Merge pull request #823 from pikasTech/fix/issue-814-cloud-web-api-key-proxy
fix(v02): proxy API key writes through cloud web
This commit is contained in:
@@ -46,6 +46,7 @@ export function isCloudApiProxyRoute(method, pathname) {
|
|||||||
}
|
}
|
||||||
if (normalizedMethod === "POST") {
|
if (normalizedMethod === "POST") {
|
||||||
return POST_PROXY_ROUTES.has(normalizedPath) ||
|
return POST_PROXY_ROUTES.has(normalizedPath) ||
|
||||||
|
isApiKeyWriteProxyRoute(normalizedMethod, normalizedPath) ||
|
||||||
normalizedPath.startsWith("/v1/rpc/") ||
|
normalizedPath.startsWith("/v1/rpc/") ||
|
||||||
normalizedPath.startsWith("/v1/agent/sessions/") ||
|
normalizedPath.startsWith("/v1/agent/sessions/") ||
|
||||||
isDevicePodPostProxyRoute(normalizedPath) ||
|
isDevicePodPostProxyRoute(normalizedPath) ||
|
||||||
@@ -55,11 +56,20 @@ export function isCloudApiProxyRoute(method, pathname) {
|
|||||||
return isWorkbenchWorkspaceWriteProxyRoute(normalizedMethod, normalizedPath) || isAgentConversationWriteProxyRoute(normalizedMethod, normalizedPath);
|
return isWorkbenchWorkspaceWriteProxyRoute(normalizedMethod, normalizedPath) || isAgentConversationWriteProxyRoute(normalizedMethod, normalizedPath);
|
||||||
}
|
}
|
||||||
if (normalizedMethod === "DELETE") {
|
if (normalizedMethod === "DELETE") {
|
||||||
return isAgentConversationWriteProxyRoute(normalizedMethod, normalizedPath);
|
return isApiKeyWriteProxyRoute(normalizedMethod, normalizedPath) ||
|
||||||
|
isAgentConversationWriteProxyRoute(normalizedMethod, normalizedPath);
|
||||||
}
|
}
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function isApiKeyWriteProxyRoute(method, pathname) {
|
||||||
|
if (pathname === "/v1/api-keys" && method === "POST") return true;
|
||||||
|
if (!pathname.startsWith("/v1/api-keys/")) return false;
|
||||||
|
if (method === "DELETE") return true;
|
||||||
|
if (method !== "POST") return false;
|
||||||
|
return pathname.endsWith("/regenerate");
|
||||||
|
}
|
||||||
|
|
||||||
function isDevicePodPostProxyRoute(pathname) {
|
function isDevicePodPostProxyRoute(pathname) {
|
||||||
const parts = pathname.split("/").filter(Boolean);
|
const parts = pathname.split("/").filter(Boolean);
|
||||||
if (parts.length < 4 || parts[0] !== "v1" || parts[1] !== "device-pods") return false;
|
if (parts.length < 4 || parts[0] !== "v1" || parts[1] !== "device-pods") return false;
|
||||||
|
|||||||
@@ -39,6 +39,27 @@ test("cloud web proxies authenticated REST RPC bridge routes", () => {
|
|||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
test("cloud web proxies authenticated API key management write routes", () => {
|
||||||
|
assert.deepEqual(cloudWebProxyRoutePolicy("POST", "/v1/api-keys"), {
|
||||||
|
proxy: true,
|
||||||
|
authRequired: true,
|
||||||
|
publicRoute: false,
|
||||||
|
routeKey: "POST /v1/api-keys"
|
||||||
|
});
|
||||||
|
assert.deepEqual(cloudWebProxyRoutePolicy("POST", "/v1/api-keys/key_1/regenerate"), {
|
||||||
|
proxy: true,
|
||||||
|
authRequired: true,
|
||||||
|
publicRoute: false,
|
||||||
|
routeKey: "POST /v1/api-keys/key_1/regenerate"
|
||||||
|
});
|
||||||
|
assert.deepEqual(cloudWebProxyRoutePolicy("DELETE", "/v1/api-keys/key_1"), {
|
||||||
|
proxy: true,
|
||||||
|
authRequired: true,
|
||||||
|
publicRoute: false,
|
||||||
|
routeKey: "DELETE /v1/api-keys/key_1"
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
test("cloud web proxies only supported authenticated device-pod write routes", () => {
|
test("cloud web proxies only supported authenticated device-pod write routes", () => {
|
||||||
assert.deepEqual(cloudWebProxyRoutePolicy("POST", "/v1/device-pods/D601-F103-V2/jobs"), {
|
assert.deepEqual(cloudWebProxyRoutePolicy("POST", "/v1/device-pods/D601-F103-V2/jobs"), {
|
||||||
proxy: true,
|
proxy: true,
|
||||||
|
|||||||
Reference in New Issue
Block a user