mirror of
https://github.com/zkldi/Tachi.git
synced 2026-10-02 11:58:12 +03:00
If a banned user is making a request, all requests should 403.
This commit is contained in:
Vendored
+1
@@ -54,6 +54,7 @@ const staticIndexes: Partial<Record<Databases, Index[]>> = {
|
||||
],
|
||||
users: [
|
||||
index({ id: 1 }, UNIQUE),
|
||||
index({ id: 1, authLevel: 1 }, UNIQUE),
|
||||
index({ username: 1 }, UNIQUE),
|
||||
index({ usernameLowercase: 1 }, UNIQUE),
|
||||
],
|
||||
|
||||
@@ -2,8 +2,9 @@ import { RequestHandler } from "express";
|
||||
import db from "external/mongo/db";
|
||||
import { SYMBOL_TachiAPIAuth } from "lib/constants/tachi";
|
||||
import { SplitAuthorizationHeader } from "utils/misc";
|
||||
import { APITokenDocument, APIPermissions } from "tachi-common";
|
||||
import { APITokenDocument, APIPermissions, UserAuthLevels } from "tachi-common";
|
||||
import CreateLogCtx from "lib/logger/logger";
|
||||
import { TachiConfig } from "lib/setup/config";
|
||||
|
||||
const logger = CreateLogCtx(__filename);
|
||||
|
||||
@@ -186,3 +187,21 @@ const CreateRequireNotGuest =
|
||||
export const RequireNotGuest: RequestHandler = CreateRequireNotGuest("description");
|
||||
|
||||
export const FervidexStyleRequireNotGuest: RequestHandler = CreateRequireNotGuest("error");
|
||||
|
||||
export const RejectIfBanned: RequestHandler = async (req, res, next) => {
|
||||
if (req.session?.tachi?.user.id) {
|
||||
const isBanned = await db.users.findOne({
|
||||
id: req.session.tachi.user.id,
|
||||
authLevel: UserAuthLevels.BANNED,
|
||||
});
|
||||
|
||||
if (isBanned) {
|
||||
return res.status(403).json({
|
||||
success: false,
|
||||
description: `You are banned from ${TachiConfig.NAME}`,
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
next();
|
||||
};
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
import CreateLogCtx from "lib/logger/logger";
|
||||
import { RequestHandler, Response } from "express-serve-static-core";
|
||||
import { SYMBOL_TachiAPIAuth } from "lib/constants/tachi";
|
||||
import { TachiConfig } from "lib/setup/config";
|
||||
|
||||
const logger = CreateLogCtx(__filename);
|
||||
|
||||
@@ -60,6 +61,10 @@ export const RequestLoggerMiddleware: RequestHandler = (req, res, next) => {
|
||||
return;
|
||||
}
|
||||
|
||||
if (contents.body.description === `You are banned from ${TachiConfig.NAME}.`) {
|
||||
return;
|
||||
}
|
||||
|
||||
if (res.statusCode < 400 || res.statusCode === 404) {
|
||||
logger.verbose(
|
||||
`(${req.method} ${req.originalUrl}) Returned ${res.statusCode}.`,
|
||||
|
||||
@@ -8,6 +8,7 @@ import { SYMBOL_TachiAPIAuth } from "lib/constants/tachi";
|
||||
import CreateLogCtx from "lib/logger/logger";
|
||||
import { Environment, ServerConfig, TachiConfig } from "lib/setup/config";
|
||||
import { integer } from "tachi-common";
|
||||
import { RejectIfBanned } from "./middleware/auth";
|
||||
import { RequestLoggerMiddleware } from "./middleware/request-logger";
|
||||
import mainRouter from "./router/router";
|
||||
|
||||
@@ -96,6 +97,8 @@ process.on("unhandledRejection", (reason, promise) => {
|
||||
app.use(express.json({ limit: "4mb" }));
|
||||
|
||||
app.use((req, res, next) => {
|
||||
// Always mount an empty req body. We operate under the assumption that req.body is
|
||||
// always defined.
|
||||
if (req.method !== "GET" && !req.body) {
|
||||
req.body = {};
|
||||
}
|
||||
@@ -104,6 +107,7 @@ app.use((req, res, next) => {
|
||||
});
|
||||
|
||||
app.use(RequestLoggerMiddleware);
|
||||
app.use(RejectIfBanned);
|
||||
|
||||
app.use("/", mainRouter);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user