2 Commits
Author SHA1 Message Date
Harvmaster 788ed0599b Updates 2026-09-02 10:03:55 +00:00
Harvmaster 1ca9648c09 Added auth and request storage 2026-08-31 12:28:18 +00:00
12 changed files with 334 additions and 102 deletions
+49
View File
@@ -0,0 +1,49 @@
/**
* This is a shim for payments that isnt really going to be too reflective of the real world payment system.
*
* The reason im doing it in such an overly simplified way is because an actual payment system is COMPLEX.
*
* Double entry accounting, transaction objects, idempotent requests, etc... They are a LOT to implement.
*
* Im certain that we can implement this more complex system into this project, its just going to be a lot of work on the actual payment handling.
* The route side can actually remain pretty simple because it can be wrapped into a function call.
*
* This implementation will just offer a `getBalance(publicKey: string): Promise<number>` and `setBalance(publicKey: string, amount: number): Promise<void>`
*
* Routes will just do a setBalance(pulicKey, await getBalance(publicKey) - amount) where amount is the size of the data being written.
*/
export class Accounts {
private accounts: Map<string, number> = new Map();
async getBalance(publicKey: string): Promise<number> {
if (!this.accounts.has(publicKey)) {
this.accounts.set(publicKey, 1_000_000_000_000);
}
return this.accounts.get(publicKey)!;
}
async setBalance(publicKey: string, amount: number): Promise<number> {
this.accounts.set(publicKey, amount);
return amount;
}
async deductBalance(publicKey: string, amount: number): Promise<number> {
const balance = await this.getBalance(publicKey);
if (balance < amount) {
throw new Error('Insufficient balance');
}
const balanceAfterDeduction = balance - amount;
return await this.setBalance(publicKey, balanceAfterDeduction);
}
async hasSufficientBalance(publicKey: string, amount: number): Promise<boolean> {
return true;
const balance = await this.getBalance(publicKey);
return balance >= amount;
}
}
+5
View File
@@ -22,3 +22,8 @@ export const HTTP_STATUS_CODE_BAD_REQUEST = 400;
* HTTP status code for "Not Acceptable" error. * HTTP status code for "Not Acceptable" error.
*/ */
export const HTTP_STATUS_CODE_NOT_ACCEPTED = 406; export const HTTP_STATUS_CODE_NOT_ACCEPTED = 406;
/**
* Not implemented response status code.
*/
export const HTTP_STATUS_CODE_NOT_IMPLEMENTED = 501;
+13 -2
View File
@@ -7,7 +7,10 @@ import { HttpTransportRouter } from './services/transport/http-transport.ts';
import { WsTransportRouter } from './services/transport/ws-transport.ts'; import { WsTransportRouter } from './services/transport/ws-transport.ts';
import { ServerHost } from './services/server-host.ts'; import { ServerHost } from './services/server-host.ts';
import { Logger } from './utils/logger.ts'; import { Logger } from './utils/logger.ts';
import { DataRoute } from './routes/resources.ts'; import { DataRoute } from './routes/resources.ts';
import { AccountRoute } from './routes/account.ts';
import { Accounts } from './auth/accounts.ts';
/** Application composition root. */ /** Application composition root. */
export class App { export class App {
@@ -29,10 +32,12 @@ export class App {
// Domain services are shared across all transports and route modules. // Domain services are shared across all transports and route modules.
const broadcaster = new Broadcaster(debug); const broadcaster = new Broadcaster(debug);
const accounts = new Accounts();
const routes = [ const routes = [
// DataRoute owns resource read/write/subscribe logic and maps resource // DataRoute owns resource read/write/subscribe logic and maps resource
// ids to broadcaster topics. timestampWindowMs controls write replay protection. // ids to broadcaster topics. timestampWindowMs controls write replay protection.
new DataRoute(database, broadcaster, config.auth.timestampWindowMs), new DataRoute(database, broadcaster, auth, accounts),
// new AccountRoute(database, auth),
]; ];
// Route loading is an explicit startup phase, not first-request work. // Route loading is an explicit startup phase, not first-request work.
