Phase A — Public REST API (was the biggest gap). 20 JSON endpoints under
/api mirroring AtomCMS: users/[username], online(+/count), me, articles
(+/[slug]), photos, home, staff, teams, leaderboard, shop(+/categories),
values(+/categories), settings, radio/{config,now-playing,listeners,
shouts}. Shared src/lib/api.ts (apiJson — BigInt-safe + CORS, pagination).
Read-only, fail-soft, and field-safe (never exposes password/auth_ticket/
2FA secrets/mail).
Phase B — Anti-abuse on registration: CAPTCHA (Cloudflare Turnstile /
Google reCAPTCHA, settings-driven, widget rendered on the register page),
VPN/proxy detection (proxycheck.io / IPQualityScore via /admin/vpn
settings), and max-accounts-per-IP. All fail-open when unconfigured.
src/lib/services/{captcha,ip-lookup}.ts.
Phase C — jobs-worker cron suite: radio-record-songs (30s, logs track
changes to radio_song_plays), radio-auto-dj (rotates radio_auto_dj_playlist
when no live DJ), github-update-check (hourly, sets update_available).
Shared src/lib/services/radio.ts (now-playing/listeners parsing).
Verified live (prod, amx_test): /api/* return real JSON (leaderboard 6
users, settings carry no secrets, user endpoint hides password). tsc 0,
vitest 49/49, next build 0 (20 new API routes).
77 lines
2.9 KiB
TypeScript
77 lines
2.9 KiB
TypeScript
import { siteSettings } from "@/lib/services/site-settings";
|
|
|
|
/**
|
|
* Server-side CAPTCHA verification, driven by website_settings so staff pick the
|
|
* provider in housekeeping. Supports Cloudflare Turnstile and Google reCAPTCHA
|
|
* (the two AtomCMS offers, mutually exclusive). FAIL-OPEN by configuration: when
|
|
* no provider/secret is set, registration isn't blocked; only an explicitly
|
|
* configured provider with a failing/absent token blocks.
|
|
*
|
|
* Settings keys:
|
|
* captcha_provider = "turnstile" | "recaptcha" | "none" (default none)
|
|
* turnstile_secret / turnstile_site_key
|
|
* recaptcha_secret / recaptcha_site_key
|
|
*/
|
|
export interface CaptchaConfig {
|
|
provider: "turnstile" | "recaptcha" | "none";
|
|
siteKey: string;
|
|
/** Form field the widget writes the token into. */
|
|
field: string;
|
|
}
|
|
|
|
const TURNSTILE_URL = "https://challenges.cloudflare.com/turnstile/v0/siteverify";
|
|
const RECAPTCHA_URL = "https://www.google.com/recaptcha/api/siteverify";
|
|
|
|
/** Public config the register page needs to render the widget (no secrets). */
|
|
export async function captchaConfig(): Promise<CaptchaConfig> {
|
|
const provider = ((await siteSettings.get("captcha_provider", "none")) ?? "none").toLowerCase();
|
|
if (provider === "turnstile") {
|
|
return {
|
|
provider: "turnstile",
|
|
siteKey: (await siteSettings.get("turnstile_site_key", "")) ?? "",
|
|
field: "cf-turnstile-response",
|
|
};
|
|
}
|
|
if (provider === "recaptcha") {
|
|
return {
|
|
provider: "recaptcha",
|
|
siteKey: (await siteSettings.get("recaptcha_site_key", "")) ?? "",
|
|
field: "g-recaptcha-response",
|
|
};
|
|
}
|
|
return { provider: "none", siteKey: "", field: "" };
|
|
}
|
|
|
|
/** Verify a submitted token. Returns true when allowed (incl. fail-open). */
|
|
export async function verifyCaptcha(token: string | null, remoteIp?: string): Promise<boolean> {
|
|
const cfg = await captchaConfig();
|
|
if (cfg.provider === "none" || !cfg.siteKey) return true;
|
|
|
|
const secretKey = cfg.provider === "turnstile" ? "turnstile_secret" : "recaptcha_secret";
|
|
const secret = (await siteSettings.get(secretKey, "")) ?? "";
|
|
if (!secret) return true; // configured but no secret — don't hard-block
|
|
if (!token) return false;
|
|
|
|
const url = cfg.provider === "turnstile" ? TURNSTILE_URL : RECAPTCHA_URL;
|
|
const body = new URLSearchParams({ secret, response: token });
|
|
if (remoteIp) body.set("remoteip", remoteIp);
|
|
|
|
try {
|
|
const controller = new AbortController();
|
|
const timer = setTimeout(() => controller.abort(), 5000);
|
|
const res = await fetch(url, {
|
|
method: "POST",
|
|
headers: { "content-type": "application/x-www-form-urlencoded" },
|
|
body,
|
|
signal: controller.signal,
|
|
cache: "no-store",
|
|
});
|
|
clearTimeout(timer);
|
|
const data = (await res.json()) as { success?: boolean };
|
|
return data?.success === true;
|
|
} catch {
|
|
// Network/timeout — fail-open so a provider outage can't lock out signups.
|
|
return true;
|
|
}
|
|
}
|