Release v2.6.9

This commit is contained in:
2026-08-08 14:08:16 +01:00
parent 4e5a1bc393
commit ee3b1b51bf
8 changed files with 90 additions and 53 deletions
+71 -14
View File
@@ -45,6 +45,76 @@ function createPlayerRuntime(options) {
return ip;
}
function firstHeaderValue(value) {
return String(value || '').trim().split(',')[0].trim();
}
function isPrivateOrReservedIp(ip) {
const normalized = normalizeClientIp(ip);
if (!normalized) {
return true;
}
const lower = normalized.toLowerCase();
if (lower === 'localhost' || lower === '::1') {
return true;
}
if (/^10\./.test(lower) || /^192\.168\./.test(lower) || /^127\./.test(lower) || /^169\.254\./.test(lower)) {
return true;
}
if (/^172\.(1[6-9]|2\d|3[0-1])\./.test(lower)) {
return true;
}
if (lower.startsWith('fc') || lower.startsWith('fd') || lower.startsWith('fe80:') || lower.startsWith('::ffff:127.')) {
return true;
}
return false;
}
function pickForwardedIp(candidates) {
const normalizedCandidates = Array.isArray(candidates)
? candidates.map(function (candidate) {
return normalizeClientIp(candidate);
}).filter(Boolean)
: [];
const publicCandidate = normalizedCandidates.find(function (candidate) {
return !isPrivateOrReservedIp(candidate);
});
return publicCandidate || normalizedCandidates[0] || null;
}
function resolveRequestIp(request) {
const forwardedFor = String(request && request.headers && request.headers['x-forwarded-for'] || '').split(',');
const forwardedForIp = pickForwardedIp(forwardedFor);
if (forwardedForIp) {
return forwardedForIp;
}
const realIp = pickForwardedIp([firstHeaderValue(request && request.headers && request.headers['x-real-ip'])]);
if (realIp) {
return realIp;
}
const forwarded = firstHeaderValue(request && request.headers && request.headers.forwarded);
if (forwarded) {
const forwardedMatches = Array.from(forwarded.matchAll(/(?:^|,\s*|;\s*)for=(?:"?\[?)([^"\];,\s]+)/gi)).map(function (match) {
return match[1];
});
const forwardedIp = pickForwardedIp(forwardedMatches);
if (forwardedIp) {
return forwardedIp;
}
}
return normalizeClientIp(request && request.socket && request.socket.remoteAddress);
}
function parseCookies(cookieHeader) {
return String(cookieHeader || '').split(/;\s*/).reduce(function (cookies, pair) {
if (!pair) {
@@ -145,7 +215,6 @@ function createPlayerRuntime(options) {
const clientName = String(connection.clientName || '').trim();
const clientId = String(connection.clientId || '').trim();
const userAgent = String(connection.userAgent || '').trim();
const clientIp = String(connection.clientIp || '').trim();
const viewport = connection.viewport && typeof connection.viewport === 'object'
? connection.viewport
: null;
@@ -161,10 +230,6 @@ function createPlayerRuntime(options) {
labelParts.push(`id ${clientId.slice(-6)}`);
}
if (clientIp) {
labelParts.push(clientIp);
}
if (viewport && Number.isFinite(Number(viewport.width)) && Number.isFinite(Number(viewport.height))) {
labelParts.push(`${Number(viewport.width)}x${Number(viewport.height)}`);
}
@@ -198,8 +263,6 @@ function createPlayerRuntime(options) {
blackout: Boolean(connection.blackout),
currentSlideId: connection.currentSlide && connection.currentSlide.id ? connection.currentSlide.id : null,
currentSlideTitle: connection.currentSlide && connection.currentSlide.title ? connection.currentSlide.title : null,
clientIp: connection.clientIp || null,
remoteAddress: connection.remoteAddress || null,
connectedAt: connection.connectedAt ? connection.connectedAt.toISOString() : null,
lastSeenAt: connection.lastSeenAt ? connection.lastSeenAt.toISOString() : null
};
@@ -431,9 +494,6 @@ function createPlayerRuntime(options) {
return;
}
const remoteAddress = request.socket && request.socket.remoteAddress ? request.socket.remoteAddress : null;
const forwardedFor = normalizeClientIp(String(request.headers['x-forwarded-for'] || '').split(',')[0]);
const normalizedRemoteAddress = normalizeClientIp(remoteAddress);
const connectionId = crypto.randomUUID();
const connection = {
id: connectionId,
@@ -448,9 +508,7 @@ function createPlayerRuntime(options) {
paused: false,
blackout: false,
playerPublicBaseUrl: null,
clientIp: forwardedFor || normalizedRemoteAddress,
remoteAddress: normalizedRemoteAddress,
label: forwardedFor || normalizedRemoteAddress || 'connected client',
label: 'connected client',
connectedAt: new Date(),
lastSeenAt: new Date()
};
@@ -491,7 +549,6 @@ function createPlayerRuntime(options) {
}
connection.paused = Boolean(payload.paused);
connection.blackout = Boolean(payload.blackout);
connection.clientIp = payload.clientIp ? normalizeClientIp(payload.clientIp) || connection.clientIp : connection.clientIp;
connection.currentSlide = payload.currentSlide && typeof payload.currentSlide === 'object' ? {
id: payload.currentSlide.id || null,
title: payload.currentSlide.title || '',