From 91b23edb6215e87b4749bbea85040e371dfa76c1 Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Sun, 4 Oct 2026 18:25:33 +0000 Subject: [PATCH] Log intake: accepts LOG_INTAKE_KEY_NEXT during a key rotation (round 4, X23) Co-Authored-By: Claude Fable 5.1 --- site/api/log.mjs | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/site/api/log.mjs b/site/api/log.mjs index 051911c08..1dea94c8d 100644 --- a/site/api/log.mjs +++ b/site/api/log.mjs @@ -40,9 +40,11 @@ export default async function handler(req, res) { res.setHeader('Allow', 'POST'); return res.status(405).json({ ok: false, error: 'method not allowed' }); } - const key = process.env.LOG_INTAKE_KEY; + // Two keys during a rotation (4 October 2026, round 4 X23): the current key and, while apps are moving to a new + // build, LOG_INTAKE_KEY_NEXT. Drop the old value from LOG_INTAKE_KEY once every machine reports with the new one. + const keys = [process.env.LOG_INTAKE_KEY, process.env.LOG_INTAKE_KEY_NEXT].filter(k => typeof k === 'string' && k.length >= 16); const given = req.headers['x-igneum-key']; - if (!key || typeof given !== 'string' || given !== key) { + if (!keys.length || typeof given !== 'string' || !keys.includes(given)) { return res.status(401).json({ ok: false, error: 'bad key' }); } let body;