summary refs log tree commit diff
path: root/src
diff options
context:
space:
mode:
authorRory& <root@rory.gay>2026-06-16 02:39:15 +0200
committerRory& <root@rory.gay>2026-06-16 02:39:15 +0200
commit92f4099b82f9b56972aff99b74dba4c3892272cb (patch)
tree46c443c5b536d387314a86c92ef7e9ef64155c9d /src
parentDont fetch roles if role id set is empty (diff)
downloadserver-ts-92f4099b82f9b56972aff99b74dba4c3892272cb.tar.xz
Move random string to Random class in extensions
Diffstat (limited to 'src')
-rw-r--r--src/api/routes/auth/generate-registration-tokens.ts5
-rw-r--r--src/api/routes/channels/#channel_id/attachments.ts5
-rw-r--r--src/api/routes/channels/#channel_id/invites.ts5
-rw-r--r--src/api/routes/guilds/#guild_id/widget.json.ts5
-rw-r--r--src/api/util/handlers/Message.ts6
-rw-r--r--src/api/util/index.ts1
-rw-r--r--src/api/util/utility/RandomInviteID.ts68
-rw-r--r--src/database/entities/Session.ts7
-rw-r--r--src/extensions/Random.ts14
-rw-r--r--src/gateway/Server.ts7
-rw-r--r--src/gateway/events/Close.ts4
-rw-r--r--src/gateway/opcodes/Identify.ts5
-rw-r--r--src/util/util/Token.ts5
13 files changed, 43 insertions, 94 deletions
diff --git a/src/api/routes/auth/generate-registration-tokens.ts b/src/api/routes/auth/generate-registration-tokens.ts

index 626c6f66..7b54d9ef 100644 --- a/src/api/routes/auth/generate-registration-tokens.ts +++ b/src/api/routes/auth/generate-registration-tokens.ts
@@ -17,8 +17,9 @@ */ import { Request, Response, Router } from "express"; -import { randomString, route } from "@spacebar/api"; +import { route } from "@spacebar/api"; import { ValidRegistrationToken } from "@spacebar/database"; +import { Random } from "@spacebar/extensions"; import { Config } from "@spacebar/util"; const router: Router = Router({ mergeParams: true }); @@ -48,7 +49,7 @@ router.get( for (let i = 0; i < count; i++) { const token = ValidRegistrationToken.create({ - token: randomString(length), + token: Random.getString("ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789", length), expires_at: new Date(Date.now() + Config.get().security.defaultRegistrationTokenExpiration), }); tokens.push(token); diff --git a/src/api/routes/channels/#channel_id/attachments.ts b/src/api/routes/channels/#channel_id/attachments.ts
index e5b9e49c..8a14a135 100644 --- a/src/api/routes/channels/#channel_id/attachments.ts +++ b/src/api/routes/channels/#channel_id/attachments.ts
@@ -17,8 +17,9 @@ */ import { Request, Response, Router } from "express"; -import { randomString, route } from "@spacebar/api"; +import { route } from "@spacebar/api"; import { Channel, CloudAttachment } from "@spacebar/database"; +import { Random } from "@spacebar/extensions"; import { Config, Permissions } from "@spacebar/util"; import { UploadAttachmentRequestSchema, UploadAttachmentResponseSchema } from "@spacebar/schemas"; @@ -53,7 +54,7 @@ router.post( } const cdnUrl = Config.get().cdn.endpointPublic; - const batchId = `CLOUD_${user.id}_${randomString(128)}`; + const batchId = `CLOUD_${user.id}_${Random.getString("ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789", 128)}`; // validate IDs const seenIds: (string | undefined)[] = []; diff --git a/src/api/routes/channels/#channel_id/invites.ts b/src/api/routes/channels/#channel_id/invites.ts
index 3df4a5a8..6375a239 100644 --- a/src/api/routes/channels/#channel_id/invites.ts +++ b/src/api/routes/channels/#channel_id/invites.ts
@@ -18,10 +18,11 @@ import { Request, Response, Router } from "express"; import { HTTPError } from "lambert-server/HTTPError"; -import { randomString, route } from "@spacebar/api"; +import { route } from "@spacebar/api"; import { Channel, Guild, Invite, PublicInviteRelation, User } from "@spacebar/database"; import { InviteCreateEvent, emitEvent } from "@spacebar/util"; import { InviteCreateSchema, isTextChannel } from "@spacebar/schemas"; +import { Random } from "@spacebar/extensions"; const router: Router = Router({ mergeParams: true }); @@ -59,7 +60,7 @@ router.post( const expires_at = body.max_age == 0 || body.max_age == undefined ? undefined : new Date(body.max_age * 1000 + Date.now()); const invite = await Invite.create({ - code: randomString(), + code: Random.getString("ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789", 6), temporary: body.temporary || true, uses: 0, max_uses: body.max_uses ? Math.max(0, body.max_uses) : 0, diff --git a/src/api/routes/guilds/#guild_id/widget.json.ts b/src/api/routes/guilds/#guild_id/widget.json.ts
