commit
59526d83fa
6 changed files with 34 additions and 8 deletions
|
@ -44,6 +44,7 @@ function eventStateReducer(state: AppBridgeState, event: Events) {
|
||||||
/**
|
/**
|
||||||
* Event comes from API, so always assume it can be something not covered by TS
|
* Event comes from API, so always assume it can be something not covered by TS
|
||||||
*/
|
*/
|
||||||
|
// eslint-disable-next-line @typescript-eslint/no-explicit-any
|
||||||
console.warn(`Invalid event received: ${(event as any)?.type}`);
|
console.warn(`Invalid event received: ${(event as any)?.type}`);
|
||||||
return state;
|
return state;
|
||||||
}
|
}
|
||||||
|
|
|
@ -53,4 +53,4 @@ export type PayloadOfEvent<
|
||||||
TEventType extends EventType,
|
TEventType extends EventType,
|
||||||
TEvent extends Events = Events
|
TEvent extends Events = Events
|
||||||
// @ts-ignore TODO - why this is not working with this tsconfig? Fixme
|
// @ts-ignore TODO - why this is not working with this tsconfig? Fixme
|
||||||
> = TEvent extends Event<TEventType, any> ? TEvent["payload"] : never;
|
> = TEvent extends Event<TEventType, unknown> ? TEvent["payload"] : never;
|
||||||
|
|
|
@ -5,9 +5,14 @@ import {
|
||||||
SALEOR_SIGNATURE_HEADER,
|
SALEOR_SIGNATURE_HEADER,
|
||||||
} from "./const";
|
} from "./const";
|
||||||
|
|
||||||
export const getSaleorHeaders = (headers: { [name: string]: any }) => ({
|
const toStringOrUndefined = (value: string | string[] | undefined) =>
|
||||||
domain: headers[SALEOR_DOMAIN_HEADER],
|
value ? value.toString() : undefined;
|
||||||
authorizationBearer: headers[SALEOR_AUTHORIZATION_BEARER_HEADER],
|
|
||||||
signature: headers[SALEOR_SIGNATURE_HEADER],
|
export const getSaleorHeaders = (headers: {
|
||||||
event: headers[SALEOR_EVENT_HEADER],
|
[name: string]: string | string[] | undefined;
|
||||||
|
}): Record<string, string | undefined> => ({
|
||||||
|
domain: toStringOrUndefined(headers[SALEOR_DOMAIN_HEADER]),
|
||||||
|
authorizationBearer: toStringOrUndefined(headers[SALEOR_AUTHORIZATION_BEARER_HEADER]),
|
||||||
|
signature: toStringOrUndefined(headers[SALEOR_SIGNATURE_HEADER]),
|
||||||
|
event: toStringOrUndefined(headers[SALEOR_EVENT_HEADER]),
|
||||||
});
|
});
|
||||||
|
|
|
@ -2,7 +2,7 @@ import * as jose from "jose";
|
||||||
import type { Middleware, Request } from "retes";
|
import type { Middleware, Request } from "retes";
|
||||||
import { Response } from "retes/response";
|
import { Response } from "retes/response";
|
||||||
|
|
||||||
import { SALEOR_AUTHORIZATION_BEARER_HEADER } from "../const";
|
import { SALEOR_AUTHORIZATION_BEARER_HEADER, SALEOR_DOMAIN_HEADER } from "../const";
|
||||||
import { getSaleorHeaders } from "../headers";
|
import { getSaleorHeaders } from "../headers";
|
||||||
import { getJwksUrl } from "../urls";
|
import { getJwksUrl } from "../urls";
|
||||||
|
|
||||||
|
@ -24,6 +24,13 @@ export const withJWTVerified =
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (domain === undefined) {
|
||||||
|
return Response.BadRequest({
|
||||||
|
success: false,
|
||||||
|
message: `${ERROR_MESSAGE} Missing ${SALEOR_DOMAIN_HEADER} header.`,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
let tokenClaims: DashboardTokenPayload;
|
let tokenClaims: DashboardTokenPayload;
|
||||||
try {
|
try {
|
||||||
tokenClaims = jose.decodeJwt(token as string) as DashboardTokenPayload;
|
tokenClaims = jose.decodeJwt(token as string) as DashboardTokenPayload;
|
||||||
|
|
|
@ -9,6 +9,12 @@ export const withRegisteredSaleorDomainHeader =
|
||||||
(handler) =>
|
(handler) =>
|
||||||
async (request) => {
|
async (request) => {
|
||||||
const { domain: saleorDomain } = getSaleorHeaders(request.headers);
|
const { domain: saleorDomain } = getSaleorHeaders(request.headers);
|
||||||
|
if (!saleorDomain) {
|
||||||
|
return Response.BadRequest({
|
||||||
|
success: false,
|
||||||
|
message: "Domain header missing.",
|
||||||
|
});
|
||||||
|
}
|
||||||
const authData = await apl.get(saleorDomain);
|
const authData = await apl.get(saleorDomain);
|
||||||
if (!authData) {
|
if (!authData) {
|
||||||
return Response.Forbidden({
|
return Response.Forbidden({
|
||||||
|
|
|
@ -3,7 +3,7 @@ import * as jose from "jose";
|
||||||
import { Middleware } from "retes";
|
import { Middleware } from "retes";
|
||||||
import { Response } from "retes/response";
|
import { Response } from "retes/response";
|
||||||
|
|
||||||
import { SALEOR_SIGNATURE_HEADER } from "../const";
|
import { SALEOR_DOMAIN_HEADER, SALEOR_SIGNATURE_HEADER } from "../const";
|
||||||
import { getSaleorHeaders } from "../headers";
|
import { getSaleorHeaders } from "../headers";
|
||||||
import { getJwksUrl } from "../urls";
|
import { getJwksUrl } from "../urls";
|
||||||
|
|
||||||
|
@ -29,6 +29,13 @@ export const withWebhookSignatureVerified =
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (!saleorDomain) {
|
||||||
|
return Response.BadRequest({
|
||||||
|
success: false,
|
||||||
|
message: `${ERROR_MESSAGE} Missing ${SALEOR_DOMAIN_HEADER} header.`,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
if (secretKey !== undefined) {
|
if (secretKey !== undefined) {
|
||||||
const calculatedSignature = crypto
|
const calculatedSignature = crypto
|
||||||
.createHmac("sha256", secretKey)
|
.createHmac("sha256", secretKey)
|
||||||
|
|
Loading…
Reference in a new issue