2023-05-19 12:13:38 +02:00
|
|
|
import cors from "cors";
|
|
|
|
import rateLimit from "express-rate-limit";
|
|
|
|
import { randomBytes } from "crypto";
|
|
|
|
|
|
|
|
const ipSalt = randomBytes(64).toString('hex');
|
|
|
|
|
2024-04-29 13:56:05 +02:00
|
|
|
import { env, version } from "../modules/config.js";
|
2023-05-21 21:13:05 +02:00
|
|
|
import { getJSON } from "../modules/api.js";
|
|
|
|
import { apiJSON, checkJSONPost, getIP, languageCode } from "../modules/sub/utils.js";
|
|
|
|
import { Bright, Cyan } from "../modules/sub/consoleText.js";
|
|
|
|
import stream from "../modules/stream/stream.js";
|
|
|
|
import loc from "../localization/manager.js";
|
2024-03-05 15:55:17 +01:00
|
|
|
import { generateHmac } from "../modules/sub/crypto.js";
|
2024-04-26 13:53:50 +02:00
|
|
|
import { verifyStream, getInternalStream } from "../modules/stream/manage.js";
|
2023-05-19 12:13:38 +02:00
|
|
|
|
2023-06-05 08:47:03 +02:00
|
|
|
export function runAPI(express, app, gitCommit, gitBranch, __dirname) {
|
2024-04-29 13:56:05 +02:00
|
|
|
const corsConfig = !env.corsWildcard ? {
|
|
|
|
origin: env.corsURL,
|
2023-08-04 20:43:12 +02:00
|
|
|
optionsSuccessStatus: 200
|
|
|
|
} : {};
|
2023-05-19 12:13:38 +02:00
|
|
|
|
|
|
|
const apiLimiter = rateLimit({
|
|
|
|
windowMs: 60000,
|
2023-06-27 15:56:15 +02:00
|
|
|
max: 20,
|
2023-08-04 20:43:12 +02:00
|
|
|
standardHeaders: true,
|
2023-05-19 12:13:38 +02:00
|
|
|
legacyHeaders: false,
|
2024-03-05 15:55:17 +01:00
|
|
|
keyGenerator: req => generateHmac(getIP(req), ipSalt),
|
2023-05-19 12:13:38 +02:00
|
|
|
handler: (req, res, next, opt) => {
|
2023-08-04 20:43:12 +02:00
|
|
|
return res.status(429).json({
|
2023-08-13 21:51:55 +02:00
|
|
|
"status": "rate-limit",
|
2023-08-04 20:43:12 +02:00
|
|
|
"text": loc(languageCode(req), 'ErrorRateLimit')
|
|
|
|
});
|
2023-05-19 12:13:38 +02:00
|
|
|
}
|
|
|
|
});
|
|
|
|
const apiLimiterStream = rateLimit({
|
|
|
|
windowMs: 60000,
|
2023-06-27 15:56:15 +02:00
|
|
|
max: 25,
|
2023-08-04 20:43:12 +02:00
|
|
|
standardHeaders: true,
|
2023-05-19 12:13:38 +02:00
|
|
|
legacyHeaders: false,
|
2024-03-05 15:55:17 +01:00
|
|
|
keyGenerator: req => generateHmac(getIP(req), ipSalt),
|
2023-05-19 12:13:38 +02:00
|
|
|
handler: (req, res, next, opt) => {
|
2023-08-04 20:43:12 +02:00
|
|
|
return res.status(429).json({
|
2023-08-13 21:51:55 +02:00
|
|
|
"status": "rate-limit",
|
2023-08-04 20:43:12 +02:00
|
|
|
"text": loc(languageCode(req), 'ErrorRateLimit')
|
|
|
|
});
|
2023-05-19 12:13:38 +02:00
|
|
|
}
|
|
|
|
});
|
|
|
|
|
|
|
|
const startTime = new Date();
|
2024-03-05 15:41:33 +01:00
|
|
|
const startTimestamp = startTime.getTime();
|
2023-05-19 12:13:38 +02:00
|
|
|
|
2023-07-25 21:46:25 +02:00
|
|
|
app.set('trust proxy', ['loopback', 'uniquelocal']);
|
|
|
|
|
2024-03-05 13:14:26 +01:00
|
|
|
app.use('/api/:type', cors({
|
|
|
|
methods: ['GET', 'POST'],
|
|
|
|
...corsConfig
|
|
|
|
}));
|
|
|
|
|
2023-05-19 12:13:38 +02:00
|
|
|
app.use('/api/json', apiLimiter);
|
|
|
|
app.use('/api/stream', apiLimiterStream);
|
|
|
|
app.use('/api/onDemand', apiLimiter);
|
|
|
|
|
|
|
|
app.use((req, res, next) => {
|
|
|
|
try { decodeURIComponent(req.path) } catch (e) { return res.redirect('/') }
|
|
|
|
next();
|
|
|
|
});
|
2024-03-05 13:14:26 +01:00
|
|
|
|
2023-05-19 12:13:38 +02:00
|
|
|
app.use('/api/json', express.json({
|
|
|
|
verify: (req, res, buf) => {
|
2023-08-04 20:43:12 +02:00
|
|
|
let acceptCon = String(req.header('Accept')) === "application/json";
|
|
|
|
