1773ed5f95
Mirror to GitHub / mirror (push) Successful in 26s
Test and Lint / backend-test (push) Successful in 1m11s
continuous-integration/drone/push Build is passing
Test and Lint / frontend-test (push) Successful in 2m28s
Version and Release / version-bump (push) Successful in 32s
Version and Release / trigger-drone (push) Has been skipped
Original: feat: enhance security logging and ensure rate limit blocks are properly tracked - Add comprehensive logging for rate limit blocks with full request details - IP address (with proper proxy detection), user agent, headers, timestamps - Rate limit info (current count, limit, remaining, reset time) - Separate tracking for auth vs general endpoints - Enhance authentication failure logging - JWT validation failures with detailed error info - Admin auth attempts without token - Failed token validation with user context - All events include IP, path, method, user agent - Improve Winston logger configuration for production - Add automatic log rotation (10MB errors, 50MB combined) - Create separate security.log for auth/rate limit events - Ensure logs directory exists automatically - Add structured JSON format for log aggregation - Support container logging with LOG_TO_CONSOLE env var - Create comprehensive documentation - Security logging guide with examples - Monitoring recommendations - Configuration reference - Add test script to verify logging functionality All rate limit settings remain configurable via admin panel: - Window duration, max requests, auth limits - Skip authenticated requests option - Public endpoints only option 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <noreply@anthropic.com>
86 lines
2.5 KiB
JavaScript
Executable File
86 lines
2.5 KiB
JavaScript
Executable File
#!/usr/bin/env node
|
|
|
|
/**
|
|
* Script to test photo authentication
|
|
* Usage: node scripts/test-photo-auth.js <jwt-token>
|
|
*/
|
|
|
|
const axios = require('axios');
|
|
|
|
async function testPhotoAuth(token) {
|
|
if (!token) {
|
|
console.error('Usage: node scripts/test-photo-auth.js <jwt-token>');
|
|
console.error('\nTo get a token, login to a gallery and check localStorage for gallery_token_<slug>');
|
|
process.exit(1);
|
|
}
|
|
|
|
const baseUrl = process.env.API_URL || 'http://localhost:3001';
|
|
|
|
console.log(`Testing photo authentication with token: ${token.substring(0, 20)}...`);
|
|
console.log(`Base URL: ${baseUrl}\n`);
|
|
|
|
// Test URLs
|
|
const tests = [
|
|
{
|
|
name: 'Thumbnail via static route',
|
|
url: `${baseUrl}/thumbnails/thumb_Test_Gallery_uncategorized_5210.jpg`,
|
|
headers: { 'Authorization': `Bearer ${token}` }
|
|
},
|
|
{
|
|
name: 'Photo via static route',
|
|
url: `${baseUrl}/photos/wedding-test-gallery-2025-07-14-1/Test_Gallery_uncategorized_5210.jpg`,
|
|
headers: { 'Authorization': `Bearer ${token}` }
|
|
},
|
|
{
|
|
name: 'Gallery photos API',
|
|
url: `${baseUrl}/api/gallery/wedding-test-gallery-2025-07-14-1/photos`,
|
|
headers: { 'Authorization': `Bearer ${token}` }
|
|
}
|
|
];
|
|
|
|
for (const test of tests) {
|
|
console.log(`Testing: ${test.name}`);
|
|
console.log(`URL: ${test.url}`);
|
|
|
|
try {
|
|
const response = await axios.get(test.url, {
|
|
headers: test.headers,
|
|
validateStatus: () => true // Don't throw on any status
|
|
});
|
|
|
|
console.log(`Status: ${response.status}`);
|
|
console.log(`Headers:`, response.headers['content-type']);
|
|
|
|
if (response.status === 200) {
|
|
if (test.name.includes('API')) {
|
|
console.log(`Photos count: ${response.data.photos?.length || 0}`);
|
|
} else {
|
|
console.log(`Content length: ${response.headers['content-length']} bytes`);
|
|
}
|
|
} else {
|
|
console.log(`Error:`, response.data);
|
|
}
|
|
} catch (error) {
|
|
console.log(`Network error:`, error.message);
|
|
}
|
|
|
|
console.log('---\n');
|
|
}
|
|
|
|
// Decode token to show info
|
|
try {
|
|
const parts = token.split('.');
|
|
const payload = JSON.parse(Buffer.from(parts[1], 'base64').toString());
|
|
console.log('Token payload:', payload);
|
|
} catch (error) {
|
|
console.log('Failed to decode token');
|
|
}
|
|
}
|
|
|
|
// Get token from command line
|
|
const token = process.argv[2];
|
|
|
|
testPhotoAuth(token).catch(error => {
|
|
console.error('Test failed:', error);
|
|
process.exit(1);
|
|
}); |