security: harden production configuration and routes
Run Tests on Branches / Detect Changes (push) Successful in 12s
Run Tests on Branches / Frontend Tests (push) Successful in 2m12s
Run Tests on Branches / Frontend Mobile Tests (push) Has been skipped
Run Tests on Branches / Parapharmacy API Tests (push) Successful in 2m2s
Run Tests on Branches / PIP Platform Tests (push) Has been skipped
Run Tests on Branches / Backend Tests (push) Successful in 2m8s
Run Tests on Branches / Detect Changes (push) Successful in 12s
Run Tests on Branches / Frontend Tests (push) Successful in 2m12s
Run Tests on Branches / Frontend Mobile Tests (push) Has been skipped
Run Tests on Branches / Parapharmacy API Tests (push) Successful in 2m2s
Run Tests on Branches / PIP Platform Tests (push) Has been skipped
Run Tests on Branches / Backend Tests (push) Successful in 2m8s
This commit is contained in:
@@ -1,5 +1,6 @@
|
||||
import { Router } from 'express';
|
||||
import Product from '../models/Product.js';
|
||||
import { requireServiceKey } from '../middleware/service-auth.js';
|
||||
|
||||
const router = Router();
|
||||
|
||||
@@ -208,7 +209,7 @@ router.get('/:id', async (req, res) => {
|
||||
* 201:
|
||||
* description: Product created/updated
|
||||
*/
|
||||
router.post('/', async (req, res) => {
|
||||
router.post('/', requireServiceKey('INGEST_API_KEY'), async (req, res) => {
|
||||
try {
|
||||
const {
|
||||
name,
|
||||
@@ -277,13 +278,16 @@ router.post('/', async (req, res) => {
|
||||
* 200:
|
||||
* description: Upsert results
|
||||
*/
|
||||
router.post('/bulk', async (req, res) => {
|
||||
router.post('/bulk', requireServiceKey('INGEST_API_KEY'), async (req, res) => {
|
||||
try {
|
||||
const { products } = req.body;
|
||||
|
||||
if (!Array.isArray(products)) {
|
||||
return res.status(400).json({ error: 'products must be an array' });
|
||||
}
|
||||
if (products.length > 100) {
|
||||
return res.status(413).json({ error: 'products exceeds the maximum batch size of 100' });
|
||||
}
|
||||
|
||||
const results = {
|
||||
created: 0,
|
||||
@@ -337,7 +341,7 @@ router.post('/bulk', async (req, res) => {
|
||||
* 404:
|
||||
* description: Product not found
|
||||
*/
|
||||
router.put('/:id', async (req, res) => {
|
||||
router.put('/:id', requireServiceKey('ADMIN_API_KEY'), async (req, res) => {
|
||||
try {
|
||||
const product = await Product.findByIdAndUpdate(
|
||||
req.params.id,
|
||||
@@ -374,7 +378,7 @@ router.put('/:id', async (req, res) => {
|
||||
* 404:
|
||||
* description: Product not found
|
||||
*/
|
||||
router.delete('/:id', async (req, res) => {
|
||||
router.delete('/:id', requireServiceKey('ADMIN_API_KEY'), async (req, res) => {
|
||||
try {
|
||||
const product = await Product.findByIdAndDelete(req.params.id);
|
||||
|
||||
|
||||
@@ -1,12 +1,23 @@
|
||||
import { Router } from 'express';
|
||||
import { scrapeAll } from '../scraper.js';
|
||||
import rateLimit from 'express-rate-limit';
|
||||
import { requireServiceKey } from '../middleware/service-auth.js';
|
||||
|
||||
const router = Router();
|
||||
const scrapeLimiter = rateLimit({
|
||||
windowMs: 15 * 60 * 1000,
|
||||
max: 5,
|
||||
standardHeaders: true,
|
||||
legacyHeaders: false,
|
||||
});
|
||||
|
||||
// Trigger scraping
|
||||
router.post('/scrape', async (req, res) => {
|
||||
router.post('/scrape', scrapeLimiter, requireServiceKey('INGEST_API_KEY'), async (req, res) => {
|
||||
try {
|
||||
const { queries = ['crema hidratante'], sources = ['promofarma'] } = req.body;
|
||||
if (!Array.isArray(queries) || !Array.isArray(sources) || queries.length > 20 || sources.length > 10) {
|
||||
return res.status(400).json({ error: 'queries and sources must be bounded arrays' });
|
||||
}
|
||||
|
||||
console.log('[Scraper] Starting scrape...');
|
||||
console.log(`[Scraper] Queries: ${queries.join(', ')}`);
|
||||
@@ -19,7 +30,7 @@ router.post('/scrape', async (req, res) => {
|
||||
res.json(result);
|
||||
} catch (error) {
|
||||
console.error('[Scraper] Error:', error.message);
|
||||
res.status(500).json({ error: 'Scraping failed', message: error.message });
|
||||
res.status(500).json({ error: 'Scraping failed' });
|
||||
}
|
||||
});
|
||||
|
||||
|
||||
Reference in New Issue
Block a user