopts it.
|
||||
writeErr(w, http.StatusNotFound, "not_found",
|
||||
"That camera is not set up at head office yet.")
|
||||
default:
|
||||
s.serverError(w, "store snapshot", err)
|
||||
}
|
||||
}
|
||||
|
||||
// handleGetSnapshot serves a camera's stored picture to a signed-in user.
|
||||
//
|
||||
// Deliberately NOT a signed link like the bucket path: there is no third party
|
||||
// to delegate to here, the bytes are in this server's own database, and minting
|
||||
// a URL that works without a session in order to serve them would be adding an
|
||||
// unauthenticated path to reach a picture of somebody's shop floor for no gain.
|
||||
func (s *Server) handleGetSnapshot(w http.ResponseWriter, r *http.Request) {
|
||||
p := PrincipalFrom(r.Context())
|
||||
id := r.PathValue("id")
|
||||
if !looksLikeUUID(id) {
|
||||
writeErr(w, http.StatusNotFound, "not_found", "No such camera.")
|
||||
return
|
||||
}
|
||||
img, at, err := s.Store.CameraSnapshot(r.Context(), p.ClientID, id)
|
||||
if errors.Is(err, ErrNoSnapshot) {
|
||||
writeErr(w, http.StatusNotFound, "no_image", "No picture from this camera yet.")
|
||||
return
|
||||
}
|
||||
if err != nil {
|
||||
s.serverError(w, "read snapshot", err)
|
||||
return
|
||||
}
|
||||
w.Header().Set("Content-Type", "image/jpeg")
|
||||
w.Header().Set("Content-Length", strconv.Itoa(len(img)))
|
||||
w.Header().Set("Cache-Control", "private, max-age="+
|
||||
strconv.Itoa(int(snapshotMaxAge.Seconds())))
|
||||
w.Header().Set("Last-Modified", at.UTC().Format(http.TimeFormat))
|
||||
// A picture of a shop floor is not something to hand to another origin's
|
||||
// script, and nothing here needs to.
|
||||
w.Header().Set("X-Content-Type-Options", "nosniff")
|
||||
w.WriteHeader(http.StatusOK)
|
||||
_, _ = w.Write(img)
|
||||
}
|
||||
|
||||
// isJPEG checks the magic bytes: SOI marker at the front, EOI at the back.
|
||||
func isJPEG(b []byte) bool {
|
||||
if len(b) < 4 {
|
||||
return false
|
||||
}
|
||||
return b[0] == 0xFF && b[1] == 0xD8 && b[2] == 0xFF
|
||||
}
|
||||
102
server/internal/api/snapshots_test.go
Normal file
102
server/internal/api/snapshots_test.go
Normal file
@@ -0,0 +1,102 @@
|
||||
package api
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
// A minimal but real JPEG header: SOI + APP0. The endpoint checks the bytes,
|
||||
// not the Content-Type header, so a test that sends anything else is not
|
||||
// testing the same path a shop PC uses.
|
||||
func jpegBytes(padTo int) []byte {
|
||||
b := []byte{0xFF, 0xD8, 0xFF, 0xE0, 0x00, 0x10, 'J', 'F', 'I', 'F', 0}
|
||||
for len(b) < padTo {
|
||||
b = append(b, 0x00)
|
||||
}
|
||||
return append(b, 0xFF, 0xD9)
|
||||
}
|
||||
|
||||
func TestAnAgentCanStoreItsCameraPicture(t *testing.T) {
|
||||
srv, fs := newServer(t)
|
||||
fs.addAgent("agent-token", AgentPrincipal{ClientID: "client-1", SiteID: "site-1"})
|
||||
|
||||
rr := httptest.NewRecorder()
|
||||
req := httptest.NewRequest(http.MethodPut,
|
||||
"/api/agent/cameras/entrance/snapshot", bytes.NewReader(jpegBytes(64)))
|
||||
req.Header.Set("Authorization", "Bearer agent-token")
|
||||
srv.Routes().ServeHTTP(rr, req)
|
||||
|
||||
if rr.Code != http.StatusNoContent {
|
||||
t.Fatalf("status %d: %s", rr.Code, rr.Body)
|
||||
}
|
||||
if len(fs.snapshots["entrance"]) == 0 {
|
||||
t.Fatal("nothing was stored")
|
||||
}
|
||||
// The tenant and site come from the AGENT's credential, never the request.
