fix: move network-backup endpoints outside JWT auth middleware
The /network-backup and /network-backup-files routes use their own X-Network-Backup-Key authentication. Mounting them behind authenticateJWT blocked all receiver sync requests before they could be validated. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
cee84bcd61
commit
fcf6effb7b
@@ -7,6 +7,7 @@ import authRoutes from "./routes/auth";
|
||||
import twilioWebhookRoutes from "./routes/twilio-webhooks";
|
||||
import greetingRoutes from "./routes/greeting";
|
||||
import { authenticateJWT } from "./middlewares/auth.middleware";
|
||||
import networkBackupPublicRoutes from "./routes/network-backup-public";
|
||||
import dotenv from "dotenv";
|
||||
import { startBackupCron } from "./cron/backupCheck";
|
||||
import path from "path";
|
||||
@@ -77,6 +78,8 @@ app.use("/api/auth", authRoutes);
|
||||
app.use("/api/greeting", greetingRoutes);
|
||||
// Twilio webhooks are public — Twilio sends no JWT token
|
||||
app.use("/api/twilio", express.urlencoded({ extended: false }), twilioWebhookRoutes);
|
||||
// Network backup endpoints use their own API key auth — must be before authenticateJWT
|
||||
app.use("/api/database-management", networkBackupPublicRoutes);
|
||||
// All other API routes require JWT
|
||||
app.use("/api", authenticateJWT, routes);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user