summary refs log tree commit diff
path: root/src/api
diff options
context:
space:
mode:
Diffstat (limited to 'src/api')
-rw-r--r--src/api/Server.ts2
-rw-r--r--src/api/routes/auth/register.ts120
2 files changed, 62 insertions, 60 deletions
diff --git a/src/api/Server.ts b/src/api/Server.ts

index 08a1e874..9e4bb937 100644 --- a/src/api/Server.ts +++ b/src/api/Server.ts
@@ -62,7 +62,7 @@ export class SpacebarServer extends Server { await ConnectionConfig.init(); await initInstance(); WebAuthn.init(); - await BcryptWorkerPool.Init(4); // TODO: make configurable + // await BcryptWorkerPool.Init(8); // TODO: make configurable const logRequests = process.env["LOG_REQUESTS"] != undefined; if (logRequests) { diff --git a/src/api/routes/auth/register.ts b/src/api/routes/auth/register.ts
index d8313135..4f2f4a7d 100644 --- a/src/api/routes/auth/register.ts +++ b/src/api/routes/auth/register.ts
@@ -144,79 +144,81 @@ router.post( logTrace("Basic checks"); //region IP checks - const cacheBlockedIp = (ip: string, reason: string) => { - recentlyBlockedIps[ip] = { - firstHit: new Date(), - lastHit: new Date(), - hits: 0, - reason, + if (register.enableAbuseIpDb || register.enableIpData) { + const cacheBlockedIp = (ip: string, reason: string) => { + recentlyBlockedIps[ip] = { + firstHit: new Date(), + lastHit: new Date(), + hits: 0, + reason, + }; + console.log(`[Register] ${ip} blocked from registration:`, reason); }; - console.log(`[Register] ${ip} blocked from registration:`, reason); - }; - - if (!regTokenUsed && recentlyBlockedIps[ip]) { - if (new TimeSpan(recentlyBlockedIps[ip].firstHit.getTime(), new Date().getTime()).totalHours >= 24) delete recentlyBlockedIps[ip]; - else { - recentlyBlockedIps[ip].lastHit = new Date(); - recentlyBlockedIps[ip].hits++; - console.log( - `[Register] ${ip} blocked from registration: blocked since ${recentlyBlockedIps[ip].firstHit} with ${recentlyBlockedIps[ip].hits} hits and reason:`, - recentlyBlockedIps[ip].reason, - ); - throw new HTTPError("Your IP is blocked from registration"); - } - } - if (!regTokenUsed && register.enableAbuseIpDb) { - const blacklist = await AbuseIpDbClient.getBlacklist(); - if (blacklist) { - const entry = blacklist.data.find((e) => e.ipAddress === ip); - - if (entry && entry.abuseConfidenceScore >= register.blockAbuseIpDbAboveScore) { - cacheBlockedIp(ip, `AbuseIPDB score ${entry.abuseConfidenceScore} >= ${register.blockAbuseIpDbAboveScore} (BLACKLIST)`); + if (!regTokenUsed && recentlyBlockedIps[ip]) { + if (new TimeSpan(recentlyBlockedIps[ip].firstHit.getTime(), new Date().getTime()).totalHours >= 24) delete recentlyBlockedIps[ip]; + else { + recentlyBlockedIps[ip].lastHit = new Date(); + recentlyBlockedIps[ip].hits++; + console.log( + `[Register] ${ip} blocked from registration: blocked since ${recentlyBlockedIps[ip].firstHit} with ${recentlyBlockedIps[ip].hits} hits and reason:`, + recentlyBlockedIps[ip].reason, + ); throw new HTTPError("Your IP is blocked from registration"); } } - const checkIp = await AbuseIpDbClient.checkIpAddress(ip); - if (checkIp?.data && checkIp.data.abuseConfidenceScore >= register.blockAbuseIpDbAboveScore) { - cacheBlockedIp(ip, `AbuseIPDB score ${checkIp.data.abuseConfidenceScore} >= ${register.blockAbuseIpDbAboveScore} (CHECK)`); - throw new HTTPError("Your IP is blocked from registration"); - } - } + if (!regTokenUsed && register.enableAbuseIpDb) { + const blacklist = await AbuseIpDbClient.getBlacklist(); + if (blacklist) { + const entry = blacklist.data.find((e) => e.ipAddress === ip); - if (!regTokenUsed && register.enableIpData) { - const ipData = await IpDataClient.getIpInfo(ip); - if (ipData) { - if (!ipData.threat) { - console.log("Invalid IPData.co response, missing threat field", ipData); - } - const categories = Object.entries(ipData.threat) - .filter(([key, value]) => key.startsWith("is_") && value === true) - .map(([key]) => key.replace("is_", "")); - const blockedCategories = new Set(categories).intersection(new Set(register.blockIpDataCoThreatTypes)); - if (blockedCategories.size > 0) { - cacheBlockedIp(ip, `IPData.co threat types ${Array.from(blockedCategories).join(", ")}`); - throw new HTTPError("Your IP is blocked from registration"); + if (entry && entry.abuseConfidenceScore >= register.blockAbuseIpDbAboveScore) { + cacheBlockedIp(ip, `AbuseIPDB score ${entry.abuseConfidenceScore} >= ${register.blockAbuseIpDbAboveScore} (BLACKLIST)`); + throw new HTTPError("Your IP is blocked from registration"); + } } - if (ipData.asn.type && register.blockAsnTypes.includes(ipData.asn.type)) { - cacheBlockedIp(ip, `IPData.co ASN type ${ipData.asn.type} is blocked`); + const checkIp = await AbuseIpDbClient.checkIpAddress(ip); + if (checkIp?.data && checkIp.data.abuseConfidenceScore >= register.blockAbuseIpDbAboveScore) { + cacheBlockedIp(ip, `AbuseIPDB score ${checkIp.data.abuseConfidenceScore} >= ${register.blockAbuseIpDbAboveScore} (CHECK)`); throw new HTTPError("Your IP is blocked from registration"); - } else if (!ipData.asn.type) { - console.log("[Register] IPData.co response missing asn.type field", ipData); } + } - if (ipData.asn.asn && register.blockAsns.includes(ipData.asn.asn)) { - cacheBlockedIp(ip, `IPData.co ASN ${ipData.asn.name} is blocked`); - throw new HTTPError("Your IP is blocked from registration"); - } else if (!ipData.asn.asn) { - console.log("[Register] IPData.co response missing asn.asn field", ipData); + if (!regTokenUsed && register.enableIpData) { + const ipData = await IpDataClient.getIpInfo(ip); + if (ipData) { + if (!ipData.threat) { + console.log("Invalid IPData.co response, missing threat field", ipData); + } + const categories = Object.entries(ipData.threat) + .filter(([key, value]) => key.startsWith("is_") && value === true) + .map(([key]) => key.replace("is_", "")); + const blockedCategories = new Set(categories).intersection(new Set(register.blockIpDataCoThreatTypes)); + if (blockedCategories.size > 0) { + cacheBlockedIp(ip, `IPData.co threat types ${Array.from(blockedCategories).join(", ")}`); + throw new HTTPError("Your IP is blocked from registration"); + } + + if (ipData.asn.type && register.blockAsnTypes.includes(ipData.asn.type)) { + cacheBlockedIp(ip, `IPData.co ASN type ${ipData.asn.type} is blocked`); + throw new HTTPError("Your IP is blocked from registration"); + } else if (!ipData.asn.type) { + console.log("[Register] IPData.co response missing asn.type field", ipData); + } + + if (ipData.asn.asn && register.blockAsns.includes(ipData.asn.asn)) { + cacheBlockedIp(ip, `IPData.co ASN ${ipData.asn.name} is blocked`); + throw new HTTPError("Your IP is blocked from registration"); + } else if (!ipData.asn.asn) { + console.log("[Register] IPData.co response missing asn.asn field", ipData); + } } } + logTrace("IP checks"); } //endregion - logTrace("IP checks"); // TODO: gift_code_sku_id? // TODO: check password strength @@ -306,8 +308,8 @@ router.post( }); } // the salt is saved in the password refer to bcrypt docs - body.password = await BcryptWorkerPool.GetBcryptWorker().hashPassword(body.password, 12); - // body.password = await bcrypt.hash(body.password, 12); + // body.password = await BcryptWorkerPool.GetBcryptWorker().hashPassword(body.password, 12); + body.password = await bcrypt.hash(body.password, 12); } else if (register.password.required) { throw FieldErrors({ password: {