Compare commits

..
40 Commits
Author SHA1 Message Date
devlikepro 680a35a26d [core] rm start-interval from docker run - docker 24 doesn't have it (used in CI)
Release / WEBJS - chrome - amd64 - chrome (push) Waiting to run
Release / WEBJS - chromium - amd64 - latest (push) Waiting to run
Release / WEBJS - chromium - linux/arm64 - arm (push) Waiting to run
Release / GOWS - none - amd64 - gows (push) Waiting to run
Release / GOWS - none - linux/arm64 - gows-arm (push) Waiting to run
Release / NOWEB - none - amd64 - noweb (push) Waiting to run
Release / NOWEB - none - linux/arm64 - noweb-arm (push) Waiting to run
2025-06-29 11:31:54 +07:00
devlikepro 08ff59e463 [core] 2025.6.7 2025-06-29 11:17:51 +07:00
devlikepro 9db4c8c333 [core] Check docker health in CI
fix #1085
2025-06-29 11:17:51 +07:00
devlikepro 2489c2da46 [core] Install curl in all images
fix #1085
2025-06-29 11:17:51 +07:00
devlikepro fbc58b0707 [core] 2025.6.6
Release / WEBJS - chrome - amd64 - chrome (push) Waiting to run
Release / WEBJS - chromium - amd64 - latest (push) Waiting to run
Release / WEBJS - chromium - linux/arm64 - arm (push) Waiting to run
Release / GOWS - none - amd64 - gows (push) Waiting to run
Release / GOWS - none - linux/arm64 - gows-arm (push) Waiting to run
Release / NOWEB - none - amd64 - noweb (push) Waiting to run
Release / NOWEB - none - linux/arm64 - noweb-arm (push) Waiting to run
2025-06-27 11:09:33 +07:00
devlikepro d5a525789e [core] NOWEB - show poll on the device
fix #988
2025-06-27 11:09:32 +07:00
devlikepro 34066921e1 [core] run xvfb only for WEBJS engine 2025-06-27 11:09:32 +07:00
devlikepro 901c594311 [core] WEBJS - fix pin message
fix #1081
2025-06-27 11:09:32 +07:00
devlikepro 5f619e608b [core] WEBJS - return response for a message
fix #1083
2025-06-27 11:09:31 +07:00
devlikepro 49295090ad [core] Use 501 Not Implemented HTTP status for NotImplemented by engine error
fix #1047
2025-06-27 11:09:31 +07:00
devlikepro a6e43adb0a [core] use xvfb-run 2025-06-27 11:09:30 +07:00
devlikepro 1f165bb6cb [core] Puppeteer 24.10.0 2025-06-27 11:09:30 +07:00
devlikepro 8fc9d88d2e [core] No security reminder, it creates a zombie process
fix #1078
2025-06-27 11:09:29 +07:00
devlikepro d7e5a5ce05 [core] Add ping check 2025-06-27 11:09:29 +07:00
devlikepro 09d446fdeb [core] Install wget for chrome 2025-06-27 11:09:28 +07:00
devlikepro c0bbd60e15 [core] Up Dashboard 2025-06-27 11:09:28 +07:00
devlikepro af3fc137be [core] fix del usage 2025-06-27 11:09:27 +07:00
devlikepro 0ee5e1bd88 [core] Up del, rimraf 2025-06-27 11:09:27 +07:00
devlikepro f92ea18651 [core] Use Debian Bookworm 2025-06-27 11:09:27 +07:00
devlikepro 3cce2bb35f [core] 2025.6.5
Release / WEBJS - chrome - amd64 - chrome (push) Waiting to run
Release / WEBJS - chromium - amd64 - latest (push) Waiting to run
Release / WEBJS - chromium - linux/arm64 - arm (push) Waiting to run
Release / GOWS - none - amd64 - gows (push) Waiting to run
Release / GOWS - none - linux/arm64 - gows-arm (push) Waiting to run
Release / NOWEB - none - amd64 - noweb (push) Waiting to run
Release / NOWEB - none - linux/arm64 - noweb-arm (push) Waiting to run
2025-06-25 13:38:56 +07:00
devlikepro e080ce42ee [core] no dashboard username by default 2025-06-25 13:38:56 +07:00
devlikepro 5dbe41da78 [core] postgresql 127.0.0.1 2025-06-25 13:38:55 +07:00
devlikepro eef3957d4f [core] Warning about no API key 2025-06-25 13:38:55 +07:00
devlikepro 680f4596b9 [core] Up Dashboard 2025-06-25 13:38:55 +07:00
devlikepro 8de344f220 [core] Add enabled vars for dashboard and swagger 2025-06-25 13:38:54 +07:00
devlikepro 8005846955 [core] admin/admin by default for dashboard 2025-06-25 13:38:54 +07:00
devlikepro 3edd60448b [core] format .env better 2025-06-25 13:38:54 +07:00
devlikepro 4a2fa5c076 [core] message about plain key 2025-06-25 13:38:54 +07:00
devlikepro 96e9c2cc4e [core] hash key in entrypoint.sh always 2025-06-25 13:38:53 +07:00
devlikepro 2089a1bb35 [core] Handle empty key in hash case 2025-06-25 13:38:52 +07:00
devlikepro 023c2718e2 [core] Move websocket.gateway.core.ts to /api 2025-06-25 13:38:52 +07:00
devlikepro f7aacb193a [core] Add Auth methods - NoAuth, PlainApiKeyAuth, Hash 2025-06-25 13:38:52 +07:00
devlikepro e710040904 [core] Add base providers 2025-06-25 13:38:52 +07:00
devlikepro fb12826801 [core] Refactor websocket authorization - use DI 2025-06-25 13:38:51 +07:00
devlikepro 833a70c6e0 [core] Remove hot fix for closing websockets 2025-06-25 13:38:50 +07:00
devlikepro c807f9021c [core] Support WAHA_API_KEY as well as env variable
gpt often suggests this env variable, IDK why
2025-06-25 13:38:49 +07:00
devlikepro 46b66bcdf0 [core] Move built-in SSL (DEPRECATED) to WAHA Core
fix #1069
2025-06-25 13:38:48 +07:00
devlikepro 2ebade817e [core] add swagger security to WAHA Core
fix #1069
2025-06-25 13:38:48 +07:00
devlikepro 080342e619 [core] add /ws authentication
fix #1069
2025-06-25 13:38:48 +07:00
devlikepro 75b06d3ba1 [core] Copy security file to WAHA Core
fix #1069
2025-06-25 13:38:48 +07:00
30 changed files with 825 additions and 351 deletions

No files matched your search

+84 -168
View File
@@ -1,191 +1,107 @@
# WAHA Configuration
# WAHA - WhatsApp HTTP API
#
# https://waha.devlike.pro/docs/how-to/config/
#
# Common
#
# If you know the right URL, you can use it here.
# Use any port in WHATSAPP_API_PORT and domain in WHATSAPP_API_HOSTNAME
# https://waha.devlike.pro/docs/how-to/config/#common
# ==================
# ===== COMMON =====
# ==================
# Base URL for the API (used for webhooks, file URLs, etc.)
WAHA_BASE_URL=http://localhost:3000
#WHATSAPP_API_SCHEMA=http
#WHATSAPP_API_PORT=3000
#WHATSAPP_API_HOSTNAME=localhost
# Server configuration (if you need to customize hostname/port)
# WHATSAPP_API_SCHEMA=http
# WHATSAPP_API_PORT=3000
# WHATSAPP_API_HOSTNAME=localhost
#
# Set your timezone to see the right time on screenshots
# Find your timezone name in the list
# https://en.wikipedia.org/wiki/List_of_tz_database_time_zones
#TZ=Europe/Dublin
#
# Security
#
# https://waha.devlike.pro/docs/how-to/security/
#
WHATSAPP_API_KEY=admin
# ====================
# ===== SECURITY =====
# ====================
# "sha512:{SHA}" format - below is "admin" api key
WAHA_API_KEY=sha512:c7ad44cbad762a5da0a452f9e854fdc1e0e7a52a38015f23f3eab1d80b931dd472634dfac71cd34ebc35d16ab7fb8a90c81f975113d6c7538dc69dd8de9077ec
