Compare commits

..
Author SHA1 Message Date
allburov 65d0f87eeb Use -plus docker image in security
Release / deploy-docker (push) Waiting to run
2022-12-11 17:01:47 +07:00
allburov 488868d80e Add WHATSAPP_SWAGGER_USERNAME, WHATSAPP_SWAGGER_PASSWORD to config.md 2022-12-11 16:58:12 +07:00
allburov 154965efcb [core] bump version to 2022.12.11 2022-12-11 16:52:36 +07:00
allburov f364f0b495 [core] Authentication for swagger panel (available in plus only) 2022-12-11 16:52:34 +07:00
allburov 82e2f5bcb9 [core] Authentication for swagger panel (available in plus only) 2022-12-11 16:52:28 +07:00
dependabot[bot] f7a2228925 Bump venom-bot from 4.3.6 to 4.3.7
Bumps [venom-bot](https://github.com/orkestral/venom) from 4.3.6 to 4.3.7.
- [Release notes](https://github.com/orkestral/venom/releases)
- [Changelog](https://github.com/orkestral/venom/blob/master/CHANGELOG.md)
- [Commits](https://github.com/orkestral/venom/compare/v4.3.6...v4.3.7)

---
updated-dependencies:
- dependency-name: venom-bot
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-12-11 16:52:17 +07:00
allburov dadc9d4efd Up version 2022-12-11 16:52:11 +07:00
allburov df59867431 Up dependencies 2022-12-11 16:52:11 +07:00
dependabot[bot] a7c6e9dc00 Bump whatsapp-web.js from 1.18.3 to 1.18.4
Bumps [whatsapp-web.js](https://github.com/pedroslopez/whatsapp-web.js) from 1.18.3 to 1.18.4.
- [Release notes](https://github.com/pedroslopez/whatsapp-web.js/releases)
- [Commits](https://github.com/pedroslopez/whatsapp-web.js/compare/v1.18.3...v1.18.4)

---
updated-dependencies:
- dependency-name: whatsapp-web.js
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2022-12-11 16:52:11 +07:00
9 changed files with 458 additions and 308 deletions

