-
Notifications
You must be signed in to change notification settings - Fork 3
feat: anti-bot filtering with reCAPTCHA v3 #137
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Draft
privilegemendes
wants to merge
26
commits into
main
Choose a base branch
from
feature/recaptcha
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Draft
Changes from all commits
Commits
Show all changes
26 commits
Select commit
Hold shift + click to select a range
43239e9
added recaptcha detection text
732ea84
added home button to menu dialog for ease of navigation
c7e3646
added recaptcha provider, hooks and utils
86b76c0
added types, service hooks and recaptcha server functions
f0a459d
pnp files
ac0d485
Merge remote-tracking branch 'origin/main' into feature/recaptcha
c9b93e2
pnp files
6013661
fix: minor yarn build issue
b59bc29
updated env file
9cf860f
added yarn cache and hide recaptcha logo
e8c8b15
Revert "pnp files"
1273af6
added zod based types for recaptcha response
4e7929d
moved and renamed files
e8b9d8e
code refactor based on review comments
ff83345
added recaptcha secret to deployment staging
d3d9ce4
code refactor based on comment reviews
b63e4a0
refactor: removed recaptcha provider
738a8bf
refactor: updated recaptcha types and removed eslint ignores
d404c53
refactor: updated recaptcha to use a hook instead of a context
575e954
refactor: removed grecaptcha types
5b58500
refactor: yarn.lock
58b4746
Merge remote-tracking branch 'origin/main' into feature/recaptcha
7c642c2
updated based on review
0a35010
updated based on review comments
29ff6e0
updated based on review comments
e9d1605
updated based on review comments
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Large diffs are not rendered by default.
Oops, something went wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1 @@ | ||
| export * from "./home.jsx"; |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,3 +1,4 @@ | ||
| export * from "./lobby.js"; | ||
| export * from "./match.js"; | ||
| export * from "./user.js"; | ||
| export * from "./recaptcha.js"; |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,55 @@ | ||
| import { createTRPCRouter, protectedProcedure } from "../trpc.js"; | ||
| import { TRPCError } from "@trpc/server"; | ||
| import { z } from "zod"; | ||
| import { env } from "~/env.mjs"; | ||
| import { type RecaptchaResponse } from "~/types/recaptcha"; | ||
|
|
||
| const SCORE_THRESHOLD = 0.5; | ||
| export const recaptchaRouter = createTRPCRouter({ | ||
| verify: protectedProcedure | ||
| .input(z.object({ captchaToken: z.string() })) | ||
| .mutation(async ({ input }) => { | ||
| const { captchaToken } = input; | ||
|
|
||
| // Check if it's (development mode) | ||
| if (env.NODE_ENV === "development") { | ||
| return false; | ||
| } | ||
|
|
||
| try { | ||
| // Verify the Google reCaptcha token v3 | ||
| const response = await fetch( | ||
| "https://www.google.com/recaptcha/api/siteverify", | ||
| { | ||
| method: "POST", | ||
| headers: { | ||
| "Content-Type": | ||
| "application/x-www-form-urlencoded; charset=utf-8", | ||
| }, | ||
| body: `secret=${env.RECAPTCHA_SECRET_KEY}&response=${captchaToken}`, | ||
| }, | ||
| ); | ||
|
|
||
| /** | ||
| * The structure of response from the verify API is | ||
| * { | ||
| * "success": true | false, // whether this request was a valid reCAPTCHA token for your site | ||
| * "challenge_ts": timestamp, // timestamp of the challenge load (ISO format yyyy-MM-dd'T'HH:mm:ssZZ) | ||
| * "hostname": string, // the hostname of the site where the reCAPTCHA was solved | ||
| * "error-codes": [...] // optional | ||
| } | ||
| */ | ||
| const json = (await response.json()) as RecaptchaResponse; | ||
|
|
||
| if (!json.success) { | ||
| console.log(`Recaptcha token is not valid`); | ||
| throw new TRPCError({ code: "BAD_REQUEST" }); | ||
|
privilegemendes marked this conversation as resolved.
|
||
| } | ||
|
|
||
| // If the score is below < SCORE_THRESHOLD, return true | ||
| return json.score < SCORE_THRESHOLD; | ||
| } catch (error) { | ||
| console.log(`Recaptcha cannot be verified`); | ||
| } | ||
| }), | ||
| }); | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1 +1,2 @@ | ||
| export * from "./profanity-filter/index.js"; | ||
| export * from "./recaptcha/index.js"; |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1 @@ | ||
| export * from "./recaptcha.js"; |
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.