Files
Socialflow/server/middleware/apiKey.ts
T
MichaelandClaude Sonnet 4.6 391acfdb83 feat: add external API for publishing posts with image URL and scheduling
- New POST /api/v1/publish endpoint: download image from URL, create post and schedule it per page
- New GET /api/v1/pages endpoint: list available pages for external callers
- API key auth via X-API-Key header, configurable from admin settings (stored in DB)
- New app_config table (migration included) to store the external API key
- Admin-only settings section (desktop + mobile) to set/revoke the key
- Fallback to EXTERNAL_API_KEY env var if no DB key is configured

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-06 13:12:27 +02:00

29 lines
880 B
TypeScript

import type { Request, Response, NextFunction } from "express";
import { storage } from "../storage";
export async function requireApiKey(req: Request, res: Response, next: NextFunction) {
const provided = req.headers["x-api-key"];
if (!provided) {
return res.status(401).json({ error: "Clé API manquante (header X-API-Key requis)" });
}
try {
const config = await storage.getAppConfig();
const key = config?.externalApiKey || process.env.EXTERNAL_API_KEY;
if (!key) {
return res.status(503).json({ error: "API externe non configurée" });
}
if (provided !== key) {
return res.status(401).json({ error: "Clé API invalide" });
}
next();
} catch (error) {
console.error("[apiKey middleware] Error:", error);
return res.status(500).json({ error: "Erreur interne lors de la vérification de la clé API" });
}
}