Files
backend/src/internal-ssl/ssl-sync-token.guard.ts
T
Alireza HassaniandCursor 016cc15bf0 Add website API docs, SSL api-hosts, and git-only deploy workflow.
Serve public storefront docs at /docs/website, expose api.{domain} hosts for API SSL sync, and require push-then-pull deploys instead of rsync.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-22 21:39:51 +03:30

36 lines
1.0 KiB
TypeScript

import {
CanActivate,
ExecutionContext,
Injectable,
UnauthorizedException,
} from '@nestjs/common';
import { ConfigService } from '@nestjs/config';
import { timingSafeEqual } from 'crypto';
import { Request } from 'express';
@Injectable()
export class SslSyncTokenGuard implements CanActivate {
constructor(private readonly config: ConfigService) {}
canActivate(context: ExecutionContext): boolean {
const expected = this.config.get<string>('SSL_SYNC_TOKEN')?.trim();
if (!expected) {
throw new UnauthorizedException('SSL sync is not configured');
}
const req = context.switchToHttp().getRequest<Request>();
const provided = String(req.headers['x-ssl-sync-token'] ?? '').trim();
if (!provided || provided.length !== expected.length) {
throw new UnauthorizedException('Invalid SSL sync token');
}
const a = Buffer.from(provided);
const b = Buffer.from(expected);
if (!timingSafeEqual(a, b)) {
throw new UnauthorizedException('Invalid SSL sync token');
}
return true;
}
}