index 9f3ecd31..9cb4d928 100644 --- a/src/api/routes/guilds/#guild_id/widget.json.ts +++ b/src/api/routes/guilds/#guild_id/widget.json.ts
@@ -17,8 +17,9 @@ */ import { Request, Response, Router } from "express"; -import { randomString, route } from "@spacebar/api"; +import { route } from "@spacebar/api"; import { Channel, Guild, Member, Invite } from "@spacebar/database"; +import { Random } from "@spacebar/extensions"; import { Config, DiscordApiErrors, Permissions } from "@spacebar/util"; import { ChannelType, GuildWidgetJsonResponse } from "@spacebar/schemas"; @@ -93,7 +94,7 @@ async function getWidgetJsonData(guild_id: string) { const expires_at = new Date(max_age * 1000 + Date.now()); invite = await Invite.create({ - code: randomString(), + code: Random.getString("ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789", 6), temporary: false, uses: 0, max_uses: 0, diff --git a/src/api/util/handlers/Message.ts b/src/api/util/handlers/Message.ts
index 53de9b25..e2fc798d 100644 --- a/src/api/util/handlers/Message.ts +++ b/src/api/util/handlers/Message.ts
@@ -18,9 +18,9 @@ import { HTTPError } from "lambert-server/HTTPError"; import { Equal, In, Or } from "typeorm"; -import { fillMessageUrlEmbeds, randomString } from "@spacebar/api"; +import { fillMessageUrlEmbeds } from "@spacebar/api"; import { getDatabase, Application, Attachment, Channel, CloudAttachment, Guild, Member, Message, ReadState, Role, Session, Sticker, User, Webhook } from "@spacebar/database"; -import { mathLogBase, arrayDistributeSequentially, Stopwatch } from "@spacebar/extensions"; +import { mathLogBase, arrayDistributeSequentially, Stopwatch, Random } from "@spacebar/extensions"; import { Config, DiscordApiErrors, @@ -280,7 +280,7 @@ export function handleComps(components: BaseMessageComponents[], flags: number) throw FieldErrors(errors); } return async (messageId: string, user: User, channel: Channel) => { - const batchId = `CLOUD_compUploads_${randomString(128)}`; + const batchId = `CLOUD_compUploads_${Random.getString("ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789", 128)}`; (await Promise.all(medias.map((m, index) => processMedia(m, messageId, batchId, user, channel, index + "")))).forEach((_) => _?.()); }; } diff --git a/src/api/util/index.ts b/src/api/util/index.ts
index c7cbc535..1741179c 100644 --- a/src/api/util/index.ts +++ b/src/api/util/index.ts
@@ -20,7 +20,6 @@ export * from "./utility/Base64"; export * from "./utility/ipAddress"; export * from "./handlers/Message"; export * from "./utility/passwordStrength"; -export * from "./utility/RandomInviteID"; export * from "./handlers/route"; export * from "./handlers/Voice"; export * from "./utility/captcha"; diff --git a/src/api/util/utility/RandomInviteID.ts b/src/api/util/utility/RandomInviteID.ts deleted file mode 100644
index ec54a9fc..00000000 --- a/src/api/util/utility/RandomInviteID.ts +++ /dev/null
@@ -1,68 +0,0 @@ -/* - Spacebar: A FOSS re-implementation and extension of the Discord.com backend. - Copyright (C) 2023 Spacebar and Spacebar Contributors - - This program is free software: you can redistribute it and/or modify - it under the terms of the GNU Affero General Public License as published - by the Free Software Foundation, either version 3 of the License, or - (at your option) any later version. - - This program is distributed in the hope that it will be useful, - but WITHOUT ANY WARRANTY; without even the implied warranty of - MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the - GNU