@@ -47,7 +52,13 @@ export class App {
const ws = new WsTransportRouter(router, debug, config.server.maxRequestBodyBytes); const ws = new WsTransportRouter(router, debug, config.server.maxRequestBodyBytes);
const host = new ServerHost(config, debug, [ http, ws ]); const host = new ServerHost(config, debug, [ http, ws ]);
return new App(host, database); // Create the app instance
const app = new App(host, database);
// Start the unique request cleanup interval
app.startUniqueRequestCleanup(config.auth.uniqueRequestCleanupIntervalMs, config.auth.timestampWindowMs);
return app;
} }
private stopPromise: Promise<void> | undefined; private stopPromise: Promise<void> | undefined;
+105
View File
@@ -0,0 +1,105 @@
import { z } from "zod";
import type { AuthSecp256k1 } from '../auth/auth.ts';
import type { Database } from "../services/storage/database.ts";
import type { RouteDefinition, RouteStream } from './types.ts';
import type { Accounts } from '../auth/accounts.ts';
import { HTTP_STATUS_CODE_NOT_IMPLEMENTED, HTTP_STATUS_CODE_SUCCESS } from "../constants.ts";
import { UnauthorizedError } from '../errors/index.ts';
const accountSchema = z.object({
publicKey: z.string(),
signature: z.string(),
timestamp: z.coerce.number(),
});
const setBalanceSchema = z.object({
amount: z.number(),
});
export class AccountRoute {
constructor(private readonly database: Database, private readonly auth: AuthSecp256k1, private readonly accounts: Accounts) {}
async getRoutes(): Promise<Array<RouteDefinition>> {
return [
{
url: '/account',
handler: this.getAccount.bind(this),
},
{
url: '/account/balance',
handler: this.getAccount.bind(this),
},
{
url: '/account/setbalance',
handler: this.setBalance.bind(this),
},
// This one may not make sense. It could be a large overhead for something that most wont use?
// Maybe make this an optional endpoint or one that we don't support, but the client can try to hit or something?
{
url: '/account/ledger',
handler: this.getLedger.bind(this),
}
];
}
async getAccount(stream: RouteStream): Promise<void> {
// Get the public key, signature and timestamp from the headers
const { publicKey, signature, timestamp } = accountSchema.parse(stream.headers);
// Create the canonical payload for the signature verification
const payload = `${stream.path}:${timestamp}`;
// Verify the signature
const verified = await this.auth.verifySignature(publicKey, signature, payload);
if (!verified) {
throw new UnauthorizedError('Invalid signature');
}
// Get the account's balance from the database
const balance = await this.accounts.getBalance(publicKey);
// Send the balance to the client
stream.send({
statusCode: HTTP_STATUS_CODE_SUCCESS,
body: balance,
});
}
async setBalance(stream: RouteStream): Promise<void> {
const { publicKey, signature, timestamp } = accountSchema.parse(stream.headers);
const { amount } = setBalanceSchema.parse(stream.body);
// Create the canonical payload for the signature verification
const payload = `${stream.path}:${timestamp}`;
// Verify the signature
const verified = await this.auth.verifySignature(publicKey, signature, payload);
if (!verified) {
throw new UnauthorizedError('Invalid signature');
}
// Get the account's balance from the database
const balance = await this.accounts.getBalance(publicKey);
// Set the balance to the database
await this.accounts.setBalance(publicKey, amount);
// Send the balance to the client
stream.send({
statusCode: HTTP_STATUS_CODE_SUCCESS,
body: balance,
});
}
async getLedger(stream: RouteStream): Promise<void> {
stream.send({
statusCode: HTTP_STATUS_CODE_NOT_IMPLEMENTED,
body: 'Not implemented',
});
}
}
+42 -80
View File
@@ -1,14 +1,16 @@
import { createHash } from 'node:crypto';
import { hexToBin, instantiateSecp256k1, type Secp256k1 } from '@bitauth/libauth'; // NOTE: Replace this with libauth sha256
import { toExtendedJson } from '@xo-cash/utils'; import { toExtendedJson } from '@xo-cash/utils';
import { z } from 'zod'; import { z } from 'zod';
import { HTTP_STATUS_CODE_NOT_ACCEPTED } from '../constants.ts'; import { HTTP_STATUS_CODE_NOT_ACCEPTED } from '../constants.ts';
import type{ AuthSecp256k1 } from '../auth/auth.ts';
import type { BaseBroadcaster } from '../services/broadcaster.ts'; import type { BaseBroadcaster } from '../services/broadcaster.ts';
import { ApplicationError, UnauthorizedError } from '../errors/index.ts'; import { ApplicationError, UnauthorizedError } from '../errors/index.ts';
import type { Database } from '../services/storage/database.ts'; import type { Database } from '../services/storage/database.ts';
import type { RouteDefinition, RouteModule, RouteStream } from './types.ts'; import type { RouteDefinition, RouteModule, RouteStream } from './types.ts';
import type { Accounts } from '../auth/accounts.ts';
/** /**
* Schema to validate a single write resource. * Schema to validate a single write resource.
