[core] Exclude /ping and /health using WAHA_API_KEY_EXCLUDE_PATH from all auth

fix #1562
This commit is contained in:
devlikepro committed 2025-11-07 13:54:59 +07:00
1 parent c44680c987
commit 050c652480
3 files changed
+13 -4

No files matched your search

-1
View File
@@ -2,7 +2,6 @@ import { Controller, Get } from '@nestjs/common';
import { ApiOperation, ApiSecurity, ApiTags } from '@nestjs/swagger';
import { PingResponse } from '@waha/structures/ping.dto';
@ApiSecurity('api_key')
@Controller('ping')
@ApiTags('🔍 Observability')
export class PingController {
+6 -1
View File
@@ -148,7 +148,12 @@ export class WhatsappConfigService implements OnApplicationBootstrap {
if (!value) {
return [];
}
return value.split(',');
return value.split(',').filter(Boolean);
}
getExcludedFullPaths(): string[] {
const paths = this.getExcludedPaths();
return paths.map((path) => (path.startsWith('/') ? path : `/${path}`));
}
getHealthMediaFilesThreshold(): number {
+7 -2
View File
@@ -1,4 +1,5 @@
import { INestApplication } from '@nestjs/common';
import * as lodash from 'lodash';
import { DocumentBuilder, OpenAPIObject, SwaggerModule } from '@nestjs/swagger';
import { DECORATORS } from '@nestjs/swagger/dist/constants';
import { BasicAuthFunction } from '@waha/core/auth/basicAuth';
@@ -185,13 +186,17 @@ export class SwaggerConfiguratorCore {
setUpAuth(credentials: [string, string]): void {
const [username, password] = credentials;
const dashboardConfig = this.app.get(DashboardConfigServiceCore);
const exclude = [
const config = this.app.get(WhatsappConfigService);
const exclude = lodash.uniq([
'/api/',
dashboardConfig.dashboardUri,
'/health',
'/ping',
'/ws',
'/webhooks/',
];
...config.getExcludedFullPaths(),
]);
const authFunction = BasicAuthFunction(username, password, exclude);
this.app.use(authFunction);
}