diff --git a/src/api/routes/auth/generate-registration-tokens.ts b/src/api/routes/auth/generate-registration-tokens.ts
index 626c6f66..7b54d9ef 100644
--- a/src/api/routes/auth/generate-registration-tokens.ts
+++ b/src/api/routes/auth/generate-registration-tokens.ts
@@ -17,8 +17,9 @@
*/
import { Request, Response, Router } from "express";
-import { randomString, route } from "@spacebar/api";
+import { route } from "@spacebar/api";
import { ValidRegistrationToken } from "@spacebar/database";
+import { Random } from "@spacebar/extensions";
import { Config } from "@spacebar/util";
const router: Router = Router({ mergeParams: true });
@@ -48,7 +49,7 @@ router.get(
for (let i = 0; i < count; i++) {
const token = ValidRegistrationToken.create({
- token: randomString(length),
+ token: Random.getString("ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789", length),
expires_at: new Date(Date.now() + Config.get().security.defaultRegistrationTokenExpiration),
});
tokens.push(token);
diff --git a/src/api/routes/channels/#channel_id/attachments.ts b/src/api/routes/channels/#channel_id/attachments.ts
index e5b9e49c..8a14a135 100644
--- a/src/api/routes/channels/#channel_id/attachments.ts
+++ b/src/api/routes/channels/#channel_id/attachments.ts
@@ -17,8 +17,9 @@
*/
import { Request, Response, Router } from "express";
-import { randomString, route } from "@spacebar/api";
+import { route } from "@spacebar/api";
import { Channel, CloudAttachment } from "@spacebar/database";
+import { Random } from "@spacebar/extensions";
import { Config, Permissions } from "@spacebar/util";
import { UploadAttachmentRequestSchema, UploadAttachmentResponseSchema } from "@spacebar/schemas";
@@ -53,7 +54,7 @@ router.post(
}
const cdnUrl = Config.get().cdn.endpointPublic;
- const batchId = `CLOUD_${user.id}_${randomString(128)}`;
+ const batchId = `CLOUD_${user.id}_${Random.getString("ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789", 128)}`;
// validate IDs
const seenIds: (string | undefined)[] = [];
diff --git a/src/api/routes/channels/#channel_id/invites.ts b/src/api/routes/channels/#channel_id/invites.ts
index 3df4a5a8..6375a239 100644
--- a/src/api/routes/channels/#channel_id/invites.ts
+++ b/src/api/routes/channels/#channel_id/invites.ts
@@ -18,10 +18,11 @@
import { Request, Response, Router } from "express";
import { HTTPError } from "lambert-server/HTTPError";
-import { randomString, route } from "@spacebar/api";
+import { route } from "@spacebar/api";
import { Channel, Guild, Invite, PublicInviteRelation, User } from "@spacebar/database";
import { InviteCreateEvent, emitEvent } from "@spacebar/util";
import { InviteCreateSchema, isTextChannel } from "@spacebar/schemas";
+import { Random } from "@spacebar/extensions";
const router: Router = Router({ mergeParams: true });
@@ -59,7 +60,7 @@ router.post(
const expires_at = body.max_age == 0 || body.max_age == undefined ? undefined : new Date(body.max_age * 1000 + Date.now());
const invite = await Invite.create({
- code: randomString(),
+ code: Random.getString("ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789", 6),
temporary: body.temporary || true,
uses: 0,
max_uses: body.max_uses ? Math.max(0, body.max_uses) : 0,
diff --git a/src/api/routes/guilds/#guild_id/widget.json.ts b/src/api/routes/guilds/#guild_id/widget.json.ts
index 9f3ecd31..9cb4d928 100644
--- a/src/api/routes/guilds/#guild_id/widget.json.ts
+++ b/src/api/routes/guilds/#guild_id/widget.json.ts
@@ -17,8 +17,9 @@
*/
import { Request, Response, Router } from "express";
-import { randomString, route } from "@spacebar/api";
+import { route } from "@spacebar/api";
