Made captcha verification optional

This commit is contained in:
Jonathan Barrow
2022-10-09 14:23:34 -04:00
parent ce46c51c96
commit 8f5dcb2f9a
2 changed files with 35 additions and 17 deletions

View File

@@ -44,6 +44,7 @@ let config = {};
* @typedef {Object} DisabledFeatures
* @property {boolean} redis true if redis is disabled
* @property {boolean} email true if email sending is disabled
* @property {boolean} captcha true if captcha verification is disabled
*/
/**
@@ -51,7 +52,8 @@ let config = {};
*/
const disabledFeatures = {
redis: false,
email: false
email: false,
captcha: false
};
const requiredFields = [
@@ -60,7 +62,6 @@ const requiredFields = [
['mongoose.database', 'PN_ACT_CONFIG_MONGO_DB_NAME'],
['aws.spaces.key', 'PN_ACT_CONFIG_S3_ACCESS_KEY'],
['aws.spaces.secret', 'PN_ACT_CONFIG_S3_ACCESS_SECRET'],
['hcaptcha.secret', 'PN_ACT_CONFIG_HCAPTCHA_SECRET'],
['cdn_base', 'PN_ACT_CONFIG_CDN_BASE'],
['website_base', 'PN_ACT_CONFIG_WEBSITE_BASE'],
];
@@ -252,6 +253,21 @@ function configure() {
}
}
const captchaSecretConfigValue = get(config, 'hcaptcha.secret');
const captchaSecretEnvValue = get(process.env, 'PN_ACT_CONFIG_HCAPTCHA_SECRET');
if (!captchaSecretConfigValue || captchaSecretConfigValue.trim() === '') {
if (!captchaSecretEnvValue || captchaSecretEnvValue.trim() === '') {
logger.warn('Failed to find captcha secret config. Disabling feature');
disabledFeatures.email = true;
} else {
logger.info('hcaptcha.secret not found in config, using environment variable PN_ACT_CONFIG_HCAPTCHA_SECRET');
set(config, 'hcaptcha.secret', emailFromEnvValue);
}
}
module.exports.config = config;
}

View File

@@ -12,7 +12,7 @@ const database = require('../../../../database');
const cache = require('../../../../cache');
const util = require('../../../../util');
const logger = require('../../../../../logger');
const { config } = require('../../../../config-manager');
const { config, disabledFeatures } = require('../../../../config-manager');
const PNID_VALID_CHARACTERS_REGEX = /^[\w\-\.]*$/gm;
const PNID_PUNCTUATION_START_REGEX = /^[\_\-\.]/gm;
@@ -42,22 +42,24 @@ router.post('/', async (request, response) => {
const passwordConfirm = body.password_confirm?.trim();
const hCaptchaResponse = body.hCaptchaResponse?.trim();
if (!hCaptchaResponse || hCaptchaResponse === '') {
return response.status(400).json({
app: 'api',
status: 400,
error: 'Must fill in captcha'
});
}
if (!disabledFeatures.captcha) {
if (!hCaptchaResponse || hCaptchaResponse === '') {
return response.status(400).json({
app: 'api',
status: 400,
error: 'Must fill in captcha'
});
}
const captchaVerify = await hcaptcha.verify(config.hcaptcha.secret, hCaptchaResponse);
const captchaVerify = await hcaptcha.verify(config.hcaptcha.secret, hCaptchaResponse);
if (!captchaVerify.success) {
return response.status(400).json({
app: 'api',
status: 400,
error: 'Captcha verification failed'
});
if (!captchaVerify.success) {
return response.status(400).json({
app: 'api',
status: 400,
error: 'Captcha verification failed'
});
}
}
if (!email || email === '') {