mirror of
https://github.com/melgarafael/DeskcommCRM.git
synced 2026-10-02 01:28:34 +08:00
fix(auth): allow Hobby clock tick through edge auth
/api/v1/system/relogio/tick authenticates with Bearer INTERNAL_SECRET inside the route. Without a PUBLIC_PATHS entry the proxy returned 401 before the handler ran, so GitHub Actions could never advance follow-ups.
This commit is contained in:
@@ -13,6 +13,12 @@ describe("isPublicPath", () => {
|
||||
expect(isPublicPath("/api/v1/system/agent")).toBe(true);
|
||||
});
|
||||
|
||||
it("libera o tick do relógio Hobby (bearer, sem cookie)", () => {
|
||||
expect(isPublicPath("/api/v1/system/relogio/tick")).toBe(true);
|
||||
expect(isPublicPath("/api/v1/system/relogio")).toBe(false);
|
||||
expect(isPublicPath("/api/v1/system/relogio/tick/extra")).toBe(false);
|
||||
});
|
||||
|
||||
it("a âncora `$` impede que um sub-path passe de carona", () => {
|
||||
expect(isPublicPath("/api/v1/system/agent/qualquer")).toBe(false);
|
||||
});
|
||||
|
||||
@@ -18,6 +18,9 @@ export const PUBLIC_PATHS: RegExp[] = [
|
||||
// Heartbeat do agente do host (bearer INTERNAL_SECRET/INTERNAL_CRON_SECRET,
|
||||
// checado dentro da própria rota) — sem cookie de sessão, igual /cron/.
|
||||
/^\/api\/v1\/system\/agent$/,
|
||||
// Relógio Hobby (GitHub Actions / cron-job.org). Auth é Bearer na própria
|
||||
// rota — sem isto o proxy devolve 401 e o follow-up waiting_reply nunca anda.
|
||||
/^\/api\/v1\/system\/relogio\/tick$/,
|
||||
/^\/api\/internal\//,
|
||||
/^\/api\/mcp(\/.*)?$/,
|
||||
/^\/_next\//,
|
||||
|
||||
Reference in New Issue
Block a user