Harden wallet challenge proxy
This commit is contained in:
@@ -10,6 +10,42 @@ import {
|
|||||||
} from "@/lib/api-proxy";
|
} from "@/lib/api-proxy";
|
||||||
|
|
||||||
const API_BASE = process.env.POLYWEATHER_API_BASE_URL;
|
const API_BASE = process.env.POLYWEATHER_API_BASE_URL;
|
||||||
|
const BACKEND_RETRY_DELAY_MS = 250;
|
||||||
|
|
||||||
|
function sleep(ms: number) {
|
||||||
|
return new Promise((resolve) => setTimeout(resolve, ms));
|
||||||
|
}
|
||||||
|
|
||||||
|
async function fetchWalletChallengeWithRetry(
|
||||||
|
url: string,
|
||||||
|
init: RequestInit,
|
||||||
|
attempts = 2,
|
||||||
|
) {
|
||||||
|
let lastError: unknown;
|
||||||
|
for (let attempt = 1; attempt <= attempts; attempt += 1) {
|
||||||
|
try {
|
||||||
|
return await fetch(url, init);
|
||||||
|
} catch (error) {
|
||||||
|
lastError = error;
|
||||||
|
if (attempt >= attempts) break;
|
||||||
|
await sleep(BACKEND_RETRY_DELAY_MS * attempt);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
throw lastError;
|
||||||
|
}
|
||||||
|
|
||||||
|
function logWalletChallengeProxyError(
|
||||||
|
error: unknown,
|
||||||
|
authDebug: Record<string, unknown>,
|
||||||
|
) {
|
||||||
|
const source = error as { name?: unknown; message?: unknown; cause?: unknown };
|
||||||
|
console.error("[payment-wallet-challenge-proxy-exception]", {
|
||||||
|
error_name: String(source?.name || "Error"),
|
||||||
|
error_message: String(source?.message || error || "unknown"),
|
||||||
|
error_cause: source?.cause ? String(source.cause) : "",
|
||||||
|
...authDebug,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
export async function POST(req: NextRequest) {
|
export async function POST(req: NextRequest) {
|
||||||
if (!API_BASE) {
|
if (!API_BASE) {
|
||||||
@@ -18,31 +54,45 @@ export async function POST(req: NextRequest) {
|
|||||||
{ status: 500 },
|
{ status: 500 },
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
let body: unknown;
|
||||||
|
try {
|
||||||
|
body = await req.json();
|
||||||
|
} catch {
|
||||||
|
return NextResponse.json(
|
||||||
|
{ error: "Invalid wallet challenge request" },
|
||||||
|
{ status: 400 },
|
||||||
|
);
|
||||||
|
}
|
||||||
|
let authDebug: Record<string, unknown> = {};
|
||||||
try {
|
try {
|
||||||
const body = await req.json();
|
|
||||||
const auth = await buildBackendRequestHeaders(req);
|
const auth = await buildBackendRequestHeaders(req);
|
||||||
const authError = requireBackendPaymentAuth(auth);
|
const authError = requireBackendPaymentAuth(auth);
|
||||||
if (authError) return authError;
|
if (authError) return authError;
|
||||||
const proxiedHeaders = new Headers(auth.headers);
|
const proxiedHeaders = new Headers(auth.headers);
|
||||||
proxiedHeaders.set("Content-Type", "application/json");
|
proxiedHeaders.set("Content-Type", "application/json");
|
||||||
const res = await fetch(`${API_BASE}/api/payments/wallets/challenge`, {
|
authDebug = {
|
||||||
method: "POST",
|
incoming_has_authorization: Boolean(
|
||||||
headers: proxiedHeaders,
|
String(req.headers.get("authorization") || "").trim(),
|
||||||
body: JSON.stringify(body ?? {}),
|
),
|
||||||
cache: "no-store",
|
has_authorization: proxiedHeaders.has("authorization"),
|
||||||
});
|
has_entitlement: proxiedHeaders.has("x-polyweather-entitlement"),
|
||||||
|
has_forwarded_user_id: proxiedHeaders.has("x-polyweather-auth-user-id"),
|
||||||
|
has_forwarded_email: proxiedHeaders.has("x-polyweather-auth-email"),
|
||||||
|
};
|
||||||
|
const res = await fetchWalletChallengeWithRetry(
|
||||||
|
`${API_BASE}/api/payments/wallets/challenge`,
|
||||||
|
{
|
||||||
|
method: "POST",
|
||||||
|
headers: proxiedHeaders,
|
||||||
|
body: JSON.stringify(body ?? {}),
|
||||||
|
cache: "no-store",
|
||||||
|
},
|
||||||
|
);
|
||||||
if (!res.ok) {
|
if (!res.ok) {
|
||||||
const raw = await res.text();
|
const raw = await res.text();
|
||||||
const response = buildUpstreamErrorResponse(res.status, raw, {
|
const response = buildUpstreamErrorResponse(res.status, raw, {
|
||||||
detailLimit: 350,
|
detailLimit: 350,
|
||||||
extraDebug: {
|
extraDebug: authDebug,
|
||||||
