From 9cf2f7d372b3e226d9e2858ea6ed951c868c6feb Mon Sep 17 00:00:00 2001 From: Brace Sproul Date: Wed, 30 Jul 2025 17:50:29 -0700 Subject: [PATCH] chore: More logging (#620) * fix: Sync docs * chore: More logging * cr --- apps/docs/examples.mdx | 9 +++------ apps/open-swe/src/security/auth.ts | 10 +++++++++- 2 files changed, 12 insertions(+), 7 deletions(-) diff --git a/apps/docs/examples.mdx b/apps/docs/examples.mdx index f47a08ec..01ac9644 100644 --- a/apps/docs/examples.mdx +++ b/apps/docs/examples.mdx @@ -58,8 +58,7 @@ Below are a series of examples you can try out: ```txt Build a middleware that issues short-lived access tokens and long-lived refresh tokens. Store refresh tokens in a signed, HttpOnly cookie and expose `/auth/refresh` to rotate them. Protect a sample route (`/profile`) and supply - Postman collections for login and refresh flows. - ``` + Postman collections for login and refresh flows. ``` @@ -73,16 +72,14 @@ Below are a series of examples you can try out: ```txt Stand up an Apollo Server that federates data from the public JSONPlaceholder `/users` and `/posts` endpoints. Expose a `user(id)` query returning the user plus their posts in a single round-trip. Add schema-driven - TypeScript types (`codegen.yml`) and example queries in `README.md`. - ``` + TypeScript types (`codegen.yml`) and example queries in `README.md`. ``` ```txt Create an endpoint that returns a time-limited pre-signed PUT URL for an S3 bucket (use `@aws-sdk/client-s3`). Include a small React demo (Vite) that lets a user pick an image and upload it directly. Validate MIME type on - the server before signing. - ``` + the server before signing. ``` diff --git a/apps/open-swe/src/security/auth.ts b/apps/open-swe/src/security/auth.ts index 99992c06..73d452bd 100644 --- a/apps/open-swe/src/security/auth.ts +++ b/apps/open-swe/src/security/auth.ts @@ -209,10 +209,18 @@ export const auth = new Auth() } const reqCopy = request.clone(); - const reqBody = await reqCopy.text(); + let reqBody: string | Record; + try { + reqBody = (await reqCopy.json()) as Record; + } catch { + reqBody = await reqCopy.text(); + } if (!isAllowedUser(user.login)) { if (isRunReq(request.url)) { if (!apiKeysInRequestBody(reqBody)) { + logger.warn("No API keys found in run request body", { + url: request.url, + }); throw new HTTPException(401, { message: API_KEY_REQUIRED_MESSAGE, });