bug: Force Static Import should actually matter.

This commit is contained in:
zkldi
2022-03-20 15:14:40 +00:00
parent 134d419fdd
commit 4927f815b5
2 changed files with 23 additions and 1 deletions
@@ -457,5 +457,20 @@ t.test("POST /ir/fervidex/profile/submit", (t) => {
t.end();
});
t.test("Should disallow requests from non INF2 if forceStaticImport is false.", async (t) => {
await db["fer-settings"].update({ userID: 1 }, { $set: { forceStaticImport: false } });
const res = await mockApi
.post("/ir/fervidex/profile/submit")
.set("Authorization", "Bearer mock_token")
.set("User-Agent", "fervidex/1.3.0")
.set("X-Software-Model", "LDJ:J:B:A:2020092900")
.send(ferStaticBody);
t.equal(res.statusCode, 400, "Should be rejected, as FSI is not set.");
t.end();
});
t.end();
});
@@ -92,7 +92,14 @@ const RequireInf2ModelHeaderOrForceStatic: RequestHandler = async (req, res, nex
}
try {
ParseEA3SoftID(swModel);
const { model } = ParseEA3SoftID(swModel);
if (model !== MODEL_INFINITAS_2) {
return res.status(400).json({
success: false,
error: `Refusing to perform static import from non-infinitas client. To do this anyway, enable Force Static Import.`,
});
}
} catch (err) {
logger.info(`Invalid softID from ${req[SYMBOL_TachiAPIAuth].userID!}.`, { err });
return res.status(400).json({