Server (Express + better-sqlite3 + FTS5, mirroring keep's stack): /api/capture (upsert-on-url, per PROPOSAL.md's dedup decision), /api/articles (list/search/mark-read/delete), plus a minimal server-rendered reading list and reader view at / and /read/:id (token passed as ?t= there since browser navigation can't set an Authorization header). Bearer-token auth generated via `npm run token` — no login flow, matching keep's one-time identity registration pattern. Extension (Manifest V3, sideloaded, no store distribution): toolbar click or context menu "Send to stash" runs @mozilla/readability (vendored into extension/lib/) against the current page, falling back to raw rendered HTML when extraction comes back too thin. Options page for one-time server URL + token entry. Verified end-to-end with the real extension loaded in a live Chromium instance (not just unit-tested extraction logic): capture against a real page, dedup-on-recapture, mark-read, FTS5 search, 401 on missing auth, and both server-rendered views all confirmed working. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
13 lines
441 B
TypeScript
13 lines
441 B
TypeScript
import type { Request, Response, NextFunction } from 'express';
|
|
import { isValidToken } from './db.js';
|
|
|
|
export function requireToken(req: Request, res: Response, next: NextFunction) {
|
|
const header = req.header('authorization') ?? '';
|
|
const token = header.startsWith('Bearer ') ? header.slice(7) : null;
|
|
if (!token || !isValidToken(token)) {
|
|
res.status(401).json({ error: 'missing or invalid token' });
|
|
return;
|
|
}
|
|
next();
|
|
}
|