WAHA_DASHBOARD_ENABLED=True
WAHA_DASHBOARD_USERNAME=admin
WAHA_DASHBOARD_PASSWORD=admin
#WHATSAPP_SWAGGER_USERNAME=admin
#WHATSAPP_SWAGGER_PASSWORD=admin
#
# Dashboard
#
# https://waha.devlike.pro/docs/how-to/waha-dashboard/#configuration
# Enabled by default
#WAHA_DASHBOARD_ENABLED=true
#WAHA_DASHBOARD_USERNAME=admin
#WAHA_DASHBOARD_PASSWORD=admin
#
# Logging
# https://waha.devlike.pro/docs/how-to/observability/#logging
#
# Set log format to JSON if you consume logs with log management systems
WAHA_LOG_FORMAT=JSON
WAHA_LOG_LEVEL=info
# WAHA_LOG_FORMAT=PRETTY
# If you want to see more logs, you can set the log level to debug
#WAHA_LOG_LEVEL=debug
# DEBUG=1 # shortcut for setting log level to debug
#
# Engine
# https://waha.devlike.pro/docs/how-to/engines/
#
# Choose the right engine for your needs (WEBJS by default)
WHATSAPP_DEFAULT_ENGINE=WEBJS
# Use NOWEB engine for the fastest performance
#WHATSAPP_DEFAULT_ENGINE=NOWEB
# Worker
# WAHA_WORKER_ID=waha1
#
# Sessions
# https://waha.devlike.pro/docs/how-to/config/#sessions
#
# Do not print QR codes in logs
WAHA_PRINT_QR=False
#
# OR you can specify sessions by name, if you have handful amount of sessions
#WHATSAPP_START_SESSION=session1,session2
#
# Restart all sessions when container starts
# !!! Do not use it with multiple workers against one database !!!
# WHATSAPP_RESTART_ALL_SESSIONS=True
#
# Swagger
# https://waha.devlike.pro/docs/how-to/swagger/
#
WHATSAPP_SWAGGER_ENABLED=True
WHATSAPP_SWAGGER_USERNAME=admin
WHATSAPP_SWAGGER_PASSWORD=admin
# Disable Swagger
#WHATSAPP_SWAGGER_ENABLED=false
# Enable advanced Swagger configuration
#WHATSAPP_SWAGGER_CONFIG_ADVANCED=true
#
# Swagger White Label customization
# https://waha.devlike.pro/docs/how-to/swagger/#white-label
#WHATSAPP_SWAGGER_TITLE=WAHA API
#
#
# PostgresSQL Configuration
# https://waha.devlike.pro/docs/how-to/storages/#sessions---postgresql
#WHATSAPP_SESSIONS_POSTGRESQL_URL=postgres://postgres:postgres@postgres:5432/postgres?sslmode=disable
#
# Media - PostgresSQL Storage
# https://waha.devlike.pro/docs/how-to/storages/#media---postgresql
#WAHA_MEDIA_STORAGE=POSTGRESQL
#WAHA_MEDIA_POSTGRESQL_URL=postgres://postgres:postgres@postgres:5432/postgres?sslmode=disable
#
# WhatsApp engine (WEBJS is default, GOWS or NOWEB for better performance)
WHATSAPP_DEFAULT_ENGINE=WEBJS
#
# Global Proxy Settings
# https://waha.devlike.pro/docs/how-to/config/#global-proxy-configuration
#
# You can also set proxy settings for each session later when starting it
# https://waha.devlike.pro/docs/how-to/sessions/#configure-proxy
#WHATSAPP_PROXY_SERVER=proxy.example.com:3128
#WHATSAPP_PROXY_SERVER_USERNAME=user
#WHATSAPP_PROXY_SERVER_PASSWORD=pass
#
# ===================
# ===== LOGGING =====
# ===================
# Log format: JSON (for log management systems) or PRETTY (for development)
WAHA_LOG_FORMAT=JSON
#
# Media Configuration
#
# https://waha.devlike.pro/docs/how-to/config/#files
#
# Disable media (images, videos, files) download for incoming messages
#WHATSAPP_DOWNLOAD_MEDIA=false
#
# Download only specific media types
#WHATSAPP_FILES_MIMETYPES=image/jpeg,image/png
#
# Log level: info, debug, error, warn
WAHA_LOG_LEVEL=info
# Media - Local Storage
# https://waha.devlike.pro/docs/how-to/storages/#media---local
#
# Set to 0 to keep media files forever
# https://waha.devlike.pro/docs/how-to/storages/#save-media-files-between-the-container-restarts
# Don't print QR codes in logs
WAHA_PRINT_QR=False
# =========================
# ===== MEDIA STORAGE =====
# =========================
# Local storage (default)
WAHA_MEDIA_STORAGE=LOCAL
WHATSAPP_FILES_LIFETIME=0
WHATSAPP_FILES_FOLDER=/app/.media
# Keep media files for 180 seconds (3 minutes)
#WHATSAPP_FILES_LIFETIME=180
#
# Media - S3 Storage
# https://waha.devlike.pro/docs/how-to/storages/#media---s3
#WAHA_MEDIA_STORAGE=S3
#WAHA_S3_REGION=eu-west-2
#WAHA_S3_BUCKET=waha
#WAHA_S3_ACCESS_KEY_ID=minioadmin
#WAHA_S3_SECRET_ACCESS_KEY=minioadmin
#WAHA_S3_ENDPOINT=http://minio:9000 # Not required if you're using AWS S3
#WAHA_S3_FORCE_PATH_STYLE=True # Required for Minio
#WAHA_S3_PROXY_FILES=True # Required for docker-compose setup
# Media download settings
# WHATSAPP_DOWNLOAD_MEDIA=true
# WHATSAPP_FILES_MIMETYPES=image/jpeg,image/png
#
# Global Webhooks
#
# https://waha.devlike.pro/docs/how-to/config/#webhooks
# https://waha.devlike.pro/docs/how-to/webhooks/
#WHATSAPP_HOOK_URL=https://webhook.site/11111111-1111-1111-1111-11111111
#WHATSAPP_HOOK_EVENTS=session.status,message,message.reaction
#
# S3 storage (uncomment to use)
# WAHA_MEDIA_STORAGE=S3
# WAHA_S3_REGION=eu-west-2
# WAHA_S3_BUCKET=waha
# WAHA_S3_ACCESS_KEY_ID=minioadmin
# WAHA_S3_SECRET_ACCESS_KEY=minioadmin
# WAHA_S3_ENDPOINT=http://minio:9000
# WAHA_S3_FORCE_PATH_STYLE=True
# WAHA_S3_PROXY_FILES=True
#
# Local Configuration
#
# WAHA_LOCAL_STORE_BASE_DIR=/app/sessions
# Remember to map the volume to the host machine to the right direction in "volumes" field in docker-compose.yml
# volumes:
# - './.sessions:/app/sessions'
# PostgreSQL storage (uncomment to use)
# WAHA_MEDIA_STORAGE=POSTGRESQL
# WAHA_MEDIA_POSTGRESQL_URL=postgres://postgres:postgres@postgres:5432/postgres?sslmode=disable
# ===========================
# ===== SESSION STORAGE =====
# ===========================
# PostgreSQL for sessions (uncomment to use)
# WHATSAPP_SESSIONS_POSTGRESQL_URL=postgres://postgres:postgres@postgres:5432/postgres?sslmode=disable
# MongoDB for sessions (uncomment to use)
# WHATSAPP_SESSIONS_MONGO_URL=mongodb://mongouser:mongopassword@mongodb:27017
#
# MongoDB Configuration
# https://waha.devlike.pro/docs/how-to/storages/#sessions---mongodb
#WHATSAPP_SESSIONS_MONGO_URL=mongodb://mongouser:mongopassword@mongodb:27017
#
# ==================================
# ===== ADVANCED CONFIGURATION =====
# ==================================
#
# HTTPS Configuration
# https://waha.devlike.pro/docs/how-to/config/#https
#
# Consider using certbot for HTTPS
# https://waha.devlike.pro/blog/setting-up-https-for-waha/#lets-encrypt-certbot--waha
#
#WAHA_HTTPS_ENABLED=true
#WAHA_HTTPS_PATH_KEY=/etc/letsencrypt/live/waha.example.pro/privkey.pem
#WAHA_HTTPS_PATH_CERT=/etc/letsencrypt/live/waha.example.pro/cert.pem \
#WAHA_HTTPS_PATH_CA=/etc/letsencrypt/live/waha.example.pro/chain.pem
#WHATSAPP_API_SCHEMA=https
#WHATSAPP_API_PORT=3000
#WHATSAPP_API_HOSTNAME=waha.example.pro
#
# Timezone for screenshots and logs
# TZ=Europe/Dublin
# Session management
# WHATSAPP_START_SESSION=session1,session2
# WHATSAPP_RESTART_ALL_SESSIONS=False
# Webhooks
# WHATSAPP_HOOK_URL=https://webhook.site/11111111-1111-1111-1111-11111111
# WHATSAPP_HOOK_EVENTS=session.status,message,message.reaction
# Proxy configuration
# WHATSAPP_PROXY_SERVER=proxy.example.com:3128
# WHATSAPP_PROXY_SERVER_USERNAME=user
# WHATSAPP_PROXY_SERVER_PASSWORD=pass
# HTTPS configuration
# !DEPRECATED!
# Setup nginx reverse proxy to handle TLS connection
# using Let's encrypt or self-issued certificate
# WAHA_HTTPS_ENABLED=true
# WAHA_HTTPS_PATH_KEY=/etc/letsencrypt/live/waha.example.pro/privkey.pem
# WAHA_HTTPS_PATH_CERT=/etc/letsencrypt/live/waha.example.pro/cert.pem
# WAHA_HTTPS_PATH_CA=/etc/letsencrypt/live/waha.example.pro/chain.pem
+9 -1
View File
@@ -126,7 +126,15 @@ jobs:
working-directory: tests/smoke
timeout-minutes: 2
run: |
docker run -d --name smoke --rm -p3000:3000 ${{ vars.DOCKER_IMAGE }}:${{ matrix.tag }}
docker run -d \
--name smoke \
--health-interval 1s \
--health-retries 60 \
--health-timeout 2s \
--health-start-period 2s \
--rm -p3000:3000 \
${{ vars.DOCKER_IMAGE }}:${{ matrix.tag }}
sleep 3
docker logs smoke
goss validate --retry-timeout 30s --sleep 1s
+1
View File
@@ -39,6 +39,7 @@ repos:
(?x)^(
docs/.*|
README.md|
tests/smoke/goss.yaml|
)$
- repo: https://github.com/Lucas-C/pre-commit-hooks-nodejs
rev: v1.1.2
+33 -7
View File
@@ -1,8 +1,10 @@
ARG NODE_IMAGE_TAG=22.16-bookworm-slim
ARG GOLANG_IMAGE_TAG=1.23-bookworm
#
# Build
#
ARG NODE_VERSION=22.16-bullseye
FROM node:${NODE_VERSION} AS build
FROM node:${NODE_IMAGE_TAG} AS build
ENV PUPPETEER_SKIP_DOWNLOAD=True
# npm packages
@@ -10,6 +12,10 @@ WORKDIR /git
COPY package.json .