if (acceptCon) {
|
2023-05-19 12:13:38 +02:00
|
|
|
if (buf.length > 720) throw new Error();
|
2023-08-04 20:43:12 +02:00
|
|
|
JSON.parse(buf);
|
|
|
|
} else {
|
|
|
|
throw new Error();
|
2023-05-19 12:13:38 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}));
|
2024-03-05 13:14:26 +01:00
|
|
|
|
2023-08-04 20:43:12 +02:00
|
|
|
// handle express.json errors properly (https://github.com/expressjs/express/issues/4065)
|
|
|
|
app.use('/api/json', (err, req, res, next) => {
|
|
|
|
let errorText = "invalid json body";
|
|
|
|
let acceptCon = String(req.header('Accept')) !== "application/json";
|
2023-05-19 12:13:38 +02:00
|
|
|
|
2023-08-04 20:43:12 +02:00
|
|
|
if (err || acceptCon) {
|
|
|
|
if (acceptCon) errorText = "invalid accept header";
|
|
|
|
return res.status(400).json({
|
|
|
|
status: "error",
|
|
|
|
text: errorText
|
|
|
|
});
|
|
|
|
} else {
|
|
|
|
next();
|
|
|
|
}
|
|
|
|
});
|
2024-03-05 13:14:26 +01:00
|
|
|
|
2023-05-19 12:13:38 +02:00
|
|
|
app.post('/api/json', async (req, res) => {
|
|
|
|
try {
|
|
|
|
let lang = languageCode(req);
|
2023-08-04 20:43:12 +02:00
|
|
|
let j = apiJSON(0, { t: "bad request" });
|
2023-05-19 12:13:38 +02:00
|
|
|
try {
|
2023-08-04 20:43:12 +02:00
|
|
|
let contentCon = String(req.header('Content-Type')) === "application/json";
|
2023-05-19 12:13:38 +02:00
|
|
|
let request = req.body;
|
2023-08-04 20:43:12 +02:00
|
|
|
if (contentCon && request.url) {
|
2023-05-19 12:13:38 +02:00
|
|
|
request.dubLang = request.dubLang ? lang : false;
|
2023-08-04 20:43:12 +02:00
|
|
|
|
2023-05-19 12:13:38 +02:00
|
|
|
let chck = checkJSONPost(request);
|
2023-08-04 20:43:12 +02:00
|
|
|
if (!chck) throw new Error();
|
|
|
|
|
2023-12-25 13:20:51 +01:00
|
|
|
j = await getJSON(chck.url, lang, chck);
|
2023-05-19 12:13:38 +02:00
|
|
|
} else {
|
2023-08-04 20:43:12 +02:00
|
|
|
j = apiJSON(0, {
|
|
|
|
t: !contentCon ? "invalid content type header" : loc(lang, 'ErrorNoLink')
|
|
|
|
});
|
2023-05-19 12:13:38 +02:00
|
|
|
}
|
|
|
|
} catch (e) {
|
|
|
|
j = apiJSON(0, { t: loc(lang, 'ErrorCantProcess') });
|
|
|
|
}
|
2023-08-04 20:43:12 +02:00
|
|
|
return res.status(j.status).json(j.body);
|
2023-05-19 12:13:38 +02:00
|
|
|
} catch (e) {
|
2023-08-04 20:43:12 +02:00
|
|
|
return res.destroy();
|
2023-05-19 12:13:38 +02:00
|
|
|
}
|
|
|
|
});
|
|
|
|
|
|
|
|
app.get('/api/:type', (req, res) => {
|
|
|
|
try {
|
2024-04-26 13:53:50 +02:00
|
|
|
let j;
|
2023-05-19 12:13:38 +02:00
|
|
|
switch (req.params.type) {
|
|
|
|
case 'stream':
|
2024-03-05 13:14:26 +01:00
|
|
|
const q = req.query;
|
|
|
|
const checkQueries = q.t && q.e && q.h && q.s && q.i;
|
|
|
|
const checkBaseLength = q.t.length === 21 && q.e.length === 13;
|
2024-03-05 17:49:00 +01:00
|
|
|
const checkSafeLength = q.h.length === 43 && q.s.length === 43 && q.i.length === 22;
|
2024-03-05 13:14:26 +01:00
|
|
|
if (checkQueries && checkBaseLength && checkSafeLength) {
|
|
|
|
if (q.p) {
|
2023-08-04 20:43:12 +02:00
|
|
|
return res.status(200).json({
|
|
|
|
status: "continue"
|
2024-04-27 18:44:25 +02:00
|
|
|
})
|
|
|
|
}
|
|
|
|
let streamInfo = verifyStream(q.t, q.h, q.e, q.s, q.i);
|
|
|
|
if (streamInfo.error) {
|
|
|
|
return res.status(streamInfo.status).json(apiJSON(0, { t: streamInfo.error }).body);
|
2023-05-19 12:13:38 +02:00
|
|
|
}
|
2023-08-04 20:43:12 +02:00
|
|
|
return stream(res, streamInfo);
|
2024-04-26 13:53:50 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
j = apiJSON(0, {
|
|
|
|
t: "bad request. stream link may be incomplete or corrupted."
