mirror of
https://github.com/zkldi/Tachi.git
synced 2026-10-01 03:18:06 +03:00
50 lines
1.4 KiB
TypeScript
50 lines
1.4 KiB
TypeScript
import { BotConfig } from "../config";
|
|
import { LoggerLayers } from "../data/data";
|
|
import { CreateLayeredLogger } from "../utils/logger";
|
|
import type { RequestHandler } from "express";
|
|
|
|
const logger = CreateLayeredLogger(LoggerLayers.serverAuth);
|
|
|
|
/**
|
|
* Middleware that checks that a webhook request has Authorization set to
|
|
* exactly "Bearer $CLIENT_SECRET".
|
|
*
|
|
* This is to prevent things like users spoofing webhook events.
|
|
* $CLIENT_SECRET is part of the registered tachi OAuth2 client.
|
|
*/
|
|
export const ValidateWebhookRequest: RequestHandler = (req, res, next) => {
|
|
const auth = req.header("Authorization");
|
|
|
|
if (!auth) {
|
|
logger.info(`Received unauthed request from ${req.ip}.`);
|
|
return res.status(401).json({
|
|
success: false,
|
|
description: "No authorization provided.",
|
|
});
|
|
}
|
|
|
|
const [type, value] = auth.split(" ", 2);
|
|
|
|
if (type !== "Bearer") {
|
|
logger.info(`Received invalid auth type request from ${req.ip}, got auth type ${type}.`);
|
|
return res.status(400).json({
|
|
success: false,
|
|
description: "Invalid authorization type. Expected Bearer.",
|
|
});
|
|
}
|
|
|
|
if (value !== BotConfig.OAUTH.CLIENT_SECRET) {
|
|
logger.warn(
|
|
`Recieved invalid auth value from ${req.ip}. Has the client secret been changed?`
|
|
);
|
|
return res.status(403).json({
|
|
success: false,
|
|
description: "Unauthorised.",
|
|
});
|
|
}
|
|
|
|
logger.debug("Webhook authorisation successful.");
|
|
|
|
next();
|
|
};
|