Import aus Monorepo (frischer Start)
This commit is contained in:
commit
94e79f12ac
34 files changed
+7438
No files matched your search
@@ -0,0 +1,37 @@
|
||||
/**
|
||||
* Skrift – API-Key-Hook
|
||||
* ---------------------------------------------------------------------------
|
||||
* Beim Anlegen eines api_clients-Eintrags wird automatisch ein API-Key erzeugt:
|
||||
* - key_hash = SHA-256 des Keys (dauerhaft; nur damit authentifiziert die API)
|
||||
* - key_prefix = Erkennungspräfix (Anzeige)
|
||||
* - key_plain = Klartext-Key, EINMALIG sichtbar (jetzt kopieren)
|
||||
*
|
||||
* Bei der nächsten Änderung des Eintrags wird key_plain wieder geleert
|
||||
* („reveal once"). Der Klartext wird also nie dauerhaft gespeichert.
|
||||
*/
|
||||
import crypto from 'node:crypto';
|
||||
|
||||
const sha256 = (s) => crypto.createHash('sha256').update(String(s)).digest('hex');
|
||||
|
||||
export default (register) => {
|
||||
// Anlegen: Key erzeugen, sofern noch keiner gesetzt ist.
|
||||
register.filter('api_clients.items.create', (payload) => {
|
||||
if (payload && typeof payload === 'object' && !payload.key_hash) {
|
||||
const key = `sk_live_${crypto.randomBytes(24).toString('base64url')}`;
|
||||
payload.key_hash = sha256(key);
|
||||
payload.key_prefix = key.slice(0, 14);
|
||||
payload.key_plain = key; // einmalige Anzeige
|
||||
if (payload.active === undefined) payload.active = true;
|
||||
}
|
||||
return payload;
|
||||
});
|
||||
|
||||
// Jede spätere Änderung entfernt den Klartext (nur direkt nach Anlage sichtbar),
|
||||
// außer er wird gerade explizit gesetzt.
|
||||
register.filter('api_clients.items.update', (payload) => {
|
||||
if (payload && typeof payload === 'object' && payload.key_plain === undefined) {
|
||||
payload.key_plain = null;
|
||||
}
|
||||
return payload;
|
||||
});
|
||||
};
|
||||
Reference in new issue
Block a user