Phase A — Public REST API (was the biggest gap). 20 JSON endpoints under
/api mirroring AtomCMS: users/[username], online(+/count), me, articles
(+/[slug]), photos, home, staff, teams, leaderboard, shop(+/categories),
values(+/categories), settings, radio/{config,now-playing,listeners,
shouts}. Shared src/lib/api.ts (apiJson — BigInt-safe + CORS, pagination).
Read-only, fail-soft, and field-safe (never exposes password/auth_ticket/
2FA secrets/mail).
Phase B — Anti-abuse on registration: CAPTCHA (Cloudflare Turnstile /
Google reCAPTCHA, settings-driven, widget rendered on the register page),
VPN/proxy detection (proxycheck.io / IPQualityScore via /admin/vpn
settings), and max-accounts-per-IP. All fail-open when unconfigured.
src/lib/services/{captcha,ip-lookup}.ts.
Phase C — jobs-worker cron suite: radio-record-songs (30s, logs track
changes to radio_song_plays), radio-auto-dj (rotates radio_auto_dj_playlist
when no live DJ), github-update-check (hourly, sets update_available).
Shared src/lib/services/radio.ts (now-playing/listeners parsing).
Verified live (prod, amx_test): /api/* return real JSON (leaderboard 6
users, settings carry no secrets, user endpoint hides password). tsc 0,
vitest 49/49, next build 0 (20 new API routes).
55 lines
2.3 KiB
TypeScript
55 lines
2.3 KiB
TypeScript
import { siteSettings } from "@/lib/services/site-settings";
|
|
|
|
/**
|
|
* VPN / proxy / Tor detection via an external provider, driven by
|
|
* website_settings (configured at /admin/vpn). Mirrors AtomCMS's IP lookup used
|
|
* to block registrations from anonymising IPs. FAIL-OPEN: any error, missing
|
|
* config, or disabled toggle returns "not blocked".
|
|
*
|
|
* Settings keys: vpn_block_enabled ("1"), vpn_provider ("proxycheck" |
|
|
* "ipqualityscore"), vpn_api_key.
|
|
*/
|
|
export interface IpVerdict {
|
|
blocked: boolean;
|
|
reason?: string;
|
|
}
|
|
|
|
const PRIVATE_RE =
|
|
/^(127\.|10\.|192\.168\.|172\.(1[6-9]|2\d|3[01])\.|::1|fc|fd|localhost$|0\.0\.0\.0$)/i;
|
|
|
|
export async function checkVpn(ip: string): Promise<IpVerdict> {
|
|
if (!ip || PRIVATE_RE.test(ip)) return { blocked: false };
|
|
if (!(await siteSettings.getBool("vpn_block_enabled", false))) return { blocked: false };
|
|
|
|
const provider = ((await siteSettings.get("vpn_provider", "proxycheck")) ?? "proxycheck").toLowerCase();
|
|
const apiKey = (await siteSettings.get("vpn_api_key", "")) ?? "";
|
|
|
|
try {
|
|
const controller = new AbortController();
|
|
const timer = setTimeout(() => controller.abort(), 4000);
|
|
|
|
if (provider === "ipqualityscore") {
|
|
if (!apiKey) return { blocked: false };
|
|
const res = await fetch(
|
|
`https://ipqualityscore.com/api/json/ip/${encodeURIComponent(apiKey)}/${encodeURIComponent(ip)}`,
|
|
{ signal: controller.signal, cache: "no-store" },
|
|
);
|
|
clearTimeout(timer);
|
|
const d = (await res.json()) as { proxy?: boolean; vpn?: boolean; tor?: boolean };
|
|
if (d?.vpn || d?.tor || d?.proxy) return { blocked: true, reason: "VPN/proxy detected" };
|
|
return { blocked: false };
|
|
}
|
|
|
|
// Default: proxycheck.io (works keyless at a low rate; key raises limits).
|
|
const url = `https://proxycheck.io/v2/${encodeURIComponent(ip)}?vpn=1&risk=1${apiKey ? `&key=${encodeURIComponent(apiKey)}` : ""}`;
|
|
const res = await fetch(url, { signal: controller.signal, cache: "no-store" });
|
|
clearTimeout(timer);
|
|
const d = (await res.json()) as Record<string, { proxy?: string; type?: string }>;
|
|
const entry = d?.[ip];
|
|
if (entry?.proxy === "yes") return { blocked: true, reason: `${entry.type ?? "Proxy"} detected` };
|
|
return { blocked: false };
|
|
} catch {
|
|
return { blocked: false };
|
|
}
|
|
}
|