mirror of
https://github.com/Sea-Haven-Industries/seahaven-ap.git
synced 2026-10-07 16:18:53 +00:00
Replace Bearer as the documented session path with Cognito hosted UI plus __Host-ap_* cookies so the SPA can call /api with credentials include.
18 lines
647 B
TypeScript
18 lines
647 B
TypeScript
import { timingSafeEqual } from "node:crypto";
|
|
import type { Context } from "hono";
|
|
|
|
export const ORIGIN_VERIFY_HEADER = "x-origin-verify";
|
|
|
|
export function originVerifyHeader(c: Context): string {
|
|
return c.req.header(ORIGIN_VERIFY_HEADER)?.trim() ?? "";
|
|
}
|
|
|
|
/** When a secret is configured, only CloudFront's origin header is accepted. */
|
|
export function cloudFrontOriginAllowed(c: Context, secret: string | undefined): boolean {
|
|
if (!secret) return true;
|
|
const provided = originVerifyHeader(c);
|
|
const a = Buffer.from(provided);
|
|
const b = Buffer.from(secret);
|
|
if (a.length !== b.length) return false;
|
|
return timingSafeEqual(a, b);
|
|
}
|