RelVDev2's picture
Deploy pre-receipt backup worker
d5c9d40
Raw
History Blame Contribute Delete
963 Bytes
import { Request, Response, NextFunction } from 'express';
import { config } from '../../config';
import { logger } from '../../utils/logger';
/**
* Express middleware that gates internal endpoints behind a shared secret.
* Reads the X-Admin-Secret header and compares against config.internalSecret.
* Returns 403 if the secret is missing or incorrect.
*/
export function requireAdminSecret(
req: Request,
res: Response,
next: NextFunction,
): void {
const secret = req.headers['x-admin-secret'];
if (!config.internalSecret) {
logger.error('INTERNAL_SECRET is not configured — rejecting admin request');
res.status(403).json({ error: 'Admin endpoints are not configured' });
return;
}
if (!secret || secret !== config.internalSecret) {
logger.warn('Admin secret mismatch', {
ip: req.ip,
path: req.path,
});
res.status(403).json({ error: 'Forbidden: invalid admin secret' });
return;
}
next();
}