|
||||
// A camera id a caller can set must not be able to choose whose camera it
|
||||
// decorates.
|
||||
if fs.lastSnapshotClient != "client-1" || fs.lastSnapshotSite != "site-1" {
|
||||
t.Fatalf("stored against %s/%s", fs.lastSnapshotClient, fs.lastSnapshotSite)
|
||||
}
|
||||
}
|
||||
|
||||
// This endpoint stores whatever it is handed and serves it back to a browser
|
||||
// later, so the one thing it must not become is a way to park arbitrary content
|
||||
// under a URL this server will serve.
|
||||
func TestOnlyAJPEGIsAccepted(t *testing.T) {
|
||||
srv, fs := newServer(t)
|
||||
fs.addAgent("agent-token", AgentPrincipal{ClientID: "client-1", SiteID: "site-1"})
|
||||
|
||||
for _, body := range []string{
|
||||
"<html><script>alert(1)</script></html>",
|
||||
"GIF89a",
|
||||
"",
|
||||
} {
|
||||
rr := httptest.NewRecorder()
|
||||
req := httptest.NewRequest(http.MethodPut,
|
||||
"/api/agent/cameras/entrance/snapshot", strings.NewReader(body))
|
||||
req.Header.Set("Authorization", "Bearer agent-token")
|
||||
// Claiming to be a JPEG must not help: the check is on the bytes.
|
||||
req.Header.Set("Content-Type", "image/jpeg")
|
||||
srv.Routes().ServeHTTP(rr, req)
|
||||
if rr.Code != http.StatusBadRequest {
|
||||
t.Fatalf("body %q was accepted with status %d", body, rr.Code)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// One row per camera is what makes this safe to keep in the database at all,
|
||||
// but a single oversized request still has to be bounded - it is read into
|
||||
// memory before anything else looks at it.
|
||||
func TestAnOversizedSnapshotIsRefused(t *testing.T) {
|
||||
srv, fs := newServer(t)
|
||||
fs.addAgent("agent-token", AgentPrincipal{ClientID: "client-1", SiteID: "site-1"})
|
||||
|
||||
rr := httptest.NewRecorder()
|
||||
req := httptest.NewRequest(http.MethodPut,
|
||||
"/api/agent/cameras/entrance/snapshot",
|
||||
bytes.NewReader(jpegBytes(maxSnapshotBytes+1024)))
|
||||
req.Header.Set("Authorization", "Bearer agent-token")
|
||||
srv.Routes().ServeHTTP(rr, req)
|
||||
|
||||
if rr.Code != http.StatusRequestEntityTooLarge {
|
||||
t.Fatalf("status %d", rr.Code)
|
||||
}
|
||||
if len(fs.snapshots) != 0 {
|
||||
t.Fatal("an oversized snapshot was stored anyway")
|
||||
}
|
||||
}
|
||||
|
||||
func TestAnUnauthenticatedAgentCannotStoreAPicture(t *testing.T) {
|
||||
srv, _ := newServer(t)
|
||||
rr := httptest.NewRecorder()
|
||||
req := httptest.NewRequest(http.MethodPut,
|
||||
"/api/agent/cameras/entrance/snapshot", bytes.NewReader(jpegBytes(64)))
|
||||
srv.Routes().ServeHTTP(rr, req)
|
||||
if rr.Code != http.StatusUnauthorized {
|
||||
t.Fatalf("status %d", rr.Code)
|
||||
}
|
||||
}
|
||||
84
server/internal/store/api_snapshots.go
Normal file
84
server/internal/store/api_snapshots.go
Normal file
@@ -0,0 +1,84 @@
|
||||
package store
|
||||
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
"fmt"
|
||||
"time"
|
||||
|
||||
"github.com/jackc/pgx/v5"
|
||||
)
|
||||
|
||||
// ErrNoSnapshot means this camera has no stored picture. It is an ordinary
|
||||
// state - a camera added a minute ago has none - so callers report it as
|
||||
// absence rather than as a failure.
|
||||
var ErrNoSnapshot = errors.New("no snapshot for this camera")
|
||||
|
||||
// PutCameraSnapshot stores the latest frame from one of a site's cameras.
