mirror of
https://github.com/yusufipk/RepoHub.git
synced 2026-09-11 18:46:07 +00:00
feat: add authentication and configuration for sync operations
- Implemented SyncAuth to control sync access with server-only mode and secret key authorization - Consolidated environment variables into single .env.example with improved sync configuration - Protected all sync API endpoints (ubuntu, fedora, arch, homebrew, winget) with authentication checks
This commit is contained in:
@@ -0,0 +1,86 @@
|
||||
import { NextRequest } from 'next/server'
|
||||
|
||||
export class SyncAuth {
|
||||
private static readonly SERVER_ONLY = process.env.SYNC_SERVER_ONLY === 'true'
|
||||
private static readonly SYNC_SECRET = process.env.SYNC_SECRET_KEY
|
||||
|
||||
/**
|
||||
* Check if sync operations are allowed from the current request
|
||||
*/
|
||||
static async isSyncAllowed(request: NextRequest): Promise<{ allowed: boolean; reason?: string }> {
|
||||
// If server-only mode is disabled, allow all requests
|
||||
if (!this.SERVER_ONLY) {
|
||||
return { allowed: true }
|
||||
}
|
||||
|
||||
// In server-only mode, check for secret key in header
|
||||
const secretKey = request.headers.get('x-sync-secret')
|
||||
|
||||
if (!this.SYNC_SECRET) {
|
||||
return {
|
||||
allowed: false,
|
||||
reason: 'Sync secret key not configured on server'
|
||||
}
|
||||
}
|
||||
|
||||
if (!secretKey) {
|
||||
return {
|
||||
allowed: false,
|
||||
reason: 'Sync secret key required in server-only mode'
|
||||
}
|
||||
}
|
||||
|
||||
if (secretKey !== this.SYNC_SECRET) {
|
||||
return {
|
||||
allowed: false,
|
||||
reason: 'Invalid sync secret key'
|
||||
}
|
||||
}
|
||||
|
||||
// Additional check: verify request is from localhost or same server
|
||||
const clientIP = request.headers.get('x-forwarded-for') ||
|
||||
request.headers.get('x-real-ip') ||
|
||||
'unknown'
|
||||
|
||||
const allowedIPs = ['127.0.0.1', 'localhost', '::1']
|
||||
const isLocalRequest = allowedIPs.includes(clientIP.split(',')[0].trim())
|
||||
|
||||
if (!isLocalRequest && secretKey !== this.SYNC_SECRET) {
|
||||
return {
|
||||
allowed: false,
|
||||
reason: 'Sync operations only allowed from server in server-only mode'
|
||||
}
|
||||
}
|
||||
|
||||
return { allowed: true }
|
||||
}
|
||||
|
||||
/**
|
||||
* Get automatic sync frequency in days
|
||||
*/
|
||||
static getAutoSyncDays(): number {
|
||||
const days = parseInt(process.env.AUTO_SYNC_DAYS || '1', 10)
|
||||
return isNaN(days) ? 1 : Math.max(0, days)
|
||||
}
|
||||
|
||||
/**
|
||||
* Check if automatic sync is enabled
|
||||
*/
|
||||
static isAutoSyncEnabled(): boolean {
|
||||
return this.getAutoSyncDays() > 0
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the next sync time based on frequency
|
||||
*/
|
||||
static getNextSyncTime(lastSyncTime?: Date): Date {
|
||||
const days = this.getAutoSyncDays()
|
||||
if (days === 0) {
|
||||
return new Date(0) // Return epoch time if disabled
|
||||
}
|
||||
|
||||
const nextSync = new Date(lastSyncTime || new Date())
|
||||
nextSync.setDate(nextSync.getDate() + days)
|
||||
return nextSync
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user