@@ -56,16 +58,11 @@ type WriteResource = z.infer<typeof writeResource>;
* RouteStream API. * RouteStream API.
*/ */
export class DataRoute implements RouteModule { export class DataRoute implements RouteModule {
/**
* Promise to instantiate the secp256k1 library
* This is a bit annoying, but keeping a single instance alive makes more sense than instantiating it for each verification.
*/
private readonly secp256k1Promise: Promise<Secp256k1> = instantiateSecp256k1();
constructor( constructor(
private readonly database: Database, private readonly database: Database,
private readonly broadcaster: BaseBroadcaster, private readonly broadcaster: BaseBroadcaster,
private readonly timestampWindowMs: number, private readonly auth: AuthSecp256k1,
private readonly accounts: Accounts,
) {} ) {}
/** Declare exact routes; each handler owns its stream behavior. */ /** Declare exact routes; each handler owns its stream behavior. */
@@ -92,7 +89,7 @@ export class DataRoute implements RouteModule {
/** Reads the requested resources from the database, returning all instances for each resource */ /** Reads the requested resources from the database, returning all instances for each resource */
async getData(stream: RouteStream): Promise<void> { async getData(stream: RouteStream): Promise<void> {
const resourceIds = this.getResourceIds(stream); const resourceIds = resourceIdsSchema.parse(stream.body).resourceId;
// Remove duplicates. // Remove duplicates.
const uniqueIds = [ ...new Set(resourceIds) ]; const uniqueIds = [ ...new Set(resourceIds) ];
@@ -107,7 +104,7 @@ export class DataRoute implements RouteModule {
// Read the data from the database. // Read the data from the database.
const rows = await this.database.db const rows = await this.database.db
.selectFrom('resource_data') .selectFrom('resource_data')
.select([ 'resource_id', 'public_key', 'blob', 'timestamp' ]) .select([ 'resource_id', 'public_key', 'blob', 'timestamp', 'signature' ])
.where('resource_id', 'in', uniqueIds) .where('resource_id', 'in', uniqueIds)
.orderBy('timestamp', 'asc') .orderBy('timestamp', 'asc')
.execute(); .execute();
@@ -118,6 +115,7 @@ export class DataRoute implements RouteModule {
publicKey: row.public_key, publicKey: row.public_key,
blob: new Uint8Array(row.blob), blob: new Uint8Array(row.blob),
timestamp: row.timestamp, timestamp: row.timestamp,
signature: row.signature,
})); }));
await stream.send(formattedRows); await stream.send(formattedRows);
@@ -132,6 +130,10 @@ export class DataRoute implements RouteModule {
async writeData(stream: RouteStream): Promise<void> { async writeData(stream: RouteStream): Promise<void> {
const { resources } = writeBody.parse(stream.body); const { resources } = writeBody.parse(stream.body);
// temporarily disable the signature verification for testing
// const publicKey = stream.headers?.['x-public-key']
const publicKey = 'public-key';
// Authenticate the whole batch before producing any storage side effects. // Authenticate the whole batch before producing any storage side effects.
// A single bad signature rejects the entire write — no partial commits. // A single bad signature rejects the entire write — no partial commits.
await Promise.all(resources.map((resource) => this.verifyWriteResource(resource))); await Promise.all(resources.map((resource) => this.verifyWriteResource(resource)));
@@ -141,11 +143,22 @@ export class DataRoute implements RouteModule {
resourceId: resource.id, resourceId: resource.id,
publicKey: resource.publicKey, publicKey: resource.publicKey,
blob: Buffer.from(resource.value), blob: Buffer.from(resource.value),
signature: resource.signature,
})); }));
// Get the total size of the bytes being written
const totalSize = rows.reduce((acc, row) => acc + row.blob.length, 0);
if (!await this.accounts.hasSufficientBalance(publicKey, totalSize)) {
throw new ApplicationError(203, 'Insufficient balance');
}
// Set the balance of the public key
await this.accounts.deductBalance(publicKey, totalSize);
// Upsert every row atomically; conflicts update blob and timestamp only. // Upsert every row atomically; conflicts update blob and timestamp only.
