Browse Source

fix: only require metrics password if set (#1715)

pull/1719/head v15.0.0-beta.4
Bernd Storath 4 weeks ago
committed by GitHub
parent
commit
93db67bab6
No known key found for this signature in database GPG Key ID: B5690EEEBB952194
  1. 46
      src/server/utils/handler.ts

46
src/server/utils/handler.ts

@ -138,34 +138,27 @@ export const defineMetricsHandler = <
handler: MetricsHandler<TReq, TRes>
) => {
return defineEventHandler(async (event) => {
const auth = getHeader(event, 'Authorization');
if (!auth) {
throw createError({
statusCode: 401,
statusMessage: 'Unauthorized',
});
}
const metricsConfig = await Database.general.getMetricsConfig();
const [method, value] = auth.split(' ');
if (metricsConfig.password) {
const auth = getHeader(event, 'Authorization');
if (method !== 'Bearer' || !value) {
throw createError({
statusCode: 401,
statusMessage: 'Bearer Auth required',
});
}
if (!auth) {
throw createError({
statusCode: 401,
statusMessage: 'Unauthorized',
});
}
const metricsConfig = await Database.general.getMetricsConfig();
const [method, value] = auth.split(' ');
if (metricsConfig[type] !== true) {
throw createError({
statusCode: 400,
statusMessage: 'Metrics not enabled',
});
}
if (method !== 'Bearer' || !value) {
throw createError({
statusCode: 401,
statusMessage: 'Bearer Auth required',
});
}
if (metricsConfig.password) {
const tokenValid = await isPasswordValid(value, metricsConfig.password);
if (!tokenValid) {
@ -176,6 +169,13 @@ export const defineMetricsHandler = <
}
}
if (metricsConfig[type] !== true) {
throw createError({
statusCode: 400,
statusMessage: 'Metrics not enabled',
});
}
return await handler({ event });
});
};

Loading…
Cancel
Save