fix: block direct /admin access when custom adminPath is configured
This commit is contained in:
@@ -71,6 +71,22 @@
|
|||||||
"symbol": "mfcktn",
|
"symbol": "mfcktn",
|
||||||
"group": "dickloads",
|
"group": "dickloads",
|
||||||
"toBase": 170.2399999998
|
"toBase": 170.2399999998
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "shitload",
|
||||||
|
"label": "Shitload",
|
||||||
|
"labelPlural": "Shitloads",
|
||||||
|
"symbol": "shtld",
|
||||||
|
"group": "dickloads",
|
||||||
|
"toBase": 12.6666666667
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "shit-ton",
|
||||||
|
"label": "Shit ton",
|
||||||
|
"labelPlural": "Shit tons",
|
||||||
|
"symbol": "shttn",
|
||||||
|
"group": "dickloads",
|
||||||
|
"toBase": 25.3333333333
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"groups": [
|
"groups": [
|
||||||
|
|||||||
18
src/hooks.ts
18
src/hooks.ts
@@ -6,22 +6,32 @@ import type { Reroute } from '@sveltejs/kit';
|
|||||||
let adminPath = 'admin';
|
let adminPath = 'admin';
|
||||||
try {
|
try {
|
||||||
const config = JSON.parse(fs.readFileSync(path.resolve('data', 'config.json'), 'utf8'));
|
const config = JSON.parse(fs.readFileSync(path.resolve('data', 'config.json'), 'utf8'));
|
||||||
adminPath = (config.adminPath ?? 'admin').replace(/^\/|\/$/g, '');
|
adminPath = (config.adminPath ?? 'admin').replace(/^\/|\/$/g, '') || 'admin';
|
||||||
} catch {
|
} catch {
|
||||||
// config.json missing or unreadable — fall back to 'admin'
|
// config.json missing or unreadable — fall back to 'admin'
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export { adminPath };
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Rewrites /<adminPath>/... to /admin/... before SvelteKit resolves the route.
|
* Rewrites /<adminPath>/... to /admin/... before SvelteKit resolves the route.
|
||||||
* No-op when adminPath is 'admin' (the default).
|
* When adminPath is not 'admin', direct access to /admin is rewritten to /404
|
||||||
|
* so attackers cannot enumerate the admin URL.
|
||||||
*/
|
*/
|
||||||
export const reroute: Reroute = ({ url }) => {
|
export const reroute: Reroute = ({ url }) => {
|
||||||
if (adminPath === 'admin') return url.pathname;
|
|
||||||
|
|
||||||
const prefix = `/${adminPath}`;
|
const prefix = `/${adminPath}`;
|
||||||
|
|
||||||
|
// Public path → internal /admin
|
||||||
if (url.pathname === prefix || url.pathname.startsWith(prefix + '/')) {
|
if (url.pathname === prefix || url.pathname.startsWith(prefix + '/')) {
|
||||||
return '/admin' + url.pathname.slice(prefix.length);
|
return '/admin' + url.pathname.slice(prefix.length);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Block direct /admin access when a custom path is configured
|
||||||
|
if (adminPath !== 'admin') {
|
||||||
|
if (url.pathname === '/admin' || url.pathname.startsWith('/admin/')) {
|
||||||
|
return '/404';
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
return url.pathname;
|
return url.pathname;
|
||||||
};
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user