await this.database.db.transaction().execute(async (trx) => { await this.database.db.transaction().execute(async (trx) => {
for (const { resourceId, publicKey, blob } of rows) { for (const { resourceId, publicKey, blob, signature } of rows) {
await trx await trx
.insertInto('resource_data') .insertInto('resource_data')
.values({ .values({
@@ -153,6 +166,7 @@ export class DataRoute implements RouteModule {
public_key: publicKey, public_key: publicKey,
blob, blob,
timestamp, timestamp,
signature,
}) })
.onConflict((oc) => .onConflict((oc) =>
oc.columns([ 'resource_id', 'public_key' ]).doUpdateSet({ oc.columns([ 'resource_id', 'public_key' ]).doUpdateSet({
@@ -164,36 +178,38 @@ export class DataRoute implements RouteModule {
}); });
// Format the rows into the written resource responses. // Format the rows into the written resource responses.
const written = rows.map(({ resourceId, publicKey, blob }) => ({ const written = rows.map(({ resourceId, publicKey, blob, signature }) => ({
resourceId,
instance: { instance: {
resourceId,
publicKey, publicKey,
blob: new Uint8Array(blob), blob: new Uint8Array(blob),
timestamp, timestamp,
signature,
}, },
})); }));
// Notify subscribers on each changed resource. Topic names are scoped per // Notify subscribers on each changed resource. Topic names are scoped per
// resource id so clients only receive events for resources they joined. // resource id so clients only receive events for resources they joined.
for (const { resourceId, instance } of written) { for (const { instance } of written) {
await this.broadcaster.publish(DataRoute.resourceTopic(resourceId), { await this.broadcaster.publish(DataRoute.resourceTopic(instance.resourceId), {
type: 'instance-changed', type: 'instance-changed',
data: { resourceId, ...instance }, data: instance,
}); });
} }
// Return the persisted instances so the writer can confirm what was stored. // Return the persisted instances so the writer can confirm what was stored.
await stream.send({ await stream.send({
resources: written.map(({ resourceId, instance }) => ({ resources: written.map(({ instance }) => ({
id: resourceId, id: instance.resourceId,
...instance, ...instance,
})), })),
balance: await this.accounts.getBalance(publicKey),
}); });
} }
/** Subscribe this connection to future changes for the requested resources. */ /** Subscribe this connection to future changes for the requested resources. */
async subscribeData(stream: RouteStream): Promise<void> { async subscribeData(stream: RouteStream): Promise<void> {
const resourceIds = this.getResourceIds(stream); const resourceIds = resourceIdsSchema.parse(stream.body).resourceId;
const topics = resourceIds.map((resourceId) => DataRoute.resourceTopic(resourceId)); const topics = resourceIds.map((resourceId) => DataRoute.resourceTopic(resourceId));
@@ -209,7 +225,7 @@ export class DataRoute implements RouteModule {
* unsubscribe implicitly by aborting the HTTP request. * unsubscribe implicitly by aborting the HTTP request.
*/ */
async unsubscribeData(stream: RouteStream): Promise<void> { async unsubscribeData(stream: RouteStream): Promise<void> {
const resourceIds = this.getResourceIds(stream); const resourceIds = resourceIdsSchema.parse(stream.body).resourceId;
// If the stream is not bidirectional, throw an error. // If the stream is not bidirectional, throw an error.
if (!stream.bidirectional) { if (!stream.bidirectional) {
@@ -224,14 +240,6 @@ export class DataRoute implements RouteModule {
await stream.send({}); await stream.send({});
} }
/** Extract resource id list from the decoded request body. */
private getResourceIds(stream: RouteStream): string[] {
const body =
typeof stream.body === 'object' && stream.body !== null && !Array.isArray(stream.body) ? (stream.body as Record<string, unknown>) : {};
return resourceIdsSchema.parse(body).resourceId;
}
/** /**
* Verify one write's timestamp freshness and secp256k1 signature. * Verify one write's timestamp freshness and secp256k1 signature.
