summary refs log tree commit diff
path: root/src/api
diff options
context:
space:
mode:
Diffstat (limited to 'src/api')
-rw-r--r--src/api/middlewares/corsMiddleware.js25
-rw-r--r--src/api/middlewares/index.js2
-rw-r--r--src/api/middlewares/loggingMiddleware.js14
-rw-r--r--src/api/start.js36
4 files changed, 46 insertions, 31 deletions
diff --git a/src/api/middlewares/corsMiddleware.js b/src/api/middlewares/corsMiddleware.js
new file mode 100644

index 0000000..2d06d47 --- /dev/null +++ b/src/api/middlewares/corsMiddleware.js
@@ -0,0 +1,25 @@ +export function useCors(req, res, next) { + res.set( + "Content-security-policy", + "default-src * data: blob: filesystem: about: ws: wss: 'unsafe-inline' 'unsafe-eval'; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; connect-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src * data: blob: ; style-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline';", + ); + + res.set("Access-Control-Allow-Origin", "*"); + res.set( + "Access-Control-Allow-Headers", + req.header("Access-Control-Request-Headers") || "*", + ); + res.set( + "Access-Control-Allow-Methods", + req.header("Access-Control-Request-Methods") || "*", + ); + + res.set("Access-Control-Allow-Credentials", "true"); + + // Handle preflight requests + if (req.method === "OPTIONS") { + return res.sendStatus(204); + } + + next(); +} diff --git a/src/api/middlewares/index.js b/src/api/middlewares/index.js new file mode 100644
index 0000000..3f8b800 --- /dev/null +++ b/src/api/middlewares/index.js
@@ -0,0 +1,2 @@ +export * from "./corsMiddleware.js"; +export * from "./loggingMiddleware.js"; diff --git a/src/api/middlewares/loggingMiddleware.js b/src/api/middlewares/loggingMiddleware.js new file mode 100644
index 0000000..7df9b39 --- /dev/null +++ b/src/api/middlewares/loggingMiddleware.js
@@ -0,0 +1,14 @@ +import morgan from "morgan"; + +const requestLogFormat = + ':remote-addr - :remote-user [:date[clf]] ":method :url HTTP/:http-version" :status :res[content-length] ":referrer" ":user-agent" ":response-time ms"'; + +export function useLogging(logRequests) { + return morgan(requestLogFormat, { + skip: (req, res) => { + let skip = !logRequests.includes(res.statusCode); + if (logRequests.startsWith("-")) skip = !skip; + return skip; + }, + }); +} diff --git a/src/api/start.js b/src/api/start.js
index caf7a7c..3540253 100644 --- a/src/api/start.js +++ b/src/api/start.js
@@ -1,44 +1,18 @@ import express from "express"; -import morgan from "morgan"; import { registerRoutes } from "./routes.js"; +import { useCors, useLogging } from "./middlewares/index.js"; const app = express(); -const PORT = process.env.PORT || 3000; +const PORT = process.env.PORT ?? 3000; +const logRequests = process.env["LOG_REQUESTS"] ?? "-"; // Configure Express app.use(express.json()); +app.use(useCors); app.disable("x-powered-by"); -app.use((req, res, next) => { - res.set("Access-Control-Allow-Origin", "*"); - res.set( - "Content-security-policy", - "default-src * data: blob: filesystem: about: ws: wss: 'unsafe-inline' 'unsafe-eval'; script-src * data: blob: 'unsafe-inline' 'unsafe-eval'; connect-src * data: blob: 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src * data: blob: ; style-src * data: blob: 'unsafe-inline'; font-src * data: blob: 'unsafe-inline';", - ); - res.set( - "Access-Control-Allow-Headers", - req.header("Access-Control-Request-Headers") || "*", - ); - res.set( - "Access-Control-Allow-Methods", - req.header("Access-Control-Request-Methods") || "*", - ); - - next(); -}); -const logRequests = process.env["LOG_REQUESTS"] ?? "-"; -const requestLogFormat = - ':remote-addr - :remote-user [:date[clf]] ":method :url HTTP/:http-version" :status :res[content-length] ":referrer" ":user-agent" ":response-time ms"'; if (logRequests) { - app.use( - morgan(requestLogFormat, { - skip: (req, res) => { - let skip = !logRequests.includes(res.statusCode); - if (logRequests.startsWith("-")) skip = !skip; - return skip; - }, - }), - ); + app.use(useLogging(logRequests)); } registerRoutes(app);