fix: support production Enable Banking credentials and key format
- Read _PRODUCTION env var variants for APP_ID, private key, and API URL - Handle raw base64 DER key format (production) in addition to base64-encoded PEM (sandbox) by auto-wrapping in PEM headers - Make API URL configurable (sandbox: api.tilisy.com, prod: api.enablebanking.com) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
8e60112d77
commit
325c930839
@@ -14,7 +14,11 @@
|
||||
|
||||
import { getAuthorizationHeader } from './jwt'
|
||||
|
||||
const ENABLE_BANKING_API_URL = 'https://api.enablebanking.com'
|
||||
// Prefer _PRODUCTION variant; sandbox uses api.tilisy.com, production uses api.enablebanking.com
|
||||
const ENABLE_BANKING_API_URL =
|
||||
process.env.ENABLE_BANKING_API_URL_PRODUCTION ||
|
||||
process.env.ENABLE_BANKING_API_URL ||
|
||||
'https://api.enablebanking.com'
|
||||
|
||||
// Types
|
||||
|
||||
|
||||
@@ -7,8 +7,9 @@
|
||||
|
||||
import * as crypto from 'crypto'
|
||||
|
||||
const APP_ID = process.env.ENABLE_BANKING_APP_ID
|
||||
const PRIVATE_KEY_BASE64 = process.env.ENABLE_BANKING_PRIVATE_KEY
|
||||
// Prefer _PRODUCTION variants when available (Vercel production deploys)
|
||||
const APP_ID = process.env.ENABLE_BANKING_APP_ID_PRODUCTION || process.env.ENABLE_BANKING_APP_ID
|
||||
const PRIVATE_KEY_RAW = process.env.ENABLE_BANKING_PRIVATE_KEY_PRODUCTION || process.env.ENABLE_BANKING_PRIVATE_KEY
|
||||
|
||||
interface JWTHeader {
|
||||
typ: string
|
||||
@@ -29,13 +30,19 @@ function base64UrlEncode(data: Buffer | string): string {
|
||||
}
|
||||
|
||||
function getPrivateKey(): string {
|
||||
if (!PRIVATE_KEY_BASE64) {
|
||||
if (!PRIVATE_KEY_RAW) {
|
||||
throw new Error('ENABLE_BANKING_PRIVATE_KEY environment variable is not set')
|
||||
}
|
||||
|
||||
// Decode base64 to get PEM format private key
|
||||
const privateKeyPem = Buffer.from(PRIVATE_KEY_BASE64, 'base64').toString('utf-8')
|
||||
return privateKeyPem
|
||||
// Try decoding as base64-encoded PEM (sandbox format: base64 wrapping a PEM string)
|
||||
const decoded = Buffer.from(PRIVATE_KEY_RAW, 'base64').toString('utf-8')
|
||||
if (decoded.startsWith('-----BEGIN')) {
|
||||
return decoded
|
||||
}
|
||||
|
||||
// Otherwise treat as raw base64 DER key material — wrap in PEM headers
|
||||
const lines = PRIVATE_KEY_RAW.match(/.{1,64}/g) || []
|
||||
return `-----BEGIN PRIVATE KEY-----\n${lines.join('\n')}\n-----END PRIVATE KEY-----`
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
Reference in New Issue
Block a user