| 13 | }; |
| 14 | |
| 15 | export const verifyAuth = (req: Request) => { |
| 16 | const authHeader = req.headers.get('Authorization'); |
| 17 | if (!authHeader) { |
| 18 | throw new StatusError(401, 'Unauthorized. Missing authorization header.'); |
| 19 | } |
| 20 | const [scheme, encoded] = authHeader.split(' '); |
| 21 | |
| 22 | // The Authorization header must start with Bearer, followed by a space. |
| 23 | if (!encoded || scheme !== 'Bearer') { |
| 24 | throw new StatusError(400, 'Bad Request. Malformed authorization header.'); |
| 25 | } |
| 26 | |
| 27 | if (encoded !== process.env.UPLOAD_KEY) { |
| 28 | throw new StatusError(401, 'Unauthorized. Invalid authorization token.'); |
| 29 | } |
| 30 | }; |
| 31 | |
| 32 | interface Tag { |
| 33 | id: string; |