- seed_demo_data: every seeded Store.logo/cover_image and Product.image
now points at a shared placeholder MinIO object_key
(uploads/c1508b9e-c01f-4892-b24c-c1a949b5b5f5.png) instead of null, so
demo data exercises the image_url/logo_url/etc. fields end-to-end.
Note: <field>_url will 404 until that object is actually uploaded to
the bucket.
- .env.example: drop the redundant MINIO_EXTERNAL_ENDPOINT* lines —
they already default to MINIO_ENDPOINT/MINIO_USE_HTTPS, and aren't
read anywhere in this app's actual presign/read path.
- Add MEDIA_INTEGRATION.md: reference doc for the MinIO/presigned-media
work on this branch (architecture, settings, API shape, existing-data
caveats, what was verified).
Swagger inferred these SerializerMethodFields as untyped strings and
warned on generation; annotate each with @extend_schema_field so the
generated OpenAPI schema declares them as nullable URLs.
The prior commit wired MinIO as Django's default storage backend but
kept plain ImageField multipart uploads through the Django backend and
public-bucket direct URLs — not how campaign/advertising/promotions do
it. Rework to match: image fields (ProductCategory.icon, Product.image,
StoreCategory.icon, Store.logo, Store.cover_image) now store an opaque
MinIO object_key (CharField) instead of a Django-managed file.
- utils/clients/minio_client.py — raw Minio SDK client, same shape as
the other services.
- apps/core/views/media.py — POST /api/media/presign/ mints a 30-minute
presigned PUT URL + object_key; the client uploads bytes directly to
MinIO, then submits the object_key on the owning resource.
- apps/core/media.py — presigned_media_url() helper; every serializer
with an image field now also exposes a `<field>_url` computed from a
fresh 1-hour presigned GET, rather than trusting a stored/direct URL.
- FRONTEND_GUIDE.md updated to document the new upload flow and field
shapes (object_key vs `_url`), replacing the stale "no upload
endpoint yet" note.
Verified against a live local MinIO container: presign → direct PUT
upload → object_key stored on the model → serializer mints a working
presigned GET URL → URL fetches the uploaded bytes. Also exercised the
actual DRF view (POST /api/media/presign/) end-to-end, including the
401 on an unauthenticated request.
Django 6 + DRF resource server against the Gooyal accounts OAuth2 service,
matching the Winsoo ecosystem's conventions. Covers locations, stores,
catalog, cart, checkout/orders (with the multi-store-cart split and the
status stepper), reviews, and notifications, plus a demo-data seed command.
Payment integration (wallet debits, online gateway, seller payouts) is
intentionally left out here — see feature/payment.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>