// Authorization for the scheduler tick endpoint. The editor admin surface is // otherwise unauthenticated (trusted-network self-host), so this is opt-in // hardening for installs that expose the editor: set SYNC_TICK_TOKEN in the // server's environment AND in the cron script's environment, and the tick route // will require a matching `Authorization: Bearer ` header. When the env // var is unset, the route is open (consistent with the rest of the editor). export function isSchedulerRequestAuthorized(req: Request): boolean { const token = process.env.SYNC_TICK_TOKEN; if (!token) return true; const header = req.headers.get("authorization") ?? ""; const m = /^Bearer\s+(.+)$/i.exec(header.trim()); return m?.[1] === token; }