This commit is contained in:
1 parent
8efd032cc6
commit
df38dccbf1
735 files changed
+128321
-120870
No files matched your search
+65
-49
@@ -1,70 +1,86 @@
|
||||
import { headers } from "next/headers";
|
||||
import { redirect } from "next/navigation";
|
||||
import { auth } from "@/lib/auth";
|
||||
import { isIpBlacklisted, recordRequest } from "@/lib/services/abuse-guard";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { siteSettings } from "@/lib/services/site-settings";
|
||||
import { safeRedirect } from "@/lib/foundation/security";
|
||||
import { logger } from "@/lib/logger";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { isIpBlacklisted, recordRequest } from "@/lib/services/abuse-guard";
|
||||
import { siteSettings } from "@/lib/services/site-settings";
|
||||
|
||||
const EXEMPT = ["/banned", "/maintenance", "/login", "/register", "/forgot", "/reset", "/api"];
|
||||
const EXEMPT = [
|
||||
"/banned",
|
||||
"/maintenance",
|
||||
"/login",
|
||||
"/register",
|
||||
"/forgot",
|
||||
"/reset",
|
||||
"/api",
|
||||
];
|
||||
|
||||
function isExempt(path: string): boolean {
|
||||
return EXEMPT.some((p) => path === p || path.startsWith(`${p}/`));
|
||||
return EXEMPT.some((p) => path === p || path.startsWith(`${p}/`));
|
||||
}
|
||||
|
||||
export async function enforceSiteAccess(): Promise<void> {
|
||||
const h = await headers();
|
||||
const path = h.get("x-pathname") ?? "/";
|
||||
const ip = h.get("x-real-client-ip") ?? h.get("x-forwarded-for")?.split(",")[0]?.trim() ?? "0.0.0.0";
|
||||
const h = await headers();
|
||||
const path = h.get("x-pathname") ?? "/";
|
||||
const ip =
|
||||
h.get("x-real-client-ip") ??
|
||||
h.get("x-forwarded-for")?.split(",")[0]?.trim() ??
|
||||
"0.0.0.0";
|
||||
|
||||
void recordRequest(ip).catch(() => {});
|
||||
void recordRequest(ip).catch(() => {});
|
||||
|
||||
if (isExempt(path)) return;
|
||||
if (isExempt(path)) return;
|
||||
|
||||
let target: string | null = null;
|
||||
let checksDegraded = false;
|
||||
let target: string | null = null;
|
||||
let checksDegraded = false;
|
||||
|
||||
try {
|
||||
if (await isIpBlacklisted(ip)) target = "/banned";
|
||||
} catch {
|
||||
checksDegraded = true;
|
||||
}
|
||||
try {
|
||||
if (await isIpBlacklisted(ip)) target = "/banned";
|
||||
} catch {
|
||||
checksDegraded = true;
|
||||
}
|
||||
|
||||
try {
|
||||
const session = await auth();
|
||||
const rank = session?.user?.rank ?? 0;
|
||||
try {
|
||||
const session = await auth();
|
||||
const rank = session?.user?.rank ?? 0;
|
||||
|
||||
try {
|
||||
if (!target && (await siteSettings.getBool("maintenance_enabled", false))) {
|
||||
const minLogin = Number(await siteSettings.get("min_maintenance_login_rank", "7")) || 7;
|
||||
if (rank < minLogin) target = "/maintenance";
|
||||
}
|
||||
} catch {
|
||||
checksDegraded = true;
|
||||
}
|
||||
try {
|
||||
if (
|
||||
!target &&
|
||||
(await siteSettings.getBool("maintenance_enabled", false))
|
||||
) {
|
||||
const minLogin =
|
||||
Number(await siteSettings.get("min_maintenance_login_rank", "7")) ||
|
||||
7;
|
||||
if (rank < minLogin) target = "/maintenance";
|
||||
}
|
||||
} catch {
|
||||
checksDegraded = true;
|
||||
}
|
||||
|
||||
try {
|
||||
if (!target && session?.user?.id) {
|
||||
const now = Math.floor(Date.now() / 1000);
|
||||
const ban = await prisma.ban.findFirst({
|
||||
where: { userId: Number(session.user.id), banExpire: { gt: now } },
|
||||
select: { id: true },
|
||||
});
|
||||
if (ban) target = "/banned";
|
||||
}
|
||||
} catch {
|
||||
checksDegraded = true;
|
||||
}
|
||||
} catch {
|
||||
checksDegraded = true;
|
||||
}
|
||||
try {
|
||||
if (!target && session?.user?.id) {
|
||||
const now = Math.floor(Date.now() / 1000);
|
||||
const ban = await prisma.ban.findFirst({
|
||||
where: { userId: Number(session.user.id), banExpire: { gt: now } },
|
||||
select: { id: true },
|
||||
});
|
||||
if (ban) target = "/banned";
|
||||
}
|
||||
} catch {
|
||||
checksDegraded = true;
|
||||
}
|
||||
} catch {
|
||||
checksDegraded = true;
|
||||
}
|
||||
|
||||
if (target) {
|
||||
redirect(safeRedirect(target, target));
|
||||
}
|
||||
if (target) {
|
||||
redirect(safeRedirect(target, target));
|
||||
}
|
||||
|
||||
if (checksDegraded) {
|
||||
logger.warn("Access guard degraded — some checks skipped", { ip, path });
|
||||
}
|
||||
if (checksDegraded) {
|
||||
logger.warn("Access guard degraded — some checks skipped", { ip, path });
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user