fix(auth): allow Hobby clock tick through edge auth

/api/v1/system/relogio/tick authenticates with Bearer INTERNAL_SECRET
inside the route. Without a PUBLIC_PATHS entry the proxy returned 401
before the handler ran, so GitHub Actions could never advance follow-ups.
This commit is contained in:
Ian Couto
2026-08-26 08:43:31 -03:00
parent c68afd1a40
commit 4c3453a5ea
2 changed files with 9 additions and 0 deletions
+6
View File
@@ -13,6 +13,12 @@ describe("isPublicPath", () => {
expect(isPublicPath("/api/v1/system/agent")).toBe(true);
});
it("libera o tick do relógio Hobby (bearer, sem cookie)", () => {
expect(isPublicPath("/api/v1/system/relogio/tick")).toBe(true);
expect(isPublicPath("/api/v1/system/relogio")).toBe(false);
expect(isPublicPath("/api/v1/system/relogio/tick/extra")).toBe(false);
});
it("a âncora `$` impede que um sub-path passe de carona", () => {
expect(isPublicPath("/api/v1/system/agent/qualquer")).toBe(false);
});
+3
View File
@@ -18,6 +18,9 @@ export const PUBLIC_PATHS: RegExp[] = [
// Heartbeat do agente do host (bearer INTERNAL_SECRET/INTERNAL_CRON_SECRET,
// checado dentro da própria rota) — sem cookie de sessão, igual /cron/.
/^\/api\/v1\/system\/agent$/,
// Relógio Hobby (GitHub Actions / cron-job.org). Auth é Bearer na própria
// rota — sem isto o proxy devolve 401 e o follow-up waiting_reply nunca anda.
/^\/api\/v1\/system\/relogio\/tick$/,
/^\/api\/internal\//,
/^\/api\/mcp(\/.*)?$/,
/^\/_next\//,