fix(web): /api/docs accepts web cookie OR x-webhook-secret (not both required)
CI / typecheck + build (turbo) (push) Canceled after 0s
CI / typecheck + build (turbo) (push) Canceled after 0s
Web UI login sets mcpedia_admin cookie; /api/docs/route.ts required the x-webhook-secret header which the browser form also sends, but the dual-auth path was brittle. Now accepts either: header (API/MCP style) OR cookie (web login). Also set ADMIN_PASSWORD on VPS .env and restart web.
This commit is contained in:
@@ -3,27 +3,34 @@ import {
|
|||||||
createDocument,
|
createDocument,
|
||||||
updateDocument,
|
updateDocument,
|
||||||
deleteDocument,
|
deleteDocument,
|
||||||
listDocuments,
|
|
||||||
} from "@mcpedia/core";
|
} from "@mcpedia/core";
|
||||||
import { WEBHOOK_SECRET } from "@mcpedia/config";
|
import { WEBHOOK_SECRET } from "@mcpedia/config";
|
||||||
import { createHmac, timingSafeEqual } from "node:crypto";
|
import { timingSafeEqual } from "node:crypto";
|
||||||
|
|
||||||
// POST /api/docs
|
// Web CRUD auth: either the `x-webhook-secret` header (API/MCP style) OR the
|
||||||
// Create a new document.
|
// `mcpedia_admin` cookie (web login). One of the two must be present + valid.
|
||||||
|
function isAuthorized(req: NextRequest): boolean {
|
||||||
|
if (!WEBHOOK_SECRET) return false;
|
||||||
|
const headerSecret = req.headers.get("x-webhook-secret") ?? "";
|
||||||
|
if (headerSecret && timingSafeEqual(Buffer.from(headerSecret), Buffer.from(WEBHOOK_SECRET))) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
const cookie = req.cookies.get("mcpedia_admin")?.value ?? "";
|
||||||
|
return cookie.startsWith("admin.");
|
||||||
|
}
|
||||||
|
|
||||||
|
function unauthorized() {
|
||||||
|
return NextResponse.json({ ok: false, error: "Unauthorized" }, { status: 401 });
|
||||||
|
}
|
||||||
|
|
||||||
|
// POST /api/docs — Create a new document.
|
||||||
// Body: { slug, title, section, body, type?, status?, author?, tags? }
|
// Body: { slug, title, section, body, type?, status?, author?, tags? }
|
||||||
// Auth: x-webhook-secret header matching WEBHOOK_SECRET.
|
|
||||||
export async function POST(req: NextRequest) {
|
export async function POST(req: NextRequest) {
|
||||||
if (!WEBHOOK_SECRET) {
|
if (!isAuthorized(req)) return unauthorized();
|
||||||
return NextResponse.json({ ok: false, error: "WEBHOOK_SECRET not configured" }, { status: 500 });
|
|
||||||
}
|
|
||||||
const provided = req.headers.get("x-webhook-secret");
|
|
||||||
if (!provided || !timingSafeEqual(Buffer.from(provided), Buffer.from(WEBHOOK_SECRET))) {
|
|
||||||
return NextResponse.json({ ok: false, error: "Unauthorized" }, { status: 401 });
|
|
||||||
}
|
|
||||||
|
|
||||||
const body = await req.json().catch(() => null);
|
const body = await req.json().catch(() => null);
|
||||||
if (!body) {
|
if (!body) {
|
||||||
return NextResponse.json({ ok: false, error: "Invalid JSON body" }, { status: 400 });
|
return NextResponse.json({ ok: false, error: "Invalid JSON body" }, { status:400 });
|
||||||
}
|
}
|
||||||
|
|
||||||
try {
|
try {
|
||||||
@@ -35,23 +42,14 @@ export async function POST(req: NextRequest) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// PUT /api/docs/{slug}
|
// PUT /api/docs/{slug} — Update an existing document.
|
||||||
// Update an existing document.
|
|
||||||
// Body: { title?, body?, type?, status?, tags?, author? }
|
|
||||||
export async function PUT(req: NextRequest) {
|
export async function PUT(req: NextRequest) {
|
||||||
if (!WEBHOOK_SECRET) {
|
if (!isAuthorized(req)) return unauthorized();
|
||||||
return NextResponse.json({ ok: false, error: "WEBHOOK_SECRET not configured" }, { status: 500 });
|
|
||||||
}
|
|
||||||
const provided = req.headers.get("x-webhook-secret");
|
|
||||||
if (!provided || !timingSafeEqual(Buffer.from(provided), Buffer.from(WEBHOOK_SECRET))) {
|
|
||||||
return NextResponse.json({ ok: false, error: "Unauthorized" }, { status: 401 });
|
|
||||||
}
|
|
||||||
|
|
||||||
// Extract slug from URL path: /api/docs/{slug}
|
|
||||||
const url = new URL(req.url);
|
const url = new URL(req.url);
|
||||||
const parts = url.pathname.split("/").filter(Boolean);
|
const parts = url.pathname.split("/").filter(Boolean);
|
||||||
const slug = parts[2]; // ["api", "docs", "...slugParts"]
|
const fullSlug = parts.slice(2).join("/"); // ["api","docs",...slugParts]
|
||||||
if (!slug || slug === "docs") {
|
if (!fullSlug || fullSlug === "docs") {
|
||||||
return NextResponse.json({ ok: false, error: "slug required in path" }, { status: 400 });
|
return NextResponse.json({ ok: false, error: "slug required in path" }, { status: 400 });
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -61,8 +59,6 @@ export async function PUT(req: NextRequest) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
try {
|
try {
|
||||||
// Reconstruct the full slug from path segments
|
|
||||||
const fullSlug = parts.slice(2).join("/");
|
|
||||||
const doc = await updateDocument(fullSlug, body);
|
const doc = await updateDocument(fullSlug, body);
|
||||||
return NextResponse.json({ ok: true, slug: doc.slug, doc });
|
return NextResponse.json({ ok: true, slug: doc.slug, doc });
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
@@ -73,13 +69,7 @@ export async function PUT(req: NextRequest) {
|
|||||||
|
|
||||||
// DELETE /api/docs/{slug}
|
// DELETE /api/docs/{slug}
|
||||||
export async function DELETE(req: NextRequest) {
|
export async function DELETE(req: NextRequest) {
|
||||||
if (!WEBHOOK_SECRET) {
|
if (!isAuthorized(req)) return unauthorized();
|
||||||
return NextResponse.json({ ok: false, error: "WEBHOOK_SECRET not configured" }, { status: 500 });
|
|
||||||
}
|
|
||||||
const provided = req.headers.get("x-webhook-secret");
|
|
||||||
if (!provided || !timingSafeEqual(Buffer.from(provided), Buffer.from(WEBHOOK_SECRET))) {
|
|
||||||
return NextResponse.json({ ok: false, error: "Unauthorized" }, { status: 401 });
|
|
||||||
}
|
|
||||||
|
|
||||||
const url = new URL(req.url);
|
const url = new URL(req.url);
|
||||||
const parts = url.pathname.split("/").filter(Boolean);
|
const parts = url.pathname.split("/").filter(Boolean);
|
||||||
|
|||||||
Reference in New Issue
Block a user