* *
@@ -239,62 +247,16 @@ export class DataRoute implements RouteModule {
* id, and value — not the raw HTTP/WebSocket envelope. * id, and value — not the raw HTTP/WebSocket envelope.
*/ */
private async verifyWriteResource(resource: WriteResource): Promise<void> { private async verifyWriteResource(resource: WriteResource): Promise<void> {
this.assertFreshTimestamp(resource.timestamp); this.auth.assertTimestampFreshness(resource.timestamp);
if (!(await this.verifySignature(resource.publicKey, resource.signature, DataRoute.canonicalWritePayload(resource)))) { // Compile the signature payload as `Timestamp:ID:Value`
const signaturePayload = `${resource.timestamp}:${resource.id}:${toExtendedJson(resource.value)}`;
if (!(await this.auth.verifySignature(resource.publicKey, resource.signature, signaturePayload))) {
throw new UnauthorizedError('Invalid resource signature'); throw new UnauthorizedError('Invalid resource signature');
} }
} }
/**
* Reject writes with stale timestamps to limit replay window.
*
* Both past and future timestamps outside the window are rejected.
*/
private assertFreshTimestamp(timestamp: number): void {
const age = Math.abs(Date.now() - timestamp);
if (age > this.timestampWindowMs) {
throw new UnauthorizedError('Timestamp outside allowed window');
}
}
/**
* Verify a secp256k1 signature.
*
* @param publicKeyHex - The public key to verify the signature against.
* @param signatureHex - The signature to verify.
* @param payload - The payload to verify the signature against.
* @returns Whether the signature is valid.
*/
private async verifySignature(publicKeyHex: string, signatureHex: string, payload: string): Promise<boolean> {
const secp256k1 = await this.secp256k1Promise;
try {
// Convert the public key and signature to binary.
const publicKey = hexToBin(publicKeyHex);
const signature = hexToBin(signatureHex);
// Create a SHA-256 hash of the payload.
const messageHash = createHash('sha256').update(payload)
.digest();
// Low-S normalization rejects malleable signature encodings.
return secp256k1.verifySignatureDERLowS(signature, publicKey, messageHash);
} catch {
return false;
}
}
/**
* Build the transport-independent payload authenticated by each signature.
*
* canonicalBody ensures Uint8Array values hash consistently regardless of
* whether the client sent them over HTTP or WebSocket.
*/
private static canonicalWritePayload(resource: WriteResource): string {
return `${resource.timestamp}${resource.id}${toExtendedJson(resource.value)}`;
}
/** Broadcaster topic for a single resource's instance-changed events. */ /** Broadcaster topic for a single resource's instance-changed events. */
private static resourceTopic(resourceId: string): string { private static resourceTopic(resourceId: string): string {
return `resource:${resourceId}`; return `resource:${resourceId}`;
@@ -11,6 +11,7 @@ import { ApplicationError, normalizePublicError } from '../../errors/index.ts';
import { HTTP_STATUS_CODE_BAD_REQUEST, HTTP_STATUS_CODE_NO_CONTENT } from '../../constants.ts'; import { HTTP_STATUS_CODE_BAD_REQUEST, HTTP_STATUS_CODE_NO_CONTENT } from '../../constants.ts';
import { HonoSSEStream } from '../stream/hono-sse-stream.ts'; import { HonoSSEStream } from '../stream/hono-sse-stream.ts';
import { HttpRequestStream } from '../stream/http-request-stream.ts'; import { HttpRequestStream } from '../stream/http-request-stream.ts';
import { normalizeRequestHeaders } from './request-headers.ts';
/** Hono context key where decoded Extended JSON bodies are stored. */ /** Hono context key where decoded Extended JSON bodies are stored. */
const PARSED_BODY_KEY = 'parsedBody'; const PARSED_BODY_KEY = 'parsedBody';
@@ -110,6 +111,7 @@ export class HttpTransportRouter implements TransportRouter {
return { return {
path: context.req.path, path: context.req.path,
headers: normalizeRequestHeaders(context.req.header()),
...(body === undefined ? {} : { body }), ...(body === undefined ? {} : { body }),
