umami/pages/api/collect.js

96 lines
2.4 KiB
JavaScript
Raw Normal View History

const { Resolver } = require('dns').promises;
2021-03-13 07:44:25 +01:00
import isbot from 'isbot';
import ipaddr from 'ipaddr.js';
2022-07-12 23:14:36 +02:00
import { savePageView, saveEvent } from 'queries';
2020-07-28 08:52:14 +02:00
import { useCors, useSession } from 'lib/middleware';
2022-03-11 04:01:33 +01:00
import { getJsonBody, getIpAddress } from 'lib/request';
2022-08-26 07:04:32 +02:00
import { unauthorized, send, badRequest, forbidden } from 'lib/response';
2020-10-03 05:33:46 +02:00
import { createToken } from 'lib/crypto';
import { removeTrailingSlash } from 'lib/url';
import { uuid } from 'lib/crypto';
2020-07-17 10:03:38 +02:00
export default async (req, res) => {
await useCors(req, res);
2022-08-27 05:21:53 +02:00
if (isbot(req.headers['user-agent']) && !process.env.DISABLE_BOT_CHECK) {
2022-08-26 07:04:32 +02:00
return unauthorized(res);
2020-09-11 05:37:07 +02:00
}
2022-04-10 12:51:43 +02:00
const ignoreIps = process.env.IGNORE_IP;
const ignoreHostnames = process.env.IGNORE_HOSTNAME;
if (ignoreIps || ignoreHostnames) {
const ips = [];
if (ignoreIps) {
ips.push(...ignoreIps.split(',').map(n => n.trim()));
}
if (ignoreHostnames) {
const resolver = new Resolver();
const promises = ignoreHostnames
.split(',')
.map(n => resolver.resolve4(n.trim()).catch(() => {}));
await Promise.all(promises).then(resolvedIps => {
ips.push(...resolvedIps.filter(n => n).flatMap(n => n));
});
}
const clientIp = getIpAddress(req);
const blocked = ips.find(ip => {
if (ip === clientIp) return true;
2020-10-04 04:07:56 +02:00
// CIDR notation
if (ip.indexOf('/') > 0) {
const addr = ipaddr.parse(clientIp);
const range = ipaddr.parseCIDR(ip);
if (addr.kind() === range[0].kind() && addr.match(range)) return true;
}
return false;
});
if (blocked) {
return forbidden(res);
2020-10-04 04:07:56 +02:00
}
}
2020-07-28 08:52:14 +02:00
await useSession(req, res);
2020-08-21 04:17:27 +02:00
const {
2022-07-22 23:43:19 +02:00
session: { website_id, session_id, session_uuid },
2020-08-21 04:17:27 +02:00
} = req;
2020-07-17 10:03:38 +02:00
2022-03-11 04:01:33 +01:00
const { type, payload } = getJsonBody(req);
2022-07-30 07:30:09 +02:00
let { url, referrer, event_name, event_data } = payload;
if (process.env.REMOVE_TRAILING_SLASH) {
url = removeTrailingSlash(url);
}
2020-07-24 04:56:55 +02:00
2022-08-22 21:24:57 +02:00
const event_uuid = uuid();
if (type === 'pageview') {
2022-07-22 23:43:19 +02:00
await savePageView(website_id, { session_id, session_uuid, url, referrer });
} else if (type === 'event') {
await saveEvent(website_id, {
event_uuid,
session_id,
session_uuid,
url,
event_name,
event_data,
});
} else {
return badRequest(res);
2020-07-24 04:56:55 +02:00
}
2020-07-23 05:45:09 +02:00
2022-08-10 08:32:02 +02:00
const token = await createToken({ website_id, session_id, session_uuid });
2020-10-03 05:33:46 +02:00
2022-03-11 05:39:11 +01:00
return send(res, token);
2020-07-17 10:03:38 +02:00
};