diff --git a/app/[locale]/errors/api/relay/route.ts b/app/[locale]/errors/api/relay/route.ts index cbeedc0e5..44664c754 100644 --- a/app/[locale]/errors/api/relay/route.ts +++ b/app/[locale]/errors/api/relay/route.ts @@ -1,13 +1,58 @@ import { NextResponse } from 'next/server'; +const ALLOWED_HOSTS = ['glitchtip.infra.mintel.me', 'errors.infra.mintel.me']; + export async function POST(req: Request) { try { const rawText = await req.text(); - // Sentry sends NDJSON (Newline Delimited JSON). Split by newline to parse safely. - const items = rawText.split('\n').filter(Boolean).map(line => JSON.parse(line)); - console.log("CLIENT ERROR INTERCEPTED:", JSON.stringify(items[0], null, 2)); + const items = rawText.split('\n'); + + if (items.length === 0 || !items[0]) { + return NextResponse.json({ error: 'Empty payload' }, { status: 400 }); + } + + const header = JSON.parse(items[0]); + // Use the server's configured DSN (if available) to override the client's potentially fake DSN + // This allows the client to work without exposing NEXT_PUBLIC_SENTRY_DSN + const dsn = process.env.SENTRY_DSN || header.dsn; + if (!dsn) { + return NextResponse.json({ error: 'No DSN found' }, { status: 400 }); + } + + const url = new URL(dsn); + const projectId = url.pathname.replace('/', ''); + const host = url.hostname; + + if (!ALLOWED_HOSTS.includes(host)) { + return NextResponse.json({ error: 'Invalid Sentry Host' }, { status: 400 }); + } + + // Rewrite the DSN in the envelope header so Glitchtip doesn't reject the fake client DSN + if (process.env.SENTRY_DSN) { + header.dsn = process.env.SENTRY_DSN; + items[0] = JSON.stringify(header); + } + + const sentryIngestUrl = `https://${host}/api/${projectId}/envelope/`; + const payloadToForward = items.join('\n'); + + const response = await fetch(sentryIngestUrl, { + method: 'POST', + body: payloadToForward, + headers: { + 'Content-Type': 'application/x-sentry-envelope', + }, + }); + + if (!response.ok) { + const errorText = await response.text(); + console.error(`[Sentry Tunnel] Relay rejected (${response.status}):`, errorText); + return NextResponse.json({ error: 'Sentry rejection' }, { status: response.status }); + } + + return NextResponse.json({ success: true }); } catch (e) { - console.log("Failed to parse relay body (NDJSON)", e); + console.error("[Sentry Tunnel] Failed to parse or relay body", e); + return NextResponse.json({ error: 'Relay failed' }, { status: 500 }); } - return NextResponse.json({ success: true }); }