From ea2ca86ce7fd2792b4c4c138e3e5887f80734e7d Mon Sep 17 00:00:00 2001 From: Ian Mustafa Date: Tue, 9 Dec 2025 12:14:20 +0700 Subject: [PATCH] Add verbosity to missing auth headers error --- src/middlewares/apiKeyAuth.ts | 21 ++++++++++++++++++--- 1 file changed, 18 insertions(+), 3 deletions(-) diff --git a/src/middlewares/apiKeyAuth.ts b/src/middlewares/apiKeyAuth.ts index d1b451b..fdaeff3 100644 --- a/src/middlewares/apiKeyAuth.ts +++ b/src/middlewares/apiKeyAuth.ts @@ -99,11 +99,26 @@ export const apiKeyAuthMacro = new Elysia().macro({ const nonce = headers['x-nonce'] const signature = headers['x-signature'] const rawTimestamp = headers['x-timestamp'] - if (!apiKey || !nonce || !signature || !rawTimestamp) { + + const missingHeaders = [] + if (!apiKey) { + missingHeaders.push('X-API-Key') + } + if (!nonce) { + missingHeaders.push('X-Nonce') + } + if (!rawTimestamp) { + missingHeaders.push('X-Timestamp') + } + if (!signature) { + missingHeaders.push('X-Signature') + } + if (missingHeaders.length) { + const missing = missingHeaders.join(', ') logger.debug({ 'headers.authorization': headers.authorization, - }, 'Failed API key authentication attempt due to missing auth headers') - throw new UnauthenticatedError('Missing auth headers') + }, 'Failed API key authentication attempt due to missing auth headers: ' + missing) + throw new UnauthenticatedError('Missing auth headers: ' + missing) } const timestamp = Number(rawTimestamp)