53 lines
2.2 KiB
TypeScript
53 lines
2.2 KiB
TypeScript
// Shared helpers for `m.room.server_acl` server-name globs, used by both the
|
|||
|
|
// Room Settings ACL editor and the `/acl` slash command so their validation and
|
||
|
|
// self-lockout detection stay identical.
|
||
|
|
|
||
|
|
/**
|
||
|
|
* Validate a server-name glob for an ACL entry.
|
||
|
|
*
|
||
|
|
* Matrix ACL `allow`/`deny` entries are globs where `*` (any run of chars) and
|
||
|
|
* `?` (single char) may appear ANYWHERE — e.g. `*`, `*.example.com`,
|
||
|
|
* `1.2.3.*`, `10.0.0.?`, `*.evil.*`, `*bad*`. We therefore validate the *glob*
|
||
|
|
* rather than a concrete hostname:
|
||
|
|
* - reject empty / whitespace-only
|
||
|
|
* - allow only hostname/IP chars plus the wildcards `*` and `?`
|
||
|
|
* (letters, digits, dots, hyphens, colons for ports/IPv6 — NO underscore)
|
||
|
|
* - reject consecutive/leading/trailing dots (`...`, `.foo`, `foo.`)
|
||
|
|
* - reject entries with no alphanumeric or wildcard char (bare `-`, lone `:`)
|
||
|
|
*/
|
||
|
|
export function isValidServerPattern(value: string): boolean {
|
||
|
|
const v = value.trim();
|
||
|
|
if (!v) return false;
|
||
|
|
// Only hostname/IP glob chars — wildcards may appear at any position.
|
||
|
|
if (!/^[A-Za-z0-9.:*?-]+$/.test(v)) return false;
|
||
|
|
// Structural rules for the dotted parts.
|
||
|
|
if (v.startsWith('.') || v.endsWith('.') || v.includes('..')) return false;
|
||
|
|
// Must carry actual signal — reject pure punctuation like `-`, `:` or `-.-`.
|
||
|
|
if (!/[A-Za-z0-9*?]/.test(v)) return false;
|
||
|
|
return true;
|
||
|
|
}
|
||
|
|
|
||
|
|
/**
|
||
|
|
* Convert an ACL glob (`*` = any run, `?` = single char) to an anchored RegExp,
|
||
|
|
* escaping every other regex metacharacter. Used only for local self-ban
|
||
|
|
* detection — never sent to the server.
|
||
|
|
*/
|
||
|
|
export function globToRegExp(glob: string): RegExp {
|
||
|
|
const escaped = glob.replace(/[.+^${}()|[\]\\]/g, '\\$&');
|
||
|
|
const pattern = escaped.replace(/\*/g, '.*').replace(/\?/g, '.');
|
||
|
|
// Case-INsensitive: Synapse's glob_to_regex uses IGNORECASE and hostnames are
|
||
|
|
// case-insensitive, so a deny like `MATRIX.foo.org` must still be detected as
|
||
|
|
// self-banning `matrix.foo.org` (otherwise the warning is a false negative).
|
||
|
|
return new RegExp(`^${pattern}$`, 'i');
|
||
|
|
}
|
||
|
|
|
||
|
|
export function matchesAnyGlob(domain: string, globs: string[]): boolean {
|
||
|
|
return globs.some((glob) => {
|
||
|
|
try {
|
||
|
|
return globToRegExp(glob).test(domain);
|
||
|
|
} catch {
|
||
|
|
return false;
|
||
|
|
}
|
||
|
|
});
|
||
|
|
}
|