}; };
} }
@@ -13,6 +13,7 @@ import type { AppEnv, UpgradeTransportRouter } from './transport-router.ts';
import { ApplicationError, normalizePublicError } from '../../errors/index.ts'; import { ApplicationError, normalizePublicError } from '../../errors/index.ts';
import { HTTP_STATUS_CODE_BAD_REQUEST } from '../../constants.ts'; import { HTTP_STATUS_CODE_BAD_REQUEST } from '../../constants.ts';
import { WSStream } from '../stream/ws-stream.ts'; import { WSStream } from '../stream/ws-stream.ts';
import { normalizeRequestHeaders } from './request-headers.ts';
/** Default WebSocket upgrade path for application messages. */ /** Default WebSocket upgrade path for application messages. */
const WS_ROUTE = '/ws'; const WS_ROUTE = '/ws';
@@ -24,6 +25,7 @@ const wsRequestSchema = z
.optional(), .optional(),
path: z.string().min(1), path: z.string().min(1),
body: z.unknown().optional(), body: z.unknown().optional(),
headers: z.record(z.string(), z.string()).optional(),
}) })
.strict(); .strict();
@@ -208,6 +210,7 @@ export class WsTransportRouter implements UpgradeTransportRouter {
path: envelope.path, path: envelope.path,
...(envelope.id === undefined ? {} : { requestId: envelope.id }), ...(envelope.id === undefined ? {} : { requestId: envelope.id }),
...(envelope.body === undefined ? {} : { body: envelope.body }), ...(envelope.body === undefined ? {} : { body: envelope.body }),
...(envelope.headers === undefined ? {} : { headers: normalizeRequestHeaders(envelope.headers) }),
}; };
} }
+51 -11
View File
@@ -7,6 +7,8 @@ import { ApplicationRouteStream } from '../../source/services/route-stream.ts';
import type { Database } from '../../source/services/storage/database.ts'; import type { Database } from '../../source/services/storage/database.ts';
import { TestConnection } from '../helpers/test-connection.ts'; import { TestConnection } from '../helpers/test-connection.ts';
import { HTTP_STATUS_CODE_NOT_ACCEPTED } from '../../source/constants.ts'; import { HTTP_STATUS_CODE_NOT_ACCEPTED } from '../../source/constants.ts';
import type { AuthSecp256k1 } from '../../source/auth/auth.ts';
import { Accounts } from '../../source/auth/accounts.ts';
const createBroadcasterStub = (): BaseBroadcaster => { const createBroadcasterStub = (): BaseBroadcaster => {
return { return {
@@ -17,6 +19,31 @@ const createBroadcasterStub = (): BaseBroadcaster => {
} as unknown as BaseBroadcaster; } as unknown as BaseBroadcaster;
}; };
const createAuthStub = (): AuthSecp256k1 => {
return {
verifySignature: vi.fn().mockImplementation(() => {
return true;
}),
} as unknown as AuthSecp256k1;
};
const createAccountsStub = (): Accounts => {
return {
getBalance: vi.fn().mockImplementation(() => {
return 0;
}),
setBalance: vi.fn().mockImplementation(() => {
return;
}),
deductBalance: vi.fn().mockImplementation(() => {
return;
}),
hasSufficientBalance: vi.fn().mockImplementation(() => {
return true;
}),
} as unknown as Accounts;
};
describe('DataRoute subscriptions', (): void => { describe('DataRoute subscriptions', (): void => {
it('subscribes to future resource changes until removal', async (): Promise<void> => { it('subscribes to future resource changes until removal', async (): Promise<void> => {
let resolveRemoved: () => void = () => undefined; let resolveRemoved: () => void = () => undefined;
@@ -31,10 +58,14 @@ describe('DataRoute subscriptions', (): void => {
const broadcaster = createBroadcasterStub(); const broadcaster = createBroadcasterStub();
vi.mocked(broadcaster.subscribe).mockReturnValue(removed); vi.mocked(broadcaster.subscribe).mockReturnValue(removed);
const connection = new TestConnection(true, false); const connection = new TestConnection(true, false);
const stream = new ApplicationRouteStream(connection, { const stream = new ApplicationRouteStream(
resourceId: [ 'a', 'b' ], connection,
}); {
const route = new DataRoute(storage, broadcaster, 0); resourceId: [ 'a', 'b' ],
},
'/data/subscribe',
);