has_authorization: proxiedHeaders.has("authorization"),
|
|
||||||
has_entitlement: proxiedHeaders.has("x-polyweather-entitlement"),
|
|
||||||
has_forwarded_user_id: proxiedHeaders.has(
|
|
||||||
"x-polyweather-auth-user-id",
|
|
||||||
),
|
|
||||||
has_forwarded_email: proxiedHeaders.has("x-polyweather-auth-email"),
|
|
||||||
},
|
|
||||||
});
|
});
|
||||||
return applyAuthResponseCookies(response, auth.response);
|
return applyAuthResponseCookies(response, auth.response);
|
||||||
}
|
}
|
||||||
@@ -50,8 +100,12 @@ export async function POST(req: NextRequest) {
|
|||||||
const response = NextResponse.json(data);
|
const response = NextResponse.json(data);
|
||||||
return applyAuthResponseCookies(response, auth.response);
|
return applyAuthResponseCookies(response, auth.response);
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
|
logWalletChallengeProxyError(error, authDebug);
|
||||||
return buildProxyExceptionResponse(error, {
|
return buildProxyExceptionResponse(error, {
|
||||||
publicMessage: "Failed to create wallet challenge",
|
status: 502,
|
||||||
|
publicMessage:
|
||||||
|
"Wallet challenge service is temporarily unavailable. Please retry.",
|
||||||
|
extra: { retryable: true },
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -44,6 +44,10 @@ export function runTests() {
|
|||||||
);
|
);
|
||||||
|
|
||||||
const accountCenterSource = fs.readFileSync(accountCenterPath, "utf8");
|
const accountCenterSource = fs.readFileSync(accountCenterPath, "utf8");
|
||||||
|
const walletBindSource = fs.readFileSync(
|
||||||
|
path.join(projectRoot, "components", "account", "useWalletBind.ts"),
|
||||||
|
"utf8",
|
||||||
|
);
|
||||||
const hookPath = path.join(
|
const hookPath = path.join(
|
||||||
projectRoot,
|
projectRoot,
|
||||||
"components",
|
"components",
|
||||||
@@ -221,4 +225,25 @@ export function runTests() {
|
|||||||
`${route} must allow bearer-backed payment mutations while still rejecting requests with no auth context`,
|
`${route} must allow bearer-backed payment mutations while still rejecting requests with no auth context`,
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const walletChallengeRouteSource = fs.readFileSync(
|
||||||
|
path.join(projectRoot, "app/api/payments/wallets/challenge/route.ts"),
|
||||||
|
"utf8",
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
walletChallengeRouteSource.includes("fetchWalletChallengeWithRetry"),
|
||||||
|
"wallet challenge proxy must retry a transient backend connection failure before blocking payment",
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
walletChallengeRouteSource.includes("Invalid wallet challenge request"),
|
||||||
|
"wallet challenge proxy must return a client error for malformed JSON instead of a generic payment failure",
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
walletChallengeRouteSource.includes("retryable: true"),
|
||||||
|
"wallet challenge proxy exception response must mark transient failures as retryable",
|
||||||
|
);
|
||||||
|
assert(
|
||||||
|
walletBindSource.includes("readPaymentApiErrorMessage"),
|
||||||
|
"wallet binding errors must show the API error message instead of raw JSON",
|
||||||
|
);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -68,6 +68,29 @@ export type NormalizedPaymentError = {
|
|||||||
userRejected: boolean;
|
userRejected: boolean;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
export async function readPaymentApiErrorMessage(
|
||||||
|
response: Response,
|
||||||
|
fallback = "Request failed",
|
||||||
|
limit = 300,
|
||||||
|
) {
|
||||||
|
const raw = (await response.text()).slice(0, limit);
|
||||||
|
if (!raw) return fallback;
|
||||||
|
try {
|
||||||
|
const parsed = JSON.parse(raw) as {
|
||||||
|
error?: unknown;
|
||||||
|
detail?: unknown;
|
||||||
|
message?: unknown;
|
||||||
|
};
|
||||||
|
const message = [parsed.error, parsed.detail, parsed.message].find(
|
||||||
|
(item) => typeof item === "string" && item.trim(),
|
||||||
|
);
|
||||||
|
if (typeof message === "string") return message.trim();
|
||||||
|
} catch {
|
||||||
|
// Fall back to the raw response body below.