Affero General Public License for more details. - - You should have received a copy of the GNU Affero General Public License - along with this program. If not, see <https://www.gnu.org/licenses/>. -*/ - -import { Snowflake } from "@spacebar/util"; -import crypto from "node:crypto"; - -// TODO: 'random'? seriously? who named this? -// And why is this even here? Just use cryto.randomBytes? - -export function randomString(length = 6) { - // Declare all characters - const chars = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789"; - - // Pick characers randomly - let str = ""; - for (let i = 0; i < length; i++) { - str += chars.charAt(Math.floor(crypto.randomInt(chars.length))); - } - - return str; -} - -export function snowflakeBasedInvite() { - // Declare all characters - const chars = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789"; - const base = BigInt(chars.length); - let snowflake = Snowflake.generateWorkerProcess(); - - // snowflakes hold ~10.75 characters worth of entropy; - // safe to generate a 8-char invite out of them - const str = ""; - for (let i = 0; i < 10; i++) { - str.concat(chars.charAt(Number(snowflake % base))); - snowflake = snowflake / base; - } - - return str - .slice(3, 3 + 8) - .split("") - .reverse() - .join(""); -} - -export function randomUpperString(length: number = 10) { - const chars = "ABCDEFGHIJKLMNOPQRSTUVWXYZ"; - - let result = ""; - for (let i = 0; i < length; i++) { - result += chars.charAt(Math.floor(Math.random() * chars.length)); - } - - return result; -} diff --git a/src/database/entities/Session.ts b/src/database/entities/Session.ts
index cfe7803c..57cd90d0 100644 --- a/src/database/entities/Session.ts +++ b/src/database/entities/Session.ts
@@ -18,19 +18,18 @@ import crypto from "node:crypto"; import { Column, CreateDateColumn, Entity, Index, JoinColumn, ManyToOne, PrimaryColumn, RelationId } from "typeorm"; -import { randomUpperString } from "@spacebar/api"; -import { DateBuilder, TimeSpan } from "@spacebar/extensions"; +import { DateBuilder, TimeSpan, Random } from "@spacebar/extensions"; import { User } from "./User"; import { BaseClassWithoutId } from "./BaseClass"; import { Activity, ClientStatus, GatewaySession, GatewaySessionClientInfo, PrivateStatus } from "../../util/interfaces"; -import { IpDataClient } from "../../util/util"; +import { IpDataClient } from "@spacebar/util/util/networking"; @Entity({ name: "sessions", }) export class Session extends BaseClassWithoutId { @PrimaryColumn({ nullable: false }) - session_id: string = randomUpperString(); + session_id: string = Random.getString("ABCDEFGHIJKLMNOPQRSTUVWXYZ", 10); @Column() @RelationId((session: Session) => session.user) diff --git a/src/extensions/Random.ts b/src/extensions/Random.ts
index 212e1c9a..fe865891 100644 --- a/src/extensions/Random.ts +++ b/src/extensions/Random.ts
@@ -89,4 +89,18 @@ export class Random { } return array; } + + public static getString(choices: string, length: number) { + const _choices = choices.split(""); + const result = new Array(length); + for (const i in result) { + result[i] = _choices[Random.nextInt(0, _choices.length)]; + } + + return result.join(""); + } + + public static getHexString(length: number) { + return this.getString("0123456789ABCDEF", length); + } } diff --git a/src/gateway/Server.ts b/src/gateway/Server.ts
index f0197611..dd19d9da 100644 --- a/src/gateway/Server.ts +++ b/src/gateway/Server.ts
@@ -19,8 +19,8 @@ import http from "node:http"; import { setInterval } from "node:timers"; import ws from "ws"; -import { randomString } from "@spacebar/api"; // TODO: move to util import { initDatabase } from "@spacebar/database"; +import { Random } from "@spacebar/extensions"; import { checkToken, Config, initEvent, Rights } from "@spacebar/util"; import { ProcessLifecycle } from "../util/util/ProcessLifecycle"; import { Monitoring } from "../util/monitoring/Monitoring"; @@ -66,7 +66,10 @@ export class Server { this.server = http.createServer(async (req, res) => { if (!req.headers.cookie?.split("; ").find((x) => x.startsWith("__sb_sessid="))) { - res.setHeader("Set-Cookie", `__sb_sessid=${randomString(32)}; Secure; HttpOnly; SameSite=None; Path=/`); + res.setHeader( + "Set-Cookie", + `__sb_sessid=${Random.getString("ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789", 32)}; Secure; HttpOnly; SameSite=None; Path=/`, + ); } const requestUrl = new URL(`http://${req.headers.host}${req.url}`); if (requestUrl.pathname === "/metrics") { diff --git a/src/gateway/events/Close.ts b/src/gateway/events/Close.ts
