From d520140a6ab9b3cdb4557ddb63daf6b84562aed7 Mon Sep 17 00:00:00 2001 From: Xi Xu Date: Wed, 11 Mar 2026 14:07:24 +0800 Subject: [PATCH] Disable debug endpoint by default --- AGENTS.md | 1 + src/index.ts | 10 +++++++++- tests/index.test.ts | 24 ++++++++++++++++++++++++ tests/setup.ts | 2 +- tests/utils/testHelpers.ts | 2 +- worker-configuration.d.ts | 3 +++ 6 files changed, 39 insertions(+), 3 deletions(-) create mode 100644 AGENTS.md diff --git a/AGENTS.md b/AGENTS.md new file mode 100644 index 0000000..ceb2b98 --- /dev/null +++ b/AGENTS.md @@ -0,0 +1 @@ +CLAUDE.md diff --git a/src/index.ts b/src/index.ts index 2c64bd4..3643a20 100644 --- a/src/index.ts +++ b/src/index.ts @@ -27,6 +27,14 @@ import { createStandardResponse } from "./lib/types"; */ const app = new Hono<{ Bindings: Env }>(); +function isDebugModeEnabled(value?: string): boolean { + if (!value) { + return false; + } + + return ["true", "1", "yes", "on"].includes(value.trim().toLowerCase()); +} + /** * Scheduled event handler for periodic maintenance tasks * Executes every 5 minutes as configured in wrangler.jsonc @@ -214,7 +222,7 @@ app */ .post("/debug", async (c) => { // Check if debug mode is enabled via environment variable - if (!c.env.DEBUG_MODE) { + if (!isDebugModeEnabled(c.env.DEBUG_MODE)) { return c.json(createStandardResponse(404, null), 404); } diff --git a/tests/index.test.ts b/tests/index.test.ts index 5be592d..b61ccaa 100644 --- a/tests/index.test.ts +++ b/tests/index.test.ts @@ -68,6 +68,18 @@ describe("Main App", () => { }); describe("POST /debug", () => { + it("should return 404 when debug mode is unset", async () => { + delete mockEnv.DEBUG_MODE; + + const request = new Request("http://localhost/debug", { + method: "POST", + body: JSON.stringify({ text: "Hello world" }), + }); + const response = await app.fetch(request, mockEnv); + + expect(response.status).toBe(404); + }); + it("should return 404 when debug mode is disabled", async () => { mockEnv.DEBUG_MODE = "false"; @@ -80,6 +92,18 @@ describe("Main App", () => { expect(response.status).toBe(404); }); + it("should return 404 when debug mode is a non-empty falsey-like string", async () => { + mockEnv.DEBUG_MODE = "disabled"; + + const request = new Request("http://localhost/debug", { + method: "POST", + body: JSON.stringify({ text: "Hello world" }), + }); + const response = await app.fetch(request, mockEnv); + + expect(response.status).toBe(404); + }); + it("should provide debug information when enabled", async () => { mockEnv.DEBUG_MODE = "true"; diff --git a/tests/setup.ts b/tests/setup.ts index ff3aa68..08497d1 100644 --- a/tests/setup.ts +++ b/tests/setup.ts @@ -39,7 +39,7 @@ global.createMockEnv = (): Env => ({ PROXY_URLS: "https://test1.example.com/jsonrpc,https://test2.example.com/jsonrpc", PROXY_WEIGHTS: "1,1", - DEBUG_MODE: "true", + DEBUG_MODE: "false", }); // Mock Request and Response for Cloudflare Workers environment diff --git a/tests/utils/testHelpers.ts b/tests/utils/testHelpers.ts index 0ef5126..31e3ac5 100644 --- a/tests/utils/testHelpers.ts +++ b/tests/utils/testHelpers.ts @@ -192,7 +192,7 @@ export function createTestEnvironment() { PROXY_URLS: "https://test1.example.com/jsonrpc,https://test2.example.com/jsonrpc", PROXY_WEIGHTS: "1,1", - DEBUG_MODE: "true", + DEBUG_MODE: "false", }; return { diff --git a/worker-configuration.d.ts b/worker-configuration.d.ts index 63abec2..ddb9425 100644 --- a/worker-configuration.d.ts +++ b/worker-configuration.d.ts @@ -17,6 +17,9 @@ interface Env { /** Comma-separated list of proxy weights (optional) */ PROXY_WEIGHTS?: string; + + /** Enables the /debug endpoint only when set to an explicit truthy value */ + DEBUG_MODE?: string; } /**