Custom auth
The custom strategy of @worker-manager/auth hands the decision to your code: validate a
Cloudflare Access JWT, reuse your app's API-key check, trust a header set by an authenticating
proxy. The rest of the middleware behaves as for the built-in strategies: req.user is set, the
onAuthenticated hook runs, GET ${basePath}/auth/me answers, and the dashboard header shows who
is signed in.
Options
req is Node's IncomingMessage, so the same function works on Express, Fastify, Koa and NestJS.
The default rejection is 401 with { "error": { "key": "ERRORS.UNAUTHORIZED" }, "code": "UNAUTHORIZED" }.
Cloudflare Access
Cloudflare Access puts a signed JWT in the Cf-Access-Jwt-Assertion header of every request it
lets through. Verify it against your team's keys with jose:
Always verify the JWT. The plain Cf-Access-Authenticated-User-Email header can be forged by
anything that reaches your origin without going through Cloudflare.
Reusing an API-key check (NestJS)
Customising the rejection
Redirect only page loads: the dashboard's own API calls expect a JSON 401. Checking
req.headers.accept?.includes('text/html') is enough to tell them apart.