mirror of https://gitgud.io/fatchan/jschan.git
You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
25 lines
727 B
25 lines
727 B
'use strict';
|
|
|
|
const { refererCheck, allowedHosts } = require(__dirname+'/../configs/secrets.js')
|
|
, dynamicResponse = require(__dirname+'/dynamic.js')
|
|
, allowedHostSet = new Set(allowedHosts);
|
|
|
|
module.exports = (req, res, next) => {
|
|
if (req.method !== 'POST') {
|
|
return next();
|
|
}
|
|
let validReferer = false;
|
|
try {
|
|
const url = new URL(req.headers.referer);
|
|
validReferer = allowedHostSet.has(url.hostname);
|
|
} catch(e) {
|
|
//referrer is invalid url
|
|
}
|
|
if (refererCheck === true && (!req.headers.referer || !validReferer)) {
|
|
return dynamicResponse(req, res, 403, 'message', {
|
|
'title': 'Forbidden',
|
|
'message': 'Invalid or missing "Referer" header. Are you posting from the correct URL?'
|
|
});
|
|
}
|
|
next();
|
|
}
|
|
|