mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 19:43:15 +00:00
parent
2f561796a5
commit
9cf2f7d372
2 changed files with 12 additions and 7 deletions
|
|
@ -58,8 +58,7 @@ Below are a series of examples you can try out:
|
|||
```txt Build a middleware that issues short-lived access tokens and long-lived
|
||||
refresh tokens. Store refresh tokens in a signed, HttpOnly cookie and expose
|
||||
`/auth/refresh` to rotate them. Protect a sample route (`/profile`) and supply
|
||||
Postman collections for login and refresh flows.
|
||||
```
|
||||
Postman collections for login and refresh flows. ```
|
||||
</Accordion>
|
||||
|
||||
<Accordion title="Pluggable caching service">
|
||||
|
|
@ -73,16 +72,14 @@ Below are a series of examples you can try out:
|
|||
```txt Stand up an Apollo Server that federates data from the public
|
||||
JSONPlaceholder `/users` and `/posts` endpoints. Expose a `user(id)` query
|
||||
returning the user plus their posts in a single round-trip. Add schema-driven
|
||||
TypeScript types (`codegen.yml`) and example queries in `README.md`.
|
||||
```
|
||||
TypeScript types (`codegen.yml`) and example queries in `README.md`. ```
|
||||
</Accordion>
|
||||
|
||||
<Accordion title="Image upload to S3 with signed URLs">
|
||||
```txt Create an endpoint that returns a time-limited pre-signed PUT URL for
|
||||
an S3 bucket (use `@aws-sdk/client-s3`). Include a small React demo (Vite)
|
||||
that lets a user pick an image and upload it directly. Validate MIME type on
|
||||
the server before signing.
|
||||
```
|
||||
the server before signing. ```
|
||||
</Accordion>
|
||||
|
||||
<Accordion title="Locale-aware date utility library">
|
||||
|
|
|
|||
|
|
@ -209,10 +209,18 @@ export const auth = new Auth()
|
|||
}
|
||||
|
||||
const reqCopy = request.clone();
|
||||
const reqBody = await reqCopy.text();
|
||||
let reqBody: string | Record<string, unknown>;
|
||||
try {
|
||||
reqBody = (await reqCopy.json()) as Record<string, unknown>;
|
||||
} catch {
|
||||
reqBody = await reqCopy.text();
|
||||
}
|
||||
if (!isAllowedUser(user.login)) {
|
||||
if (isRunReq(request.url)) {
|
||||
if (!apiKeysInRequestBody(reqBody)) {
|
||||
logger.warn("No API keys found in run request body", {
|
||||
url: request.url,
|
||||
});
|
||||
throw new HTTPException(401, {
|
||||
message: API_KEY_REQUIRED_MESSAGE,
|
||||
});
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue