feat: admin-only sse endpoints

This commit is contained in:
2026-04-09 07:19:04 +07:00 Unverified
parent 1d86879ac4
commit 10efbb4a9f
2 changed files with 5 additions and 1 deletions
+4 -1
View File
@@ -1,4 +1,5 @@
import { sse, tlSse } from "@/lib/db/sse-endpoints";
import { adminCheck } from "@/lib/auth";
import { adminSseList, sse, tlSse } from "@/lib/db/sse-endpoints";
function isValidKey<T extends { [x: string]: unknown }>(
map: T,
@@ -17,5 +18,7 @@ export async function GET(
if (tlRegex.test(topic)) return tlSse(topic.match(tlRegex)![1]).stream();
if (!isValidKey(sse, topic))
return new Response("Invalid SSE Endpoint", { status: 404 });
if (adminSseList.includes(topic) && !(await adminCheck()))
return new Response("Unauthorized", { status: 401 });
return sse[topic].stream();
}
+1
View File
@@ -41,6 +41,7 @@ export const sse = sseEndpointMap({
update: z.custom<typeof auditLog.$inferSelect>(),
},
});
export const adminSseList: (keyof typeof sse)[] = ["log"];
export function tlSse<T extends string>(list: T) {
return sseEndpoint(`tl.${list}`, {
update_states: z.custom<(typeof tierlistStates.$inferSelect)[]>(),