visual-journal / src /lib /agent-auth.ts
misonL's picture
Deploy 09324ad to Docker Space
b1cfe1b verified
Raw
History Blame Contribute Delete
1.51 kB
import { AgentApiError } from './api-error-response';
import { verifyPasswordHash } from './server-runtime';
import crypto from 'crypto';
export function assertAgentAuthorized(headers: Headers, env: Record<string, string | undefined> = process.env): void {
const configuredToken = env.AGENT_API_TOKEN?.trim();
if (configuredToken) {
const authorization = headers.get('authorization') || '';
const expected = `Bearer ${configuredToken}`;
if (!timingSafeStringEqual(authorization, expected)) {
throw new AgentApiError({
code: 'unauthorized',
message: '未授权:Bearer token 无效或缺失。',
status: 401,
retryable: false
});
}
return;
}
const appPassword = env.APP_PASSWORD?.trim();
if (!appPassword) return;
const passwordHash = headers.get('x-app-password-hash');
if (!passwordHash || !verifyPasswordHash(passwordHash, appPassword)) {
throw new AgentApiError({
code: 'unauthorized',
message: '未授权:访问码哈希无效或缺失。',
status: 401,
retryable: false
});
}
}
function timingSafeStringEqual(actual: string, expected: string): boolean {
const actualHash = crypto.createHash('sha256').update(actual).digest();
const expectedHash = crypto.createHash('sha256').update(expected).digest();
return crypto.timingSafeEqual(actualHash, expectedHash);
}