File
Blob: src/worker/router.ts
| 1 | import { Hono } from "hono"; |
| 2 | import { cors } from "hono/cors"; |
| 3 | import { ZodError } from "zod"; |
| 4 | |
| 5 | import { createSessionDb, selectHttpSessionConstraint } from "@/worker/db/d1/client"; |
| 6 | import type { AppContext } from "@/worker/app-context"; |
| 7 | import { auth } from "@/worker/routes/auth"; |
| 8 | import { invitesRouter } from "@/worker/routes/invites"; |
| 9 | import { oidcRouter } from "@/worker/routes/oidc"; |
| 10 | import { workspacesRouter } from "@/worker/routes/workspaces"; |
| 11 | import { pagesRouter } from "@/worker/routes/pages"; |
| 12 | import { pageTreeRouter } from "@/worker/routes/page-tree"; |
| 13 | import { pageContextRouter } from "@/worker/routes/page-context"; |
| 14 | import { pageMentionsRouter } from "@/worker/routes/page-mentions"; |
| 15 | import { aiRouter } from "@/worker/routes/ai"; |
| 16 | import { uploadsRouter, uploadServingRouter } from "@/worker/routes/uploads"; |
| 17 | import { searchRouter } from "@/worker/routes/search"; |
| 18 | import { sharesRouter, shareLinkRouter } from "@/worker/routes/shares"; |
| 19 | import { sitesRouter } from "@/worker/routes/sites"; |
| 20 | import { health } from "@/worker/routes/health"; |
| 21 | import { isLocalRequestUrl } from "@/worker/http"; |
| 22 | import { D1_BOOKMARK_HEADER } from "@/shared/bookmark"; |
| 23 | import { createLogger, errorContext } from "@/worker/lib/logger"; |
| 24 | import { isAllowedOrigin } from "@/worker/lib/origins"; |
| 25 | import { applyBaselineSecurityHeaders } from "@/worker/lib/security-headers"; |
| 26 | |
| 27 | const log = createLogger("router"); |
| 28 | const app = new Hono<AppContext>(); |
| 29 | |
| 30 | app.use( |
| 31 | "*", |
| 32 | cors({ |
| 33 | origin: (origin, c) => (isAllowedOrigin(origin, c.env) ? origin : null), |
| 34 | allowMethods: ["GET", "POST", "PATCH", "PUT", "DELETE", "OPTIONS"], |
| 35 | allowHeaders: ["Content-Type", "Authorization", D1_BOOKMARK_HEADER], |
| 36 | exposeHeaders: [D1_BOOKMARK_HEADER], |
| 37 | credentials: true, |
| 38 | maxAge: 86400, |
| 39 | }), |
| 40 | ); |
| 41 | |
| 42 | app.use("*", async (c, next) => { |
| 43 | await next(); |
| 44 | c.res = applyBaselineSecurityHeaders(c.res); |
| 45 | }); |
| 46 | |
| 47 | app.use("*", async (c, next) => { |
| 48 | const bookmark = c.req.header(D1_BOOKMARK_HEADER); |
| 49 | const constraint = selectHttpSessionConstraint(c.req.method, bookmark); |
| 50 | |
| 51 | const { db, session } = createSessionDb(c.env.DB, constraint); |
| 52 | c.set("db", db); |
| 53 | c.set("user", null); |
| 54 | c.set("jwtPayload", null); |
| 55 | |
| 56 | await next(); |
| 57 | |
| 58 | // Return the bookmark for client to use on next request |
| 59 | const latestBookmark = session.getBookmark(); |
| 60 | if (latestBookmark) { |
| 61 | c.header(D1_BOOKMARK_HEADER, latestBookmark); |
| 62 | } |
| 63 | }); |
| 64 | |
| 65 | app.use("*", async (c, next) => { |
| 66 | await next(); |
| 67 | |
| 68 | // Local dev uses 403 here because the current Miniflare/Vite bridge can mis-handle some 401 |
| 69 | // responses and surface them as `fetch failed` overlays instead of returning the JSON body. |
| 70 | if (!isLocalRequestUrl(c.req.url) || c.res.status !== 401) { |
| 71 | return; |
| 72 | } |
| 73 | |
| 74 | c.res = new Response(c.res.body, { |
| 75 | status: 403, |
| 76 | statusText: c.res.statusText, |
| 77 | headers: c.res.headers, |
| 78 | }); |
| 79 | }); |
| 80 | |
| 81 | app.route("/api/v1", health); |
| 82 | app.route("/api/v1", auth); |
| 83 | app.route("/api/v1", oidcRouter); |
| 84 | app.route("/api/v1", invitesRouter); |
| 85 | app.route("/api/v1", workspacesRouter); |
| 86 | app.route("/api/v1", pagesRouter); |
| 87 | app.route("/api/v1", pageTreeRouter); |
| 88 | app.route("/api/v1", uploadsRouter); |
| 89 | app.route("/api/v1", searchRouter); |
| 90 | app.route("/api/v1", sharesRouter); |
| 91 | app.route("/api/v1", shareLinkRouter); |
| 92 | app.route("/api/v1", pageContextRouter); |
| 93 | app.route("/api/v1", pageMentionsRouter); |
| 94 | app.route("/api/v1", aiRouter); |
| 95 | app.route("/api/v1", sitesRouter); |
| 96 | app.route("/uploads", uploadServingRouter); |
| 97 | |
| 98 | app.notFound((c) => { |
| 99 | return c.json({ error: "not_found", message: "Route not found" }, 404); |
| 100 | }); |
| 101 | |
| 102 | app.onError((err, c) => { |
| 103 | if (err instanceof ZodError) { |
| 104 | return c.json({ error: "validation_error", message: "Invalid request body", issues: err.issues }, 400); |
| 105 | } |
| 106 | |
| 107 | log.error("unhandled_error", errorContext(err)); |
| 108 | return c.json({ error: "internal_error", message: "An unexpected error occurred" }, 500); |
| 109 | }); |
| 110 | |
| 111 | export { app }; |