umami/pages/api/send.ts

170 lines
4.2 KiB
TypeScript
Raw Normal View History

import isbot from 'isbot';
import ipaddr from 'ipaddr.js';
2023-02-08 01:29:25 +01:00
import { createToken, ok, send, badRequest, forbidden } from 'next-basics';
2023-07-25 18:55:38 +02:00
import { saveEvent, saveSessionData } from 'queries';
import { useCors, useSession } from 'lib/middleware';
2022-12-28 05:20:44 +01:00
import { getJsonBody, getIpAddress } from 'lib/detect';
import { secret } from 'lib/crypto';
2022-11-15 22:21:14 +01:00
import { NextApiRequest, NextApiResponse } from 'next';
2023-02-08 01:29:25 +01:00
import { Resolver } from 'dns/promises';
import { CollectionType } from 'lib/types';
import { COLLECTION_TYPE } from 'lib/constants';
2022-11-15 22:21:14 +01:00
2023-03-30 20:18:57 +02:00
export interface CollectRequestBody {
payload: {
data: { [key: string]: any };
hostname: string;
language: string;
referrer: string;
screen: string;
title: string;
url: string;
website: string;
name: string;
};
type: CollectionType;
2023-03-30 20:18:57 +02:00
}
2022-11-15 22:21:14 +01:00
export interface NextApiRequestCollect extends NextApiRequest {
2023-03-30 20:18:57 +02:00
body: CollectRequestBody;
2022-11-15 22:21:14 +01:00
session: {
id: string;
websiteId: string;
2023-05-16 05:41:12 +02:00
ownerId: string;
2022-11-15 22:21:14 +01:00
hostname: string;
browser: string;
os: string;
device: string;
screen: string;
language: string;
country: string;
subdivision1: string;
subdivision2: string;
city: string;
2022-11-15 22:21:14 +01:00
};
2023-03-30 20:18:57 +02:00
headers: { [key: string]: any };
2022-11-15 22:21:14 +01:00
}
export default async (req: NextApiRequestCollect, res: NextApiResponse) => {
await useCors(req, res);
if (isbot(req.headers['user-agent']) && !process.env.DISABLE_BOT_CHECK) {
2023-02-08 01:29:25 +01:00
return ok(res);
}
2023-03-30 20:18:57 +02:00
const { type, payload } = getJsonBody<CollectRequestBody>(req);
2022-11-23 00:06:52 +01:00
validateBody(res, { type, payload });
if (await hasBlockedIp(req)) {
return forbidden(res);
2023-03-26 13:15:08 +02:00
}
2023-06-15 08:48:11 +02:00
const { url, referrer, name: eventName, data: eventData, title: pageTitle } = payload;
await useSession(req, res);
const session = req.session;
if (type === COLLECTION_TYPE.event) {
// eslint-disable-next-line prefer-const
let [urlPath, urlQuery] = url?.split('?') || [];
let [referrerPath, referrerQuery] = referrer?.split('?') || [];
let referrerDomain;
if (!urlPath) {
urlPath = '/';
}
if (referrerPath?.startsWith('http')) {
const refUrl = new URL(referrer);
referrerPath = refUrl.pathname;
referrerQuery = refUrl.search.substring(1);
referrerDomain = refUrl.hostname.replace(/www\./, '');
}
if (process.env.REMOVE_TRAILING_SLASH) {
urlPath = urlPath.replace(/.+\/$/, '');
}
await saveEvent({
urlPath,
urlQuery,
referrerPath,
referrerQuery,
referrerDomain,
pageTitle,
eventName,
2023-06-15 08:48:11 +02:00
eventData,
...session,
sessionId: session.id,
});
}
if (type === COLLECTION_TYPE.identify) {
2023-06-15 08:48:11 +02:00
if (!eventData) {
return badRequest(res, 'Data required.');
}
2023-06-15 08:48:11 +02:00
await saveSessionData({ ...session, sessionData: eventData, sessionId: session.id });
}
const token = createToken(session, secret());
return send(res, token);
};
function validateBody(res: NextApiResponse, { type, payload }: CollectRequestBody) {
2023-07-21 08:12:15 +02:00
const { data } = payload || {};
// Validate type
if (type !== COLLECTION_TYPE.event && type !== COLLECTION_TYPE.identify) {
return badRequest(res, 'Wrong payload type.');
}
// Validate eventData is JSON
if (data && !(typeof data === 'object' && !Array.isArray(data))) {
2023-03-26 13:15:08 +02:00
return badRequest(res, 'Invalid event data.');
}
}
async function hasBlockedIp(req: NextApiRequestCollect) {
const ignoreIps = process.env.IGNORE_IP;
const ignoreHostnames = process.env.IGNORE_HOSTNAME;
if (ignoreIps || ignoreHostnames) {
const ips = [];
if (ignoreIps) {
ips.push(...ignoreIps.split(',').map(n => n.trim()));
}
if (ignoreHostnames) {
const resolver = new Resolver();
const promises = ignoreHostnames
.split(',')
.map(n => resolver.resolve4(n.trim()).catch(() => {}));
await Promise.all(promises).then(resolvedIps => {
2023-02-08 01:29:25 +01:00
ips.push(...resolvedIps.filter(n => n).flatMap(n => n as string[]));
});
}
const clientIp = getIpAddress(req);
2023-06-15 08:48:11 +02:00
return ips.find(ip => {
if (ip === clientIp) return true;
// CIDR notation
if (ip.indexOf('/') > 0) {
const addr = ipaddr.parse(clientIp);
const range = ipaddr.parseCIDR(ip);
if (addr.kind() === range[0].kind() && addr.match(range)) return true;
}
return false;
});
2023-03-16 00:06:51 +01:00
}
}