diff --git a/.dockerignore b/.dockerignore new file mode 100644 index 0000000..da89b6b --- /dev/null +++ b/.dockerignore @@ -0,0 +1,7 @@ +data/ +.git/ +node_modules/ +web/dist/ +.superpowers/ +*.log +*.tsbuildinfo diff --git a/server/src/app.ts b/server/src/app.ts index da2b03d..81f913f 100644 --- a/server/src/app.ts +++ b/server/src/app.ts @@ -21,6 +21,7 @@ export function createApp(deps: Deps) { app.route("/api", authRoutes({ db: deps.db })); app.route("/api", settingsRoutes(deps)); // Later route groups (connectors, chat) mount here. + app.all("/api/*", (c) => c.json({ error: "not found" }, 404)); app.use("/*", serveStatic({ root: "./web/dist" })); app.get("/*", serveStatic({ path: "./web/dist/index.html" })); return app; diff --git a/server/test/auth.test.ts b/server/test/auth.test.ts index 6fc5cb2..ec11563 100644 --- a/server/test/auth.test.ts +++ b/server/test/auth.test.ts @@ -52,4 +52,19 @@ describe("auth", () => { } expect(last).toBe(429); }); + + test("unknown /api/* returns 404 when authed, 401 when unauthed", async () => { + const app = makeApp(); + await app.request("/api/setup", json({ password: "hunter2hunter2" })); + + // Unauthed request to unknown endpoint returns 401 + expect((await app.request("/api/nope")).status).toBe(401); + + // Authed request to unknown endpoint returns 404 + const login = await app.request("/api/login", json({ password: "hunter2hunter2" })); + const cookie = login.headers.get("set-cookie")!; + const res = await app.request("/api/nope", { headers: { cookie } }); + expect(res.status).toBe(404); + expect(await res.json()).toEqual({ error: "not found" }); + }); });