COPY yarn.lock .
ENV YARN_CHECKSUM_BEHAVIOR=update
# git
RUN apt-get update && apt-get install -y git
RUN npm install -g corepack && corepack enable
RUN yarn set version 3.6.3
RUN yarn install
@@ -23,11 +29,14 @@ RUN yarn build && find ./dist -name "*.d.ts" -delete
#
# Dashboard
#
FROM node:${NODE_VERSION} AS dashboard
FROM node:${NODE_IMAGE_TAG} AS dashboard
# jq to parse json
RUN apt-get update && apt-get install -y jq && rm -rf /var/lib/apt/lists/*
# wget, unzip
RUN apt-get update && apt-get install -y wget unzip && rm -rf /var/lib/apt/lists/*
COPY waha.config.json /tmp/waha.config.json
RUN \
WAHA_DASHBOARD_GITHUB_REPO=$(jq -r '.waha.dashboard.repo' /tmp/waha.config.json) && \
@@ -42,7 +51,7 @@ RUN \
#
# GOWS
#
FROM golang:1.23-bullseye AS gows
FROM golang:${GOLANG_IMAGE_TAG} AS gows
# jq to parse json
RUN apt-get update && apt-get install -y jq && rm -rf /var/lib/apt/lists/*
@@ -73,7 +82,7 @@ RUN \
#
# Final
#
FROM node:${NODE_VERSION} AS release
FROM node:${NODE_IMAGE_TAG} AS release
ENV PUPPETEER_SKIP_DOWNLOAD=True
# Quick fix for memory potential memory leaks
# https://github.com/devlikeapro/waha/issues/347
@@ -98,6 +107,13 @@ RUN if [ "$USE_BROWSER" = "chromium" ] || [ "$USE_BROWSER" = "chrome" ]; then \
&& rm -rf /var/lib/apt/lists/*; \
fi
# Install wget - either for chromium or chrome
RUN if [ "$USE_BROWSER" = "chromium" ] || [ "$USE_BROWSER" = "chrome" ]; then \
apt-get update \
&& apt-get install -y wget \
&& rm -rf /var/lib/apt/lists/*; \
fi
# Install fonts if using either chromium or chrome
RUN if [ "$USE_BROWSER" = "chromium" ] || [ "$USE_BROWSER" = "chrome" ]; then \
apt-get update \
@@ -119,10 +135,11 @@ RUN if [ "$USE_BROWSER" = "chromium" ] || [ "$USE_BROWSER" = "chrome" ]; then \
&& rm -rf /var/lib/apt/lists/*; \
fi
# Install xvfb
# Install xvfb, xauth
RUN if [ "$USE_BROWSER" = "chromium" ] || [ "$USE_BROWSER" = "chrome" ]; then \
apt-get update && apt-get install -y --no-install-recommends \
xvfb \
xauth \
libnss3 \
libxss1 \
libasound2 \
@@ -130,7 +147,6 @@ RUN if [ "$USE_BROWSER" = "chromium" ] || [ "$USE_BROWSER" = "chrome" ]; then \
libgtk-3-0 \
libdrm2 \
ca-certificates \
curl \
&& rm -rf /var/lib/apt/lists/*; \
fi
@@ -155,6 +171,11 @@ RUN if [ "$USE_BROWSER" = "chrome" ]; then \
&& rm -rf /var/lib/apt/lists/*; \
fi
# curl
RUN apt-get update \
&& apt-get install -y curl \
&& rm -rf /var/lib/apt/lists/*
# GOWS requirements
# libc6
RUN apt-get update \
@@ -179,6 +200,11 @@ ENV WAHA_GOWS_SOCKET /tmp/gows.sock
COPY entrypoint.sh /entrypoint.sh
# Add healthcheck
COPY ping-check.sh /ping-check.sh
RUN chmod +x /ping-check.sh
HEALTHCHECK --interval=60s --timeout=10s --retries=3 --start-period=30s CMD ["/bin/bash", "/ping-check.sh"]
# Chokidar options to monitor file changes
ENV CHOKIDAR_USEPOLLING=1
ENV CHOKIDAR_INTERVAL=5000
+1 -1
View File
@@ -38,7 +38,7 @@ services:
# POSTGRES_PASSWORD: postgres
# POSTGRES_DB: postgres
# ports:
# - "5432:5432"
# - "127.0.0.1:5432:5432"
# volumes:
# - pg_data:/var/lib/postgresql/data
# command:
+1 -1
View File
@@ -10,7 +10,7 @@ services:
- './.sessions:/app/.sessions'
- './.media:/app/.media'
environment:
- WHATSAPP_API_KEY=321
- WAHA_API_KEY=321
- WAHA_DASHBOARD_USERNAME=admin
- WAHA_DASHBOARD_PASSWORD=admin
- WHATSAPP_DEFAULT_ENGINE=WEBJS
+2 -2
View File
@@ -29,7 +29,7 @@ services:
# - WHATSAPP_HOOK_EVENTS=message
# - WHATSAPP_API_HOSTNAME=localhost
- WHATSAPP_DEFAULT_ENGINE=WEBJS
- WHATSAPP_API_KEY=321
- WAHA_API_KEY=321
# Username and password for Swagger
- WHATSAPP_SWAGGER_USERNAME=swagger
- WHATSAPP_SWAGGER_PASSWORD=admin
@@ -55,7 +55,7 @@ services:
# Environment variables from https://waha.devlike.pro/docs/how-to/config/
# - WHATSAPP_HOOK_URL=https://webhook.site/11111111-1111-1111-1111-11111111
# - WHATSAPP_HOOK_EVENTS=message
# - WHATSAPP_API_KEY=321
# - WAHA_API_KEY=321
# - WHATSAPP_SWAGGER_USERNAME=admin
# - WHATSAPP_SWAGGER_PASSWORD=123
# - WAHA_DASHBOARD_USERNAME=admin
+55 -10
View File
@@ -1,21 +1,66 @@
#!/bin/sh
# Check if Xvfb command exists
if command -v Xvfb > /dev/null 2>&1; then
# Start virtual X server in the background
Xvfb :99 -screen 0 1280x720x24 &
export DISPLAY=:99
sleep 2
else
echo "Xvfb command not found, skipping virtual X server setup"
fi
#
# Calculate UV_THREADPOOL_SIZE based on number of CPUs
#
cpus=$(node -e "const os = require('os'); console.log(os.cpus().length);")
uv_threadpool_size=$(($cpus * 1))
# Set UV_THREADPOOL_SIZE as an environment variable
export UV_THREADPOOL_SIZE="${UV_THREADPOOL_SIZE:-$uv_threadpool_size}"
#
# Handle API key hashing
#
# Save WHATSAPP_API_KEY or WAHA_API_KEY in a variable (WHATSAPP_API_KEY has priority)
if [ -n "$WHATSAPP_API_KEY" ]; then
key="$WHATSAPP_API_KEY"
elif [ -n "$WAHA_API_KEY" ]; then
key="$WAHA_API_KEY"
fi
# Unset both environment variables
unset WHATSAPP_API_KEY
unset WAHA_API_KEY
# Process the key if it exists
if [ -n "$key" ]; then
# Check if key is already hashed
if echo "$key" | grep -q "^sha512:"; then
# If already hashed, use it as is
export WAHA_API_KEY="$key"
else
# Display warning about using plain text API key
echo "⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️"
echo "WARNING: Plain text API key detected. Converting to hashed format for security."
