-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathproxy-server.cjs
More file actions
109 lines (94 loc) · 3.17 KB
/
Copy pathproxy-server.cjs
File metadata and controls
109 lines (94 loc) · 3.17 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
// Likey Figma Plugin - Image Proxy Server
// Deploy to Render.com: https://render.com
// This proxies image requests to bypass CORS restrictions in Figma plugins
const http = require('http');
const https = require('https');
const PORT = process.env.PORT || 7777;
const ALLOWED_DOMAINS = [
'static.likeycontents.xyz',
'lh3.googleusercontent.com',
'drive.google.com',
'i.pravatar.cc',
'picsum.photos',
];
const server = http.createServer(function(req, res) {
// CORS headers - allow Figma plugin (null origin)
res.setHeader('Access-Control-Allow-Origin', '*');
res.setHeader('Access-Control-Allow-Methods', 'GET, OPTIONS');
res.setHeader('Access-Control-Allow-Headers', 'Content-Type');
if (req.method === 'OPTIONS') {
res.writeHead(204);
res.end();
return;
}
if (req.method !== 'GET') {
res.writeHead(405);
res.end('Method Not Allowed');
return;
}
const url = new URL(req.url, 'http://localhost:' + PORT);
if (url.pathname === '/health') {
res.writeHead(200, { 'Content-Type': 'application/json' });
res.end(JSON.stringify({ status: 'ok' }));
return;
}
if (url.pathname !== '/proxy-image') {
res.writeHead(404);
res.end('Not Found');
return;
}
const imageUrl = url.searchParams.get('url');
if (!imageUrl) {
res.writeHead(400, { 'Content-Type': 'application/json' });
res.end(JSON.stringify({ error: 'url parameter required' }));
return;
}
// Security: only allow whitelisted domains
let parsedUrl;
try {
parsedUrl = new URL(imageUrl);
} catch (e) {
res.writeHead(400, { 'Content-Type': 'application/json' });
res.end(JSON.stringify({ error: 'Invalid URL' }));
return;
}
const isAllowed = ALLOWED_DOMAINS.some(d => parsedUrl.hostname === d || parsedUrl.hostname.endsWith('.' + d));
if (!isAllowed) {
res.writeHead(403, { 'Content-Type': 'application/json' });
res.end(JSON.stringify({ error: 'Domain not allowed: ' + parsedUrl.hostname }));
return;
}
function fetchWithRedirects(fetchUrl, redirectCount) {
if (redirectCount > 5) {
res.writeHead(502);
res.end(JSON.stringify({ error: 'Too many redirects' }));
return;
}
const mod = fetchUrl.startsWith('https') ? https : http;
mod.get(fetchUrl, function(proxyRes) {
if ([301, 302, 303, 307, 308].includes(proxyRes.statusCode) && proxyRes.headers.location) {
fetchWithRedirects(proxyRes.headers.location, redirectCount + 1);
return;
}
if (proxyRes.statusCode !== 200) {
res.writeHead(proxyRes.statusCode);
res.end(JSON.stringify({ error: 'Upstream error: ' + proxyRes.statusCode }));
return;
}
const contentType = proxyRes.headers['content-type'] || 'application/octet-stream';
res.writeHead(200, {
'Content-Type': contentType,
'Access-Control-Allow-Origin': '*',
'Cache-Control': 'public, max-age=3600',
});
proxyRes.pipe(res);
}).on('error', function(e) {
res.writeHead(500);
res.end(JSON.stringify({ error: e.message }));
});
}
fetchWithRedirects(imageUrl, 0);
});
server.listen(PORT, function() {
console.log('Likey image proxy running on port ' + PORT);
});