import { Channel, Guild, Member, Invite } from "@spacebar/database";
+import { Random } from "@spacebar/extensions";
import { Config, DiscordApiErrors, Permissions } from "@spacebar/util";
import { ChannelType, GuildWidgetJsonResponse } from "@spacebar/schemas";
@@ -93,7 +94,7 @@ async function getWidgetJsonData(guild_id: string) {
const expires_at = new Date(max_age * 1000 + Date.now());
invite = await Invite.create({
- code: randomString(),
+ code: Random.getString("ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789", 6),
temporary: false,
uses: 0,
max_uses: 0,
diff --git a/src/api/util/handlers/Message.ts b/src/api/util/handlers/Message.ts
index 53de9b25..e2fc798d 100644
--- a/src/api/util/handlers/Message.ts
+++ b/src/api/util/handlers/Message.ts
@@ -18,9 +18,9 @@
import { HTTPError } from "lambert-server/HTTPError";
import { Equal, In, Or } from "typeorm";
-import { fillMessageUrlEmbeds, randomString } from "@spacebar/api";
+import { fillMessageUrlEmbeds } from "@spacebar/api";
import { getDatabase, Application, Attachment, Channel, CloudAttachment, Guild, Member, Message, ReadState, Role, Session, Sticker, User, Webhook } from "@spacebar/database";
-import { mathLogBase, arrayDistributeSequentially, Stopwatch } from "@spacebar/extensions";
+import { mathLogBase, arrayDistributeSequentially, Stopwatch, Random } from "@spacebar/extensions";
import {
Config,
DiscordApiErrors,
@@ -280,7 +280,7 @@ export function handleComps(components: BaseMessageComponents[], flags: number)
throw FieldErrors(errors);
}
return async (messageId: string, user: User, channel: Channel) => {
- const batchId = `CLOUD_compUploads_${randomString(128)}`;
+ const batchId = `CLOUD_compUploads_${Random.getString("ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789", 128)}`;
(await Promise.all(medias.map((m, index) => processMedia(m, messageId, batchId, user, channel, index + "")))).forEach((_) => _?.());
};
}
diff --git a/src/api/util/index.ts b/src/api/util/index.ts
index c7cbc535..1741179c 100644
--- a/src/api/util/index.ts
+++ b/src/api/util/index.ts
@@ -20,7 +20,6 @@ export * from "./utility/Base64";
export * from "./utility/ipAddress";
export * from "./handlers/Message";
export * from "./utility/passwordStrength";
-export * from "./utility/RandomInviteID";
export * from "./handlers/route";
export * from "./handlers/Voice";
export * from "./utility/captcha";
diff --git a/src/api/util/utility/RandomInviteID.ts b/src/api/util/utility/RandomInviteID.ts
deleted file mode 100644
index ec54a9fc..00000000
--- a/src/api/util/utility/RandomInviteID.ts
+++ /dev/null
@@ -1,68 +0,0 @@
-/*
- Spacebar: A FOSS re-implementation and extension of the Discord.com backend.
- Copyright (C) 2023 Spacebar and Spacebar Contributors
-
- This program is free software: you can redistribute it and/or modify
- it under the terms of the GNU Affero General Public License as published
- by the Free Software Foundation, either version 3 of the License, or
- (at your option) any later version.
-
- This program is distributed in the hope that it will be useful,
- but WITHOUT ANY WARRANTY; without even the implied warranty of
- MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
- GNU Affero General Public License for more details.
-
- You should have received a copy of the GNU Affero General Public License
- along with this program. If not, see <https://www.gnu.org/licenses/>.
-*/
-
-import { Snowflake } from "@spacebar/util";
-import crypto from "node:crypto";
-
-// TODO: 'random'? seriously? who named this?
-// And why is this even here? Just use cryto.randomBytes?
