MiniSearch / server /validateAccessKeyServerHook.ts
github-actions[bot]
Sync from https://github.com/felladrin/MiniSearch
6c3af4e
Raw
History Blame Contribute Delete
4.36 kB
import { argon2Verify } from "hash-wasm";
import type { PreviewServer, ViteDevServer } from "vite";
import { ARGON2_HASH_PREFIX } from "../shared/argon2Parameters.ts";
import { consumeRateLimitPoint } from "./verifyTokenAndRateLimit.ts";
/**
* The body is one argon2 encoded hash (~130 bytes), so a few KiB is generous.
* Without a cap a caller can stream unbounded bytes into the string before
* `JSON.parse` ever runs; the same lever `/inference` closes with its 1 MiB cap.
*/
const MAX_BODY_BYTES = 4 * 1024;
/** POST /api/validate-access-key: checks an argon2id hash against the configured `ACCESS_KEYS`. */
export function validateAccessKeyServerHook<
T extends ViteDevServer | PreviewServer,
>(server: T) {
server.middlewares.use(async (req, res, next) => {
if (req.url !== "/api/validate-access-key" || req.method !== "POST") {
return next();
}
// Consume a rate-limit point before the argon2 loop. A wrong hash costs one
// full argon2 verification per configured key, so nothing may bound that
// work other than the limiter - the same lever the search token path closes.
// It shares the search path's limiter, so a caller cannot hold a second
// budget. The answer is a 429, not a `{ valid: false }`, so a client can
// tell "too many attempts" from "wrong key".
if (!(await consumeRateLimitPoint(req))) {
res.statusCode = 429;
res.setHeader("Content-Type", "application/json");
res.end(JSON.stringify({ error: "Too many requests." }));
return;
}
const accessKeys = process.env.ACCESS_KEYS?.split(",") ?? [];
const chunks: Buffer[] = [];
let bodyBytes = 0;
let bodyTooLarge = false;
req.on("data", (chunk) => {
if (bodyTooLarge) return;
bodyBytes += Buffer.byteLength(chunk);
if (bodyBytes <= MAX_BODY_BYTES) {
// Decoded once at the end, so a multi-byte sequence split across two
// chunks survives. Bounded by the cap above.
chunks.push(Buffer.from(chunk));
return;
}
bodyTooLarge = true;
res.statusCode = 413;
res.setHeader("Content-Type", "application/json");
// The socket is dropped below to cut the upload off, and a keep-alive
// client that had pooled it would send its next request into a dead
// connection. Closing tells it not to pool this one.
res.setHeader("Connection", "close");
res.end(JSON.stringify({ error: "Request body too large" }), () => {
// Only once the 413 is on the wire, so the answer is not truncated.
// Either this or the header above bounds the read; with neither, Node
// drains the whole upload to keep the connection reusable. Measured on
// an 8 MiB flood: 64 KiB here, 191 KiB on the header alone, all 8 MiB
// with neither. What the header uniquely buys is the caller's next
// request, which would otherwise land on this dropped socket.
req.destroy();
});
});
req.on("end", async () => {
if (bodyTooLarge) return;
try {
const { accessKeyHash } = JSON.parse(Buffer.concat(chunks).toString());
// The client hashes with the shared parameters, so a hash carrying any
// other block cannot be valid against this server. Checking before
// argon2Verify refuses a mismatch for free, before any allocation or
// work starts. Without it a caller could embed m=4194304,t=1000,p=1 and
// force a multi-gigabyte allocation per configured key.
if (
typeof accessKeyHash !== "string" ||
!accessKeyHash.startsWith(ARGON2_HASH_PREFIX)
) {
res.setHeader("Content-Type", "application/json");
res.end(JSON.stringify({ valid: false }));
return;
}
let isValid = false;
for (const key of accessKeys) {
try {
if (await argon2Verify({ password: key, hash: accessKeyHash })) {
isValid = true;
break;
}
} catch (error) {
void error;
}
}
res.setHeader("Content-Type", "application/json");
res.end(JSON.stringify({ valid: isValid }));
} catch {
res.statusCode = 400;
res.end(JSON.stringify({ valid: false, error: "Invalid request" }));
}
});
});
}