No files matched your search

@@ -24,6 +24,7 @@ docker run -it -e WHATSAPP_HOOK_EVENTS=* -e WHATSAPP_HOOK_URL=https://httpbin.or
- `WHATSAPP_API_HOSTNAME=localhost` - Hostname for HTTP server (default: `localhost`)
- `WHATSAPP_API_KEY=mysecret` - protect the api with a secret code. If you set it - add `X-Api-Key: mysecret` to all
requests.
- `WHATSAPP_SWAGGER_USERNAME=admin` + `WHATSAPP_SWAGGER_PASSWORD=admin` - protect the Swagger panel with `admin / admin` credentials. It doesn't affect api access!
- `WHATSAPP_START_SESSION=default` - start session with the name right after launching the app
-
@@ -15,19 +15,35 @@ We do not recommend exposing the API on any public networks!
Either protect the API with [Api Key](https://www.fortinet.com/resources/cyberglossary/api-key) or deny access by using
firewalls.
## Swagger Security ![](/images/versions/plus.png)
If you want to hide the project Swagger panel under the password - run the following command to hide under `admin/admin`
login and password.
```bash
docker run -it -e WHATSAPP_SWAGGER_USERNAME=admin -eWHATSAPP_SWAGGER_PASSWORD=admin devlikeapro/whatsapp-http-api-plus
```
Open http://localhost:3000/ and enter `admin / admin` in the inputs:
![](swagger-basic-auth.png)
{{< alert icon="👉" text="Protecting Swagger under the password does not protect your API from other request! Use both techniques to protect your API and Swagger!" />}}
## API security ![](/images/versions/plus.png)
You can protect the API by requiring Api Key in a request's headers.
{{< alert icon="👉" text="Api Key does not hide your Swagger documentation. Please have a look at the previous section to find how to hide Swagger under the password." />}}
### Set Api Key
Set `WHATSAPP_API_KEY=yoursecretkey` environment variable for that:
```bash
docker run -it -e WHATSAPP_API_KEY=yoursecretkey devlikeapro/whatsapp-http-api
docker run -it -e WHATSAPP_API_KEY=yoursecretkey devlikeapro/whatsapp-http-api-plus
```
### Swagger
### Use Api-Key in Swagger
After you set api key - to authorize on swagger use **Authorize** button at the top:
![](swagger-auth.png)
@@ -49,5 +65,3 @@ headers = {
requests.get("http://localhost:3000/api/sessions", headers=headers)
```
## Swagger Security ![](/images/versions/plus-soon.png)
If you want to hide under a password the swagger UI - please create an issue on GitHub, we'll do it!
Binary file not shown.

After

Width:  |  Height:  |  Size: 36 KiB

+378 -278
View File
File diff suppressed because it is too large. Load diff
+3 -2
View File
@@ -31,6 +31,7 @@
"@nestjs/swagger": "^6.0.5",
"class-validator": "^0.12.2",
"del": "^6.0.0",
"express-basic-auth": "^1.2.1",
"mime-types": "^2.1.27",
"passport": "^0.6.0",
"passport-headerapikey": "^1.2.2",
@@ -41,8 +42,8 @@
"rimraf": "^3.0.2",
"rxjs": "^7.1.0",
"swagger-ui-express": "^4.1.4",
"venom-bot": "^4.3.5",
"whatsapp-web.js": "^1.18.3"
"venom-bot": "^4.3.7",
"whatsapp-web.js": "^1.18.4"
},
"devDependencies": {
"@nestjs/cli": "^9.0.0",
+11
View File
@@ -76,4 +76,15 @@ export class WhatsappConfigService {
getApiKey(): string | undefined {
return this.configService.get("WHATSAPP_API_KEY", "")
}
getSwaggerUsernamePassword(): [string, string] | undefined {
const user = this.configService.get("WHATSAPP_SWAGGER_USERNAME", undefined)
const password = this.configService.get("WHATSAPP_SWAGGER_PASSWORD", undefined)
if (!user && !password) {
console.log("Please set up both WHATSAPP_SWAGGER_USERNAME and WHATSAPP_SWAGGER_PASSWORD " +
"to enable swagger authentication.")
return undefined
}
return [user, password]
}
}
+33
View File
@@ -0,0 +1,33 @@
import {DocumentBuilder, SwaggerModule} from "@nestjs/swagger";
import {INestApplication} from "@nestjs/common";
import {VERSION} from "../version";
export class SwaggerModuleCore {
configure(app: INestApplication){
this.setUpAuth(app)
const options = new DocumentBuilder()
.setTitle('WAHA - WhatsApp HTTP API')
.setDescription('WhatsApp HTTP API that you can configure in a click!')
.setExternalDoc("Documentation", "https://waha.devlike.pro/")
.setVersion(VERSION.version)
.addTag('sessions', 'Control your WhatsApp sessions')
.addTag('screenshot', 'Get screenshot of WhatsApp and show QR code')
.addTag('chatting', 'Chat methods')
.addTag('other', 'Other endpoints')
.addApiKey({
type: 'apiKey',
description: 'Your secret api key',
name: 'X-Api-Key'
}
)
.build();
const document = SwaggerModule.createDocument(app, options);
SwaggerModule.setup('', app, document);
}
protected setUpAuth(app: INestApplication) {
return undefined
}
}
+13 -23
View File
@@ -1,25 +1,29 @@
import {NestFactory} from '@nestjs/core';
import {DocumentBuilder, SwaggerModule} from "@nestjs/swagger";
import {WhatsappConfigService} from "./config.service";
import {AllExceptionsFilter} from "./api/exception.filter";
import {getWAHAVersion, VERSION, WAHAVersion} from "./version";
import {AppModuleCore} from "./core/app.module.core";
import {SwaggerModuleCore} from "./core/swagger.module.core";
async function getAppModule() {
async function loadModules(): Promise<[typeof AppModuleCore, typeof SwaggerModuleCore]> {
const version = getWAHAVersion()
console.log(`WAHA (WhatsApp HTTP API) - Running ${version} version...`)
if (version === WAHAVersion.CORE) {
const {AppModuleCore} = await import("./core/app.module.core")
return AppModuleCore
const {SwaggerModuleCore} = await import("./core/swagger.module.core")
return [AppModuleCore, SwaggerModuleCore]
}
// Ignore if it's core version - there's no plus module
// @ts-ignore
const {AppModulePlus} = await import("./plus/app.module.plus")
return AppModulePlus
// @ts-ignore
const {SwaggerModulePlus} = await import("./plus/swagger.module.plus")
return [AppModulePlus, SwaggerModulePlus]
}
async function bootstrap() {
const AppModule = await getAppModule()
const [AppModule, SwaggerModule] = await loadModules()
const app = await NestFactory.create(AppModule, {
logger: process.env.DEBUG != undefined ? ['log', 'debug', 'error', 'verbose', 'warn'] :
['log', 'error', 'warn'],
@@ -27,24 +31,10 @@ async function bootstrap() {
app.enableShutdownHooks();
app.useGlobalFilters(new AllExceptionsFilter());
const options = new DocumentBuilder()
.setTitle('WAHA - WhatsApp HTTP API')
.setDescription('WhatsApp HTTP API that you can configure in a click!')
.setExternalDoc("Documentation", "https://waha.devlike.pro/")
.setVersion(VERSION.version)
.addTag('sessions', 'Control your WhatsApp sessions')
.addTag('screenshot', 'Get screenshot of WhatsApp and show QR code')
.addTag('chatting', 'Chat methods')
.addTag('other', 'Other endpoints')
.addApiKey({
type: 'apiKey',
description: 'Your secret api key',
name: 'X-Api-Key'
}
)
.build();
const document = SwaggerModule.createDocument(app, options);
SwaggerModule.setup('', app, document);
// Configure swagger
const swagger = new SwaggerModule()
swagger.configure(app)
const config = app.get(WhatsappConfigService);
await app.listen(config.port);
+1 -1
View File
@@ -24,4 +24,4 @@ export function getWAHAVersion(): WAHAVersion {
return WAHAVersion.CORE
}
export const VERSION = {version: "2022.11.20", tier: getWAHAVersion()}
export const VERSION = {version: "2022.12.11", tier: getWAHAVersion()}