mirror of
https://github.com/roleypoly/roleypoly.git
synced 2025-04-25 11:59:11 +00:00
* miniflare init * feat(api): add tests * chore: more tests, almost 100% * add sessions/state spec * add majority of routes and datapaths, start on interactions * nevermind, no interactions * nevermind x2, tweetnacl is bad but SubtleCrypto has what we need apparently * simplify interactions verify * add brute force interactions tests * every primary path API route is refactored! * automatically import from legacy, or die trying. * check that we only fetch legacy once, ever * remove old-src, same some historic pieces * remove interactions & worker-utils package, update misc/types * update some packages we don't need specific pinning for anymore * update web references to API routes since they all changed * fix all linting issues, upgrade most packages * fix tests, divorce enzyme where-ever possible * update web, fix integration issues * pre-build api * fix tests * move api pretest to api package.json instead of CI * remove interactions from terraform, fix deploy side configs * update to tf 1.1.4 * prevent double writes to worker in GCS, port to newer GCP auth workflow * fix api.tf var refs, upgrade node action * change to curl-based script upload for worker script due to terraform provider limitations * oh no, cloudflare freaked out :(
67 lines
1.5 KiB
TypeScript
67 lines
1.5 KiB
TypeScript
import { Context, RoleypolyMiddleware } from '@roleypoly/api/src/utils/context';
|
|
import { unauthorized } from '@roleypoly/api/src/utils/response';
|
|
import { SessionData } from '@roleypoly/types';
|
|
|
|
export const withSession: RoleypolyMiddleware = async (
|
|
request: Request,
|
|
context: Context
|
|
) => {
|
|
if (context.authMode.type !== 'bearer') {
|
|
return;
|
|
}
|
|
|
|
const session = await context.config.kv.sessions.get<SessionData>(
|
|
context.authMode.sessionId
|
|
);
|
|
if (!session) {
|
|
return;
|
|
}
|
|
|
|
context.session = session;
|
|
};
|
|
|
|
export const requireSession: RoleypolyMiddleware = (
|
|
request: Request,
|
|
context: Context
|
|
) => {
|
|
if (context.authMode.type !== 'bearer' || !context.session) {
|
|
return unauthorized();
|
|
}
|
|
};
|
|
|
|
export const withAuthMode: RoleypolyMiddleware = (request: Request, context: Context) => {
|
|
const auth = extractAuthentication(request);
|
|
|
|
if (auth.authType === 'Bearer') {
|
|
context.authMode = {
|
|
type: 'bearer',
|
|
sessionId: auth.token,
|
|
};
|
|
|
|
return;
|
|
}
|
|
|
|
if (auth.authType === 'Bot') {
|
|
context.authMode = {
|
|
type: 'bot',
|
|
identity: auth.token,
|
|
};
|
|
return;
|
|
}
|
|
|
|
context.authMode = {
|
|
type: 'anonymous',
|
|
};
|
|
};
|
|
|
|
export const extractAuthentication = (
|
|
request: Request
|
|
): { authType: string; token: string } => {
|
|
const authHeader = request.headers.get('authorization');
|
|
if (!authHeader) {
|
|
return { authType: 'None', token: '' };
|
|
}
|
|
|
|
const [authType, token] = authHeader.split(' ');
|
|
return { authType, token };
|
|
};
|