mirror of
https://github.com/kremalicious/umami.git
synced 2024-06-30 13:41:50 +02:00
Added IGNORE_HOSTNAME environment variable. Closes #1151.
This commit is contained in:
parent
ca385af8c4
commit
8175f13f96
|
@ -1,9 +1,10 @@
|
||||||
|
const { Resolver } = require('dns').promises;
|
||||||
import isbot from 'isbot';
|
import isbot from 'isbot';
|
||||||
import ipaddr from 'ipaddr.js';
|
import ipaddr from 'ipaddr.js';
|
||||||
import { savePageView, saveEvent } from 'lib/queries';
|
import { savePageView, saveEvent } from 'lib/queries';
|
||||||
import { useCors, useSession } from 'lib/middleware';
|
import { useCors, useSession } from 'lib/middleware';
|
||||||
import { getJsonBody, getIpAddress } from 'lib/request';
|
import { getJsonBody, getIpAddress } from 'lib/request';
|
||||||
import { ok, send, badRequest } from 'lib/response';
|
import { ok, send, badRequest, forbidden } from 'lib/response';
|
||||||
import { createToken } from 'lib/crypto';
|
import { createToken } from 'lib/crypto';
|
||||||
import { removeTrailingSlash } from 'lib/url';
|
import { removeTrailingSlash } from 'lib/url';
|
||||||
|
|
||||||
|
@ -15,16 +16,35 @@ export default async (req, res) => {
|
||||||
}
|
}
|
||||||
|
|
||||||
const ignoreIps = process.env.IGNORE_IP;
|
const ignoreIps = process.env.IGNORE_IP;
|
||||||
if (ignoreIps) {
|
const ignoreHostnames = process.env.IGNORE_HOSTNAME;
|
||||||
const ips = ignoreIps.split(',').map(n => n.trim());
|
|
||||||
const ip = getIpAddress(req);
|
if (ignoreIps || ignoreHostnames) {
|
||||||
const blocked = ips.find(i => {
|
const ips = [];
|
||||||
if (i === ip) return true;
|
|
||||||
|
if (ignoreIps) {
|
||||||
|
ips.push(...ignoreIps.split(',').map(n => n.trim()));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (ignoreHostnames) {
|
||||||
|
const resolver = new Resolver();
|
||||||
|
const promises = ignoreHostnames
|
||||||
|
.split(',')
|
||||||
|
.map(n => resolver.resolve4(n.trim()).catch(() => {}));
|
||||||
|
|
||||||
|
await Promise.all(promises).then(resolvedIps => {
|
||||||
|
ips.push(...resolvedIps.filter(n => n).flatMap(n => n));
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
const clientIp = getIpAddress(req);
|
||||||
|
|
||||||
|
const blocked = ips.find(ip => {
|
||||||
|
if (ip === clientIp) return true;
|
||||||
|
|
||||||
// CIDR notation
|
// CIDR notation
|
||||||
if (i.indexOf('/') > 0) {
|
if (ip.indexOf('/') > 0) {
|
||||||
const addr = ipaddr.parse(ip);
|
const addr = ipaddr.parse(clientIp);
|
||||||
const range = ipaddr.parseCIDR(i);
|
const range = ipaddr.parseCIDR(ip);
|
||||||
|
|
||||||
if (addr.kind() === range[0].kind() && addr.match(range)) return true;
|
if (addr.kind() === range[0].kind() && addr.match(range)) return true;
|
||||||
}
|
}
|
||||||
|
@ -33,7 +53,7 @@ export default async (req, res) => {
|
||||||
});
|
});
|
||||||
|
|
||||||
if (blocked) {
|
if (blocked) {
|
||||||
return ok(res);
|
return forbidden(res);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue
Block a user