Today both proxies are effectively open to anyone who can set an Origin header for trails.cool — a third party can use us as a free BRouter/Overpass relay. Require a live planner session on every call so abuse traffic costs the scraper a session row (observable, revocable) before they can issue a single query. Server: - New `requireSession(id)` helper — returns the session row or a 401 Response. Reused by both route handlers. - `/api/route`: `sessionId` in body is now required and verified; rate-limit key always falls back to the session id. - `/api/overpass`: new `X-Trails-Session` header, verified. Header keeps the session out of the request body so the body-keyed cache is unaffected. Client plumbing: - `useRouting(yjs, sessionId)` — sessionId goes into the /api/route body. - `usePois(sessionId)` → `queryPois(..., sessionId)` → `X-Trails-Session` on the proxy call. - `PlannerMap` + `YjsDebugPanel` gain a `sessionId` prop from `SessionView`. Journal server-to-server: - Demo-bot and `/api/v1/routes/compute` now POST `/api/sessions` to mint a throwaway planner session, then cite it on the forwarded `/api/route` call. Planner's `expire-sessions` cron cleans these up (7d window) so nothing needs explicit teardown. Tests: - 5 unit tests for `requireSession` covering missing / empty / non-string / unknown-session / valid-session cases. - Two integration E2E tests document the 401 for missing session on each proxy. - Pre-existing `/api/route` integration tests updated to mint a session first. Caveat: existing browser tabs lose their /api/route ability until reload (the old JS doesn't know to send sessionId). Acceptable for an anonymous planner. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
51 lines
1.7 KiB
TypeScript
51 lines
1.7 KiB
TypeScript
import { describe, it, expect, vi, beforeEach } from "vitest";
|
|
|
|
vi.mock("./sessions.ts", () => ({
|
|
getSession: vi.fn(),
|
|
}));
|
|
|
|
import { requireSession } from "./require-session.ts";
|
|
import { getSession } from "./sessions.ts";
|
|
|
|
const mockedGetSession = vi.mocked(getSession);
|
|
|
|
beforeEach(() => {
|
|
vi.clearAllMocks();
|
|
});
|
|
|
|
describe("requireSession", () => {
|
|
it("returns the session when it exists and is open", async () => {
|
|
mockedGetSession.mockResolvedValueOnce({ id: "abc" } as never);
|
|
const result = await requireSession("abc");
|
|
expect(result).toEqual({ id: "abc" });
|
|
expect(mockedGetSession).toHaveBeenCalledWith("abc");
|
|
});
|
|
|
|
it("returns 401 when the id is missing", async () => {
|
|
const result = await requireSession(undefined);
|
|
expect(result).toBeInstanceOf(Response);
|
|
expect((result as Response).status).toBe(401);
|
|
expect(mockedGetSession).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it("returns 401 for empty-string id (doesn't look it up)", async () => {
|
|
const result = await requireSession("");
|
|
expect(result).toBeInstanceOf(Response);
|
|
expect((result as Response).status).toBe(401);
|
|
expect(mockedGetSession).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it("returns 401 for a non-string id", async () => {
|
|
const result = await requireSession(null);
|
|
expect(result).toBeInstanceOf(Response);
|
|
expect((result as Response).status).toBe(401);
|
|
expect(mockedGetSession).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it("returns 401 when the session doesn't exist (or is closed)", async () => {
|
|
mockedGetSession.mockResolvedValueOnce(undefined);
|
|
const result = await requireSession("nonexistent");
|
|
expect(result).toBeInstanceOf(Response);
|
|
expect((result as Response).status).toBe(401);
|
|
});
|
|
});
|