2023-02-08 21:51:58 +00:00
|
|
|
import { get } from "@vercel/edge-config";
|
2022-06-02 16:19:01 +00:00
|
|
|
import { collectEvents } from "next-collect/server";
|
2023-02-16 22:39:57 +00:00
|
|
|
import type { NextMiddleware } from "next/server";
|
|
|
|
import { NextResponse, userAgent } from "next/server";
|
2022-06-02 16:19:01 +00:00
|
|
|
|
2022-08-16 19:55:50 +00:00
|
|
|
import { CONSOLE_URL, WEBAPP_URL, WEBSITE_URL } from "@calcom/lib/constants";
|
2022-08-23 21:34:10 +00:00
|
|
|
import { isIpInBanlist } from "@calcom/lib/getIP";
|
2022-07-28 19:58:26 +00:00
|
|
|
import { extendEventData, nextCollectBasicSettings } from "@calcom/lib/telemetry";
|
2022-06-02 16:19:01 +00:00
|
|
|
|
2022-08-09 09:21:15 +00:00
|
|
|
const middleware: NextMiddleware = async (req) => {
|
|
|
|
const url = req.nextUrl;
|
2023-04-21 15:08:59 +00:00
|
|
|
const requestHeaders = new Headers(req.headers);
|
2022-08-09 09:21:15 +00:00
|
|
|
|
2023-06-14 14:38:34 +00:00
|
|
|
if (isIpInBanlist(req) && url.pathname !== "/api/nope") {
|
|
|
|
// DDOS Prevention: Immediately end request with no response - Avoids a redirect as well initiated by NextAuth on invalid callback
|
|
|
|
req.nextUrl.pathname = "/api/nope";
|
|
|
|
return NextResponse.redirect(req.nextUrl);
|
|
|
|
}
|
|
|
|
|
2023-02-08 21:51:58 +00:00
|
|
|
if (!url.pathname.startsWith("/api")) {
|
|
|
|
//
|
|
|
|
// NOTE: When tRPC hits an error a 500 is returned, when this is received
|
|
|
|
// by the application the user is automatically redirected to /auth/login.
|
|
|
|
//
|
|
|
|
// - For this reason our matchers are sufficient for an app-wide maintenance page.
|
|
|
|
//
|
|
|
|
try {
|
|
|
|
// Check whether the maintenance page should be shown
|
|
|
|
const isInMaintenanceMode = await get<boolean>("isInMaintenanceMode");
|
|
|
|
// If is in maintenance mode, point the url pathname to the maintenance page
|
|
|
|
if (isInMaintenanceMode) {
|
|
|
|
req.nextUrl.pathname = `/maintenance`;
|
|
|
|
return NextResponse.rewrite(req.nextUrl);
|
|
|
|
}
|
|
|
|
} catch (error) {
|
|
|
|
// show the default page if EDGE_CONFIG env var is missing,
|
|
|
|
// but log the error to the console
|
|
|
|
// console.error(error);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-08-23 21:34:10 +00:00
|
|
|
if (["/api/collect-events", "/api/auth"].some((p) => url.pathname.startsWith(p))) {
|
2022-08-16 17:15:13 +00:00
|
|
|
const callbackUrl = url.searchParams.get("callbackUrl");
|
2022-08-16 19:50:09 +00:00
|
|
|
const { isBot } = userAgent(req);
|
2022-08-16 19:55:50 +00:00
|
|
|
|
|
|
|
if (
|
|
|
|
isBot ||
|
2022-08-23 21:34:10 +00:00
|
|
|
(callbackUrl && ![CONSOLE_URL, WEBAPP_URL, WEBSITE_URL].some((u) => callbackUrl.startsWith(u))) ||
|
|
|
|
isIpInBanlist(req)
|
2022-08-16 19:55:50 +00:00
|
|
|
) {
|
2022-08-16 17:15:13 +00:00
|
|
|
// DDOS Prevention: Immediately end request with no response - Avoids a redirect as well initiated by NextAuth on invalid callback
|
2022-08-16 19:59:38 +00:00
|
|
|
req.nextUrl.pathname = "/api/nope";
|
|
|
|
return NextResponse.redirect(req.nextUrl);
|
2022-08-16 17:15:13 +00:00
|
|
|
}
|
|
|
|
}
|
2022-09-22 17:23:43 +00:00
|
|
|
|
2022-10-19 21:25:03 +00:00
|
|
|
// Ensure that embed query param is there in when /embed is added.
|
|
|
|
// query param is the way in which client side code knows that it is in embed mode.
|
|
|
|
if (url.pathname.endsWith("/embed") && typeof url.searchParams.get("embed") !== "string") {
|
|
|
|
url.searchParams.set("embed", "");
|
|
|
|
return NextResponse.redirect(url);
|
|
|
|
}
|
|
|
|
|
2022-09-22 17:23:43 +00:00
|
|
|
// Don't 404 old routing_forms links
|
|
|
|
if (url.pathname.startsWith("/apps/routing_forms")) {
|
|
|
|
url.pathname = url.pathname.replace("/apps/routing_forms", "/apps/routing-forms");
|
|
|
|
return NextResponse.rewrite(url);
|
|
|
|
}
|
|
|
|
|
2023-02-09 01:12:45 +00:00
|
|
|
if (url.pathname.startsWith("/api/trpc/")) {
|
|
|
|
requestHeaders.set("x-cal-timezone", req.headers.get("x-vercel-ip-timezone") ?? "");
|
|
|
|
}
|
|
|
|
|
2023-02-06 22:50:08 +00:00
|
|
|
if (url.pathname.startsWith("/auth/login")) {
|
|
|
|
// Use this header to actually enforce CSP, otherwise it is running in Report Only mode on all pages.
|
2023-04-21 15:08:59 +00:00
|
|
|
requestHeaders.set("x-csp-enforce", "true");
|
2023-02-06 22:50:08 +00:00
|
|
|
}
|
|
|
|
|
2023-04-21 15:08:59 +00:00
|
|
|
return NextResponse.next({
|
|
|
|
request: {
|
|
|
|
headers: requestHeaders,
|
|
|
|
},
|
|
|
|
});
|
2022-08-09 09:21:15 +00:00
|
|
|
};
|
|
|
|
|
2022-11-03 14:51:43 +00:00
|
|
|
export const config = {
|
2023-02-06 22:50:08 +00:00
|
|
|
matcher: [
|
2023-06-14 14:38:34 +00:00
|
|
|
"/:path*",
|
2023-02-06 22:50:08 +00:00
|
|
|
"/api/collect-events/:path*",
|
|
|
|
"/api/auth/:path*",
|
|
|
|
"/apps/routing_forms/:path*",
|
|
|
|
"/:path*/embed",
|
2023-02-09 01:12:45 +00:00
|
|
|
"/api/trpc/:path*",
|
2023-02-06 22:50:08 +00:00
|
|
|
"/auth/login",
|
|
|
|
],
|
2022-11-03 14:51:43 +00:00
|
|
|
};
|
|
|
|
|
2022-06-02 16:19:01 +00:00
|
|
|
export default collectEvents({
|
2022-08-09 09:21:15 +00:00
|
|
|
middleware,
|
2022-06-02 16:19:01 +00:00
|
|
|
...nextCollectBasicSettings,
|
|
|
|
cookieName: "__clnds",
|
|
|
|
extend: extendEventData,
|
|
|
|
});
|