Remove js/newsletter-config.js
This commit is contained in:
@@ -1,44 +0,0 @@
|
|||||||
/**
|
|
||||||
* Newsletter signup configuration.
|
|
||||||
*
|
|
||||||
* Only the non-secret serverless endpoint URL lives here. The serverless
|
|
||||||
* function authenticates with an API token it reads from platform env/secrets
|
|
||||||
* at deploy time — never from this module and never from any client-served
|
|
||||||
* asset. Do NOT add a token or any other secret to this file: the client must
|
|
||||||
* never carry a credential, and anything committed here is public.
|
|
||||||
*/
|
|
||||||
|
|
||||||
/** True when the value is an absolute URL whose protocol is https:. */
|
|
||||||
export function isHttpsUrl(value) {
|
|
||||||
try {
|
|
||||||
return new URL(String(value)).protocol === "https:";
|
|
||||||
} catch {
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Enforce the https-only rule on a configured endpoint, mirroring the protocol
|
|
||||||
* allowlist pattern in js/reading-list.js (tightened to https). Throws when the
|
|
||||||
* endpoint would silently downgrade submissions to plaintext.
|
|
||||||
*
|
|
||||||
* @param {string} endpoint
|
|
||||||
* @returns {true}
|
|
||||||
*/
|
|
||||||
export function validateEndpoint(endpoint) {
|
|
||||||
if (!isHttpsUrl(endpoint)) {
|
|
||||||
throw new Error("NEWSLETTER_ENDPOINT must be an https:// URL");
|
|
||||||
}
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* The serverless endpoint the signup form POSTs to.
|
|
||||||
*
|
|
||||||
* https-only is asserted here at config load time (and covered by tests), so a
|
|
||||||
* deployer pointing this at an http:// URL fails fast instead of shipping a
|
|
||||||
* downgraded endpoint.
|
|
||||||
*/
|
|
||||||
export const NEWSLETTER_ENDPOINT = "https://example.com/api/newsletter-subscribers";
|
|
||||||
|
|
||||||
validateEndpoint(NEWSLETTER_ENDPOINT);
|
|
||||||
Reference in New Issue
Block a user