Files
sign/packages/trpc/server/trpc.ts

133 lines
3.4 KiB
TypeScript
Raw Normal View History

2023-06-09 18:21:18 +10:00
import { TRPCError, initTRPC } from '@trpc/server';
import SuperJSON from 'superjson';
2024-12-14 01:23:35 +09:00
import type { OpenApiMeta } from 'trpc-openapi';
2023-06-09 18:21:18 +10:00
import { AppError, genericErrorCodeToTrpcErrorCodeMap } from '@documenso/lib/errors/app-error';
2023-10-11 12:32:33 +03:00
import { isAdmin } from '@documenso/lib/next-auth/guards/is-admin';
2024-12-14 01:23:35 +09:00
import { getApiTokenByToken } from '@documenso/lib/server-only/public-api/get-api-token-by-token';
2023-10-11 12:32:33 +03:00
import type { TrpcContext } from './context';
2023-06-09 18:21:18 +10:00
2024-12-14 01:23:35 +09:00
const t = initTRPC
.meta<OpenApiMeta>()
.context<TrpcContext>()
.create({
transformer: SuperJSON,
errorFormatter(opts) {
const { shape, error } = opts;
2024-12-14 01:23:35 +09:00
const originalError = error.cause;
2024-12-14 01:23:35 +09:00
let data: Record<string, unknown> = shape.data;
2024-12-14 01:23:35 +09:00
// Default unknown errors to 400, since if you're throwing an AppError it is expected
// that you already know what you're doing.
if (originalError instanceof AppError) {
data = {
...data,
appError: AppError.toJSON(originalError),
code: originalError.code,
httpStatus:
originalError.statusCode ??
genericErrorCodeToTrpcErrorCodeMap[originalError.code]?.status ??
400,
};
}
2024-12-14 01:23:35 +09:00
return {
...shape,
data,
};
},
});
2023-06-09 18:21:18 +10:00
/**
* Middlewares
*/
2023-08-29 13:01:19 +10:00
export const authenticatedMiddleware = t.middleware(async ({ ctx, next }) => {
2024-12-14 01:23:35 +09:00
const authorizationHeader = ctx.req.headers.authorization;
// Taken from `authenticatedMiddleware` in `@documenso/api/v1/middleware/authenticated.ts`.
if (authorizationHeader) {
// Support for both "Authorization: Bearer api_xxx" and "Authorization: api_xxx"
const [token] = (authorizationHeader || '').split('Bearer ').filter((s) => s.length > 0);
if (!token) {
throw new Error('Token was not provided for authenticated middleware');
}
const apiToken = await getApiTokenByToken({ token });
return await next({
ctx: {
...ctx,
user: apiToken.user,
session: null,
source: 'api',
},
});
}
2023-06-09 18:21:18 +10:00
if (!ctx.session) {
throw new TRPCError({
code: 'UNAUTHORIZED',
message: 'You must be logged in to perform this action.',
});
}
2023-08-29 13:01:19 +10:00
return await next({
2023-06-09 18:21:18 +10:00
ctx: {
...ctx,
user: ctx.user,
session: ctx.session,
2024-12-14 01:23:35 +09:00
source: 'app',
2023-06-09 18:21:18 +10:00
},
});
});
export const maybeAuthenticatedMiddleware = t.middleware(async ({ ctx, next }) => {
return await next({
ctx: {
...ctx,
user: ctx.user,
session: ctx.session,
},
});
});
2023-10-11 12:32:33 +03:00
export const adminMiddleware = t.middleware(async ({ ctx, next }) => {
if (!ctx.session || !ctx.user) {
throw new TRPCError({
code: 'UNAUTHORIZED',
message: 'You must be logged in to perform this action.',
});
}
const isUserAdmin = isAdmin(ctx.user);
if (!isUserAdmin) {
throw new TRPCError({
code: 'UNAUTHORIZED',
message: 'Not authorized to perform this action.',
});
}
return await next({
ctx: {
...ctx,
user: ctx.user,
session: ctx.session,
},
});
});
2023-06-09 18:21:18 +10:00
/**
* Routers and Procedures
*/
export const router = t.router;
export const procedure = t.procedure;
export const authenticatedProcedure = t.procedure.use(authenticatedMiddleware);
// While this is functionally the same as `procedure`, it's useful for indicating purpose
export const maybeAuthenticatedProcedure = t.procedure.use(maybeAuthenticatedMiddleware);
2023-10-11 12:32:33 +03:00
export const adminProcedure = t.procedure.use(adminMiddleware);