/** * Whether a device request arrived over a transport we accept. * * The panel's firmware carries a fixed certificate-authority bundle, so it * cannot validate a chain rooted in an authority created after the firmware * was built. When that happens the only way to reach the device is plain HTTP, * and `DEVICE_ALLOW_HTTP` is the deliberate, auditable decision to allow it. * * Without that decision recorded, a proxy misconfiguration could silently * start serving the device token in clear. This turns the setting from a * comment into a rule. */ import { deviceAllowsHttp } from '@/lib/config'; export type TransportCheck = { ok: true } | { ok: false; response: Response }; export function checkTransport(request: Request): TransportCheck { // Behind a reverse proxy the socket is always plain; the forwarded header is // what says how the client actually connected. const forwarded = request.headers.get('x-forwarded-proto'); const protocol = forwarded ?? new URL(request.url).protocol.replace(':', ''); if (protocol === 'https' || deviceAllowsHttp()) { return { ok: true }; } return { ok: false, response: Response.json( { error: 'HTTPS requis pour cet appareil.' }, { status: 403, headers: { 'Cache-Control': 'no-store' } }, ), }; }