From 9bb2c437cfc61d117373973045a03de66f8e5e49 Mon Sep 17 00:00:00 2001 From: Rory& Date: Tue, 16 Jun 2026 17:59:23 +0200 Subject: Authentication: allow - in webhook token --- src/api/middlewares/Authentication.ts | 2 +- src/api/util/index.ts | 1 - src/api/util/utility/Base64.ts | 65 ----------------------------------- src/extensions/Base64.ts | 65 +++++++++++++++++++++++++++++++++++ src/extensions/String.ts | 6 ++-- src/extensions/index.ts | 1 + 6 files changed, 70 insertions(+), 70 deletions(-) delete mode 100644 src/api/util/utility/Base64.ts create mode 100644 src/extensions/Base64.ts diff --git a/src/api/middlewares/Authentication.ts b/src/api/middlewares/Authentication.ts index 9b14a4ae..a71dfdf1 100644 --- a/src/api/middlewares/Authentication.ts +++ b/src/api/middlewares/Authentication.ts @@ -34,7 +34,7 @@ export const NO_AUTHORIZATION_ROUTES = [ "POST /auth/fingerprint", "GET /invites/", // Routes with a seperate auth system - /^(POST|HEAD|GET|PATCH|DELETE) \/webhooks\/\d+\/\w+\/?/, // no token requires auth + /^(POST|HEAD|GET|PATCH|DELETE) \/webhooks\/\d+\/[\w-]+\/?/, // no token requires auth /^POST \/interactions\/\d+\/[A-Za-z0-9_-]+\/callback/, // Public information endpoints "GET /ping", diff --git a/src/api/util/index.ts b/src/api/util/index.ts index 1741179c..b04af8d1 100644 --- a/src/api/util/index.ts +++ b/src/api/util/index.ts @@ -16,7 +16,6 @@ along with this program. If not, see . */ -export * from "./utility/Base64"; export * from "./utility/ipAddress"; export * from "./handlers/Message"; export * from "./utility/passwordStrength"; diff --git a/src/api/util/utility/Base64.ts b/src/api/util/utility/Base64.ts deleted file mode 100644 index 78a56f63..00000000 --- a/src/api/util/utility/Base64.ts +++ /dev/null @@ -1,65 +0,0 @@ -/* - Spacebar: A FOSS re-implementation and extension of the Discord.com backend. - Copyright (C) 2023 Spacebar and Spacebar Contributors - - This program is free software: you can redistribute it and/or modify - it under the terms of the GNU Affero General Public License as published - by the Free Software Foundation, either version 3 of the License, or - (at your option) any later version. - - This program is distributed in the hope that it will be useful, - but WITHOUT ANY WARRANTY; without even the implied warranty of - MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the - GNU Affero General Public License for more details. - - You should have received a copy of the GNU Affero General Public License - along with this program. If not, see . -*/ - -const alphabet = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+"; - -// binary to string lookup table -const b2s = alphabet.split(""); - -// string to binary lookup table -// 123 == 'z'.charCodeAt(0) + 1 -const s2b = new Array(123); -for (let i = 0; i < alphabet.length; i++) { - s2b[alphabet.charCodeAt(i)] = i; -} - -// number to base64 -export const ntob = (n: number): string => { - if (n < 0) return `-${ntob(-n)}`; - - let lo = n >>> 0; - let hi = (n / 4294967296) >>> 0; - - let right = ""; - while (hi > 0) { - right = b2s[0x3f & lo] + right; - lo >>>= 6; - lo |= (0x3f & hi) << 26; - hi >>>= 6; - } - - let left = ""; - do { - left = b2s[0x3f & lo] + left; - lo >>>= 6; - } while (lo > 0); - - return left + right; -}; - -// base64 to number -export const bton = (base64: string) => { - let number = 0; - const sign = base64.charAt(0) === "-" ? 1 : 0; - - for (let i = sign; i < base64.length; i++) { - number = number * 64 + s2b[base64.charCodeAt(i)]; - } - - return sign ? -number : number; -}; diff --git a/src/extensions/Base64.ts b/src/extensions/Base64.ts new file mode 100644 index 00000000..78a56f63 --- /dev/null +++ b/src/extensions/Base64.ts @@ -0,0 +1,65 @@ +/* + Spacebar: A FOSS re-implementation and extension of the Discord.com backend. + Copyright (C) 2023 Spacebar and Spacebar Contributors + + This program is free software: you can redistribute it and/or modify + it under the terms of the GNU Affero General Public License as published + by the Free Software Foundation, either version 3 of the License, or + (at your option) any later version. + + This program is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + GNU Affero General Public License for more details. + + You should have received a copy of the GNU Affero General Public License + along with this program. If not, see . +*/ + +const alphabet = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+"; + +// binary to string lookup table +const b2s = alphabet.split(""); + +// string to binary lookup table +// 123 == 'z'.charCodeAt(0) + 1 +const s2b = new Array(123); +for (let i = 0; i < alphabet.length; i++) { + s2b[alphabet.charCodeAt(i)] = i; +} + +// number to base64 +export const ntob = (n: number): string => { + if (n < 0) return `-${ntob(-n)}`; + + let lo = n >>> 0; + let hi = (n / 4294967296) >>> 0; + + let right = ""; + while (hi > 0) { + right = b2s[0x3f & lo] + right; + lo >>>= 6; + lo |= (0x3f & hi) << 26; + hi >>>= 6; + } + + let left = ""; + do { + left = b2s[0x3f & lo] + left; + lo >>>= 6; + } while (lo > 0); + + return left + right; +}; + +// base64 to number +export const bton = (base64: string) => { + let number = 0; + const sign = base64.charAt(0) === "-" ? 1 : 0; + + for (let i = sign; i < base64.length; i++) { + number = number * 64 + s2b[base64.charCodeAt(i)]; + } + + return sign ? -number : number; +}; diff --git a/src/extensions/String.ts b/src/extensions/String.ts index 5c623e30..fb34600f 100644 --- a/src/extensions/String.ts +++ b/src/extensions/String.ts @@ -18,9 +18,8 @@ import { Request } from "express"; import { SPECIAL_CHAR } from "@spacebar/util/util/Regex"; -import { Random } from "@spacebar/extensions/Random"; -import { ntob } from "@spacebar/api"; -import { FieldErrors } from "@spacebar/util"; +import { Random, ntob } from "@spacebar/extensions"; +import { FieldErrors } from "@spacebar/util/util/FieldError"; export function trimSpecial(str?: string): string { if (!str) return ""; @@ -49,6 +48,7 @@ export function stringGlobToRegexp(str: string, flags?: string): RegExp { return new RegExp(escaped, flags); } +// TODO: use exception type export function stringCheckLength(str: string, min: number, max: number, key: string, req: Request) { if (str.length < min || str.length > max) { throw FieldErrors({ diff --git a/src/extensions/index.ts b/src/extensions/index.ts index 15563724..f22d3d3b 100644 --- a/src/extensions/index.ts +++ b/src/extensions/index.ts @@ -17,6 +17,7 @@ */ export * from "./Array"; +export * from "./Base64"; export * from "./DateBuilder"; export * from "./ElapsedTime"; export * from "./Math"; -- cgit 1.5.1