echo "For better security, use WAHA_API_KEY=sha512:{SHA512_HASH_FOR_YOUR_API_KEY}"
echo "⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️"
# Hash the key using sha512sum
HASHED_KEY=$(echo -n "$key" | sha512sum | awk '{print $1}')
export WAHA_API_KEY="sha512:$HASHED_KEY"
fi
fi
#
# xvfb-run
#
USE_XVFB=false
if [ -z "$WHATSAPP_DEFAULT_ENGINE" ] || [ "$WHATSAPP_DEFAULT_ENGINE" = "WEBJS" ]; then
# Try to run xvfb-run with a test command
if xvfb-run --auto-servernum echo "xvfb-run is working!"; then
USE_XVFB=true
else
echo "xvfb-run test failed, do not run it"
USE_XVFB=false
fi
fi
#
# Start your application using node with exec to ensure proper signal handling
exec node dist/main
#
if [ "$USE_XVFB" = "true" ]; then
exec xvfb-run --auto-servernum node dist/main
else
exec node dist/main
fi
+3 -3
View File
@@ -56,7 +56,7 @@
"chokidar": "^3.6.0",
"class-transformer": "^0.5.1",
"class-validator": "0.14.0",
"del": "^6.0.0",
"del": "^8.0.0",
"express-basic-auth": "^1.2.1",
"file-type": "16.5.4",
"fs-extra": "^11.2.0",
@@ -79,11 +79,11 @@
"pino-pretty": "^11.2.1",
"pretty-bytes": "5.6.0",
"promise-retry": "^2.0.1",
"puppeteer": "^23.6.0",
"puppeteer": "^24.10.0",
"qrcode": "^1.5.1",
"qrcode-terminal": "^0.12.0",
"reflect-metadata": "^0.1.13",
"rimraf": "^3.0.2",
"rimraf": "^4.3.0",
"rxjs": "^7.8.1",
"sharp": "^0.33.4",
"swagger-ui-express": "^4.1.4",
+14
View File
@@ -0,0 +1,14 @@
#!/bin/bash
# Default port is 3000
PORT=${WHATSAPP_API_PORT:-3000}
# Check if HTTPS is enabled
if [[ "${WAHA_HTTPS_ENABLED}" == "true" || "${WAHA_HTTPS_ENABLED}" == "1" ]]; then
PROTOCOL="https"
else
PROTOCOL="http"
fi
# Execute curl command with SSL verification disabled
curl -f -s -k "${PROTOCOL}://127.0.0.1:${PORT}/ping" || exit 1
@@ -12,6 +12,7 @@ import {
WebSocketServer,
} from '@nestjs/websockets';
import { SessionManager } from '@waha/core/abc/manager.abc';
import { WebSocketAuth } from '@waha/core/auth/WebSocketAuth';
import { WebsocketHeartbeatJob } from '@waha/nestjs/ws/WebsocketHeartbeatJob';
import { WebSocket } from '@waha/nestjs/ws/ws';
import { WAHAEvents, WAHAEventsWild } from '@waha/structures/enums.dto';
@@ -21,6 +22,15 @@ import { IncomingMessage } from 'http';
import * as url from 'url';
import { Server } from 'ws';
export enum WebSocketCloseCode {
NORMAL = 1000,
GOING_AWAY = 1001,
PROTOCOL_ERROR = 1002,
UNSUPPORTED_DATA = 1003,
POLICY_VIOLATION = 1008,
INTERNAL_ERROR = 1011,
}
@WebSocketGateway({
path: '/ws',
cors: true,
@@ -41,7 +51,10 @@ export class WebsocketGatewayCore
private heartbeat: WebsocketHeartbeatJob;
private eventUnmask = new EventWildUnmask(WAHAEvents, WAHAEventsWild);
constructor(private manager: SessionManager) {
constructor(
private manager: SessionManager,
private auth: WebSocketAuth,
) {
this.logger = new Logger('WebsocketGateway');
this.heartbeat = new WebsocketHeartbeatJob(
this.logger,
@@ -51,14 +64,23 @@ export class WebsocketGatewayCore
handleConnection(socket: WebSocket, request: IncomingMessage, ...args): any {
// wsc - websocket client
const id = generatePrefixedId('wsc');
socket.id = id;
this.logger.debug(`New client connected: ${request.url}`);
socket.id = generatePrefixedId('wsc');
if (!this.auth.validateRequest(request)) {
// Not authorized - close connection
socket.close(WebSocketCloseCode.POLICY_VIOLATION, 'Unauthorized');
this.logger.debug(
`Unauthorized websocket connection attempt: ${request.url} - ${socket.id}`,
);
return;
}
this.logger.debug(`New client connected: ${request.url} - ${socket.id}`);
const params = this.getParams(request);
const session: string = params.session;
const events: WAHAEvents[] = params.events;
this.logger.debug(
`Client connected to session: '${session}', events: ${events}, ${id}`,
`Client connected to session: '${session}', events: ${events}, ${socket.id}`,
);
const sub = this.manager
@@ -97,26 +119,11 @@ export class WebsocketGatewayCore
async beforeApplicationShutdown(signal?: string) {
this.logger.log('Shutting down websocket server');
this.heartbeat?.stop();
// Allow pending messages to be sent, it can be even 1ms, just to release the event loop
await sleep(100);
// Close clients and server
await this.close(this.server);
this.logger.log('Websocket server is down');
}
// Cherry-pick from nestjs new version
// https://github.com/nestjs/nest/pull/13531/files
private async close(server: any) {
// const closeEventSignal = new Promise((resolve, reject) =>
// server.close((err) => (err ? reject(err) : resolve(undefined))),
// );
for (const ws of server.clients) {
ws.terminate();
}
// await closeEventSignal;
}
afterInit(server: Server) {
this.logger.debug('Websocket server initialized');
+4 -1
View File
@@ -138,7 +138,10 @@ export class WhatsappConfigService implements OnApplicationBootstrap {
}
getApiKey(): string | undefined {
return this.configService.get('WHATSAPP_API_KEY', '');
return (
this.configService.get('WHATSAPP_API_KEY', '') ||
this.configService.get('WAHA_API_KEY', '')
);
}
getExcludedPaths(): string[] {
+27 -2
View File
@@ -1,6 +1,8 @@
import { INestApplication } from '@nestjs/common';
import { DocumentBuilder, OpenAPIObject, SwaggerModule } from '@nestjs/swagger';
import { DECORATORS } from '@nestjs/swagger/dist/constants';
import { BasicAuthFunction } from '@waha/core/auth/basicAuth';
import { DashboardConfigServiceCore } from '@waha/core/config/DashboardConfigServiceCore';
import { Logger } from 'nestjs-pino';
import { WhatsappConfigService } from '../config.service';
@@ -9,16 +11,22 @@ import { SwaggerConfigServiceCore } from './config/SwaggerConfigServiceCore';
export class SwaggerConfiguratorCore {
protected logger: any;
private config: SwaggerConfigServiceCore;
constructor(protected app: INestApplication) {
this.logger = app.get(Logger);
this.config = app.get(SwaggerConfigServiceCore);
}
get title() {
return 'WAHA - WhatsApp HTTP API';
return this.config.title || 'WAHA - WhatsApp HTTP API';
}
get description() {
if (this.config.description) {
return this.config.description;
}
return (
'<b>WhatsApp HTTP API</b> that you can run in a click!<br/>' +
'<a href="/dashboard"><b>📊 Dashboard</b></a><br/>' +
@@ -43,10 +51,19 @@ export class SwaggerConfiguratorCore {
}
get externalDocUrl() {
return 'https://waha.devlike.pro/';
return this.config.externalDocUrl || 'https://waha.devlike.pro/';
}
configure(webhooks: any[]) {
if (!this.config.enabled) {
return;
}
const credentials = this.config.credentials;
if (credentials) {
this.setUpAuth(credentials);
}
const app = this.app;
const builder = new DocumentBuilder();
@@ -163,4 +180,12 @@ export class SwaggerConfiguratorCore {
document.webhooks = webhooks;
return document;
}
setUpAuth(credentials: [string, string]): void {
const [username, password] = credentials;
const dashboardConfig = this.app.get(DashboardConfigServiceCore);
const exclude = ['/api/', dashboardConfig.dashboardUri, '/health', '/ws'];
const authFunction = BasicAuthFunction(username, password, exclude);
this.app.use(authFunction);
}
}
+71 -17
View File
@@ -1,4 +1,7 @@
import { INestApplication, Module } from '@nestjs/common';
import * as process from 'node:process';
import { INestApplication, MiddlewareConsumer, Module } from '@nestjs/common';
import { Provider } from '@nestjs/common/interfaces/modules/provider.interface';
import { ConfigModule } from '@nestjs/config';
import { APP_INTERCEPTOR } from '@nestjs/core';
import { PassportModule } from '@nestjs/passport';
@@ -11,20 +14,29 @@ import {
ServerController,
ServerDebugController,
} from '@waha/api/server.controller';
import { WebsocketGatewayCore } from '@waha/core/api/websocket.gateway.core';
