- seed_demo_data: every seeded Store.logo/cover_image and Product.image
now points at a shared placeholder MinIO object_key
(uploads/c1508b9e-c01f-4892-b24c-c1a949b5b5f5.png) instead of null, so
demo data exercises the image_url/logo_url/etc. fields end-to-end.
Note: <field>_url will 404 until that object is actually uploaded to
the bucket.
- .env.example: drop the redundant MINIO_EXTERNAL_ENDPOINT* lines —
they already default to MINIO_ENDPOINT/MINIO_USE_HTTPS, and aren't
read anywhere in this app's actual presign/read path.
- Add MEDIA_INTEGRATION.md: reference doc for the MinIO/presigned-media
work on this branch (architecture, settings, API shape, existing-data
caveats, what was verified).
The prior commit wired MinIO as Django's default storage backend but
kept plain ImageField multipart uploads through the Django backend and
public-bucket direct URLs — not how campaign/advertising/promotions do
it. Rework to match: image fields (ProductCategory.icon, Product.image,
StoreCategory.icon, Store.logo, Store.cover_image) now store an opaque
MinIO object_key (CharField) instead of a Django-managed file.
- utils/clients/minio_client.py — raw Minio SDK client, same shape as
the other services.
- apps/core/views/media.py — POST /api/media/presign/ mints a 30-minute
presigned PUT URL + object_key; the client uploads bytes directly to
MinIO, then submits the object_key on the owning resource.
- apps/core/media.py — presigned_media_url() helper; every serializer
with an image field now also exposes a `<field>_url` computed from a
fresh 1-hour presigned GET, rather than trusting a stored/direct URL.
- FRONTEND_GUIDE.md updated to document the new upload flow and field
shapes (object_key vs `_url`), replacing the stale "no upload
endpoint yet" note.
Verified against a live local MinIO container: presign → direct PUT
upload → object_key stored on the model → serializer mints a working
presigned GET URL → URL fetches the uploaded bytes. Also exercised the
actual DRF view (POST /api/media/presign/) end-to-end, including the
401 on an unauthenticated request.
Django 6 + DRF resource server against the Gooyal accounts OAuth2 service,
matching the Winsoo ecosystem's conventions. Covers locations, stores,
catalog, cart, checkout/orders (with the multi-store-cart split and the
status stepper), reviews, and notifications, plus a demo-data seed command.
Payment integration (wallet debits, online gateway, seller payouts) is
intentionally left out here — see feature/payment.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>