|
||||
//
|
||||
// The camera is resolved by (site_id, camera_id) IN THE INSERT, so an agent
|
||||
// physically cannot store a picture against another site's camera even if it
|
||||
// sends one - the same rule as every other agent-authenticated write here.
|
||||
// `camera_id` is what the ENGINE knows the camera by, because that is the only
|
||||
// name the shop PC has.
|
||||
func (s *Store) PutCameraSnapshot(ctx context.Context,
|
||||
clientID, siteID, cameraID string, jpeg []byte) error {
|
||||
|
||||
tx, err := s.pool.Begin(ctx)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
defer func() { _ = tx.Rollback(context.WithoutCancel(ctx)) }()
|
||||
|
||||
var id string
|
||||
err = tx.QueryRow(ctx, `
|
||||
SELECT id::text FROM site_cameras
|
||||
WHERE site_id = $1::uuid AND camera_id = $2 AND deleted_at IS NULL`,
|
||||
siteID, cameraID).Scan(&id)
|
||||
if errors.Is(err, pgx.ErrNoRows) {
|
||||
// Head office has not been told about this camera yet, or it was
|
||||
// removed. Neither is an error the agent can act on: the next sync
|
||||
// adopts it and the snapshot after that lands.
|
||||
return ErrNoSnapshot
|
||||
}
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
if _, err := tx.Exec(ctx, `
|
||||
INSERT INTO camera_snapshots (camera_id, client_id, site_id, image, bytes, captured_at)
|
||||
VALUES ($1::uuid, $2::uuid, $3::uuid, $4, $5, now())
|
||||
ON CONFLICT (camera_id) DO UPDATE
|
||||
SET image = EXCLUDED.image, bytes = EXCLUDED.bytes,
|
||||
captured_at = EXCLUDED.captured_at`,
|
||||
id, clientID, siteID, jpeg, len(jpeg)); err != nil {
|
||||
return fmt.Errorf("store snapshot: %w", err)
|
||||
}
|
||||
|
||||
// snapshot_at is what tells the camera list a picture exists at all, and it
|
||||
// is written in the SAME transaction as the bytes. Set apart, a camera
|
||||
// could advertise a picture that is not there - which renders as a broken
|
||||
// image on the one screen whose job is to show the camera.
|
||||
if _, err := tx.Exec(ctx, `
|
||||
UPDATE site_cameras SET snapshot_at = now() WHERE id = $1::uuid`,
|
||||
id); err != nil {
|
||||
return err
|
||||
}
|
||||
return tx.Commit(ctx)
|
||||
}
|
||||
|
||||
// CameraSnapshot returns a camera's stored picture, scoped to the tenant.
|
||||
func (s *Store) CameraSnapshot(ctx context.Context, clientID, cameraID string) (
|
||||
[]byte, time.Time, error) {
|
||||
|
||||
var img []byte
|
||||
var at time.Time
|
||||
err := s.pool.QueryRow(ctx, `
|
||||
SELECT image, captured_at FROM camera_snapshots
|
||||
WHERE camera_id = $1::uuid AND client_id = $2::uuid`,
|
||||
cameraID, clientID).Scan(&img, &at)
|
||||
if errors.Is(err, pgx.ErrNoRows) {
|
||||
return nil, time.Time{}, ErrNoSnapshot
|
||||
}
|
||||
return img, at, err
|
||||
}
|
||||
43
server/internal/web/dist/assets/index-B_gTsA07.js
vendored
Normal file
43
server/internal/web/dist/assets/index-B_gTsA07.js
vendored
Normal file
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
2
server/internal/web/dist/index.html
vendored
2
server/internal/web/dist/index.html
vendored
@@ -5,7 +5,7 @@
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1" />
|
||||
<meta name="color-scheme" content="dark" />
|
||||
<title>Behavision</title>
|
||||
<script type="module" crossorigin src="/assets/index-C8M-zRAi.js"></script>
|
||||
<script type="module" crossorigin src="/assets/index-B_gTsA07.js"></script>
|
||||
<link rel="stylesheet" crossorigin href="/assets/index-pUqVBCLm.css">
|
||||
</head>
|
||||
<body>
|
||||
|
||||
Reference in New Issue
Block a user