forked from ytgov/internal-data-portal
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request #57 from icefoganalytics/issue-54/dataset-visualiz…
…e-dataset-entry-search-and-download Dataset Visualize Dataset Entry Search and Download
- Loading branch information
Showing
35 changed files
with
1,450 additions
and
39 deletions.
There are no files selected for viewing
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,29 @@ | ||
import { TEMPORARY_ACCESS_COOKIE_NAME } from "@/middlewares/temporary-access-cookie-hoist-middleware" | ||
|
||
import BaseController from "@/controllers/base-controller" | ||
|
||
export const TEMPORARY_ACCESS_COOKIE_EXPIRY = 60 * 1000 // 1 minute in milliseconds | ||
|
||
export class TemporaryAccessCookieController extends BaseController { | ||
async create() { | ||
const authHeader = this.request.headers.authorization | ||
if (authHeader && authHeader.startsWith("Bearer ")) { | ||
const token = authHeader.substring(7, authHeader.length) | ||
|
||
const secure = process.env.NODE_ENV !== "development" | ||
this.response.cookie(TEMPORARY_ACCESS_COOKIE_NAME, token, { | ||
httpOnly: true, | ||
secure, | ||
sameSite: "strict", | ||
maxAge: TEMPORARY_ACCESS_COOKIE_EXPIRY, | ||
}) | ||
this.response.end() | ||
} else { | ||
this.response.status(401).send({ | ||
message: "Authorization token missing or improperly formatted", | ||
}) | ||
} | ||
} | ||
} | ||
|
||
export default TemporaryAccessCookieController |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,25 @@ | ||
import { Request, Response, NextFunction } from "express" | ||
|
||
export type RequestWithFormat = Request & { | ||
format?: string | ||
} | ||
|
||
/** | ||
* Adds support for /my/url.xxx on all routes, where xxx is a format | ||
* | ||
* TODO: also support /my/url?format=xxx style | ||
*/ | ||
export default function pathFormatMiddleware(req: RequestWithFormat, res: Response, next: NextFunction) { | ||
const formatRegex = /(.+)\.(\w+)$/ | ||
const match = req.path.match(formatRegex) | ||
|
||
if (match) { | ||
// Add the format as a parameter to req.params | ||
req.format = match[2] | ||
|
||
// Modify the URL path to strip off the format | ||
req.url = match[1] | ||
} | ||
|
||
next() | ||
} |
18 changes: 18 additions & 0 deletions
18
api/src/middlewares/temporary-access-cookie-hoist-middleware.ts
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,18 @@ | ||
import { Request, Response, NextFunction } from "express" | ||
|
||
export const TEMPORARY_ACCESS_COOKIE_NAME = "temporary_access_token" | ||
|
||
export function temporaryAccessCookieHoistMiddleware( | ||
req: Request, | ||
res: Response, | ||
next: NextFunction | ||
) { | ||
const temporaryAccessToken = req.cookies?.[TEMPORARY_ACCESS_COOKIE_NAME] | ||
if (temporaryAccessToken && !req.headers.authorization) { | ||
req.headers.authorization = `Bearer ${temporaryAccessToken}` | ||
} | ||
|
||
next() | ||
} | ||
|
||
export default temporaryAccessCookieHoistMiddleware |
Oops, something went wrong.