fix: move network-backup endpoints outside JWT auth middleware

The /network-backup and /network-backup-files routes use their own
X-Network-Backup-Key authentication. Mounting them behind authenticateJWT
blocked all receiver sync requests before they could be validated.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Summit Dental Care
2026-06-22 23:50:19 -04:00
co-authored by Claude Sonnet 4.6
parent cee84bcd61
commit fcf6effb7b
2 changed files with 84 additions and 0 deletions
+3
View File
@@ -7,6 +7,7 @@ import authRoutes from "./routes/auth";
import twilioWebhookRoutes from "./routes/twilio-webhooks";
import greetingRoutes from "./routes/greeting";
import { authenticateJWT } from "./middlewares/auth.middleware";
import networkBackupPublicRoutes from "./routes/network-backup-public";
import dotenv from "dotenv";
import { startBackupCron } from "./cron/backupCheck";
import path from "path";
@@ -77,6 +78,8 @@ app.use("/api/auth", authRoutes);
app.use("/api/greeting", greetingRoutes);
// Twilio webhooks are public — Twilio sends no JWT token
app.use("/api/twilio", express.urlencoded({ extended: false }), twilioWebhookRoutes);
// Network backup endpoints use their own API key auth — must be before authenticateJWT
app.use("/api/database-management", networkBackupPublicRoutes);
// All other API routes require JWT
app.use("/api", authenticateJWT, routes);