security: harden production configuration and routes
Run Tests on Branches / Detect Changes (push) Successful in 12s
Run Tests on Branches / Frontend Tests (push) Successful in 2m12s
Run Tests on Branches / Frontend Mobile Tests (push) Has been skipped
Run Tests on Branches / Parapharmacy API Tests (push) Successful in 2m2s
Run Tests on Branches / PIP Platform Tests (push) Has been skipped
Run Tests on Branches / Backend Tests (push) Successful in 2m8s

This commit is contained in:
Antoni Nuñez Romeu
2026-07-22 17:24:54 +02:00
parent f60af5f6b2
commit 849763896d
21 changed files with 638 additions and 68 deletions
+8 -4
View File
@@ -1,5 +1,6 @@
import { Router } from 'express';
import Product from '../models/Product.js';
import { requireServiceKey } from '../middleware/service-auth.js';
const router = Router();
@@ -208,7 +209,7 @@ router.get('/:id', async (req, res) => {
* 201:
* description: Product created/updated
*/
router.post('/', async (req, res) => {
router.post('/', requireServiceKey('INGEST_API_KEY'), async (req, res) => {
try {
const {
name,
@@ -277,13 +278,16 @@ router.post('/', async (req, res) => {
* 200:
* description: Upsert results
*/
router.post('/bulk', async (req, res) => {
router.post('/bulk', requireServiceKey('INGEST_API_KEY'), async (req, res) => {
try {
const { products } = req.body;
if (!Array.isArray(products)) {
return res.status(400).json({ error: 'products must be an array' });
}
if (products.length > 100) {
return res.status(413).json({ error: 'products exceeds the maximum batch size of 100' });
}
const results = {
created: 0,
@@ -337,7 +341,7 @@ router.post('/bulk', async (req, res) => {
* 404:
* description: Product not found
*/
router.put('/:id', async (req, res) => {
router.put('/:id', requireServiceKey('ADMIN_API_KEY'), async (req, res) => {
try {
const product = await Product.findByIdAndUpdate(
req.params.id,
@@ -374,7 +378,7 @@ router.put('/:id', async (req, res) => {
* 404:
* description: Product not found
*/
router.delete('/:id', async (req, res) => {
router.delete('/:id', requireServiceKey('ADMIN_API_KEY'), async (req, res) => {
try {
const product = await Product.findByIdAndDelete(req.params.id);