import { WebsocketGatewayCore } from '@waha/api/websocket.gateway.core';
import { ApiKeyStrategy } from '@waha/core/auth/apiKey.strategy';
import { IApiKeyAuth } from '@waha/core/auth/auth';
import { AuthMiddleware } from '@waha/core/auth/auth.middleware';
import { BasicAuthFunction } from '@waha/core/auth/basicAuth';
import { WebSocketAuth } from '@waha/core/auth/WebSocketAuth';
import { GowsEngineConfigService } from '@waha/core/config/GowsEngineConfigService';
import { WebJSEngineConfigService } from '@waha/core/config/WebJSEngineConfigService';
import { MediaLocalStorageModule } from '@waha/core/media/local/media.local.storage.module';
import { MediaLocalStorageConfig } from '@waha/core/media/local/MediaLocalStorageConfig';
import { ChannelsInfoServiceCore } from '@waha/core/services/ChannelsInfoServiceCore';
import { parseBool } from '@waha/helpers';
import { BufferJsonReplacerInterceptor } from '@waha/nestjs/BufferJsonReplacerInterceptor';
import { HttpsExpress } from '@waha/nestjs/HttpsExpress';
import {
getPinoHttpUseLevel,
getPinoLogLevel,
getPinoTransport,
} from '@waha/utils/logging';
import { noSlashAtTheEnd } from '@waha/utils/string';
import * as Joi from 'joi';
import { LoggerModule } from 'nestjs-pino';
import { Logger as NestJSPinoLogger } from 'nestjs-pino';
import { join } from 'path';
import { Logger } from 'pino';
@@ -46,6 +58,7 @@ import { VersionController } from '../api/version.controller';
import { WhatsappConfigService } from '../config.service';
import { SessionManager } from './abc/manager.abc';
import { WAHAHealthCheckService } from './abc/WAHAHealthCheckService';
import { ApiKeyAuthFactory } from './auth/ApiKeyAuthFactory';
import { DashboardConfigServiceCore } from './config/DashboardConfigServiceCore';
import { EngineConfigService } from './config/EngineConfigService';
import { SwaggerConfigServiceCore } from './config/SwaggerConfigServiceCore';
@@ -63,6 +76,7 @@ export const IMPORTS_CORE = [
autoLogging: {
ignore: (req) => {
return (
req.url.startsWith('/ping') ||
req.url.startsWith('/dashboard/') ||
req.url.startsWith('/api/files/') ||
req.url.startsWith('/api/s3/')
@@ -144,6 +158,28 @@ export const CONTROLLERS = [
VersionController,
MediaController,
];
export const PROVIDERS_BASE: Provider[] = [
{
provide: APP_INTERCEPTOR,
useClass: BufferJsonReplacerInterceptor,
},
DashboardConfigServiceCore,
SwaggerConfigServiceCore,
WebJSEngineConfigService,
GowsEngineConfigService,
WhatsappConfigService,
EngineConfigService,
WebsocketGatewayCore,
MediaLocalStorageConfig,
WebSocketAuth,
ApiKeyStrategy,
{
provide: IApiKeyAuth,
useFactory: ApiKeyAuthFactory,
inject: [WhatsappConfigService, NestJSPinoLogger],
},
];
const PROVIDERS = [
{
provide: SessionManager,
@@ -153,19 +189,8 @@ const PROVIDERS = [
provide: WAHAHealthCheckService,
useClass: WAHAHealthCheckServiceCore,
},
{
provide: APP_INTERCEPTOR,
useClass: BufferJsonReplacerInterceptor,
},
ChannelsInfoServiceCore,
DashboardConfigServiceCore,
SwaggerConfigServiceCore,
WebJSEngineConfigService,
GowsEngineConfigService,
WhatsappConfigService,
EngineConfigService,
WebsocketGatewayCore,
MediaLocalStorageConfig,
...PROVIDERS_BASE,
];
@Module({
@@ -176,15 +201,44 @@ const PROVIDERS = [
export class AppModuleCore {
public startTimestamp: number;
constructor(protected config: WhatsappConfigService) {
constructor(
protected config: WhatsappConfigService,
private dashboardConfig: DashboardConfigServiceCore,
) {
this.startTimestamp = Date.now();
}
static getHttpsOptions(logger: Logger) {
return undefined;
const httpsEnabled = parseBool(process.env.WAHA_HTTPS_ENABLED);
if (!httpsEnabled) {
return undefined;
}
const httpsExpress = new HttpsExpress(logger);
return httpsExpress.readSync();
}
static appReady(app: INestApplication, logger: Logger) {
return;
const httpsEnabled = parseBool(process.env.WAHA_HTTPS_ENABLED);
if (!httpsEnabled) {
return;
}
const httpd = app.getHttpServer();
const httpsExpress = new HttpsExpress(logger);
httpsExpress.watchCertChanges(httpd);
}
configure(consumer: MiddlewareConsumer) {
const exclude = this.config.getExcludedPaths();
consumer
.apply(AuthMiddleware)
.exclude(...exclude)
.forRoutes('api', 'health', 'ws');
const dashboardCredentials = this.dashboardConfig.credentials;
if (dashboardCredentials) {
const username = dashboardCredentials[0];
const password = dashboardCredentials[1];
const route = noSlashAtTheEnd(this.dashboardConfig.dashboardUri);
consumer.apply(BasicAuthFunction(username, password)).forRoutes(route);
}
}
}
+53
View File
@@ -0,0 +1,53 @@
import { LoggerService } from '@nestjs/common';
import { WhatsappConfigService } from '@waha/config.service';
import {
HashAuth,
IApiKeyAuth,
NoAuth,
PlainApiKeyAuth,
} from '@waha/core/auth/auth';
export function ApiKeyAuthFactory(
config: WhatsappConfigService,
logger: LoggerService,
): IApiKeyAuth {
const apiKey = config.getApiKey();
if (!apiKey) {
setTimeout(() => {
logger.warn('🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫');
logger.warn('WARNING: No API key detected. This is a security risk.');
logger.warn(
'Your API is publicly accessible without any authentication.',
);
logger.warn(
'To secure your API, set environment variable: WAHA_API_KEY=your_api_key',
);
logger.warn(
'For better security, use WAHA_API_KEY=sha512:{SHA512_HASH_FOR_YOUR_API_KEY}',
);
logger.warn('🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫🚫');
}, 3000);
return new NoAuth();
}
if (apiKey.startsWith('sha512:')) {
const hash = apiKey.slice(7);
return new HashAuth(hash, 'sha512');
}
// Fallback to plain text
setTimeout(() => {
logger.warn('⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️');
logger.warn(
'WARNING: Plain text API key detected. This is a security risk.',
);
logger.warn(
'Your API key can be exposed in environment variables or process lists.',
);
logger.warn(
'For better security, use WAHA_API_KEY=sha512:{SHA512_HASH_FOR_YOUR_API_KEY}',
);
logger.warn('⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️⚠️');
}, 2000);
return new PlainApiKeyAuth(apiKey);
}
+34
View File
@@ -0,0 +1,34 @@
import { Injectable } from '@nestjs/common';
import { IncomingMessage } from 'http';
import * as url from 'url';
import { IApiKeyAuth } from './auth';
@Injectable()
export class WebSocketAuth {
constructor(private auth: IApiKeyAuth) {}
validateRequest(request: IncomingMessage) {
if (this.auth.skipAuth()) {
return true;
}
const provided = this.getKeyFromQueryParams(request);
return this.auth.isValid(provided);
}
private getKeyFromQueryParams(request: IncomingMessage) {
let query = url.parse(request.url, true).query;
// case-insensitive query params
query = Object.keys(query).reduce((acc, key) => {
acc[key.toLowerCase()] = query[key];
return acc;
}, {});
const provided = query['x-api-key'];
// Check if it's array - return first
if (Array.isArray(provided)) {
return provided[0];
}
return provided;
}
}
+19
View File
@@ -0,0 +1,19 @@
import { Injectable } from '@nestjs/common';
import { PassportStrategy } from '@nestjs/passport';
import { IApiKeyAuth } from '@waha/core/auth/auth';
import { HeaderAPIKeyStrategy } from 'passport-headerapikey';
@Injectable()
export class ApiKeyStrategy extends PassportStrategy(HeaderAPIKeyStrategy) {
constructor(private auth: IApiKeyAuth) {
super({ header: 'X-Api-Key', prefix: '' }, true, (apikey, done) => {
const isValid = this.auth.isValid(apikey);
return done(isValid);
});
}
validate(apikey: string, done: (result: boolean) => void): void {
const isValid = this.auth.isValid(apikey);
return done(isValid);
}
}
+28
View File
