mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-10-04 09:02:10 +00:00
56 lines
1.8 KiB
C#
56 lines
1.8 KiB
C#
using Api.SeaHavenIndustries.Options;
|
|
using Microsoft.AspNetCore.Mvc;
|
|
using Microsoft.AspNetCore.Mvc.Filters;
|
|
using Microsoft.Extensions.Options;
|
|
|
|
namespace Api.SeaHavenIndustries.Filters
|
|
{
|
|
/// <summary>Validates X-Ingest-Key for POST /api/workorders/ingest.</summary>
|
|
public class IngestApiKeyFilter : IAsyncActionFilter
|
|
{
|
|
private readonly WorkOrderIngestOptions _options;
|
|
|
|
public IngestApiKeyFilter(IOptions<WorkOrderIngestOptions> options)
|
|
{
|
|
_options = options.Value;
|
|
}
|
|
|
|
public async Task OnActionExecutionAsync(ActionExecutingContext context, ActionExecutionDelegate next)
|
|
{
|
|
if (!_options.Enabled)
|
|
{
|
|
context.Result = new ObjectResult(new { message = "Work order ingest is disabled." })
|
|
{
|
|
StatusCode = StatusCodes.Status503ServiceUnavailable
|
|
};
|
|
return;
|
|
}
|
|
|
|
if (string.IsNullOrWhiteSpace(_options.ApiKey))
|
|
{
|
|
context.Result = new ObjectResult(new { message = "Ingest API key is not configured." })
|
|
{
|
|
StatusCode = StatusCodes.Status503ServiceUnavailable
|
|
};
|
|
return;
|
|
}
|
|
|
|
if (!context.HttpContext.Request.Headers.TryGetValue("X-Ingest-Key", out var provided)
|
|
|| provided != _options.ApiKey)
|
|
{
|
|
context.Result = new UnauthorizedObjectResult(new { message = "Invalid or missing X-Ingest-Key." });
|
|
return;
|
|
}
|
|
|
|
await next();
|
|
}
|
|
}
|
|
|
|
[AttributeUsage(AttributeTargets.Class | AttributeTargets.Method)]
|
|
public sealed class IngestApiKeyAttribute : ServiceFilterAttribute
|
|
{
|
|
public IngestApiKeyAttribute() : base(typeof(IngestApiKeyFilter))
|
|
{
|
|
}
|
|
}
|
|
}
|