Files
worldmonitor/api/_relay.js
Elie Habib bdd8743a26 refactor: dedupe edge api json response assembly (#1702)
* refactor: dedupe edge api json response assembly

* refactor: expand jsonResponse helper to all edge functions

Roll out jsonResponse() from _json-response.js to 16 files (14 handlers
+ 2 shared helpers), eliminating 55 instances of the
new Response(JSON.stringify(...)) boilerplate.

Only exception: health.js uses JSON.stringify(body, null, indent) for
pretty-print mode, which is incompatible with the helper signature.

Replaced local jsonResponse/json() definitions in contact.js,
register-interest.js, and cache-purge.js with the shared import.
2026-03-16 11:52:56 +04:00

107 lines
3.7 KiB
JavaScript

import { getCorsHeaders, isDisallowedOrigin } from './_cors.js';
import { validateApiKey } from './_api-key.js';
import { checkRateLimit } from './_rate-limit.js';
import { jsonResponse } from './_json-response.js';
export function getRelayBaseUrl() {
const relayUrl = process.env.WS_RELAY_URL;
if (!relayUrl) return null;
return relayUrl.replace('wss://', 'https://').replace('ws://', 'http://').replace(/\/$/, '');
}
export function getRelayHeaders(baseHeaders = {}) {
const headers = { ...baseHeaders };
const relaySecret = process.env.RELAY_SHARED_SECRET || '';
if (relaySecret) {
const relayHeader = (process.env.RELAY_AUTH_HEADER || 'x-relay-key').toLowerCase();
headers[relayHeader] = relaySecret;
headers.Authorization = `Bearer ${relaySecret}`;
}
return headers;
}
export async function fetchWithTimeout(url, options, timeoutMs = 15000) {
const controller = new AbortController();
const timeout = setTimeout(() => controller.abort(), timeoutMs);
try {
return await fetch(url, { ...options, signal: controller.signal });
} finally {
clearTimeout(timeout);
}
}
export function createRelayHandler(cfg) {
return async function handler(req) {
const corsHeaders = getCorsHeaders(req, 'GET, OPTIONS');
if (isDisallowedOrigin(req)) {
return jsonResponse({ error: 'Origin not allowed' }, 403, corsHeaders);
}
if (req.method === 'OPTIONS') {
return new Response(null, { status: 204, headers: corsHeaders });
}
if (req.method !== 'GET') {
return jsonResponse({ error: 'Method not allowed' }, 405, corsHeaders);
}
if (cfg.requireApiKey) {
const keyCheck = validateApiKey(req);
if (keyCheck.required && !keyCheck.valid) {
return jsonResponse({ error: keyCheck.error }, 401, corsHeaders);
}
}
if (cfg.requireRateLimit) {
const rateLimitResponse = await checkRateLimit(req, corsHeaders);
if (rateLimitResponse) return rateLimitResponse;
}
const relayBaseUrl = getRelayBaseUrl();
if (!relayBaseUrl) {
if (cfg.fallback) return cfg.fallback(req, corsHeaders);
return jsonResponse({ error: 'WS_RELAY_URL is not configured' }, 503, corsHeaders);
}
try {
const requestUrl = new URL(req.url);
const path = typeof cfg.buildRelayPath === 'function'
? cfg.buildRelayPath(req, requestUrl)
: cfg.relayPath;
const search = cfg.forwardSearch !== false ? (requestUrl.search || '') : '';
const relayUrl = `${relayBaseUrl}${path}${search}`;
const reqHeaders = cfg.requestHeaders || { Accept: 'application/json' };
const response = await fetchWithTimeout(relayUrl, {
headers: getRelayHeaders(reqHeaders),
}, cfg.timeout || 15000);
if (cfg.onlyOk && !response.ok && cfg.fallback) {
return cfg.fallback(req, corsHeaders);
}
const extraHeaders = cfg.extraHeaders ? cfg.extraHeaders(response) : {};
const body = await response.text();
const isSuccess = response.status >= 200 && response.status < 300;
const cacheHeaders = cfg.cacheHeaders ? cfg.cacheHeaders(isSuccess) : {};
return new Response(body, {
status: response.status,
headers: {
'Content-Type': response.headers.get('content-type') || 'application/json',
...cacheHeaders,
...extraHeaders,
...corsHeaders,
},
});
} catch (error) {
if (cfg.fallback) return cfg.fallback(req, corsHeaders);
const isTimeout = error?.name === 'AbortError';
return jsonResponse({
error: isTimeout ? 'Relay timeout' : 'Relay request failed',
details: error?.message || String(error),
}, isTimeout ? 504 : 502, corsHeaders);
}
};
}