index.js 7.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269
  1. const fs = require('fs');
  2. const https = require('https');
  3. const seedrandom = require('seedrandom');
  4. const express = require('express');
  5. const app = express();
  6. const options = {
  7. key: fs.readFileSync("ssl/private.key"),
  8. cert: fs.readFileSync("ssl/certificate.crt"),
  9. ca: [fs.readFileSync('ssl/ca_bundle.crt')]
  10. };
  11. const server = https.createServer(options, app);
  12. const io = require('socket.io')(server);
  13. var port = 443;
  14. var admins = {}
  15. fs.readFile("config/admins.json", "utf8", (err, data) => {
  16. if (!err && data) {
  17. admins = JSON.parse(data);
  18. }
  19. })
  20. var users = [];
  21. var bannedIps = [];
  22. fs.readFile("config/ban.json", "utf8", (err, data) => {
  23. if (!err && data) {
  24. bannedIps = JSON.parse(data);
  25. }
  26. })
  27. var randomColors = [
  28. '#c42020',
  29. '#de801e',
  30. '#f6c60b',
  31. '#19ce19',
  32. '#129696',
  33. '#2c53e3',
  34. '#6f23e3',
  35. '#883f88',
  36. ];
  37. var historySize = 50;
  38. var history = [];
  39. fs.readFile("config/config.json", "utf8", (err, data) => {
  40. if (!err) {
  41. const config = JSON.parse(data);
  42. if (config.port) port = config.port;
  43. if (config.historySize) historySize = config.historySize;
  44. if (config.randomColors) randomColors = config.randomColors;
  45. }
  46. })
  47. app.use(express.static(__dirname + '/www'));
  48. app.use('/node_modules', express.static(__dirname + '/node_modules'));
  49. app.get('/img/ava/:username', (req, res) => {
  50. let username = req.params.username; //.toLowerCase();
  51. username = username.normalize('NFD');
  52. username = username.replace(/[\u0300-\u036f]/g, '');
  53. username = username.replace(/ß/g, 'ss');
  54. username = username.replace(/[^\x00-\x7F]/g, '');
  55. const filePath = __dirname + '/www/img/ava/' + username + '.png';
  56. var file = '';
  57. if (fs.existsSync(filePath)) {
  58. file = filePath;
  59. } else {
  60. const files = fs.readdirSync(__dirname + '/www/img/ava/random/').filter((f) => f.toLowerCase().endsWith('.png'));
  61. const seededRandom = seedrandom(username)();
  62. const randomFile = files[Math.floor(seededRandom * files.length)];
  63. file = __dirname + '/www/img/ava/random/' + randomFile;
  64. }
  65. res.sendFile(file);
  66. });
  67. io.on('connection', (socket) => {
  68. const ip = socket.handshake.address;
  69. log('- New user joined the server:', ip);
  70. for (const bannedItem of bannedIps) {
  71. if (bannedItem.ip == ip) {
  72. log('- User blacklisted, kicking:', ip)
  73. socket.emit('serverKick');
  74. socket.disconnect();
  75. break;
  76. }
  77. }
  78. socket.emit('serverHandshake');
  79. const user = {ip: ip, socket: socket};
  80. users.push(user);
  81. socket.on('login', (username, password) => {
  82. if (!username) {
  83. socket.emit('usernameInvalid');
  84. return;
  85. }
  86. for (let user of users) {
  87. if (user.name == username) {
  88. socket.emit('usernameTaken');
  89. return;
  90. }
  91. }
  92. if (admins && admins[username]) {
  93. if (!password) {
  94. log('- Attempted login as admin without password.', username, '(' + ip + ')');
  95. socket.emit('passwordRequired');
  96. return;
  97. } else if (admins[username] != password) {
  98. log('- Attempted login as admin with wrong password.', username, '(' + ip + ')');
  99. socket.emit('passwordWrong');
  100. return;
  101. }
  102. log('- Admin "' + username + '" login successful');
  103. user.admin = true;
  104. socket.on('requestKick', (userToBeKicked) => {
  105. log('- Admin "' + username + '" requested kick of User "' + userToBeKicked.name + '"');