@@ -0,0 +1,28 @@
import {
Injectable,
NestMiddleware,
UnauthorizedException,
} from '@nestjs/common';
import * as passport from 'passport';
import { IApiKeyAuth } from './auth';
@Injectable()
export class AuthMiddleware implements NestMiddleware {
constructor(private auth: IApiKeyAuth) {}
use(req: any, res: any, next: () => void) {
// Skip authentication if auth says so
if (this.auth.skipAuth()) {
next();
return;
}
passport.authenticate('headerapikey', { session: false }, (value) => {
if (!value) {
throw new UnauthorizedException();
}
next();
})(req, res, next);
}
}
+79
View File
@@ -0,0 +1,79 @@
import * as crypto from 'crypto';
export abstract class IApiKeyAuth {
abstract isValid(plain: string): boolean;
abstract skipAuth(): boolean;
}
export class NoAuth implements IApiKeyAuth {
isValid(plain: string): boolean {
return true;
}
skipAuth(): boolean {
return true;
}
}
export class PlainApiKeyAuth implements IApiKeyAuth {
constructor(private key: string) {}
isValid(plain: string): boolean {
return compare(plain, this.key);
}
skipAuth(): boolean {
return false;
}
}
export class HashAuth implements IApiKeyAuth {
constructor(
private hash: string,
private algorithm: string,
) {
this.algorithm = algorithm;
}
isValid(plain: string): boolean {
if (!plain) {
return false;
}
const hash = crypto.createHash(this.algorithm).update(plain).digest('hex');
return compare(hash, this.hash);
}
skipAuth(): boolean {
return false;
}
}
/**
* Securely compare 2 strings
*/
export function compare(provided: string, stored: string | undefined): boolean {
if (!stored || !provided) {
return false;
}
try {
// Convert strings to buffers for constant-time comparison
const providedBuffer = Buffer.from(provided);
const storedBuffer = Buffer.from(stored);
// If lengths are different, return false but use a dummy comparison to prevent timing attacks
if (providedBuffer.length !== storedBuffer.length) {
// Create a dummy buffer of the same length as the provided key
const dummyBuffer = Buffer.alloc(providedBuffer.length);
// Perform comparison with dummy buffer to maintain constant time
crypto.timingSafeEqual(providedBuffer, dummyBuffer);
return false;
}
// Perform constant-time comparison
return crypto.timingSafeEqual(providedBuffer, storedBuffer);
} catch (error) {
return false;
}
}
+21
View File
@@ -0,0 +1,21 @@
import * as basicAuth from 'express-basic-auth';
export function BasicAuthFunction(username, password, exclude: string[] = []) {
function authFunction(req, res, next) {
const ignore = exclude.filter((url) => req.url.startsWith(url)).length > 0;
if (ignore) {
next();
return;
}
const auth = basicAuth({
challenge: true,
users: {
[username]: password,
},
});
auth(req, res, next);
}
return authFunction;
}
@@ -18,4 +18,20 @@ export class DashboardConfigServiceCore {
const value = this.configService.get('WAHA_DASHBOARD_ENABLED', 'true');
return parseBool(value);
}
get credentials(): [string, string] | null {
const user = this.configService.get('WAHA_DASHBOARD_USERNAME', '');
const password = this.configService.get('WAHA_DASHBOARD_PASSWORD', '');
if (!user && !password) {
return null;
}
if ((user && !password) || (!user && password)) {
this.logger.warn(
'Set up both WAHA_DASHBOARD_USERNAME and WAHA_DASHBOARD_PASSWORD ' +
'to enable dashboard authentication.',
);
return null;
}
return [user, password];
}
}
@@ -19,4 +19,43 @@ export class SwaggerConfigServiceCore {
);
return parseBool(value);
}
get enabled(): boolean {
const value = this.configService.get('WHATSAPP_SWAGGER_ENABLED', 'true');
return parseBool(value);
}
get credentials(): [string, string] | undefined {
const user = this.configService.get<string>(
'WHATSAPP_SWAGGER_USERNAME',
undefined,
);
const password = this.configService.get<string>(
'WHATSAPP_SWAGGER_PASSWORD',
undefined,
);
if (!user && !password) {
return null;
}
if ((user && !password) || (!user && password)) {
this.logger.warn(
'Set up both WHATSAPP_SWAGGER_USERNAME and WHATSAPP_SWAGGER_PASSWORD ' +
'to enable swagger authentication.',
);
return null;
}
return [user, password];
}
get title() {
return this.configService.get('WHATSAPP_SWAGGER_TITLE', '');
}
get description() {
return this.configService.get('WHATSAPP_SWAGGER_DESCRIPTION', '');
}
get externalDocUrl() {
return this.configService.get('WHATSAPP_SWAGGER_EXTERNAL_DOC_URL', '');
}
}
+5 -2
View File
@@ -1,8 +1,11 @@
import { UnprocessableEntityException } from '@nestjs/common';
import {
NotImplementedException,
UnprocessableEntityException,
} from '@nestjs/common';
export const DOCS_URL = 'https://waha.devlike.pro/';
export class NotImplementedByEngineError extends UnprocessableEntityException {
export class NotImplementedByEngineError extends NotImplementedException {
constructor(msg = '') {
let error = 'The method is not implemented by the engine.';
if (msg) {
+2 -2
View File
@@ -4,8 +4,8 @@ import * as fsp from 'fs/promises';
import * as path from 'path';
import { Logger } from 'pino';
import fs = require('fs');
import del = require('del');
import { fileExists } from '@waha/utils/files';
import { deleteAsync } from 'del';
// eslint-disable-next-line @typescript-eslint/no-var-requires
const writeFileAtomic = require('write-file-atomic');
@@ -59,7 +59,7 @@ export class MediaLocalStorage implements IMediaStorage {
}
if (fs.existsSync(this.filesFolder)) {
del([`${this.filesFolder}/*`], { force: true }).then((paths) => {
deleteAsync([`${this.filesFolder}/*`], { force: true }).then((paths) => {
if (paths.length === 0) {
return;
}
+8 -15
View File
@@ -47,31 +47,24 @@ process.on('SIGTERM', () => {
logger.info('SIGTERM received');
});
async function loadModules(): Promise<
[typeof AppModuleCore, typeof SwaggerConfiguratorCore]
> {
async function loadModules(): Promise<typeof AppModuleCore> {
const version = getWAHAVersion();
if (version === WAHAVersion.CORE) {
const { AppModuleCore } = await import('./core/app.module.core');
const { SwaggerConfiguratorCore } = await import(
'./core/SwaggerConfiguratorCore'
);
return [AppModuleCore, SwaggerConfiguratorCore];
return AppModuleCore;
}
// Ignore if it's core version - there's no plus module
// Ignore if it's a core version - there's no plus module
// @ts-ignore
const { AppModulePlus } = await import('./plus/app.module.plus');
// @ts-ignore
const { SwaggerConfiguratorPlus } = await import('./plus/SwaggerConfiguratorPlus'); // prettier-ignore
// @ts-ignore
return [AppModulePlus, SwaggerConfiguratorPlus];
return AppModulePlus;
}
async function bootstrap() {
const version = getWAHAVersion();
logger.info(`WAHA (WhatsApp HTTP API) - Running ${version} version...`);
const [AppModule, SwaggerModule] = await loadModules();
const AppModule = await loadModules();
const httpsOptions = AppModule.getHttpsOptions(logger);
const app = await NestFactory.create(AppModule, {
logger: getNestJSLogLevels(),
@@ -81,7 +74,7 @@ async function bootstrap() {
});
app.useLogger(app.get(NestJSPinoLogger));
// Print original stack, not pino one
// Print the original stack, not pino one
// https://github.com/iamolegga/nestjs-pino?tab=readme-ov-file#expose-stack-trace-and-error-class-in-err-property
app.useGlobalInterceptors(new LoggerErrorInterceptor());
@@ -91,13 +84,13 @@ async function bootstrap() {
// but for now we added it ValidationPipe on Controller or endpoint level
// app.useGlobalPipes(new ValidationPipe({ transform: true }));
// Allow to send big body - for images and attachments
// Allow sending big body - for images and attachments
app.use(json({ limit: '50mb' }));
app.use(urlencoded({ limit: '50mb', extended: false }));
