Staff report: add shared-secret key validator
This commit is contained in:
@@ -0,0 +1,18 @@
|
||||
/**
|
||||
* Shared-secret auth for the internal staff routes.
|
||||
*
|
||||
* Staff hit URLs of the form /staff/report?org=<id>&key=<secret>. The
|
||||
* secret is read from the STAFF_REPORT_KEY env var. If unset, the routes
|
||||
* refuse every request (closed by default).
|
||||
*
|
||||
* Stub mode (CIVI_* unset) does NOT bypass this check — we want to test
|
||||
* the auth surface in dev too. For local dev, set STAFF_REPORT_KEY=dev in
|
||||
* .env.local.
|
||||
*/
|
||||
|
||||
export function isStaffKeyValid(key: string | null | undefined): boolean {
|
||||
const expected = process.env.STAFF_REPORT_KEY;
|
||||
if (!expected) return false;
|
||||
if (!key) return false;
|
||||
return key === expected;
|
||||
}
|
||||
Reference in New Issue
Block a user