fix(security): authorize site uploads and harden tokens, media and request identity
This commit is contained in:
1 parent
52f6d1491f
commit
8abfe352ef
70 files changed
+1609
-204
No files matched your search
@@ -7,7 +7,7 @@ import { db, RadioListenerPoints } from "@/lib/db";
|
||||
// radio_listener_points.points rows for that user_id.
|
||||
|
||||
export async function GET(req: Request) {
|
||||
const uid = await bearerUserId(req);
|
||||
const uid = await bearerUserId(req, ["radio:read"]);
|
||||
if (!uid) return apiError("Unauthorized", 401);
|
||||
|
||||
try {
|
||||
|
||||
@@ -69,7 +69,7 @@ export async function GET(_req: Request) {
|
||||
|
||||
// Post a new radio shout as the Bearer-authed user into radio_shouts.
|
||||
export async function POST(req: Request) {
|
||||
const uid = await bearerUserId(req);
|
||||
const uid = await bearerUserId(req, ["radio:write"]);
|
||||
if (!uid) return apiError("Unauthorized", 401);
|
||||
|
||||
if (!(await rateLimit(`radio-shout:${uid}`, 10, 60_000)).ok) {
|
||||
|
||||
Reference in new issue
Block a user