-
Notifications
You must be signed in to change notification settings - Fork 1
/
Copy pathmiddleware.ts
34 lines (25 loc) · 959 Bytes
/
middleware.ts
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
// This middleware is to protect the proxied api to be called only by the same host
// In the future it could get more logic, for example JWT tokens, etc.
import { NextResponse } from 'next/server';
import type { NextRequest } from 'next/server';
interface CustomHeaders extends Headers {
referer?: string[];
}
interface CustomNextRequest extends NextRequest {
headers: CustomHeaders;
}
export function middleware(req: CustomNextRequest) {
const res = NextResponse.next();
if (!process.env.NEXT_PUBLIC_MULTIVERSX_API?.includes('/api')) return res;
if (req.nextUrl.pathname.startsWith(process.env.NEXT_PUBLIC_MULTIVERSX_API)) {
const definedHost = process.env.API_ALLOWED_DAPP_HOST;
if (!definedHost) return res;
const referer = req.headers.get('referer');
if (!referer?.includes(definedHost)) {
return NextResponse.redirect(
new URL('/api/dapp-api-access-denied', req.url)
);
}
return res;
}
}