fdsafs
This commit is contained in:
@@ -12,6 +12,24 @@ export default router => {
|
||||
* POST /api/v2/anon/session
|
||||
* Authenticate via OpenSSH Ed25519 signature and establish an anonymous session.
|
||||
*/
|
||||
const formatCascadeReason = (sourceReason, prefix = 'Cascade ban from device') => {
|
||||
if (!sourceReason) return prefix;
|
||||
let clean = sourceReason;
|
||||
while (/^Cascade ban from (device|hardware ID|key) \((.*)\)$/.test(clean)) {
|
||||
clean = clean.replace(/^Cascade ban from (device|hardware ID|key) \((.*)\)$/, '$2');
|
||||
}
|
||||
return `${prefix} (${clean || 'Violation of community rules'})`;
|
||||
};
|
||||
|
||||
const setBanCookie = (res, reason, expires) => {
|
||||
const payload = encodeURIComponent(JSON.stringify({
|
||||
banned: true,
|
||||
reason: reason || 'Banned',
|
||||
expires: expires ? new Date(expires).toISOString() : null
|
||||
}));
|
||||
res.setHeader('Set-Cookie', `f0ck_banned=${payload}; Path=/; Max-Age=31536000; SameSite=Lax`);
|
||||
};
|
||||
|
||||
group.post(/\/session$/, async (req, res) => {
|
||||
try {
|
||||
if (!getEnableAnonymousAccess()) {
|
||||
@@ -21,6 +39,7 @@ export default router => {
|
||||
const clientIp = security.getRealIP(req);
|
||||
const ipBan = await security.isIpBanned(clientIp);
|
||||
if (ipBan) {
|
||||
setBanCookie(res, ipBan.reason || 'IP address is banned', ipBan.expires);
|
||||
return res.json({
|
||||
success: false,
|
||||
banned: true,
|
||||
@@ -64,15 +83,19 @@ export default router => {
|
||||
const activeTombstoneBan = tombstoneBan || tombstoneHwBan;
|
||||
|
||||
if (activeTombstoneBan) {
|
||||
await security.banAnonymousUser({
|
||||
fingerprint: parsed.fingerprint,
|
||||
hwFingerprint: hwFingerprint || tombstoneHw,
|
||||
bannedBy: activeTombstoneBan.banned_by,
|
||||
reason: `Cascade ban from device (${activeTombstoneBan.reason || 'Banned'})`,
|
||||
expires: activeTombstoneBan.expires,
|
||||
banIps: true,
|
||||
banHardware: true
|
||||
});
|
||||
const alreadyFpBanned = await security.isFingerprintBanned(parsed.fingerprint);
|
||||
if (!alreadyFpBanned) {
|
||||
await security.banAnonymousUser({
|
||||
fingerprint: parsed.fingerprint,
|
||||
hwFingerprint: hwFingerprint || tombstoneHw,
|
||||
bannedBy: activeTombstoneBan.banned_by,
|
||||
reason: formatCascadeReason(activeTombstoneBan.reason, 'Cascade ban from device'),
|
||||
expires: activeTombstoneBan.expires,
|
||||
banIps: true,
|
||||
banHardware: true
|
||||
});
|
||||
}
|
||||
setBanCookie(res, activeTombstoneBan.reason || 'Device is banned', activeTombstoneBan.expires);
|
||||
return res.json({
|
||||
success: false,
|
||||
banned: true,
|
||||
@@ -90,15 +113,19 @@ export default router => {
|
||||
if (hwFingerprint) {
|
||||
const hwBan = await security.isHardwareBanned(hwFingerprint);
|
||||
if (hwBan) {
|
||||
await security.banAnonymousUser({
|
||||
fingerprint: parsed.fingerprint,
|
||||
hwFingerprint,
|
||||
bannedBy: hwBan.banned_by,
|
||||
reason: `Cascade ban from hardware ID (${hwBan.reason || 'Banned'})`,
|
||||
expires: hwBan.expires,
|
||||
banIps: true,
|
||||
banHardware: true
|
||||
});
|
||||
const alreadyFpBanned = await security.isFingerprintBanned(parsed.fingerprint);
|
||||
if (!alreadyFpBanned) {
|
||||
await security.banAnonymousUser({
|
||||
fingerprint: parsed.fingerprint,
|
||||
hwFingerprint,
|
||||
bannedBy: hwBan.banned_by,
|
||||
reason: formatCascadeReason(hwBan.reason, 'Cascade ban from hardware ID'),
|
||||
expires: hwBan.expires,
|
||||
banIps: true,
|
||||
banHardware: true
|
||||
});
|
||||
}
|
||||
setBanCookie(res, hwBan.reason || 'Hardware ID is banned', hwBan.expires);
|
||||
return res.json({
|
||||
success: false,
|
||||
banned: true,
|
||||
@@ -116,16 +143,20 @@ export default router => {
|
||||
const fpBan = await security.isFingerprintBanned(parsed.fingerprint);
|
||||
if (fpBan) {
|
||||
if (hwFingerprint) {
|
||||
await security.banAnonymousUser({
|
||||
fingerprint: parsed.fingerprint,
|
||||
hwFingerprint,
|
||||
bannedBy: fpBan.banned_by,
|
||||
reason: `Cascade ban from key (${fpBan.reason || 'Banned'})`,
|
||||
expires: fpBan.expires,
|
||||
banIps: true,
|
||||
banHardware: true
|
||||
});
|
||||
const alreadyHwBanned = await security.isHardwareBanned(hwFingerprint);
|
||||
if (!alreadyHwBanned) {
|
||||
await security.banAnonymousUser({
|
||||
fingerprint: parsed.fingerprint,
|
||||
hwFingerprint,
|
||||
bannedBy: fpBan.banned_by,
|
||||
reason: formatCascadeReason(fpBan.reason, 'Cascade ban from key'),
|
||||
expires: fpBan.expires,
|
||||
banIps: true,
|
||||
banHardware: true
|
||||
});
|
||||
}
|
||||
}
|
||||
setBanCookie(res, fpBan.reason || 'Key fingerprint is banned', fpBan.expires);
|
||||
return res.json({
|
||||
success: false,
|
||||
banned: true,
|
||||
@@ -144,15 +175,19 @@ export default router => {
|
||||
const userRows = await db`SELECT banned, ban_reason, ban_expires FROM "user" WHERE id = ${userId} LIMIT 1`;
|
||||
if (userRows.length > 0 && userRows[0].banned) {
|
||||
const u = userRows[0];
|
||||
await security.banAnonymousUser({
|
||||
userId,
|
||||
fingerprint: parsed.fingerprint,
|
||||
hwFingerprint,
|
||||
reason: u.ban_reason || 'Banned',
|
||||
expires: u.ban_expires,
|
||||
banIps: true,
|
||||
banHardware: true
|
||||
});
|
||||
const alreadyFpBanned = await security.isFingerprintBanned(parsed.fingerprint);
|
||||
if (!alreadyFpBanned) {
|
||||
await security.banAnonymousUser({
|
||||
userId,
|
||||
fingerprint: parsed.fingerprint,
|
||||
hwFingerprint,
|
||||
reason: u.ban_reason || 'Banned',
|
||||
expires: u.ban_expires,
|
||||
banIps: true,
|
||||
banHardware: true
|
||||
});
|
||||
}
|
||||
setBanCookie(res, u.ban_reason || 'Banned', u.ban_expires);
|
||||
return res.json({
|
||||
success: false,
|
||||
banned: true,
|
||||
|
||||
Reference in New Issue
Block a user