  106. kickUser(userToBeKicked);
  107. });
  108. socket.on('requestLiftBan', (ip) => {
  109. log('- Admin "' + username + '" requested to lift ban for ip "' + ip + '"');
  110. liftBan(ip);
  111. });
  112. }
  113. log('- New user logged in:', username, '(' + ip + ')');
  114. user.name = username;
  115. user.color = getRandomColor(username);
  116. socket.emit('serverLogin', getCleanUser(user), history);
  117. io.emit('userJoined', username);
  118. updateUsers();
  119. updateBanned();
  120. socket.on('disconnect', () => {
  121. log('- User joined the server:', ip);
  122. users = users.filter((listUser) => listUser !== user);
  123. io.emit('userLeft', username);
  124. updateUsers();
  125. });
  126. socket.on('message', (msg) => {
  127. if (msg) {
  128. if (!user.admin) {
  129. const regex = /(&nbsp;|<([^>]+)>)/ig;
  130. msg = msg.replace(regex, "");
  131. }
  132. msg = msg.replace(/(?<!(href|src)=")(\b[\w]+:\/\/[\w-?&;#~=\.\/\@%]+[\w\/])/g, (url) => {
  133. try {
  134. const urlObj = new URL(url);
  135. const urlWithoutParams = urlObj.origin + urlObj.pathname;
  136. if (urlWithoutParams.toLowerCase().endsWith('.jpg')
  137. || urlWithoutParams.toLowerCase().endsWith('.gif')
  138. || urlWithoutParams.toLowerCase().endsWith('.png')) {
  139. return '<a href="' + url + '"><img src="' + url + '" alt="" /></a>';
  140. }
  141. } catch (e) {}
  142. var faviconUrl;
  143. try {
  144. faviconUrl = new URL(url).origin + '/favicon.ico';
  145. } catch (e) {
  146. log('Error getting favicon for "' + url + '"');
  147. }
  148. return '<a href="' + url + '"><img class="favicon" src="' + faviconUrl + '" alt="" />' + url + '</a>';
  149. });
  150. for (const u of users) {
  151. while (msg.indexOf('@' + u.name) > -1) {
  152. msg = msg.replace('@' + u.name, '<span class="mention" style="color: ' + u.color + '">' + u.name + '</span>');
  153. }
  154. }
  155. log(user.name + ':', msg, '(' + user.ip + ')');
  156. if (history.length >= historySize) {
  157. history = history.slice(1);
  158. }
  159. history.push({msg: msg, user: getCleanUser(user), timestamp: Date.now()});
  160. io.emit('message', msg, getCleanUser(user), Date.now());
  161. }
  162. });
  163. });
  164. });
  165. function updateUsers() {
  166. io.emit('usersUpdated', users.filter((user) => user.name != null).map(getCleanUser));
  167. }
  168. function getCleanUser(user) {
  169. return {
  170. name: user.name,
  171. admin: user.admin,
  172. color: user.color
  173. }
  174. }
  175. function kickUser(user) {
  176. let ip;
  177. for (const exUser of users) {
  178. if (exUser.name == user.name) {
  179. ip = exUser.ip;
  180. break;
  181. }
  182. }
  183. bannedIps.push({ip: ip, user: user});
  184. updateBanned();
  185. for (const exUser of users) {
  186. if (exUser.ip == ip) {
  187. exUser.socket.emit('serverKick');
  188. exUser.socket.disconnect();
  189. }
  190. }
  191. }
  192. function liftBan(ip) {
  193. bannedIps = bannedIps.filter((listItem) => listItem.ip != ip);
  194. updateBanned();
  195. }
  196. function updateBanned() {
  197. fs.writeFile('config/ban.json', JSON.stringify(bannedIps), (e) => {
  198. });
  199. io.emit('bannedUpdated', bannedIps);
  200. }
  201. function getRandomColor(seed) {
  202. return randomColors[Math.floor(seedrandom(seed)() * randomColors.length)];
  203. }
  204. function log(...inputs) {
  205. var output = '[' + new Date().toISOString().substr(0, 19).replace('T', ', ') + '] ';
  206. for (const i of inputs) {
  207. output += i + ' ';
  208. }
  209. console.log(output);
  210. fs.appendFile('log.txt', '' + output + '\n', (e) => {
  211. });
  212. }
  213. server.listen(port, () => {
  214. log('- Server up and running at port ' + port);
  215. });