Compare commits

...
5 Commits
Author SHA1 Message Date
Chris Troutner 9cd06630ea Merge pull request #103 from Permissionless-Software-Foundation/ct-unstable
fix(rate limits): Passing JWT token to internal calls
2021-02-24 17:10:17 -08:00
Chris Troutner 6b281e2842 fix(rate limits): Passing JWT token to internal calls 2021-02-24 17:07:24 -08:00
Chris Troutner 2e143d5a9e Merge pull request #102 from Permissionless-Software-Foundation/ct-unstable
More debugging around rate limits
2021-02-24 16:53:40 -08:00
Chris Troutner eb817da044 Merge branch 'master' into ct-unstable 2021-02-24 16:50:50 -08:00
Chris Troutner 1c88aa7d72 fix(bch-js): Bumping to v4.15.7 2021-02-24 16:50:38 -08:00
4 changed files with 53 additions and 14 deletions
+7 -7
View File
@@ -8,7 +8,7 @@
"version": "1.16.0", "version": "1.16.0",
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
"@psf/bch-js": "^4.15.4", "@psf/bch-js": "^4.15.7",
"apidoc": "^0.26.0", "apidoc": "^0.26.0",
"axios": "^0.21.1", "axios": "^0.21.1",
"bitcore-lib-cash": "^8.23.1", "bitcore-lib-cash": "^8.23.1",
@@ -458,9 +458,9 @@
} }
}, },
"node_modules/@psf/bch-js": { "node_modules/@psf/bch-js": {
"version": "4.15.4", "version": "4.15.7",
"resolved": "https://registry.npmjs.org/@psf/bch-js/-/bch-js-4.15.4.tgz", "resolved": "https://registry.npmjs.org/@psf/bch-js/-/bch-js-4.15.7.tgz",
"integrity": "sha512-UqUC3uHLZRtmF4eCJ7ABH0tDOH2jKBM5wZ5SRu6qRSaNCSqQsSHlN/y+98muk4c+7RAFER5v0DyekWo/J1HP6w==", "integrity": "sha512-8PuPlAksbBiEG4UnLBp7uyPW+EM+qv/T9CQcEiQa66FtXndECEFLCsx0eMC+keVSzVUiwBGzGERK1JPFqd8euw==",
"dependencies": { "dependencies": {
"@psf/bip21": "^2.0.1", "@psf/bip21": "^2.0.1",
"@psf/bip32-utils": "^0.13.1", "@psf/bip32-utils": "^0.13.1",
@@ -18627,9 +18627,9 @@
} }
}, },
"@psf/bch-js": { "@psf/bch-js": {
"version": "4.15.4", "version": "4.15.7",
"resolved": "https://registry.npmjs.org/@psf/bch-js/-/bch-js-4.15.4.tgz", "resolved": "https://registry.npmjs.org/@psf/bch-js/-/bch-js-4.15.7.tgz",
"integrity": "sha512-UqUC3uHLZRtmF4eCJ7ABH0tDOH2jKBM5wZ5SRu6qRSaNCSqQsSHlN/y+98muk4c+7RAFER5v0DyekWo/J1HP6w==", "integrity": "sha512-8PuPlAksbBiEG4UnLBp7uyPW+EM+qv/T9CQcEiQa66FtXndECEFLCsx0eMC+keVSzVUiwBGzGERK1JPFqd8euw==",
"requires": { "requires": {
"@psf/bip21": "^2.0.1", "@psf/bip21": "^2.0.1",
"@psf/bip32-utils": "^0.13.1", "@psf/bip32-utils": "^0.13.1",
+1 -1
View File
@@ -29,7 +29,7 @@
"node": ">=10.15.1" "node": ">=10.15.1"
}, },
"dependencies": { "dependencies": {
"@psf/bch-js": "^4.15.4", "@psf/bch-js": "^4.15.7",
"apidoc": "^0.26.0", "apidoc": "^0.26.0",
"axios": "^0.21.1", "axios": "^0.21.1",
"bitcore-lib-cash": "^8.23.1", "bitcore-lib-cash": "^8.23.1",
+35 -4
View File
@@ -113,6 +113,27 @@ class RateLimits {
err err
) )
} }
//
} else if (req.body && req.body.usrObj) {
// Same as above, but this code path is activated from internal calls to
// bch-js, like hydrateUtxo() which passes the user object from the
// original API call.
try {
decoded = _this.jwt.verify(
req.body.usrObj.jwtToken,
_this.config.apiTokenSecret
)
// console.log(`decoded: ${JSON.stringify(decoded, null, 2)}`)
userId = decoded.id
} catch (err) {
// This handler will be triggered if the JWT token does not match the
// token secret.
wlogger.error(
'Error in route-ratelimit.js trying to decode JWT token in usrObj'
)
}
} else { } else {
wlogger.debug('No JWT token found!') wlogger.debug('No JWT token found!')
} }
@@ -136,9 +157,17 @@ class RateLimits {
// For internal calls that make a lot of internal calls, like // For internal calls that make a lot of internal calls, like
// hydrateUtxoDetails(), the origin of the caller will be passed in // hydrateUtxoDetails(), the origin of the caller will be passed in
// via the POST body. // via the POST body.
const keyIsLocal = key.includes('172.17.0.1') || key.includes('127.0.0.1') const keyIsLocal =
if (req.body && req.body.ip && keyIsLocal) { key.includes('172.17.0.1') || key.includes('127.0.0.1')
key = req.body.ip if (req.body && req.body.usrObj && keyIsLocal) {
// key = req.body.ip
console.log(
`route-ratelimit usrObj: ${JSON.stringify(
req.body.usrObj,
null,
2
)}`
)
} }
console.log(`key: ${key}`) console.log(`key: ${key}`)
@@ -297,7 +326,9 @@ class RateLimits {
return retVal return retVal
} catch (err) { } catch (err) {
wlogger.error('Error in route-ratelimit.js/isInWhitelist(). Returning false by default.') wlogger.error(
'Error in route-ratelimit.js/isInWhitelist(). Returning false by default.'
)
return false return false
} }
} }
+10 -2
View File
@@ -1979,8 +1979,16 @@ class Slp {
try { try {
const utxos = req.body.utxos const utxos = req.body.utxos
// console.log('req: ', req)
console.log(`req._remoteAddress: ${req._remoteAddress}`) console.log(`req._remoteAddress: ${req._remoteAddress}`)
const ip = req._remoteAddress // const ip = req._remoteAddress
const usrObj = {
ip: req._remoteAddress,
jwtToken: req.locals.jwtToken,
proLimit: req.locals.proLimit,
apiLevel: req.locals.apiLevel
}
// Validate inputs // Validate inputs
if (!Array.isArray(utxos)) { if (!Array.isArray(utxos)) {
@@ -2016,7 +2024,7 @@ class Slp {
const theseUtxos = utxos[i].utxos const theseUtxos = utxos[i].utxos
// Get SLP token details. // Get SLP token details.
const details = await _this.bchjs.SLP.Utils.tokenUtxoDetails(theseUtxos, ip) const details = await _this.bchjs.SLP.Utils.tokenUtxoDetails(theseUtxos, usrObj)
// console.log('details: ', details) // console.log('details: ', details)
// Replace the original UTXO data with the hydrated data. // Replace the original UTXO data with the hydrated data.