mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 14:26:38 +00:00
Update index.ts
This commit is contained in:
+15
-18
@@ -12,25 +12,25 @@ export enum IPType {
|
|||||||
* Handles both IPv4 (e.g. 1.2.3.4:1234) and IPv6 (e.g. [2001:db8::1]:8080) formats.
|
* Handles both IPv4 (e.g. 1.2.3.4:1234) and IPv6 (e.g. [2001:db8::1]:8080) formats.
|
||||||
* Returns the IP address without port and a boolean indicating if a port was present.
|
* Returns the IP address without port and a boolean indicating if a port was present.
|
||||||
*/
|
*/
|
||||||
const stripPort = (ip: string): { ipAddress: string; hasPort: boolean } => {
|
const stripPort = (ip: string): { ipAddress: string } => {
|
||||||
// Handle IPv6 with port (e.g. [2001:db8::1]:8080)
|
// Handle IPv6 with port (e.g. [2001:db8::1]:8080)
|
||||||
if (ip.startsWith("[") && ip.includes("]:")) {
|
if (ip.startsWith("[") && ip.includes("]:")) {
|
||||||
const endBracketIndex = ip.indexOf("]");
|
const endBracketIndex = ip.indexOf("]");
|
||||||
if (endBracketIndex === -1) return { ipAddress: ip, hasPort: false };
|
if (endBracketIndex === -1) return { ipAddress: ip };
|
||||||
const ipPart = ip.slice(1, endBracketIndex);
|
const ipPart = ip.slice(1, endBracketIndex);
|
||||||
const portPart = ip.slice(endBracketIndex + 2);
|
const portPart = ip.slice(endBracketIndex + 2);
|
||||||
if (!portPart || !/^\d+$/.test(portPart)) return { ipAddress: ip, hasPort: false };
|
if (!portPart || !/^\d+$/.test(portPart)) return { ipAddress: ip };
|
||||||
return { ipAddress: ipPart, hasPort: true };
|
return { ipAddress: ipPart };
|
||||||
}
|
}
|
||||||
|
|
||||||
// Handle IPv4 with port (e.g. 1.2.3.4:1234)
|
// Handle IPv4 with port (e.g. 1.2.3.4:1234)
|
||||||
if (ip.includes(":")) {
|
if (ip.includes(":")) {
|
||||||
const [ipPart, portPart] = ip.split(":");
|
const [ipPart, portPart] = ip.split(":");
|
||||||
if (!portPart || !/^\d+$/.test(portPart)) return { ipAddress: ip, hasPort: false };
|
if (!portPart || !/^\d+$/.test(portPart)) return { ipAddress: ip };
|
||||||
return { ipAddress: ipPart, hasPort: true };
|
return { ipAddress: ipPart };
|
||||||
}
|
}
|
||||||
|
|
||||||
return { ipAddress: ip, hasPort: false };
|
return { ipAddress: ip };
|
||||||
};
|
};
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -41,22 +41,19 @@ const stripPort = (ip: string): { ipAddress: string; hasPort: boolean } => {
|
|||||||
export const extractIPDetails = (ip: string) => {
|
export const extractIPDetails = (ip: string) => {
|
||||||
const { ipAddress } = stripPort(ip);
|
const { ipAddress } = stripPort(ip);
|
||||||
|
|
||||||
// Handle IPv6 addresses with brackets
|
if (net.isIPv4(ipAddress))
|
||||||
const cleanIp = ipAddress.startsWith("[") && ipAddress.endsWith("]") ? ipAddress.slice(1, -1) : ipAddress;
|
|
||||||
|
|
||||||
if (net.isIPv4(cleanIp))
|
|
||||||
return {
|
return {
|
||||||
ipAddress: cleanIp,
|
ipAddress,
|
||||||
type: IPType.IPV4
|
type: IPType.IPV4
|
||||||
};
|
};
|
||||||
|
|
||||||
if (net.isIPv6(cleanIp))
|
if (net.isIPv6(ipAddress))
|
||||||
return {
|
return {
|
||||||
ipAddress: cleanIp,
|
ipAddress,
|
||||||
type: IPType.IPV6
|
type: IPType.IPV6
|
||||||
};
|
};
|
||||||
|
|
||||||
const [ipNet, prefix] = cleanIp.split("/");
|
const [ipNet, prefix] = ipAddress.split("/");
|
||||||
|
|
||||||
let type;
|
let type;
|
||||||
switch (net.isIP(ipNet)) {
|
switch (net.isIP(ipNet)) {
|
||||||
@@ -162,9 +159,9 @@ export const checkIPAgainstBlocklist = ({ ipAddress, trustedIps }: { ipAddress:
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
const { type } = extractIPDetails(ipAddress);
|
const { type, ipAddress: cleanIpAddress } = extractIPDetails(ipAddress);
|
||||||
const { ipAddress: cleanIp } = stripPort(ipAddress);
|
|
||||||
const check = blockList.check(cleanIp, type);
|
const check = blockList.check(cleanIpAddress, type);
|
||||||
|
|
||||||
if (!check)
|
if (!check)
|
||||||
throw new ForbiddenRequestError({
|
throw new ForbiddenRequestError({
|
||||||
|
|||||||
Reference in New Issue
Block a user