Log intake: accepts LOG_INTAKE_KEY_NEXT during a key rotation (round 4, X23)

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
igneum-labs 2026-10-04 18:25:33 +00:00
parent 63174a5b6a
commit 91b23edb62

View file

@ -40,9 +40,11 @@ export default async function handler(req, res) {
res.setHeader('Allow', 'POST');
return res.status(405).json({ ok: false, error: 'method not allowed' });
}
const key = process.env.LOG_INTAKE_KEY;
// Two keys during a rotation (4 October 2026, round 4 X23): the current key and, while apps are moving to a new
// build, LOG_INTAKE_KEY_NEXT. Drop the old value from LOG_INTAKE_KEY once every machine reports with the new one.
const keys = [process.env.LOG_INTAKE_KEY, process.env.LOG_INTAKE_KEY_NEXT].filter(k => typeof k === 'string' && k.length >= 16);
const given = req.headers['x-igneum-key'];
if (!key || typeof given !== 'string' || given !== key) {
if (!keys.length || typeof given !== 'string' || !keys.includes(given)) {
return res.status(401).json({ ok: false, error: 'bad key' });
}
let body;