summary refs log tree commit diff
diff options
context:
space:
mode:
authorRory& <root@rory.gay>2025-12-02 16:46:08 +0100
committerRory& <root@rory.gay>2025-12-02 16:46:08 +0100
commit8b10d85d296253375bf4ddad7c97350ca0883853 (patch)
treec61d5f15cea79bef0d55326b407080539b2db1a8
parentDont export classes as default (diff)
downloadserver-ts-8b10d85d296253375bf4ddad7c97350ca0883853.tar.xz
Use IpDataClient in places
-rw-r--r--src/api/routes/auth/location-metadata.ts5
-rw-r--r--src/api/routes/auth/register.ts6
-rw-r--r--src/api/util/handlers/Voice.ts10
-rw-r--r--src/api/util/utility/ipAddress.ts76
-rw-r--r--src/util/config/types/RegisterConfiguration.ts4
5 files changed, 15 insertions, 86 deletions
diff --git a/src/api/routes/auth/location-metadata.ts b/src/api/routes/auth/location-metadata.ts

index 2ebfd019..a08c98ab 100644 --- a/src/api/routes/auth/location-metadata.ts +++ b/src/api/routes/auth/location-metadata.ts
@@ -16,7 +16,8 @@ along with this program. If not, see <https://www.gnu.org/licenses/>. */ -import { IPAnalysis, getIpAdress, route } from "@spacebar/api"; +import { getIpAdress, route } from "@spacebar/api"; +import { IpDataClient } from "@spacebar/util"; import { Request, Response, Router } from "express"; const router = Router({ mergeParams: true }); @@ -32,7 +33,7 @@ router.get( async (req: Request, res: Response) => { //TODO //Note: It's most likely related to legal. At the moment Discord hasn't finished this too - const country_code = (await IPAnalysis(getIpAdress(req))).country_code; + const country_code = (await IpDataClient.getIpInfo(getIpAdress(req)))?.country_code; res.json({ consent_required: false, country_code: country_code, diff --git a/src/api/routes/auth/register.ts b/src/api/routes/auth/register.ts
index 2db60abd..96e65b9a 100644 --- a/src/api/routes/auth/register.ts +++ b/src/api/routes/auth/register.ts
@@ -17,9 +17,7 @@ */ import { - IPAnalysis, getIpAdress, - isProxy, route, verifyCaptcha, } from "@spacebar/api"; @@ -30,6 +28,7 @@ import { User, ValidRegistrationToken, generateToken, + IpDataClient } from "@spacebar/util"; import bcrypt from "bcrypt"; import { Request, Response, Router } from "express"; @@ -148,7 +147,8 @@ router.post( } if (!regTokenUsed && register.blockProxies) { - if (isProxy(await IPAnalysis(ip))) { + const ipData = await IpDataClient.getIpInfo(ip); + if (ipData && IpDataClient.isProxy(ipData)) { console.log(`proxy ${ip} blocked from registration`); throw new HTTPError("Your IP is blocked from registration"); } diff --git a/src/api/util/handlers/Voice.ts b/src/api/util/handlers/Voice.ts
index db06bd33..21d5ee41 100644 --- a/src/api/util/handlers/Voice.ts +++ b/src/api/util/handlers/Voice.ts
@@ -16,8 +16,8 @@ along with this program. If not, see <https://www.gnu.org/licenses/>. */ -import { Config } from "@spacebar/util"; -import { distanceBetweenLocations, IPAnalysis } from "../utility/ipAddress"; +import { Config, IpDataClient } from "@spacebar/util"; +import { distanceBetweenLocations } from "../utility/ipAddress"; export async function getVoiceRegions(ipAddress: string, vip: boolean) { const regions = Config.get().regions; @@ -27,15 +27,15 @@ export async function getVoiceRegions(ipAddress: string, vip: boolean) { let optimalId = regions.default; if (!regions.useDefaultAsOptimal) { - const clientIpAnalysis = await IPAnalysis(ipAddress); + const clientIpAnalysis = await IpDataClient.getIpInfo(ipAddress); let min = Number.POSITIVE_INFINITY; for (const ar of availableRegions) { //TODO the endpoint location should be saved in the database if not already present to prevent IPAnalysis call const dist = distanceBetweenLocations( - clientIpAnalysis, - ar.location || (await IPAnalysis(ar.endpoint)), + clientIpAnalysis!, + ar.location || (await IpDataClient.getIpInfo(ar.endpoint))!, ); if (dist < min) { diff --git a/src/api/util/utility/ipAddress.ts b/src/api/util/utility/ipAddress.ts
index 2609dae1..e5acc89d 100644 --- a/src/api/util/utility/ipAddress.ts +++ b/src/api/util/utility/ipAddress.ts
@@ -18,82 +18,6 @@ import { Config } from "@spacebar/util"; import { Request } from "express"; -// use ipdata package instead of simple fetch because of integrated caching - -const exampleData = { - ip: "", - is_eu: true, - city: "", - region: "", - region_code: "", - country_name: "", - country_code: "", - continent_name: "", - continent_code: "", - latitude: 0, - longitude: 0, - postal: "", - calling_code: "", - flag: "", - emoji_flag: "", - emoji_unicode: "", - asn: { - asn: "", - name: "", - domain: "", - route: "", - type: "isp", - }, - languages: [ - { - name: "", - native: "", - }, - ], - currency: { - name: "", - code: "", - symbol: "", - native: "", - plural: "", - }, - time_zone: { - name: "", - abbr: "", - offset: "", - is_dst: true, - current_time: "", - }, - threat: { - is_tor: false, - is_proxy: false, - is_anonymous: false, - is_known_attacker: false, - is_known_abuser: false, - is_threat: false, - is_bogon: false, - }, - count: 0, - status: 200, -}; - -//TODO add function that support both ip and domain names -export async function IPAnalysis(ip: string): Promise<typeof exampleData> { - const { ipdataApiKey } = Config.get().security; - if (!ipdataApiKey) return { ...exampleData, ip }; - - return ( - await fetch(`https://api.ipdata.co/${ip}?api-key=${ipdataApiKey}`) - ).json() as Promise<typeof exampleData>; -} - -export function isProxy(data: typeof exampleData) { - if (!data || !data.asn || !data.threat) return false; - if (data.asn.type !== "isp") return true; - if (Object.values(data.threat).some((x) => x)) return true; - - return false; -} export function getIpAdress(req: Request): string { // TODO: express can do this (trustProxies: true)? diff --git a/src/util/config/types/RegisterConfiguration.ts b/src/util/config/types/RegisterConfiguration.ts
index 9d8e036e..c1e97593 100644 --- a/src/util/config/types/RegisterConfiguration.ts +++ b/src/util/config/types/RegisterConfiguration.ts
@@ -34,6 +34,10 @@ export class RegisterConfiguration { allowNewRegistration: boolean = true; allowMultipleAccounts: boolean = true; blockProxies: boolean = true; + blockIpDataCoThreatTypes: string[] = ["tor", "icloud_relay", "proxy", "datacenter", "anonymous", "known_attacker", "known_abuser", "threat"]; // matching ipdata's threat.is_* fields as of 2025/11/30, minus bogon + blockAsnTypes: string[] = [""]; + blockAsns: string[] = [""]; + blockAbuseIpDbAboveScore: number = 0; // 0 to disable incrementingDiscriminators: boolean = false; // random otherwise defaultRights: string = "875069521787904"; // See `npm run generate:rights` }