MCPcopy Create free account
hub / github.com/PIKACHUIM/CFWorkerACME / apiAuthMiddleware

Function apiAuthMiddleware

src/routes/openapi.ts:72–91  ·  view source on GitHub ↗

* 鉴权 + 限流中间件 * 将当前用户挂到 c.set("apiUser", user)

(c: Context, next: Next)

Source from the content-addressed store, hash-verified

70 * 将当前用户挂到 c.set("apiUser", user)
71 */
72async function apiAuthMiddleware(c: Context, next: Next): Promise<Response | void> {
73 const parsed = parseAuth(c);
74 if (!parsed) {
75 return c.json({code: "UNAUTHORIZED", message: "缺少鉴权头 X-API-Mail / X-API-Token"}, 401);
76 }
77 const dao = await ensureDao(c.env as any);
78 const user = await dao.getUser(parsed.mail);
79 if (!user || !user.apis || user.apis !== parsed.token) {
80 return c.json({code: "UNAUTHORIZED", message: "鉴权失败"}, 401);
81 }
82 if (Number(user.flag) !== 1) {
83 return c.json({code: "ACCOUNT_INACTIVE", message: "账号未激活或已禁用"}, 403);
84 }
85 const limit = await readInt(c.env as any, "API_RATE_LIMIT", 60);
86 if (!rateLimit(user.mail, Math.max(1, limit))) {
87 return c.json({code: "RATE_LIMITED", message: "请求过于频繁,请稍后重试"}, 429);
88 }
89 c.set("apiUser", user);
90 await next();
91}
92
93/** 对订单进行所有权校验(管理员默认可读) */
94async function ownsApply(dao: any, user: UserRow, uuid: string): Promise<ApplyRow | null> {

Callers

nothing calls this directly

Calls 6

ensureDaoFunction · 0.90
readIntFunction · 0.90
parseAuthFunction · 0.85
rateLimitFunction · 0.85
getUserMethod · 0.65
nextFunction · 0.50

Tested by

no test coverage detected