aboutsummaryrefslogtreecommitdiff
path: root/Jellyfin.Api/Middleware/IpBasedAccessValidationMiddleware.cs
blob: a0ed6c81267b5314ec141ea8b24ea6e60bf8a915 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
using System.Net;
using System.Threading.Tasks;
using System.Web;
using MediaBrowser.Common.Extensions;
using MediaBrowser.Common.Net;
using Microsoft.AspNetCore.Http;
using Microsoft.Extensions.Logging;

namespace Jellyfin.Api.Middleware;

/// <summary>
/// Validates the IP of requests coming from local networks wrt. remote access.
/// </summary>
public class IPBasedAccessValidationMiddleware
{
    private readonly RequestDelegate _next;
    private readonly ILogger<IPBasedAccessValidationMiddleware> _logger;

    /// <summary>
    /// Initializes a new instance of the <see cref="IPBasedAccessValidationMiddleware"/> class.
    /// </summary>
    /// <param name="next">The next delegate in the pipeline.</param>
    /// <param name="logger">The logger to log to.</param>
    public IPBasedAccessValidationMiddleware(RequestDelegate next, ILogger<IPBasedAccessValidationMiddleware> logger)
    {
        _next = next;
        _logger = logger;
    }

    /// <summary>
    /// Executes the middleware action.
    /// </summary>
    /// <param name="httpContext">The current HTTP context.</param>
    /// <param name="networkManager">The network manager.</param>
    /// <returns>The async task.</returns>
    public async Task Invoke(HttpContext httpContext, INetworkManager networkManager)
    {
        if (httpContext.IsLocal())
        {
            // Accessing from the same machine as the server.
            await _next(httpContext).ConfigureAwait(false);
            return;
        }

        var remoteIP = httpContext.GetNormalizedRemoteIP();

        var result = networkManager.ShouldAllowServerAccess(remoteIP);
        if (result != RemoteAccessPolicyResult.Allow)
        {
            // No access from network, respond with 503 instead of 200.
            _logger.LogWarning(
                "Blocking request to {Path} by {RemoteIP} due to IP filtering rule, reason: {Reason}",
                // url-encode to block log injection
                HttpUtility.UrlEncode(httpContext.Request.Path),
                remoteIP,
                result);
            httpContext.Response.StatusCode = StatusCodes.Status503ServiceUnavailable;
            return;
        }

        await _next(httpContext).ConfigureAwait(false);
    }
}