fix: Set auth type before disable check
This commit is contained in:
@@ -119,6 +119,13 @@ export const requireProjectAccess = async (req: Request, res: Response, next: Ne
|
|||||||
throw new HttpException(403, 'You do not have access to this project', ErrorCode.PROJECT_ACCESS_DENIED);
|
throw new HttpException(403, 'You do not have access to this project', ErrorCode.PROJECT_ACCESS_DENIED);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Set auth response with project ID (before disabled check so it's available for logging)
|
||||||
|
res.locals.auth = {
|
||||||
|
type: 'jwt',
|
||||||
|
userId,
|
||||||
|
projectId,
|
||||||
|
} as AuthResponse;
|
||||||
|
|
||||||
// Check if project is disabled - block write operations
|
// Check if project is disabled - block write operations
|
||||||
if (project?.disabled) {
|
if (project?.disabled) {
|
||||||
const method = req.method.toUpperCase();
|
const method = req.method.toUpperCase();
|
||||||
@@ -133,13 +140,6 @@ export const requireProjectAccess = async (req: Request, res: Response, next: Ne
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Set auth response with project ID
|
|
||||||
res.locals.auth = {
|
|
||||||
type: 'jwt',
|
|
||||||
userId,
|
|
||||||
projectId,
|
|
||||||
} as AuthResponse;
|
|
||||||
|
|
||||||
next();
|
next();
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
next(error);
|
next(error);
|
||||||
@@ -189,6 +189,12 @@ export const requirePublicKey = async (req: Request, res: Response, next: NextFu
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Set auth response with project ID (before disabled check so it's available for logging)
|
||||||
|
res.locals.auth = {
|
||||||
|
type: 'apiKey',
|
||||||
|
projectId: project.id,
|
||||||
|
} as AuthResponse;
|
||||||
|
|
||||||
// Check if project is disabled - block write operations
|
// Check if project is disabled - block write operations
|
||||||
if (project.disabled) {
|
if (project.disabled) {
|
||||||
const method = req.method.toUpperCase();
|
const method = req.method.toUpperCase();
|
||||||
@@ -203,12 +209,6 @@ export const requirePublicKey = async (req: Request, res: Response, next: NextFu
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Set auth response with project ID
|
|
||||||
res.locals.auth = {
|
|
||||||
type: 'apiKey',
|
|
||||||
projectId: project.id,
|
|
||||||
} as AuthResponse;
|
|
||||||
|
|
||||||
next();
|
next();
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
next(error);
|
next(error);
|
||||||
@@ -258,6 +258,12 @@ export const requireSecretKey = async (req: Request, res: Response, next: NextFu
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Set auth response with project ID (before disabled check so it's available for logging)
|
||||||
|
res.locals.auth = {
|
||||||
|
type: 'apiKey',
|
||||||
|
projectId: project.id,
|
||||||
|
} as AuthResponse;
|
||||||
|
|
||||||
// Check if project is disabled - block write operations
|
// Check if project is disabled - block write operations
|
||||||
if (project.disabled) {
|
if (project.disabled) {
|
||||||
const method = req.method.toUpperCase();
|
const method = req.method.toUpperCase();
|
||||||
@@ -272,12 +278,6 @@ export const requireSecretKey = async (req: Request, res: Response, next: NextFu
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Set auth response with project ID
|
|
||||||
res.locals.auth = {
|
|
||||||
type: 'apiKey',
|
|
||||||
projectId: project.id,
|
|
||||||
} as AuthResponse;
|
|
||||||
|
|
||||||
next();
|
next();
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
next(error);
|
next(error);
|
||||||
@@ -325,6 +325,12 @@ export const requireAuth = async (req: Request, res: Response, next: NextFunctio
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Set auth response with project ID (before disabled check so it's available for logging)
|
||||||
|
res.locals.auth = {
|
||||||
|
type: 'apiKey',
|
||||||
|
projectId: project.id,
|
||||||
|
} as AuthResponse;
|
||||||
|
|
||||||
// Check if project is disabled - block write operations
|
// Check if project is disabled - block write operations
|
||||||
if (project.disabled) {
|
if (project.disabled) {
|
||||||
const method = req.method.toUpperCase();
|
const method = req.method.toUpperCase();
|
||||||
@@ -339,12 +345,6 @@ export const requireAuth = async (req: Request, res: Response, next: NextFunctio
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Set auth response with project ID
|
|
||||||
res.locals.auth = {
|
|
||||||
type: 'apiKey',
|
|
||||||
projectId: project.id,
|
|
||||||
} as AuthResponse;
|
|
||||||
|
|
||||||
return next();
|
return next();
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -378,6 +378,13 @@ export const requireAuth = async (req: Request, res: Response, next: NextFunctio
|
|||||||
throw new HttpException(403, 'You do not have access to this project', ErrorCode.PROJECT_ACCESS_DENIED);
|
throw new HttpException(403, 'You do not have access to this project', ErrorCode.PROJECT_ACCESS_DENIED);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Set auth response with project ID (before disabled check so it's available for logging)
|
||||||
|
res.locals.auth = {
|
||||||
|
type: 'jwt',
|
||||||
|
userId,
|
||||||
|
projectId,
|
||||||
|
} as AuthResponse;
|
||||||
|
|
||||||
// Check if project is disabled - block write operations
|
// Check if project is disabled - block write operations
|
||||||
if (project?.disabled) {
|
if (project?.disabled) {
|
||||||
const method = req.method.toUpperCase();
|
const method = req.method.toUpperCase();
|
||||||
@@ -392,13 +399,6 @@ export const requireAuth = async (req: Request, res: Response, next: NextFunctio
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Set auth response with project ID
|
|
||||||
res.locals.auth = {
|
|
||||||
type: 'jwt',
|
|
||||||
userId,
|
|
||||||
projectId,
|
|
||||||
} as AuthResponse;
|
|
||||||
|
|
||||||
next();
|
next();
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
next(error);
|
next(error);
|
||||||
|
|||||||
Reference in New Issue
Block a user