Files
EvoBGP/internal/observability/metrics_auth.go
T
DenozordecandCursor 6c6e76fca3
CI / changes (push) Successful in 7s
CI / openapi (push) Failing after 40s
CI / web (push) Successful in 56s
CI / commitlint (push) Skipped
CI / go (push) Failing after 34s
CI / bird2 (push) Skipped
CI / release (push) Skipped
feat(ops): protect metrics, rate-limit auth, agent secret timing, e2e smoke
Bearer для /metrics (EVOBGP_METRICS_TOKEN); rate limit /v1/auth/config; constant-time agent secret; OTel stub; Playwright smoke; HTTP_PROXY note; checklist обновлён.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-31 12:29:00 +07:00

33 lines
850 B
Go

package observability
import (
"crypto/subtle"
"net/http"
"os"
"strings"
)
// ProtectMetrics wraps the Prometheus handler. When EVOBGP_METRICS_TOKEN is set,
// scrapes must send Authorization: Bearer <token> (constant-time compare).
// Empty token keeps /metrics open (dev / private network).
func ProtectMetrics(next http.Handler) http.Handler {
token := strings.TrimSpace(os.Getenv("EVOBGP_METRICS_TOKEN"))
if token == "" {
return next
}
want := []byte(token)
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
h := r.Header.Get("Authorization")
const p = "Bearer "
got := ""
if strings.HasPrefix(h, p) {
got = strings.TrimSpace(h[len(p):])
}
if subtle.ConstantTimeCompare([]byte(got), want) != 1 {
http.Error(w, "Unauthorized", http.StatusUnauthorized)
return
}
next.ServeHTTP(w, r)
})
}