const route = new DataRoute(storage, broadcaster, createAuthStub(), createAccountsStub(), 0);
const execution = route.subscribeData(stream); const execution = route.subscribeData(stream);
@@ -55,8 +86,8 @@ describe('DataRoute subscriptions', (): void => {
} as unknown as Database; } as unknown as Database;
const broadcaster = createBroadcasterStub(); const broadcaster = createBroadcasterStub();
const connection = new TestConnection(true, true); const connection = new TestConnection(true, true);
const stream = new ApplicationRouteStream(connection, { resourceId: [ 'a' ] }, 'unsubscribe-1'); const stream = new ApplicationRouteStream(connection, { resourceId: [ 'a' ] }, '/data/unsubscribe', 'unsubscribe-1');
const route = new DataRoute(storage, broadcaster, 0); const route = new DataRoute(storage, broadcaster, createAuthStub(), createAccountsStub(), 0);
await route.unsubscribeData(stream); await route.unsubscribeData(stream);
@@ -78,10 +109,14 @@ describe('DataRoute subscriptions', (): void => {
}, },
} as unknown as Database; } as unknown as Database;
const broadcaster = createBroadcasterStub(); const broadcaster = createBroadcasterStub();
const stream = new ApplicationRouteStream(new TestConnection(true, false), { const stream = new ApplicationRouteStream(
resourceId: [ 'a' ], new TestConnection(true, false),
}); {
const route = new DataRoute(storage, broadcaster, 0); resourceId: [ 'a' ],
},
'/data/unsubscribe',
);
const route = new DataRoute(storage, broadcaster, createAuthStub(), createAccountsStub(), 0);
await expect(route.unsubscribeData(stream)).rejects.toMatchObject({ statusCode: HTTP_STATUS_CODE_NOT_ACCEPTED }); await expect(route.unsubscribeData(stream)).rejects.toMatchObject({ statusCode: HTTP_STATUS_CODE_NOT_ACCEPTED });
expect(broadcaster.unsubscribe).not.toHaveBeenCalled(); expect(broadcaster.unsubscribe).not.toHaveBeenCalled();
@@ -97,7 +132,7 @@ describe('DataRoute resource write auth', (): void => {
} as unknown as Database; } as unknown as Database;
const broadcaster = createBroadcasterStub(); const broadcaster = createBroadcasterStub();
const route = new DataRoute(storage, broadcaster, 0); const route = new DataRoute(storage, broadcaster, createAuthStub(), createAccountsStub(), 0);
await expect(route.writeData({ await expect(route.writeData({
connection: new TestConnection(true, true), connection: new TestConnection(true, true),
@@ -115,6 +150,11 @@ describe('DataRoute resource write auth', (): void => {
}, },
], ],
}, },
headers: {
publicKey: 'public-key',
signature: 'signature',
timestamp: Date.now(),
},
} as unknown as ApplicationRouteStream)).rejects.toBeInstanceOf(UnauthorizedError); } as unknown as ApplicationRouteStream)).rejects.toBeInstanceOf(UnauthorizedError);
expect(storage.db.transaction).not.toHaveBeenCalled(); expect(storage.db.transaction).not.toHaveBeenCalled();
+1 -1
View File
@@ -10,7 +10,7 @@ const createBroadcaster = (): Broadcaster => {
}; };
const routeStream = (connection: TestConnection): ApplicationRouteStream => { const routeStream = (connection: TestConnection): ApplicationRouteStream => {
return new ApplicationRouteStream(connection, undefined); return new ApplicationRouteStream(connection, undefined, '/test');
}; };
const expectPending = async (promise: Promise<void>): Promise<void> => { const expectPending = async (promise: Promise<void>): Promise<void> => {
+2 -2
View File
@@ -172,13 +172,13 @@ describe('ApplicationRouter dispatch', (): void => {
id: 'B', id: 'B',
type: 'response', type: 'response',
statusCode: 200, statusCode: 200,
body: { key: 'B' }, body: { key: 'B', token: 'token-b' },
}, },
{ {
id: 'A', id: 'A',
type: 'response', type: 'response',
statusCode: 200, statusCode: 200,
body: { key: 'A' }, body: { key: 'A', token: 'token-a' },
}, },
]); ]);
}); });
@@ -70,6 +70,23 @@ describe('HttpTransportRouter', (): void => {
expect(await response.text()).toBe(''); expect(await response.text()).toBe('');
}); });