|
|
|
|
})
|
|
|
|
return res.status(j.status).json(j.body);
|
|
|
|
case 'istream':
|
|
|
|
if (!req.ip.endsWith('127.0.0.1'))
|
|
|
|
return res.sendStatus(403);
|
|
|
|
if (('' + req.query.t).length !== 21)
|
|
|
|
return res.sendStatus(400);
|
|
|
|
|
|
|
|
let streamInfo = getInternalStream(req.query.t);
|
|
|
|
if (!streamInfo) return res.sendStatus(404);
|
|
|
|
streamInfo.headers = req.headers;
|
|
|
|
|
|
|
|
return stream(res, { type: 'internal', ...streamInfo });
|
2023-05-19 12:13:38 +02:00
|
|
|
case 'serverInfo':
|
2023-08-04 20:43:12 +02:00
|
|
|
return res.status(200).json({
|
2023-05-19 12:13:38 +02:00
|
|
|
version: version,
|
2023-05-21 21:13:05 +02:00
|
|
|
commit: gitCommit,
|
|
|
|
branch: gitBranch,
|
2024-04-29 13:56:05 +02:00
|
|
|
name: env.apiName,
|
|
|
|
url: env.apiURL,
|
|
|
|
cors: Number(env.corsWildcard),
|
2023-05-19 12:13:38 +02:00
|
|
|
startTime: `${startTimestamp}`
|
|
|
|
});
|
|
|
|
default:
|
2024-04-26 13:53:50 +02:00
|
|
|
j = apiJSON(0, {
|
2023-08-04 20:43:12 +02:00
|
|
|
t: "unknown response type"
|
|
|
|
})
|
|
|
|
return res.status(j.status).json(j.body);
|
2023-05-19 12:13:38 +02:00
|
|
|
}
|
|
|
|
} catch (e) {
|
2023-08-04 20:43:12 +02:00
|
|
|
return res.status(500).json({
|
|
|
|
status: "error",
|
|
|
|
text: loc(languageCode(req), 'ErrorCantProcess')
|
|
|
|
});
|
2023-05-19 12:13:38 +02:00
|
|
|
}
|
|
|
|
});
|
2024-03-05 13:14:26 +01:00
|
|
|
|
2023-05-21 21:13:05 +02:00
|
|
|
app.get('/api/status', (req, res) => {
|
2023-05-19 12:13:38 +02:00
|
|
|
res.status(200).end()
|
|
|
|
});
|
2024-03-05 13:14:26 +01:00
|
|
|
|
2023-05-21 21:13:05 +02:00
|
|
|
app.get('/favicon.ico', (req, res) => {
|
|
|
|
res.sendFile(`${__dirname}/src/front/icons/favicon.ico`)
|
2023-05-19 12:13:38 +02:00
|
|
|
});
|
2024-03-05 13:14:26 +01:00
|
|
|
|
2023-05-21 21:13:05 +02:00
|
|
|
app.get('/*', (req, res) => {
|
2023-05-19 12:13:38 +02:00
|
|
|
res.redirect('/api/json')
|
|
|
|
});
|
|
|
|
|
2024-04-29 13:56:05 +02:00
|
|
|
app.listen(env.apiPort, () => {
|
2023-08-04 20:43:12 +02:00
|
|
|
console.log(`\n` +
|
|
|
|
`${Cyan("cobalt")} API ${Bright(`v.${version}-${gitCommit} (${gitBranch})`)}\n` +
|
|
|
|
`Start time: ${Bright(`${startTime.toUTCString()} (${startTimestamp})`)}\n\n` +
|
2024-04-29 13:56:05 +02:00
|
|
|
`URL: ${Cyan(`${env.apiURL}`)}\n` +
|
|
|
|
`Port: ${env.apiPort}\n`
|
2023-08-04 20:43:12 +02:00
|
|
|
)
|
2023-05-21 21:13:05 +02:00
|
|
|
});
|
2023-05-19 12:13:38 +02:00
|
|
|
}
|