-
Notifications
You must be signed in to change notification settings - Fork 10
Expand file tree
/
Copy pathvite-dev-proxy.ts
More file actions
125 lines (113 loc) · 3.4 KB
/
Copy pathvite-dev-proxy.ts
File metadata and controls
125 lines (113 loc) · 3.4 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
import type { ProxyOptions } from 'vite'
/**
* Proxy dev : une URL par cible, vide = route désactivée (hybride local / k8s / etc.).
* Variables lues depuis .env (loadEnv prefix '' dans vite.config).
*/
const E = {
back: 'VITE_DEV_PROXY_BACK',
fhir: 'VITE_DEV_PROXY_FHIR',
request: 'VITE_DEV_PROXY_REQUEST',
datamodel: 'VITE_DEV_PROXY_DATAMODEL',
portail: 'VITE_DEV_PROXY_PORTAIL',
secure: 'VITE_DEV_PROXY_SECURE'
} as const
/** TLS upstream : true par défaut ; `VITE_DEV_PROXY_SECURE=false` pour auto-signé / proxy d’entreprise. */
function tlsVerify(envVal: string | undefined): boolean {
const x = (envVal ?? 'true').trim().toLowerCase()
return !['0', 'false', 'no'].includes(x)
}
/**
* FhirApi local attend souvent `authorizationMethod: OIDC` (RS256) alors que `oidcAuth` reste false
* pour le back Django (JWT). Sans toucher au code React : même rôle qu’un nginx qui ajoute le header
* sur /fhir. Voir `VITE_DEV_PROXY_FHIR_AUTH_METHOD` dans `.env.dev-proxy.example`.
*/
function withFhirAuthHeaderOverride(
opts: ProxyOptions,
mode: 'OIDC' | undefined
): ProxyOptions {
if (mode !== 'OIDC') {
return opts
}
const prevConfigure = opts.configure
return {
...opts,
configure(proxy, options) {
prevConfigure?.(proxy, options)
proxy.on('proxyReq', (proxyReq) => {
proxyReq.setHeader('authorizationMethod', 'OIDC')
})
}
}
}
export function buildDevProxy(env: Record<string, string | undefined>): Record<string, ProxyOptions> {
const secure = tlsVerify(env[E.secure])
const proxy: Record<string, ProxyOptions> = {}
const back = env[E.back]?.trim()
const fhir = env[E.fhir]?.trim()
const requestRaw = env[E.request]?.trim()
const request =
requestRaw === '-' || requestRaw === 'off'
? undefined
: requestRaw || fhir
const datamodel = env[E.datamodel]?.trim()
const fhirAuthOverride =
env.VITE_DEV_PROXY_FHIR_AUTH_METHOD?.trim().toUpperCase() === 'OIDC' ? ('OIDC' as const) : undefined
const baseOpts = (): ProxyOptions => ({
changeOrigin: true,
secure
})
if (back) {
proxy['/api/back/ws'] = {
...baseOpts(),
target: back,
ws: true,
rewrite: (path) => path.replace(/^\/api\/back\/ws/, '/ws')
}
proxy['/api/back'] = {
...baseOpts(),
target: back,
rewrite: (path) => path.replace(/^\/api\/back/, '') || '/'
}
// Filet de sécurité : /auth/... sans préfixe /api/back (regex pour ne pas matcher /author…).
proxy['^/auth/'] = {
...baseOpts(),
target: back
}
}
const portailTarget = env[E.portail]?.trim() || back
if (portailTarget) {
proxy['/api/portail'] = {
...baseOpts(),
target: portailTarget,
rewrite: (path) => path.replace(/^\/api\/portail/, '') || '/'
}
}
if (fhir) {
proxy['/api/fhir'] = withFhirAuthHeaderOverride(
{
...baseOpts(),
target: fhir,
rewrite: (path) => path.replace(/^\/api\/fhir/, '/fhir')
},
fhirAuthOverride
)
}
if (request) {
proxy['/api/request'] = withFhirAuthHeaderOverride(
{
...baseOpts(),
target: request,
rewrite: (path) => path.replace(/^\/api\/request/, '/fhir')
},
fhirAuthOverride
)
}
if (datamodel) {
proxy['/api/datamodel'] = {
...baseOpts(),
target: datamodel,
rewrite: (path) => path.replace(/^\/api\/datamodel/, '') || '/'
}
}
return proxy
}