app.useWebSocketAdapter(new WsAdapter(app));
// Configure swagger
const swaggerConfigurator = new SwaggerModule(app);
const swaggerConfigurator = new SwaggerConfiguratorCore(app);
swaggerConfigurator.configure(WAHA_WEBHOOKS);
AppModule.appReady(app, logger);
+73
View File
@@ -0,0 +1,73 @@
import * as fs from 'node:fs';
import { LoggerBuilder } from '@waha/utils/logging';
import { Logger } from 'pino';
// eslint-disable-next-line @typescript-eslint/no-var-requires
const chokidar = require('chokidar');
export class HttpsExpress {
private readonly keyPath: string;
private readonly certPath: string;
private readonly caPath: string;
constructor(private logger: Logger) {
//
// Let's encrypt certificates default paths
// cert.pem chain.pem fullchain.pem privkey.pem
//
this.keyPath = process.env.WAHA_HTTPS_PATH_KEY || './.secrets/privkey.pem';
this.certPath = process.env.WAHA_HTTPS_PATH_CERT || './.secrets/cert.pem';
this.caPath = process.env.WAHA_HTTPS_PATH_CA;
if (this.caPath == null) {
this.caPath = './.secrets/chain.pem';
}
}
readSync() {
this.logger.info('Reading HTTPS certificates...');
this.logger.info('HTTPS Key Path:', this.keyPath);
const key = fs.readFileSync(this.keyPath);
this.logger.info('HTTPS Cert Path:', this.certPath);
const cert = fs.readFileSync(this.certPath);
this.logger.info('HTTPS CA Path:', this.caPath);
const ca = this.caPath ? fs.readFileSync(this.caPath) : undefined;
this.logger.info('HTTPS certificates read successfully');
return { key: key, cert: cert, ca: ca };
}
/**
* https://stackoverflow.com/a/74076392
*/
watchCertChanges(httpd) {
let waitForCertAndFullChainToGetUpdatedTooTimeout: any;
const paths = [this.keyPath, this.certPath, this.caPath].filter(
(path) => !!path,
);
const watcher = chokidar.watch(paths, {
followSymlinks: false,
persistent: true,
ignoreInitial: true,
disableGlobbing: true,
});
// IDK why, but it has few bugs:
// 1. It issues 'add' event at the start, even tho ignoreInitial is set to true
// 2. It issues additional 'add' for the same file, but without full path
watcher.on('all', (eventName, path, stats) => {
this.logger.info(`HTTPS file '${path}' has been '${eventName}'...`);
clearTimeout(waitForCertAndFullChainToGetUpdatedTooTimeout);
waitForCertAndFullChainToGetUpdatedTooTimeout = setTimeout(() => {
this.logger.info('Updating HTTPS configuration...');
httpd.setSecureContext(this.readSync());
}, 1000);
});
process.on('SIGTERM', () => {
this.logger.info('SIGTERM received, closing HTTP file watchers');
clearTimeout(waitForCertAndFullChainToGetUpdatedTooTimeout);
watcher.close();
});
}
}
+1 -1
View File
@@ -33,7 +33,7 @@ export function getEngineName(): string {
}
export const VERSION: WAHAEnvironment = {
version: '2025.6.4',
version: '2025.6.7',
engine: getEngineName(),
tier: getWAHAVersion(),
browser:
+8
View File
@@ -5,3 +5,11 @@ http:
no-follow-redirects: true
timeout: 5000
body: ['version']
command:
docker smoke health:
exec: "docker inspect --format '{{`{{if .State.Health}}{{.State.Health.Status}}{{else}}no healthcheck{{end}}`}}' smoke"
exit-status: 0
stdout:
- 'healthy'
timeout: 5000
+1 -1
View File
@@ -6,7 +6,7 @@
},
"dashboard": {
"repo": "devlikeapro/dashboard",
"ref": "3fb6694d849ca0b567679dd59311a50b9d727f2f"
"ref": "fd8594d89ef369ed669c8b8b529ab29058c0d13c"
}
}
}
+106 -97
View File
@@ -7,7 +7,7 @@ __metadata:
"@adiwajshing/baileys@github:devlikeapro/Baileys#fork-master-2025-05-01":
version: 6.7.16
resolution: "@adiwajshing/baileys@https://github.com/devlikeapro/Baileys.git#commit=5835c558607cb85ff81a32ea93f12a4bd3e36648"
resolution: "@adiwajshing/baileys@https://github.com/devlikeapro/Baileys.git#commit=17db13bd44d54e00d5740b002aca0b33c15b6e7b"
dependencies:
"@cacheable/node-cache": ^1.4.0
"@hapi/boom": ^9.1.3
@@ -34,7 +34,7 @@ __metadata:
optional: true
sharp:
optional: true
checksum: e90ede6bdfd1a79afe4a3f1946ba820f92796f06e13414106cdefbc0060a7e826a04b5d9f7ef47f4233e12e7f9130ace4dd3f80e1a754191a72b6650bd769410
checksum: f89150418538cc3d11ed94da91ff5ba89a49b9a29c1d8a060fd8a211c3ab2e9cdf84c2f8bd3962e67835decc4fb78783dd8f1d297b8caf6d4b026dfa3bd42126
languageName: node
linkType: hard
@@ -2665,6 +2665,13 @@ __metadata:
languageName: node
linkType: hard
"@sindresorhus/merge-streams@npm:^2.1.0":
version: 2.3.0
resolution: "@sindresorhus/merge-streams@npm:2.3.0"
checksum: e989d53dee68d7e49b4ac02ae49178d561c461144cea83f66fa91ff012d981ad0ad2340cbd13f2fdb57989197f5c987ca22a74eb56478626f04e79df84291159
languageName: node
linkType: hard
"@sinonjs/commons@npm:^3.0.0":
version: 3.0.1
resolution: "@sinonjs/commons@npm:3.0.1"
@@ -4316,16 +4323,6 @@ __metadata:
languageName: node
linkType: hard
"aggregate-error@npm:^3.0.0":
version: 3.1.0
resolution: "aggregate-error@npm:3.1.0"
dependencies:
clean-stack: ^2.0.0
indent-string: ^4.0.0
checksum: 1101a33f21baa27a2fa8e04b698271e64616b886795fd43c31068c07533c7b3facfcaf4e9e0cab3624bd88f729a592f1c901a1a229c9e490eafce411a8644b79
languageName: node
linkType: hard
"ajv-formats@npm:3.0.1":
version: 3.0.1
resolution: "ajv-formats@npm:3.0.1"
@@ -4624,13 +4621,6 @@ __metadata:
languageName: node
linkType: hard
"array-union@npm:^2.1.0":
version: 2.1.0
resolution: "array-union@npm:2.1.0"
checksum: 5bee12395cba82da674931df6d0fea23c4aa4660cb3b338ced9f828782a65caa232573e6bf3968f23e0c5eb301764a382cef2f128b170a9dc59de0e36c39f98d
languageName: node
linkType: hard
"array.prototype.findlastindex@npm:^1.2.5":
version: 1.2.6
resolution: "array.prototype.findlastindex@npm:1.2.6"
@@ -5516,13 +5506,6 @@ __metadata:
languageName: node
linkType: hard
"clean-stack@npm:^2.0.0":
version: 2.2.0
resolution: "clean-stack@npm:2.2.0"
checksum: 2ac8cd2b2f5ec986a3c743935ec85b07bc174d5421a5efc8017e1f146a1cf5f781ae962618f416352103b32c9cd7e203276e8c28241bbe946160cab16149fb68
languageName: node
linkType: hard
"cli-boxes@npm:^2.2.1":
version: 2.2.1
resolution: "cli-boxes@npm:2.2.1"
@@ -6140,19 +6123,17 @@ __metadata:
languageName: node
linkType: hard
"del@npm:^6.0.0":
version: 6.1.1
resolution: "del@npm:6.1.1"
"del@npm:^8.0.0":
version: 8.0.0
resolution: "del@npm:8.0.0"
dependencies:
globby: ^11.0.1
graceful-fs: ^4.2.4
is-glob: ^4.0.1
is-path-cwd: ^2.2.0
is-path-inside: ^3.0.2
p-map: ^4.0.0
rimraf: ^3.0.2
slash: ^3.0.0
checksum: 563288b73b8b19a7261c47fd21a330eeab6e2acd7c6208c49790dfd369127120dd7836cdf0c1eca216b77c94782a81507eac6b4734252d3bef2795cb366996b6
globby: ^14.0.2
is-glob: ^4.0.3
is-path-cwd: ^3.0.0
is-path-inside: ^4.0.0
p-map: ^7.0.2
slash: ^5.1.0
checksum: 502dea7a846f989e1d921733f5d41ae4ae9b3eff168d335bfc050c9ce938ddc46198180be133814269268c4b0aed441a82fbace948c0ec5eed4ed086a4ad3b0e
languageName: node
linkType: hard
@@ -6226,15 +6207,6 @@ __metadata:
languageName: node
linkType: hard
"dir-glob@npm:^3.0.1":
version: 3.0.1
resolution: "dir-glob@npm:3.0.1"
dependencies:
path-type: ^4.0.0
checksum: fa05e18324510d7283f55862f3161c6759a3f2f8dbce491a2fc14c8324c498286c54282c1f0e933cb930da8419b30679389499b919122952a4f8592362ef4615
languageName: node
linkType: hard
"doctrine@npm:^2.1.0":
version: 2.1.0
resolution: "doctrine@npm:2.1.0"
@@ -7074,7 +7046,7 @@ __metadata:
languageName: node
linkType: hard
"fast-glob@npm:^3.2.9, fast-glob@npm:^3.3.2":
"fast-glob@npm:^3.3.2, fast-glob@npm:^3.3.3":
version: 3.3.3
resolution: "fast-glob@npm:3.3.3"
dependencies:
@@ -7701,6 +7673,18 @@ __metadata:
languageName: node
linkType: hard
"glob@npm:^9.2.0":
version: 9.3.5
resolution: "glob@npm:9.3.5"
dependencies:
fs.realpath: ^1.0.0
minimatch: ^8.0.2
minipass: ^4.2.4
path-scurry: ^1.6.1
checksum: 94b093adbc591bc36b582f77927d1fb0dbf3ccc231828512b017601408be98d1fe798fc8c0b19c6f2d1a7660339c3502ce698de475e9d938ccbb69b47b647c84
