budibase/packages/worker/src/api/index.js

106 lines
2.0 KiB
JavaScript
Raw Normal View History

const Router = require("@koa/router")
const compress = require("koa-compress")
const zlib = require("zlib")
const { routes } = require("./routes")
2021-08-04 11:02:24 +02:00
const { buildAuthMiddleware, auditLog } = require("@budibase/auth").auth
const PUBLIC_ENDPOINTS = [
{
2021-08-04 11:02:24 +02:00
route: "/api/admin/users/init",
method: "POST",
},
{
2021-08-04 11:02:24 +02:00
route: "/api/admin/users/invite/accept",
method: "POST",
},
{
route: "/api/admin/auth",
method: "POST",
},
{
route: "/api/admin/auth/google",
method: "GET",
},
{
2021-08-04 11:02:24 +02:00
route: "/api/admin/auth/google/callback",
2021-06-27 16:46:04 +02:00
method: "GET",
},
{
2021-08-04 11:02:24 +02:00
route: "/api/admin/auth/oidc",
method: "GET",
},
{
2021-08-04 11:02:24 +02:00
route: "/api/admin/auth/oidc/callback",
method: "GET",
},
2021-05-06 12:56:53 +02:00
{
2021-08-04 11:02:24 +02:00
route: "/api/admin/auth/reset",
method: "POST",
2021-05-06 12:56:53 +02:00
},
{
2021-08-04 11:02:24 +02:00
route: "/api/admin/configs/checklist",
method: "GET",
},
{
2021-08-04 11:02:24 +02:00
route: "/api/apps",
method: "GET",
},
{
route: "/api/admin/configs/public",
method: "GET",
},
{
2021-08-04 11:02:24 +02:00
route: "/api/admin/configs/publicOidc",
method: "GET",
},
2021-04-26 16:44:28 +02:00
]
const router = new Router()
router
.use(
compress({
threshold: 2048,
gzip: {
2021-03-29 16:06:00 +02:00
flush: zlib.constants.Z_SYNC_FLUSH,
},
deflate: {
2021-03-29 16:06:00 +02:00
flush: zlib.constants.Z_SYNC_FLUSH,
},
br: false,
})
)
2021-05-04 12:32:22 +02:00
.use("/health", ctx => (ctx.status = 200))
.use(buildAuthMiddleware(PUBLIC_ENDPOINTS))
// for now no public access is allowed to worker (bar health check)
.use((ctx, next) => {
2021-08-04 11:02:24 +02:00
if (!ctx.isAuthenticated) {
2021-05-12 13:38:49 +02:00
ctx.throw(403, "Unauthorized - no public worker access")
}
return next()
})
2021-05-28 11:09:32 +02:00
.use(auditLog)
// error handling middleware
router.use(async (ctx, next) => {
try {
await next()
} catch (err) {
ctx.log.error(err)
ctx.status = err.status || err.statusCode || 500
ctx.body = {
message: err.message,
status: ctx.status,
}
}
})
2021-05-04 12:32:22 +02:00
router.get("/health", ctx => (ctx.status = 200))
// authenticated routes
for (let route of routes) {
router.use(route.routes())
router.use(route.allowedMethods())
}
module.exports = router