it('passes normalized HTTP request headers to the route stream', async (): Promise<void> => {
const app = await createApp([
{
url: '/headers',
handler: async (stream): Promise<void> => stream.send({ path: stream.path, token: stream.headers['x-request-token'] }),
},
]);
const response = await app.request('/headers', {
method: 'POST',
headers: { 'X-Request-Token': 'http-token' },
});
expect(response.status).toBe(200);
expect(await response.json()).toEqual({ path: '/headers', token: 'http-token' });
});
it('returns normalized errors for non-streaming requests', async (): Promise<void> => { it('returns normalized errors for non-streaming requests', async (): Promise<void> => {
const app = await createApp([]); const app = await createApp([]);
@@ -149,6 +166,27 @@ describe('HttpTransportRouter', (): void => {
expect(events).toContain('data: {"ok":true}'); expect(events).toContain('data: {"ok":true}');
}); });
it('passes normalized HTTP request headers to an SSE route stream', async (): Promise<void> => {
const app = await createApp([
{
url: '/headers',
handler: (stream): Promise<void> => stream.send({ token: stream.headers['x-request-token'] }),
},
]);
const response = await app.request('/headers', {
method: 'POST',
headers: {
accept: 'text/event-stream',
'X-Request-Token': 'sse-token',
},
});
const events = await response.text();
expect(response.status).toBe(200);
expect(events).toContain('data: {"token":"sse-token"}');
});
it("keeps SSE open until the route's subscription promise resolves", async (): Promise<void> => { it("keeps SSE open until the route's subscription promise resolves", async (): Promise<void> => {
let removeSubscription: () => Promise<void> = async () => undefined; let removeSubscription: () => Promise<void> = async () => undefined;
let markSubscribed: () => void = () => undefined; let markSubscribed: () => void = () => undefined;
+23 -6
View File
@@ -13,19 +13,36 @@ describe('WebSocket request decoding', (): void => {
id: 'request-1', id: 'request-1',
path: '/data/write', path: '/data/write',
body: { value: new Uint8Array([ 1, 2, 3 ]) }, body: { value: new Uint8Array([ 1, 2, 3 ]) },
headers: { 'X-Request-Token': 'ws-token' },
}))).resolves.toEqual({ }))).resolves.toEqual({
requestId: 'request-1', requestId: 'request-1',
path: '/data/write', path: '/data/write',
body: { value: new Uint8Array([ 1, 2, 3 ]) }, body: { value: new Uint8Array([ 1, 2, 3 ]) },
headers: { 'x-request-token': 'ws-token' },
}); });
}); });
it.each([ '{}', '{"path":42}', '{"path":"/data/get","id":1}', '{"path":"/data/get","method":"POST"}' ])( it('allows the optional headers object to be omitted', async (): Promise<void> => {
'rejects an invalid envelope: %s', await expect(WsTransportRouter.decodeWebSocketRequest('{"path":"/data/get"}')).resolves.toEqual({ path: '/data/get' });
async (payload) => { });
await expect(WsTransportRouter.decodeWebSocketRequest(payload)).rejects.toBeInstanceOf(z.ZodError);
}, it.each([
); '{}',
'{"path":42}',
'{"path":"/data/get","id":1}',
'{"path":"/data/get","method":"POST"}',
'{"path":"/data/get","headers":{"x-request-token":1}}',
])('rejects an invalid envelope: %s', async (payload) => {
await expect(WsTransportRouter.decodeWebSocketRequest(payload)).rejects.toBeInstanceOf(z.ZodError);
});
it.each([
'{"path":"/data/get","headers":{"bad header":"value"}}',
'{"path":"/data/get","headers":{"x-request-token":"first","X-Request-Token":"second"}}',
'{"path":"/data/get","headers":{"x-request-token":"first\\r\\nsecond"}}',
])('rejects malformed request headers: %s', async (payload): Promise<void> => {
await expect(WsTransportRouter.decodeWebSocketRequest(payload)).rejects.toMatchObject({ statusCode: 400 });
});
it('rejects malformed JSON', async (): Promise<void> => { it('rejects malformed JSON', async (): Promise<void> => {
await expect(WsTransportRouter.decodeWebSocketRequest('{')).rejects.toMatchObject({ await expect(WsTransportRouter.decodeWebSocketRequest('{')).rejects.toMatchObject({