This commit is contained in:
Shotaro Nakamura
2026-06-21 10:34:34 +09:00
parent 30639c5ae4
commit 17c5a1156e
4 changed files with 76 additions and 55 deletions
+3 -3
View File
@@ -20,14 +20,14 @@ export type StoredSbiPasskeySecret = {
deviceId?: string
}
const requireAuth: MiddlewareHandler<AppBindings> = async (c, next) => {
if (!c.get('authenticated')) return c.json({ error: 'unauthorized' }, 401)
const requireOwnerSession: MiddlewareHandler<AppBindings> = async (c, next) => {
if (c.get('auth').type !== 'session') return c.json({ error: 'unauthorized' }, 401)
await next()
}
export const createAdminRoutes = () => {
const app = new Hono<AppBindings>()
app.use('*', requireAuth)
app.use('*', requireOwnerSession)
app.get('/api-keys', async (c) => c.json({ apiKeys: await listApiKeys(c.get('db')) }))
+5 -2
View File
@@ -1,5 +1,6 @@
import { eq } from 'drizzle-orm'
import { Hono } from 'hono'
import type { Context } from 'hono'
import type { AppBindings } from '../context'
import { oauthClients } from '../db/schema'
import type { ApiKeySettings } from '../security/api-keys'
@@ -31,11 +32,13 @@ const redirectUriAllowed = (redirectUri: string, registeredUris: string[]) => {
})
}
const isOwnerSession = (c: Context<AppBindings>) => c.get('auth').type === 'session'
export const createOAuthRoutes = () => {
const app = new Hono<AppBindings>()
app.get('/client/:id', async (c) => {
if (!c.get('authenticated')) return c.json({ error: 'unauthorized' }, 401)
if (!isOwnerSession(c)) return c.json({ error: 'unauthorized' }, 401)
const [client] = await c
.get('db')
.select()
@@ -46,7 +49,7 @@ export const createOAuthRoutes = () => {
})
app.post('/approve', async (c) => {
if (!c.get('authenticated')) return c.json({ error: 'unauthorized' }, 401)
if (!isOwnerSession(c)) return c.json({ error: 'unauthorized' }, 401)
const body = await c.req.json<{
clientId?: string
redirectUri?: string