Vendune
src/assets/README.mdView on GitHub ↗

src/assets

This folder owns the Rust modules listed below. Each source begins with its responsibility contract. The crate currently shares internal types/imports through a facade; APIs, MCP and UCP delegate to shared domain operations.

  • download.rs: Public attachments honor sales-channel visibility; downloads require a paid, owned order snapshot.
  • image_jobs.rs: Durable image jobs: tenant admission, revision-bound private previews and explicit publication, without automatic paid retries.
  • image_provider.rs: Optional OpenAI Images adapter; bounded responses and decoded PNG output, no remote user URLs or leaked provider errors.
  • mod.rs: Product attachments and paid digital downloads: bounded binary persistence and tenant/account ACL.
  • rich.rs: Safe structured rich content, never executable HTML. Same schema for merchant API and frontend.
  • rich_document.rs: Allow-listed editor JSON with bounded depth and content; HTML/handlers/styles cannot enter the renderer.
  • upload.rs: File admission, immutable bytes and explicit publishing; binary content never enters merchant list responses.

The source inventory is checked in CI. The behavioral map identifies integration suites, and testing describes actual coverage and limits. Every file is limited to 320 lines; main.rs to 120.