qwen_2.5_model / src /modules /auth /auth-validate.controller.ts
Muhammad Noman
Deploy OpenWA to Hugging Face Spaces
46252cd
Raw
History Blame Contribute Delete
1.54 kB
import { Controller, Post, HttpCode, HttpStatus } from '@nestjs/common';
import { ApiTags, ApiOperation, ApiResponse, ApiHeader } from '@nestjs/swagger';
import { CurrentApiKey } from './decorators/auth.decorators';
import { ApiKey } from './entities/api-key.entity';
@ApiTags('auth')
@Controller('auth')
export class AuthValidateController {
@Post('validate')
@HttpCode(HttpStatus.OK)
@ApiOperation({ summary: 'Validate an API key' })
@ApiHeader({ name: 'X-API-Key', description: 'API key to validate' })
@ApiResponse({ status: 200, description: 'API key is valid' })
@ApiResponse({ status: 401, description: 'Invalid or missing API key' })
validate(@CurrentApiKey() apiKey?: ApiKey): { valid: boolean; role?: string } {
// This route is behind the global API-key guard, so only a validated key reaches this handler
// (a missing/invalid key 401s first). The guard has already verified the key — including its
// client-IP and session-scope restrictions — and attached it to the request. Re-validating here
// would repeat that work without the client IP, double-counting usage and, for an IP-restricted
// key, failing closed (no IP) and wrongly reporting valid:false. So we trust the guard's result.
// The valid:false branch is unreachable in normal operation; it's retained as defense-in-depth in
// case the guard config ever changes, keeping the endpoint safe to expose directly.
if (!apiKey) {
return { valid: false };
}
return { valid: true, role: apiKey.role };
}
}