aboutsummaryrefslogtreecommitdiff
path: root/node_modules/algoliasearch/src/server/builds/AlgoliaSearchServer.js
blob: c6e5dfec82958a5ad62199ca0d516f1529b62303 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
'use strict';

// Some methods only accessible server side

module.exports = AlgoliaSearchServer;

var inherits = require('inherits');

var AlgoliaSearch = require('../../AlgoliaSearch');

function AlgoliaSearchServer(applicationID, apiKey, opts) {
  // Default protocol is https: on the server, to avoid leaking admin keys
  if (opts.protocol === undefined) {
    opts.protocol = 'https:';
  }

  AlgoliaSearch.apply(this, arguments);
}

inherits(AlgoliaSearchServer, AlgoliaSearch);

/*
 * Allow to use IP rate limit when you have a proxy between end-user and Algolia.
 * This option will set the X-Forwarded-For HTTP header with the client IP and the X-Forwarded-API-Key with the API Key having rate limits.
 * @param adminAPIKey the admin API Key you can find in your dashboard
 * @param endUserIP the end user IP (you can use both IPV4 or IPV6 syntax)
 * @param rateLimitAPIKey the API key on which you have a rate limit
 */
AlgoliaSearchServer.prototype.enableRateLimitForward = function(adminAPIKey, endUserIP, rateLimitAPIKey) {
  this._forward = {
    adminAPIKey: adminAPIKey,
    endUserIP: endUserIP,
    rateLimitAPIKey: rateLimitAPIKey
  };
};

/*
 * Disable IP rate limit enabled with enableRateLimitForward() function
 */
AlgoliaSearchServer.prototype.disableRateLimitForward = function() {
  this._forward = null;
};

/*
 * Specify the securedAPIKey to use with associated information
 */
AlgoliaSearchServer.prototype.useSecuredAPIKey = function(securedAPIKey, securityTags, userToken) {
  this._secure = {
    apiKey: securedAPIKey,
    securityTags: securityTags,
    userToken: userToken
  };
};

/*
 * If a secured API was used, disable it
 */
AlgoliaSearchServer.prototype.disableSecuredAPIKey = function() {
  this._secure = null;
};

AlgoliaSearchServer.prototype._computeRequestHeaders = function(additionalUA) {
  var headers = AlgoliaSearchServer.super_.prototype._computeRequestHeaders.call(this, additionalUA);

  if (this._forward) {
    headers['x-algolia-api-key'] = this._forward.adminAPIKey;
    headers['x-forwarded-for'] = this._forward.endUserIP;
    headers['x-forwarded-api-key'] = this._forward.rateLimitAPIKey;
  }

  if (this._secure) {
    headers['x-algolia-api-key'] = this._secure.apiKey;
    headers['x-algolia-tagfilters'] = this._secure.securityTags;
    headers['x-algolia-usertoken'] = this._secure.userToken;
  }

  return headers;
};