|
||||||
|
}
|
||||||
|
return raw;
|
||||||
|
}
|
||||||
|
|
||||||
export function normalizePaymentError(error: unknown): NormalizedPaymentError {
|
export function normalizePaymentError(error: unknown): NormalizedPaymentError {
|
||||||
const source = error as any;
|
const source = error as any;
|
||||||
const code = Number(
|
const code = Number(
|
||||||
|
|||||||
@@ -16,7 +16,11 @@ import {
|
|||||||
WALLET_TRANSACTION_REQUEST_TIMEOUT_MS,
|
WALLET_TRANSACTION_REQUEST_TIMEOUT_MS,
|
||||||
} from "./constants";
|
} from "./constants";
|
||||||
import { shortAddress } from "./formatters";
|
import { shortAddress } from "./formatters";
|
||||||
import { normalizePaymentError, requestWalletWithTimeout } from "./payment-utils";
|
import {
|
||||||
|
normalizePaymentError,
|
||||||
|
readPaymentApiErrorMessage,
|
||||||
|
requestWalletWithTimeout,
|
||||||
|
} from "./payment-utils";
|
||||||
import {
|
import {
|
||||||
eip6963Providers,
|
eip6963Providers,
|
||||||
getEvmProvider,
|
getEvmProvider,
|
||||||
@@ -300,8 +304,8 @@ export function useWalletBind(params: UseWalletBindParams) {
|
|||||||
method: "POST", headers: authHeaders, body: JSON.stringify({ address }),
|
method: "POST", headers: authHeaders, body: JSON.stringify({ address }),
|
||||||
});
|
});
|
||||||
if (!challengeRes.ok) {
|
if (!challengeRes.ok) {
|
||||||
const raw = (await challengeRes.text()).slice(0, 300);
|
const message = await readPaymentApiErrorMessage(challengeRes);
|
||||||
throw new Error(copy.challengeFailed.replace("{raw}", raw));
|
throw new Error(copy.challengeFailed.replace("{raw}", message));
|
||||||
}
|
}
|
||||||
|
|
||||||
const challengeJson = (await challengeRes.json()) as { nonce?: string; message?: string };
|
const challengeJson = (await challengeRes.json()) as { nonce?: string; message?: string };
|
||||||
@@ -314,8 +318,8 @@ export function useWalletBind(params: UseWalletBindParams) {
|
|||||||
method: "POST", headers: authHeaders, body: JSON.stringify({ address, nonce, signature }),
|
method: "POST", headers: authHeaders, body: JSON.stringify({ address, nonce, signature }),
|
||||||
});
|
});
|
||||||
if (!verifyRes.ok) {
|
if (!verifyRes.ok) {
|
||||||
const raw = (await verifyRes.text()).slice(0, 300);
|
const message = await readPaymentApiErrorMessage(verifyRes);
|
||||||
throw new Error(copy.verifyFailedRaw.replace("{raw}", raw));
|
throw new Error(copy.verifyFailedRaw.replace("{raw}", message));
|
||||||
}
|
}
|
||||||
|
|
||||||
setPaymentInfo(`${walletLabel} 绑定成功: ${shortAddress(address)}。${binanceBindHint || "现在可点击“立即订阅并激活服务”。"}`);
|
setPaymentInfo(`${walletLabel} 绑定成功: ${shortAddress(address)}。${binanceBindHint || "现在可点击“立即订阅并激活服务”。"}`);
|
||||||
|
|||||||
Reference in New Issue
Block a user