Add public REST API, anti-abuse protections, radio/GitHub cron jobs
Phase A — Public REST API (was the biggest gap). 20 JSON endpoints under
/api mirroring AtomCMS: users/[username], online(+/count), me, articles
(+/[slug]), photos, home, staff, teams, leaderboard, shop(+/categories),
values(+/categories), settings, radio/{config,now-playing,listeners,
shouts}. Shared src/lib/api.ts (apiJson — BigInt-safe + CORS, pagination).
Read-only, fail-soft, and field-safe (never exposes password/auth_ticket/
2FA secrets/mail).
Phase B — Anti-abuse on registration: CAPTCHA (Cloudflare Turnstile /
Google reCAPTCHA, settings-driven, widget rendered on the register page),
VPN/proxy detection (proxycheck.io / IPQualityScore via /admin/vpn
settings), and max-accounts-per-IP. All fail-open when unconfigured.
src/lib/services/{captcha,ip-lookup}.ts.
Phase C — jobs-worker cron suite: radio-record-songs (30s, logs track
changes to radio_song_plays), radio-auto-dj (rotates radio_auto_dj_playlist
when no live DJ), github-update-check (hourly, sets update_available).
Shared src/lib/services/radio.ts (now-playing/listeners parsing).
Verified live (prod, amx_test): /api/* return real JSON (leaderboard 6
users, settings carry no secrets, user endpoint hides password). tsc 0,
vitest 49/49, next build 0 (20 new API routes).
This commit is contained in:
1 parent
5a4b6f27e9
commit
80f591a343
29 files changed
+1697
-7
No files matched your search
+31
-6
@@ -1,11 +1,13 @@
|
||||
"use server";
|
||||
|
||||
import { headers } from "next/headers";
|
||||
import { redirect } from "next/navigation";
|
||||
import { sendVerification } from "@/actions/email-verify";
|
||||
import { hashPassword } from "@/lib/auth/password";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { clientIp, rateLimit } from "@/lib/rate-limit";
|
||||
import { captchaConfig, verifyCaptcha } from "@/lib/services/captcha";
|
||||
import { checkVpn } from "@/lib/services/ip-lookup";
|
||||
import { siteSettings } from "@/lib/services/site-settings";
|
||||
|
||||
const USERNAME_RE = /^[A-Za-z0-9_\-=?!@:.,]{3,25}$/;
|
||||
const EMAIL_RE = /^[^@\s]+@[^@\s]+\.[^@\s]+$/;
|
||||
@@ -17,15 +19,41 @@ export async function register(formData: FormData): Promise<void> {
|
||||
const mail = String(formData.get("mail") ?? "").trim().toLowerCase();
|
||||
const password = String(formData.get("password") ?? "");
|
||||
|
||||
const ip = await clientIp();
|
||||
|
||||
let error: string | null = null;
|
||||
if (!USERNAME_RE.test(username)) error = "Username must be 3-25 valid characters";
|
||||
else if (password.length < 6) error = "Password must be at least 6 characters";
|
||||
else if (!EMAIL_RE.test(mail)) error = "Enter a valid email address";
|
||||
|
||||
// Throttle sign-ups per IP (5 per 10 minutes) to curb account spam.
|
||||
if (!error && !rateLimit(`register:${ip}`, 5, 10 * 60_000).ok) {
|
||||
error = "Too many sign-up attempts. Please wait a few minutes and try again.";
|
||||
}
|
||||
|
||||
// CAPTCHA (Turnstile / reCAPTCHA) — only enforced when configured in settings.
|
||||
if (!error) {
|
||||
const limit = rateLimit(`register:${await clientIp()}`, 5, 10 * 60_000);
|
||||
if (!limit.ok) error = "Too many sign-up attempts. Please wait a few minutes and try again.";
|
||||
const cfg = await captchaConfig();
|
||||
if (cfg.provider !== "none") {
|
||||
const token = String(formData.get(cfg.field) ?? "");
|
||||
if (!(await verifyCaptcha(token, ip))) error = "Captcha verification failed. Please try again.";
|
||||
}
|
||||
}
|
||||
|
||||
// VPN/proxy block (only when enabled in /admin/vpn).
|
||||
if (!error && (await checkVpn(ip)).blocked) {
|
||||
error =
|
||||
(await siteSettings.get("vpn_block_message", "")) ||
|
||||
"Registrations from VPN/proxy connections are not allowed.";
|
||||
}
|
||||
|
||||
// Max accounts per IP (0 / unset = unlimited), mirrors AtomCMS.
|
||||
if (!error) {
|
||||
const max = Number(await siteSettings.get("max_accounts_per_ip", "0")) || 0;
|
||||
if (max > 0) {
|
||||
const count = await prisma.user.count({ where: { ipRegister: ip } }).catch(() => 0);
|
||||
if (count >= max) error = "You have reached the maximum number of accounts for your connection.";
|
||||
}
|
||||
}
|
||||
|
||||
// Uniqueness check (kept out of the success path's try so NEXT_REDIRECT propagates).
|
||||
@@ -42,9 +70,6 @@ export async function register(formData: FormData): Promise<void> {
|
||||
}
|
||||
|
||||
if (!error) {
|
||||
const h = await headers();
|
||||
const ip =
|
||||
h.get("x-forwarded-for")?.split(",")[0]?.trim() ?? h.get("x-real-ip") ?? "0.0.0.0";
|
||||
const now = Math.floor(Date.now() / 1000);
|
||||
try {
|
||||
const created = await prisma.user.create({
|
||||
|
||||
Reference in new issue
Block a user