-
Notifications
You must be signed in to change notification settings - Fork 1
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request #39 from dallen4/alpha
IP Limiting & CORS
- Loading branch information
Showing
21 changed files
with
279 additions
and
94 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,19 @@ | ||
import { generateIV } from '@shared/lib/util'; | ||
import { getRedis } from 'lib/redis'; | ||
import { formatDropKey } from 'lib/util'; | ||
import { nanoid } from 'nanoid'; | ||
|
||
const FIVE_MINS_IN_SEC = 10 * 60; | ||
|
||
export const createDrop = async (peerId: string) => { | ||
const client = getRedis(); | ||
|
||
const dropId = nanoid(); | ||
const nonce = generateIV(); | ||
|
||
const key = formatDropKey(dropId); | ||
await client.hset(key, { peerId, nonce }); | ||
await client.expire(key, FIVE_MINS_IN_SEC); | ||
|
||
return { dropId, nonce }; | ||
}; |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,22 @@ | ||
import { hashRaw } from '@shared/lib/crypto/operations'; | ||
import { getRedis } from '../lib/redis'; | ||
|
||
const DAY_IN_SEC = 60 * 60 * 24; | ||
|
||
export const checkAndIncrementDropCount = async (ipAddress: string) => { | ||
const userIpHash = await hashRaw(ipAddress); | ||
|
||
const client = getRedis(); | ||
|
||
const userDropCount = await client.get(userIpHash); | ||
|
||
if (!userDropCount) { | ||
await client.setex(userIpHash, DAY_IN_SEC, 1); | ||
} else { | ||
if (parseInt(userDropCount) >= 5) | ||
return false; | ||
else await client.incr(userIpHash); | ||
} | ||
|
||
return true; | ||
}; |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,20 @@ | ||
import Cors from 'cors'; | ||
|
||
export const cors = Cors({ | ||
methods: ['POST', 'GET', 'DELETE'], | ||
origin: (origin, callback) => { | ||
console.log(origin); | ||
if ( | ||
!origin || | ||
origin.endsWith('deadrop.io') || | ||
origin.includes('vscode-webview:') | ||
) | ||
callback(null, true); | ||
else if ( | ||
process.env.NODE_ENV !== 'production' && | ||
origin.startsWith('http://localhost:') | ||
) | ||
callback(null, true); | ||
else callback(new Error('Invalid origin')); | ||
}, | ||
}); |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,21 @@ | ||
import { NextApiRequest, NextApiResponse } from 'next/types'; | ||
|
||
export function runMiddleware( | ||
req: NextApiRequest, | ||
res: NextApiResponse, | ||
fn: ( | ||
req: NextApiRequest, | ||
res: NextApiResponse, | ||
cb: (result: any) => void, | ||
) => any, | ||
) { | ||
return new Promise((resolve, reject) => { | ||
fn(req, res, (result) => { | ||
if (result instanceof Error) { | ||
return reject(result); | ||
} | ||
|
||
return resolve(result); | ||
}); | ||
}); | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,9 @@ | ||
export const BEGIN_DROP_BTN_ID = 'begin-drop-btn'; | ||
|
||
export const CONFIRM_PAYLOAD_BTN_ID = 'confirm-payload-btn'; | ||
|
||
export const DROP_LINK_ID = 'drop-link'; | ||
|
||
export const DROP_SECRET_BTN_ID = 'drop-secret-btn'; | ||
|
||
export const DROP_SECRET_VALUE_ID = 'drop-secret-value'; |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
dec4813
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Successfully deployed to the following URLs:
deadrop – ./
deadrop-dallen4.vercel.app
deadrop-git-main-dallen4.vercel.app
deaddrop.vercel.app
www.deadrop.io
drop.nieky.dev
deadrop.io