forked from EduCraft/curriculum-project-hub
Revert "fix: accept SDK provider capability headers"
This reverts commit e7ad5580ec.
This commit is contained in:
@@ -102,7 +102,7 @@ async function forwardProviderRequest(
|
||||
upstream: ProviderUpstreamCredential,
|
||||
options: ProviderProxyOptions,
|
||||
): Promise<void> {
|
||||
if (!authorized(request.headers.authorization, header(request.headers["x-api-key"]), capability)) {
|
||||
if (!authorized(request.headers.authorization, capability)) {
|
||||
options.onDiagnostic?.({ code: "provider_proxy_unauthorized", category: "authorization" });
|
||||
response.writeHead(401, { "content-type": "text/plain; charset=utf-8" });
|
||||
response.end("unauthorized");
|
||||
@@ -165,24 +165,13 @@ async function forwardProviderRequest(
|
||||
}
|
||||
}
|
||||
|
||||
function authorized(
|
||||
authorization: string | undefined,
|
||||
apiKey: string | undefined,
|
||||
capability: string,
|
||||
): boolean {
|
||||
const value = authorization?.startsWith("Bearer ")
|
||||
? authorization.slice("Bearer ".length)
|
||||
: apiKey;
|
||||
if (value === undefined) return false;
|
||||
const supplied = Buffer.from(value);
|
||||
function authorized(value: string | undefined, capability: string): boolean {
|
||||
if (value === undefined || !value.startsWith("Bearer ")) return false;
|
||||
const supplied = Buffer.from(value.slice("Bearer ".length));
|
||||
const expected = Buffer.from(capability);
|
||||
return supplied.byteLength === expected.byteLength && timingSafeEqual(supplied, expected);
|
||||
}
|
||||
|
||||
function header(value: string | string[] | undefined): string | undefined {
|
||||
return Array.isArray(value) ? value[0] : value;
|
||||
}
|
||||
|
||||
function forwardedRequestHeaders(source: IncomingHttpHeaders): Headers {
|
||||
const result = new Headers();
|
||||
for (const [name, value] of Object.entries(source)) {
|
||||
|
||||
Reference in New Issue
Block a user