-
-export function randomString(length = 6) {
- // Declare all characters
- const chars = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789";
-
- // Pick characers randomly
- let str = "";
- for (let i = 0; i < length; i++) {
- str += chars.charAt(Math.floor(crypto.randomInt(chars.length)));
- }
-
- return str;
-}
-
-export function snowflakeBasedInvite() {
- // Declare all characters
- const chars = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789";
- const base = BigInt(chars.length);
- let snowflake = Snowflake.generateWorkerProcess();
-
- // snowflakes hold ~10.75 characters worth of entropy;
- // safe to generate a 8-char invite out of them
- const str = "";
- for (let i = 0; i < 10; i++) {
- str.concat(chars.charAt(Number(snowflake % base)));
- snowflake = snowflake / base;
- }
-
- return str
- .slice(3, 3 + 8)
- .split("")
- .reverse()
- .join("");
-}
-
-export function randomUpperString(length: number = 10) {
- const chars = "ABCDEFGHIJKLMNOPQRSTUVWXYZ";
-
- let result = "";
- for (let i = 0; i < length; i++) {
- result += chars.charAt(Math.floor(Math.random() * chars.length));
- }
-
- return result;
-}
diff --git a/src/database/entities/Session.ts b/src/database/entities/Session.ts
index cfe7803c..57cd90d0 100644
--- a/src/database/entities/Session.ts
+++ b/src/database/entities/Session.ts
@@ -18,19 +18,18 @@
import crypto from "node:crypto";
import { Column, CreateDateColumn, Entity, Index, JoinColumn, ManyToOne, PrimaryColumn, RelationId } from "typeorm";
-import { randomUpperString } from "@spacebar/api";
-import { DateBuilder, TimeSpan } from "@spacebar/extensions";
+import { DateBuilder, TimeSpan, Random } from "@spacebar/extensions";
import { User } from "./User";
import { BaseClassWithoutId } from "./BaseClass";
import { Activity, ClientStatus, GatewaySession, GatewaySessionClientInfo, PrivateStatus } from "../../util/interfaces";
-import { IpDataClient } from "../../util/util";
+import { IpDataClient } from "@spacebar/util/util/networking";
@Entity({
name: "sessions",
})
export class Session extends BaseClassWithoutId {
@PrimaryColumn({ nullable: false })
- session_id: string = randomUpperString();
+ session_id: string = Random.getString("ABCDEFGHIJKLMNOPQRSTUVWXYZ", 10);
@Column()
@RelationId((session: Session) => session.user)
diff --git a/src/extensions/Random.ts b/src/extensions/Random.ts
index 212e1c9a..fe865891 100644
--- a/src/extensions/Random.ts
+++ b/src/extensions/Random.ts
@@ -89,4 +89,18 @@ export class Random {
}
return array;
}
+
+ public static getString(choices: string, length: number) {
+ const _choices = choices.split("");
+ const result = new Array(length);
+ for (const i in result) {
+ result[i] = _choices[Random.nextInt(0, _choices.length)];
+ }
+
+ return result.join("");
+ }
+
+ public static getHexString(length: number) {
+ return this.getString("0123456789ABCDEF", length);
+ }
}
diff --git a/src/gateway/Server.ts b/src/gateway/Server.ts
index f0197611..dd19d9da 100644
--- a/src/gateway/Server.ts
+++ b/src/gateway/Server.ts
@@ -19,8 +19,8 @@
import http from "node:http";
import { setInterval } from "node:timers";
import ws from "ws";
-import { randomString } from "@spacebar/api"; // TODO: move to util
import { initDatabase } from "@spacebar/database";
+import { Random } from "@spacebar/extensions";
import { checkToken, Config, initEvent, Rights } from "@spacebar/util";
import { ProcessLifecycle } from "../util/util/ProcessLifecycle";
import { Monitoring } from "../util/monitoring/Monitoring";
@@ -66,7 +66,10 @@ export class Server {
this.server = http.createServer(async (req, res) => {
if (!req.headers.cookie?.split("; ").find((x) => x.startsWith("__sb_sessid="))) {
- res.setHeader("Set-Cookie", `__sb_sessid=${randomString(32)}; Secure; HttpOnly; SameSite=None; Path=/`);