index c227c33d..366e3b7c 100644 --- a/src/gateway/events/Close.ts +++ b/src/gateway/events/Close.ts
@@ -16,8 +16,8 @@ along with this program. If not, see <https://www.gnu.org/licenses/>. */ -import { randomString } from "@spacebar/api"; import { Member, Session, User, VoiceState } from "@spacebar/database"; +import { Random } from "@spacebar/extensions"; import { WebSocket } from "@spacebar/gateway"; import { emitEvent, PresenceUpdateEvent, SessionsReplace, VoiceStateUpdateEvent, distributePresenceUpdate } from "@spacebar/util"; import { ProcessLifecycle } from "../../util/util/ProcessLifecycle"; @@ -56,7 +56,7 @@ export async function Close(this: WebSocket, code: number, reason: Buffer) { activities: this.session!.activities, }, origin: "GATEWAY_CLOSE", - transaction_id: `IDENT_${this.user_id}_${randomString()}`, + transaction_id: `IDENT_${this.user_id}_${Random.getString("ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789", 6)}`, } satisfies PresenceUpdateEvent); console.log("... done!"); } else console.log("... Discarding presence update as the session reactivated"); diff --git a/src/gateway/opcodes/Identify.ts b/src/gateway/opcodes/Identify.ts
index e1ce6e8c..08b77b65 100644 --- a/src/gateway/opcodes/Identify.ts +++ b/src/gateway/opcodes/Identify.ts
@@ -19,7 +19,7 @@ import { In, Not } from "typeorm"; import { PreloadedUserSettings } from "discord-protos"; import { Capabilities, CLOSECODES, OPCODES, Payload, Send, setupListener, WebSocket } from "@spacebar/gateway"; -import { arrayGroupBy, ElapsedTime, Stopwatch, timeFunction, timePromise } from "@spacebar/extensions"; +import { arrayGroupBy, ElapsedTime, Stopwatch, timeFunction, timePromise, Random } from "@spacebar/extensions"; import { getDatabase, Application, @@ -59,7 +59,6 @@ import { TraceRoot, } from "@spacebar/util"; import { ChannelType, DefaultUserGuildSettings, DMChannel, IdentifySchema, PrivateUserProjection, PublicUser, PublicUserProjection } from "@spacebar/schemas"; -import { randomString } from "@spacebar/api"; import { check } from "./instanceOf"; // TODO: user sharding @@ -202,7 +201,7 @@ export async function onIdentify(this: WebSocket, data: Payload) { activities: this.session.activities, }, origin: "GATEWAY_IDENTIFY", - transaction_id: `IDENT_${this.user_id}_${randomString()}`, + transaction_id: `IDENT_${this.user_id}_${Random.getString("ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789", 6)}`, } satisfies PresenceUpdateEvent; } } diff --git a/src/util/util/Token.ts b/src/util/util/Token.ts
index 4eaa4bc9..3f654495 100644 --- a/src/util/util/Token.ts +++ b/src/util/util/Token.ts
@@ -23,8 +23,7 @@ import fs from "node:fs/promises"; import jwt from "jsonwebtoken"; import { HTTPError } from "lambert-server/HTTPError"; import { InstanceBan, Session, User } from "@spacebar/database"; -import { randomUpperString } from "@spacebar/api"; -import { TimeSpan } from "@spacebar/extensions"; +import { Random, TimeSpan } from "@spacebar/extensions"; import { Config } from "./Config"; import { OrmUtils } from "@spacebar/util"; @@ -162,7 +161,7 @@ export async function generateToken(id: string, isAdminSession: boolean = false) let newSession; do { newSession = Session.create({ - session_id: randomUpperString(10), // readable at a glance + session_id: Random.getString("ABCDEFGHIJKLMNOPQRSTUVWXYZ", 10), // readable at a glance user_id: id, is_admin_session: isAdminSession, client_status: {},