blocked all nextcloud requests in demo mode to stop fake-credential logins tripping brute-force protection
This commit is contained in:
@@ -0,0 +1,28 @@
|
||||
import 'package:http/http.dart' as http;
|
||||
import 'package:http/io_client.dart';
|
||||
|
||||
import '../../model/endpoint_data.dart';
|
||||
import '../errors/network_exception.dart';
|
||||
import 'demo_mode.dart';
|
||||
|
||||
/// Demo sessions carry made-up credentials. Every request they sent to the
|
||||
/// real Nextcloud would count as a failed login there and, in bulk, trip the
|
||||
/// server's brute-force throttle for the whole IP (HTTP 429 for everyone
|
||||
/// behind it). Installed app-wide via [http.runWithClient].
|
||||
class DemoHttpClient extends http.BaseClient {
|
||||
final http.Client _inner = IOClient();
|
||||
|
||||
@override
|
||||
Future<http.StreamedResponse> send(http.BaseRequest request) {
|
||||
if (DemoMode.active && isNextcloudHost(request.url)) {
|
||||
return Future.error(NetworkException.demoBlocked(request.url));
|
||||
}
|
||||
return _inner.send(request);
|
||||
}
|
||||
|
||||
@override
|
||||
void close() => _inner.close();
|
||||
|
||||
static bool isNextcloudHost(Uri url) =>
|
||||
url.host == EndpointData().nextcloud().domain;
|
||||
}
|
||||
@@ -13,4 +13,10 @@ class NetworkException extends AppException {
|
||||
'Der Server hat zu lange gebraucht. Bitte versuche es erneut.',
|
||||
technicalDetails: technicalDetails,
|
||||
);
|
||||
|
||||
/// A request a demo session must never send (see `DemoHttpClient`).
|
||||
factory NetworkException.demoBlocked(Uri url) => NetworkException(
|
||||
userMessage: 'Im Demo-Modus nicht verfügbar.',
|
||||
technicalDetails: 'demo mode blocked $url',
|
||||
);
|
||||
}
|
||||
|
||||
@@ -3,6 +3,8 @@ import 'package:nextcloud/nextcloud.dart';
|
||||
import '../../../model/endpoint_data.dart';
|
||||
import '../../../session/session_manager.dart';
|
||||
import '../../api_response.dart';
|
||||
import '../../demo/demo_mode.dart';
|
||||
import '../../errors/network_exception.dart';
|
||||
|
||||
abstract class WebdavApi<T> {
|
||||
T genericParams;
|
||||
@@ -18,6 +20,14 @@ abstract class WebdavApi<T> {
|
||||
/// changes (app password minted/renewed, account switch) so it never keeps
|
||||
/// authenticating with stale credentials.
|
||||
static Future<WebDavClient> get webdav {
|
||||
// The WebDAV client talks dart:io directly, past DemoHttpClient.
|
||||
if (DemoMode.active) {
|
||||
return Future.error(
|
||||
NetworkException.demoBlocked(
|
||||
Uri.parse(EndpointData().nextcloud().origin()),
|
||||
),
|
||||
);
|
||||
}
|
||||
// Keyed by user too: two accounts may share a password (no app password
|
||||
// minted), and the client would keep the previous login name.
|
||||
final nextcloud = SessionManager().requireNextcloud();
|
||||
|
||||
Reference in New Issue
Block a user