+ res.setHeader(
+ "Set-Cookie",
+ `__sb_sessid=${Random.getString("ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789", 32)}; Secure; HttpOnly; SameSite=None; Path=/`,
+ );
}
const requestUrl = new URL(`http://${req.headers.host}${req.url}`);
if (requestUrl.pathname === "/metrics") {
diff --git a/src/gateway/events/Close.ts b/src/gateway/events/Close.ts
index c227c33d..366e3b7c 100644
--- a/src/gateway/events/Close.ts
+++ b/src/gateway/events/Close.ts
@@ -16,8 +16,8 @@
along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
-import { randomString } from "@spacebar/api";
import { Member, Session, User, VoiceState } from "@spacebar/database";
+import { Random } from "@spacebar/extensions";
import { WebSocket } from "@spacebar/gateway";
import { emitEvent, PresenceUpdateEvent, SessionsReplace, VoiceStateUpdateEvent, distributePresenceUpdate } from "@spacebar/util";
import { ProcessLifecycle } from "../../util/util/ProcessLifecycle";
@@ -56,7 +56,7 @@ export async function Close(this: WebSocket, code: number, reason: Buffer) {
activities: this.session!.activities,
},
origin: "GATEWAY_CLOSE",
- transaction_id: `IDENT_${this.user_id}_${randomString()}`,
+ transaction_id: `IDENT_${this.user_id}_${Random.getString("ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789", 6)}`,
} satisfies PresenceUpdateEvent);
console.log("... done!");
} else console.log("... Discarding presence update as the session reactivated");
diff --git a/src/gateway/opcodes/Identify.ts b/src/gateway/opcodes/Identify.ts
index e1ce6e8c..08b77b65 100644
--- a/src/gateway/opcodes/Identify.ts
+++ b/src/gateway/opcodes/Identify.ts
@@ -19,7 +19,7 @@
import { In, Not } from "typeorm";
import { PreloadedUserSettings } from "discord-protos";
import { Capabilities, CLOSECODES, OPCODES, Payload, Send, setupListener, WebSocket } from "@spacebar/gateway";
-import { arrayGroupBy, ElapsedTime, Stopwatch, timeFunction, timePromise } from "@spacebar/extensions";
+import { arrayGroupBy, ElapsedTime, Stopwatch, timeFunction, timePromise, Random } from "@spacebar/extensions";
import {
getDatabase,
Application,
@@ -59,7 +59,6 @@ import {
TraceRoot,
} from "@spacebar/util";
import { ChannelType, DefaultUserGuildSettings, DMChannel, IdentifySchema, PrivateUserProjection, PublicUser, PublicUserProjection } from "@spacebar/schemas";
-import { randomString } from "@spacebar/api";
import { check } from "./instanceOf";
// TODO: user sharding
@@ -202,7 +201,7 @@ export async function onIdentify(this: WebSocket, data: Payload) {
activities: this.session.activities,
},
origin: "GATEWAY_IDENTIFY",
- transaction_id: `IDENT_${this.user_id}_${randomString()}`,
+ transaction_id: `IDENT_${this.user_id}_${Random.getString("ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789", 6)}`,
} satisfies PresenceUpdateEvent;
}
}
diff --git a/src/util/util/Token.ts b/src/util/util/Token.ts
index 4eaa4bc9..3f654495 100644
--- a/src/util/util/Token.ts
+++ b/src/util/util/Token.ts
@@ -23,8 +23,7 @@ import fs from "node:fs/promises";
import jwt from "jsonwebtoken";
import { HTTPError } from "lambert-server/HTTPError";
import { InstanceBan, Session, User } from "@spacebar/database";
-import { randomUpperString } from "@spacebar/api";
-import { TimeSpan } from "@spacebar/extensions";
+import { Random, TimeSpan } from "@spacebar/extensions";
import { Config } from "./Config";
import { OrmUtils } from "@spacebar/util";
@@ -162,7 +161,7 @@ export async function generateToken(id: string, isAdminSession: boolean = false)
let newSession;
do {
newSession = Session.create({
- session_id: randomUpperString(10), // readable at a glance
+ session_id: Random.getString("ABCDEFGHIJKLMNOPQRSTUVWXYZ", 10), // readable at a glance
user_id: id,
is_admin_session: isAdminSession,
client_status: {},
|