mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-10-06 20:32:12 +00:00
parent
2f561796a5
commit
9cf2f7d372
2 changed files with 12 additions and 7 deletions
|
|
@ -58,8 +58,7 @@ Below are a series of examples you can try out:
|
||||||
```txt Build a middleware that issues short-lived access tokens and long-lived
|
```txt Build a middleware that issues short-lived access tokens and long-lived
|
||||||
refresh tokens. Store refresh tokens in a signed, HttpOnly cookie and expose
|
refresh tokens. Store refresh tokens in a signed, HttpOnly cookie and expose
|
||||||
`/auth/refresh` to rotate them. Protect a sample route (`/profile`) and supply
|
`/auth/refresh` to rotate them. Protect a sample route (`/profile`) and supply
|
||||||
Postman collections for login and refresh flows.
|
Postman collections for login and refresh flows. ```
|
||||||
```
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="Pluggable caching service">
|
<Accordion title="Pluggable caching service">
|
||||||
|
|
@ -73,16 +72,14 @@ Below are a series of examples you can try out:
|
||||||
```txt Stand up an Apollo Server that federates data from the public
|
```txt Stand up an Apollo Server that federates data from the public
|
||||||
JSONPlaceholder `/users` and `/posts` endpoints. Expose a `user(id)` query
|
JSONPlaceholder `/users` and `/posts` endpoints. Expose a `user(id)` query
|
||||||
returning the user plus their posts in a single round-trip. Add schema-driven
|
returning the user plus their posts in a single round-trip. Add schema-driven
|
||||||
TypeScript types (`codegen.yml`) and example queries in `README.md`.
|
TypeScript types (`codegen.yml`) and example queries in `README.md`. ```
|
||||||
```
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="Image upload to S3 with signed URLs">
|
<Accordion title="Image upload to S3 with signed URLs">
|
||||||
```txt Create an endpoint that returns a time-limited pre-signed PUT URL for
|
```txt Create an endpoint that returns a time-limited pre-signed PUT URL for
|
||||||
an S3 bucket (use `@aws-sdk/client-s3`). Include a small React demo (Vite)
|
an S3 bucket (use `@aws-sdk/client-s3`). Include a small React demo (Vite)
|
||||||
that lets a user pick an image and upload it directly. Validate MIME type on
|
that lets a user pick an image and upload it directly. Validate MIME type on
|
||||||
the server before signing.
|
the server before signing. ```
|
||||||
```
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="Locale-aware date utility library">
|
<Accordion title="Locale-aware date utility library">
|
||||||
|
|
|
||||||
|
|
@ -209,10 +209,18 @@ export const auth = new Auth()
|
||||||
}
|
}
|
||||||
|
|
||||||
const reqCopy = request.clone();
|
const reqCopy = request.clone();
|
||||||
const reqBody = await reqCopy.text();
|
let reqBody: string | Record<string, unknown>;
|
||||||
|
try {
|
||||||
|
reqBody = (await reqCopy.json()) as Record<string, unknown>;
|
||||||
|
} catch {
|
||||||
|
reqBody = await reqCopy.text();
|
||||||
|
}
|
||||||
if (!isAllowedUser(user.login)) {
|
if (!isAllowedUser(user.login)) {
|
||||||
if (isRunReq(request.url)) {
|
if (isRunReq(request.url)) {
|
||||||
if (!apiKeysInRequestBody(reqBody)) {
|
if (!apiKeysInRequestBody(reqBody)) {
|
||||||
|
logger.warn("No API keys found in run request body", {
|
||||||
|
url: request.url,
|
||||||
|
});
|
||||||
throw new HTTPException(401, {
|
throw new HTTPException(401, {
|
||||||
message: API_KEY_REQUIRED_MESSAGE,
|
message: API_KEY_REQUIRED_MESSAGE,
|
||||||
});
|
});
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue