fix: 404 unknown API routes, add .dockerignore
- Add catch-all 404 handler for unknown /api/* routes after API mounts - Unauthed requests to unknown API paths now return 401, authed return 404 - Add .dockerignore to prevent leaking data/ (DB, secret.key), .git/, node_modules/ - Add test in auth.test.ts verifying unknown /api/nope returns 401 unauthed, 404 authed Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
7
.dockerignore
Normal file
7
.dockerignore
Normal file
@@ -0,0 +1,7 @@
|
|||||||
|
data/
|
||||||
|
.git/
|
||||||
|
node_modules/
|
||||||
|
web/dist/
|
||||||
|
.superpowers/
|
||||||
|
*.log
|
||||||
|
*.tsbuildinfo
|
||||||
@@ -21,6 +21,7 @@ export function createApp(deps: Deps) {
|
|||||||
app.route("/api", authRoutes({ db: deps.db }));
|
app.route("/api", authRoutes({ db: deps.db }));
|
||||||
app.route("/api", settingsRoutes(deps));
|
app.route("/api", settingsRoutes(deps));
|
||||||
// Later route groups (connectors, chat) mount here.
|
// Later route groups (connectors, chat) mount here.
|
||||||
|
app.all("/api/*", (c) => c.json({ error: "not found" }, 404));
|
||||||
app.use("/*", serveStatic({ root: "./web/dist" }));
|
app.use("/*", serveStatic({ root: "./web/dist" }));
|
||||||
app.get("/*", serveStatic({ path: "./web/dist/index.html" }));
|
app.get("/*", serveStatic({ path: "./web/dist/index.html" }));
|
||||||
return app;
|
return app;
|
||||||
|
|||||||
@@ -52,4 +52,19 @@ describe("auth", () => {
|
|||||||
}
|
}
|
||||||
expect(last).toBe(429);
|
expect(last).toBe(429);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
test("unknown /api/* returns 404 when authed, 401 when unauthed", async () => {
|
||||||
|
const app = makeApp();
|
||||||
|
await app.request("/api/setup", json({ password: "hunter2hunter2" }));
|
||||||
|
|
||||||
|
// Unauthed request to unknown endpoint returns 401
|
||||||
|
expect((await app.request("/api/nope")).status).toBe(401);
|
||||||
|
|
||||||
|
// Authed request to unknown endpoint returns 404
|
||||||
|
const login = await app.request("/api/login", json({ password: "hunter2hunter2" }));
|
||||||
|
const cookie = login.headers.get("set-cookie")!;
|
||||||
|
const res = await app.request("/api/nope", { headers: { cookie } });
|
||||||
|
expect(res.status).toBe(404);
|
||||||
|
expect(await res.json()).toEqual({ error: "not found" });
|
||||||
|
});
|
||||||
});
|
});
|
||||||
|
|||||||
Reference in New Issue
Block a user