Files
EpicNext-Cms/src/lib/services/ip-lookup.ts
T
openhands df38dccbf1
Local Build and Deploy / deploy (push) Failing after 46s
style: format code biome
2026-07-13 21:57:41 +02:00

71 lines
2.4 KiB
TypeScript

import { siteSettings } from "@/lib/services/site-settings";
/**
* VPN / proxy / Tor detection via an external provider, driven by
* website_settings (configured at /admin/vpn). Mirrors AtomCMS's IP lookup used
* to block registrations from anonymising IPs. FAIL-OPEN: any error, missing
* config, or disabled toggle returns "not blocked".
*
* Settings keys: vpn_block_enabled ("1"), vpn_provider ("proxycheck" |
* "ipqualityscore"), vpn_api_key.
*/
export interface IpVerdict {
blocked: boolean;
reason?: string;
}
const PRIVATE_RE =
/^(127\.|10\.|192\.168\.|172\.(1[6-9]|2\d|3[01])\.|::1|fc|fd|localhost$|0\.0\.0\.0$)/i;
export async function checkVpn(ip: string): Promise<IpVerdict> {
if (!ip || PRIVATE_RE.test(ip)) return { blocked: false };
if (!(await siteSettings.getBool("vpn_block_enabled", false)))
return { blocked: false };
const provider = (
(await siteSettings.get("vpn_provider", "proxycheck")) ?? "proxycheck"
).toLowerCase();
const apiKey = (await siteSettings.get("vpn_api_key", "")) ?? "";
try {
const controller = new AbortController();
const timer = setTimeout(() => controller.abort(), 4000);
if (provider === "ipqualityscore") {
if (!apiKey) return { blocked: false };
const res = await fetch(
`https://ipqualityscore.com/api/json/ip/${encodeURIComponent(apiKey)}/${encodeURIComponent(ip)}`,
{ signal: controller.signal, cache: "no-store" },
);
clearTimeout(timer);
const d = (await res.json()) as {
proxy?: boolean;
vpn?: boolean;
tor?: boolean;
};
if (d?.vpn || d?.tor || d?.proxy)
return { blocked: true, reason: "VPN/proxy detected" };
return { blocked: false };
}
// Default: proxycheck.io (works keyless at a low rate; key raises limits).
const url = `https://proxycheck.io/v2/${encodeURIComponent(ip)}?vpn=1&risk=1${apiKey ? `&key=${encodeURIComponent(apiKey)}` : ""}`;
const res = await fetch(url, {
signal: controller.signal,
cache: "no-store",
});
clearTimeout(timer);
const d = (await res.json()) as Record<
string,
{ proxy?: string; type?: string }
>;
// eslint-disable-next-line security/detect-object-injection -- ip is the API response key from proxycheck
const entry = d?.[ip];
if (entry?.proxy === "yes")
return { blocked: true, reason: `${entry.type ?? "Proxy"} detected` };
return { blocked: false };
} catch {
return { blocked: false };
}
}