languageName: node
linkType: hard
"globals@npm:^11.1.0":
version: 11.12.0
resolution: "globals@npm:11.12.0"
@@ -7727,17 +7711,17 @@ __metadata:
languageName: node
linkType: hard
"globby@npm:^11.0.1":
version: 11.1.0
resolution: "globby@npm:11.1.0"
"globby@npm:^14.0.2":
version: 14.1.0
resolution: "globby@npm:14.1.0"
dependencies:
array-union: ^2.1.0
dir-glob: ^3.0.1
fast-glob: ^3.2.9
ignore: ^5.2.0
merge2: ^1.4.1
slash: ^3.0.0
checksum: b4be8885e0cfa018fc783792942d53926c35c50b3aefd3fdcfb9d22c627639dc26bd2327a40a0b74b074100ce95bb7187bfeae2f236856aa3de183af7a02aea6
"@sindresorhus/merge-streams": ^2.1.0
fast-glob: ^3.3.3
ignore: ^7.0.3
path-type: ^6.0.0
slash: ^5.1.0
unicorn-magic: ^0.3.0
checksum: b1f27dccc999c010ee7e0ce7c6581fd2326ac86cf0508474d526d699a029b66b35d6fa4361c8b4ad8e80809582af71d5e2080e671cf03c26e98ca67aba8834bd
languageName: node
linkType: hard
@@ -7990,14 +7974,7 @@ __metadata:
languageName: node
linkType: hard
"ignore@npm:^5.2.0":
version: 5.3.2
resolution: "ignore@npm:5.3.2"
checksum: 2acfd32a573260ea522ea0bfeff880af426d68f6831f973129e2ba7363f422923cf53aab62f8369cbf4667c7b25b6f8a3761b34ecdb284ea18e87a5262a865be
languageName: node
linkType: hard
"ignore@npm:^7.0.0":
"ignore@npm:^7.0.0, ignore@npm:^7.0.3":
version: 7.0.5
resolution: "ignore@npm:7.0.5"
checksum: d0862bf64d3d58bf34d5fb0a9f725bec9ca5ce8cd1aecc8f28034269e8f69b8009ffd79ca3eda96962a6a444687781cd5efdb8c7c8ddc0a6996e36d31c217f14
@@ -8033,13 +8010,6 @@ __metadata:
languageName: node
linkType: hard
"indent-string@npm:^4.0.0":
version: 4.0.0
resolution: "indent-string@npm:4.0.0"
checksum: 824cfb9929d031dabf059bebfe08cf3137365e112019086ed3dcff6a0a7b698cb80cf67ccccde0e25b9e2d7527aa6cc1fed1ac490c752162496caba3e6699612
languageName: node
linkType: hard
"inflight@npm:^1.0.4":
version: 1.0.6
resolution: "inflight@npm:1.0.6"
@@ -8298,17 +8268,17 @@ __metadata:
languageName: node
linkType: hard
"is-path-cwd@npm:^2.2.0":
version: 2.2.0
resolution: "is-path-cwd@npm:2.2.0"
checksum: 46a840921bb8cc0dc7b5b423a14220e7db338072a4495743a8230533ce78812dc152548c86f4b828411fe98c5451959f07cf841c6a19f611e46600bd699e8048
"is-path-cwd@npm:^3.0.0":
version: 3.0.0
resolution: "is-path-cwd@npm:3.0.0"
checksum: bc34d13b6a03dfca4a3ab6a8a5ba78ae4b24f4f1db4b2b031d2760c60d0913bd16a4b980dcb4e590adfc906649d5f5132684079a3972bd219da49deebb9adea8
languageName: node
linkType: hard
"is-path-inside@npm:^3.0.2":
version: 3.0.3
resolution: "is-path-inside@npm:3.0.3"
checksum: abd50f06186a052b349c15e55b182326f1936c89a78bf6c8f2b707412517c097ce04bc49a0ca221787bc44e1049f51f09a2ffb63d22899051988d3a618ba13e9
"is-path-inside@npm:^4.0.0":
version: 4.0.0
resolution: "is-path-inside@npm:4.0.0"
checksum: 8810fa11c58e6360b82c3e0d6cd7d9c7d0392d3ac9eb10f980b81f9839f40ac6d1d6d6f05d069db0d227759801228f0b072e1b6c343e4469b065ab5fe0b68fe5
languageName: node
linkType: hard
@@ -9552,7 +9522,7 @@ __metadata:
languageName: node
linkType: hard
"merge2@npm:^1.3.0, merge2@npm:^1.4.1":
"merge2@npm:^1.3.0":
version: 1.4.1
resolution: "merge2@npm:1.4.1"
checksum: 7268db63ed5169466540b6fb947aec313200bcf6d40c5ab722c22e242f651994619bcd85601602972d3c85bd2cc45a358a4c61937e9f11a061919a1da569b0c2
@@ -9667,6 +9637,15 @@ __metadata:
languageName: node
linkType: hard
"minimatch@npm:^8.0.2":
version: 8.0.4
resolution: "minimatch@npm:8.0.4"
dependencies:
brace-expansion: ^2.0.1
checksum: 2e46cffb86bacbc524ad45a6426f338920c529dd13f3a732cc2cf7618988ee1aae88df4ca28983285aca9e0f45222019ac2d14ebd17c1edadd2ee12221ab801a
languageName: node
linkType: hard
"minimatch@npm:^9.0.4":
version: 9.0.5
resolution: "minimatch@npm:9.0.5"
@@ -9743,6 +9722,13 @@ __metadata:
languageName: node
linkType: hard
"minipass@npm:^4.2.4":
version: 4.2.8
resolution: "minipass@npm:4.2.8"
checksum: 7f4914d5295a9a30807cae5227a37a926e6d910c03f315930fde52332cf0575dfbc20295318f91f0baf0e6bb11a6f668e30cde8027dea7a11b9d159867a3c830
languageName: node
linkType: hard
"minipass@npm:^5.0.0":
version: 5.0.0
resolution: "minipass@npm:5.0.0"
@@ -10344,15 +10330,6 @@ __metadata:
languageName: node
linkType: hard
"p-map@npm:^4.0.0":
version: 4.0.0
resolution: "p-map@npm:4.0.0"
dependencies:
aggregate-error: ^3.0.0
checksum: cb0ab21ec0f32ddffd31dfc250e3afa61e103ef43d957cc45497afe37513634589316de4eb88abdfd969fe6410c22c0b93ab24328833b8eb1ccc087fc0442a1c
languageName: node
linkType: hard
"p-map@npm:^7.0.2":
version: 7.0.3
resolution: "p-map@npm:7.0.3"
@@ -10503,7 +10480,7 @@ __metadata:
languageName: node
linkType: hard
"path-scurry@npm:^1.11.1":
"path-scurry@npm:^1.11.1, path-scurry@npm:^1.6.1":
version: 1.11.1
resolution: "path-scurry@npm:1.11.1"
dependencies:
@@ -10544,6 +10521,13 @@ __metadata:
languageName: node
linkType: hard
"path-type@npm:^6.0.0":
version: 6.0.0
resolution: "path-type@npm:6.0.0"
checksum: b9f6eaf7795c48d5c9bc4c6bc3ac61315b8d36975a73497ab2e02b764c0836b71fb267ea541863153f633a069a1c2ed3c247cb781633842fc571c655ac57c00e
languageName: node
linkType: hard
"pause@npm:0.0.1":
version: 0.0.1
resolution: "pause@npm:0.0.1"
@@ -11482,6 +11466,17 @@ __metadata:
languageName: node
linkType: hard
"rimraf@npm:^4.3.0":
version: 4.4.1
resolution: "rimraf@npm:4.4.1"
dependencies:
glob: ^9.2.0
bin:
rimraf: dist/cjs/src/bin.js
checksum: b786adc02651e2e24bbedb04bbdea80652fc9612632931ff2d9f898c5e4708fe30956186597373c568bd5230a4dc2fadfc816ccacba8a1daded3a006a6b74f1a
languageName: node
linkType: hard
"router@npm:^2.2.0":
version: 2.2.0
resolution: "router@npm:2.2.0"
@@ -11925,6 +11920,13 @@ __metadata:
languageName: node
linkType: hard
"slash@npm:^5.1.0":
version: 5.1.0
resolution: "slash@npm:5.1.0"
checksum: 70434b34c50eb21b741d37d455110258c42d2cf18c01e6518aeb7299f3c6e626330c889c0c552b5ca2ef54a8f5a74213ab48895f0640717cacefeef6830a1ba4
languageName: node
linkType: hard
"slice-ansi@npm:^2.1.0":
version: 2.1.0
resolution: "slice-ansi@npm:2.1.0"
@@ -13057,6 +13059,13 @@ __metadata:
languageName: node
linkType: hard
"unicorn-magic@npm:^0.3.0":
version: 0.3.0
resolution: "unicorn-magic@npm:0.3.0"
checksum: bdd7d7c522f9456f32a0b77af23f8854f9a7db846088c3868ec213f9550683ab6a2bdf3803577eacbafddb4e06900974385841ccb75338d17346ccef45f9cb01
languageName: node
linkType: hard
"unique-filename@npm:^4.0.0":
version: 4.0.0
resolution: "unique-filename@npm:4.0.0"
@@ -13248,7 +13257,7 @@ __metadata:
chokidar: ^3.6.0
class-transformer: ^0.5.1
class-validator: 0.14.0
del: ^6.0.0
del: ^8.0.0
eslint: 7.7.0
eslint-config-prettier: ^6.10.0
eslint-plugin-import: ^2.20.1
@@ -13279,11 +13288,11 @@ __metadata:
pretty-bytes: 5.6.0
promise-retry: ^2.0.1
protoc-gen-ts: ^0.8.7
puppeteer: ^23.6.0
puppeteer: ^24.10.0
qrcode: ^1.5.1
qrcode-terminal: ^0.12.0
reflect-metadata: ^0.1.13
rimraf: ^3.0.2
rimraf: ^4.3.0
rxjs: ^7.8.1
sharp: ^0.33.4
supertest: ^4.0.2
@@ -13390,7 +13399,7 @@ __metadata:
"whatsapp-web.js@github:devlikeapro/whatsapp-web.js#fork-main-2025-06-09":
version: 1.30.1-alpha.2
resolution: "whatsapp-web.js@https://github.com/devlikeapro/whatsapp-web.js.git#commit=f0e8284c9a281fa15ce2086d5668c02011947416"
resolution: "whatsapp-web.js@https://github.com/devlikeapro/whatsapp-web.js.git#commit=48fcc59575b46386747673d1b01b8f89e8c49c2d"
dependencies:
"@pedroslopez/moduleraid": ^5.0.2
archiver: ^5.3.1
@@ -13408,7 +13417,7 @@ __metadata:
optional: true
unzipper:
optional: true
checksum: ad0b97ac3b5246801af33e4e7cc34ce34b8541a3737bb97f53322f4612b8eb435eec2b47a6ef9f7f794649324d70041e3f6f6f5453be8d4b74da0051334ee98e
checksum: 7d867a4180321e85477e57b15f9ea85d2e26b6d1cf875f7e40131e4a047aaae1ad5e8b977c1ff9b3a64538276271fed06202ac6eb9168c7c5dd01eb155402f7f
languageName: node
linkType: hard