mirror of
https://github.com/Kareadita/Kavita.git
synced 2025-05-31 12:14:44 -04:00
* Fixed bookmarking failing to convert to webp * Brought the ag-swipe/ng-swipe code into Kavita due to being abandoned by developer and angular requirements. * Fixed average reading time per week finally * Cleaned up some extra decimals on time duration pipe * Don't try to update index.html for base url on local. Fixed ag-swipe on prod mode. * Updated a link on theme manager to point to the new github * Range knobs should be primary color on firefox too * Implemented the ability to get thumbnails of pages inside an archive or pdf. * Updated packages and fixed opds-ps 1.2 issue * Fixed lock file * Allow Kavita's Swagger to hit instances with CORS * Added IP/Request logging for Security Audits * Linked up Summary tag from CBL into Kavita. * Redid the migration so SecurityEvent now has UTC date as well. * Split security logging to a separate file * Update to new versions of checkout and setup * Added a PR check on PR body to ensure that it doesn't contain any characters that break our discord hook. * Updating action * optimize regex in action * Fixed an issue where fit to width would cause the actual height of the image to be shown for pagination bars, instead of rendered. * Added some new code in GetPageFromFiles to ensure pages that exceed array map down to last file. * Added comment about robots * Fixed up unit tests for new ReaderService signature * Kavita now cleans up empty reading lists at night * Don't allow nightly cleanup to run if we are running media conversion tasks * Fixed some bugs in typeahead, it should behave much more reliably. * Fix an issue where emulate comic book wasn't extending to the bottom properly * Added support for Series Chapter 001 Volume 001 * Refactor XFrameOptions="SameOrigins" out to allow users to override in appsettings.json. * Added a rate limiter for some endpoints, but it doesn't seem to be triggering --------- Co-authored-by: Robbie Davis <robbie@therobbiedavis.com>
63 lines
1.8 KiB
C#
63 lines
1.8 KiB
C#
using System;
|
|
using System.IO;
|
|
using System.Security.AccessControl;
|
|
using System.Threading.Tasks;
|
|
using API.Data;
|
|
using API.DTOs;
|
|
using API.Entities;
|
|
using API.Logging;
|
|
using API.Services;
|
|
using Microsoft.AspNetCore.Http;
|
|
using Microsoft.Extensions.DependencyInjection;
|
|
using Microsoft.Extensions.Logging;
|
|
using Serilog;
|
|
using Serilog.Core;
|
|
using ILogger = Serilog.ILogger;
|
|
|
|
namespace API.Middleware;
|
|
|
|
public class SecurityEventMiddleware
|
|
{
|
|
private readonly RequestDelegate _next;
|
|
private readonly ILogger _logger;
|
|
|
|
public SecurityEventMiddleware(RequestDelegate next)
|
|
{
|
|
_next = next;
|
|
|
|
_logger = new LoggerConfiguration()
|
|
.MinimumLevel.Debug()
|
|
.WriteTo.File(Path.Join(Directory.GetCurrentDirectory(), "config/logs/", "security.log"), rollingInterval: RollingInterval.Day)
|
|
.CreateLogger();
|
|
}
|
|
|
|
public async Task InvokeAsync(HttpContext context)
|
|
{
|
|
var ipAddress = context.Connection.RemoteIpAddress?.ToString();
|
|
var requestMethod = context.Request.Method;
|
|
var requestPath = context.Request.Path;
|
|
var userAgent = context.Request.Headers["User-Agent"];
|
|
|
|
var securityEvent = new SecurityEvent
|
|
{
|
|
IpAddress = ipAddress,
|
|
RequestMethod = requestMethod,
|
|
RequestPath = requestPath,
|
|
UserAgent = userAgent,
|
|
CreatedAt = DateTime.Now,
|
|
CreatedAtUtc = DateTime.UtcNow,
|
|
};
|
|
|
|
using (var scope = context.RequestServices.CreateScope())
|
|
{
|
|
var dbContext = scope.ServiceProvider.GetRequiredService<DataContext>();
|
|
dbContext.Add(securityEvent);
|
|
await dbContext.SaveChangesAsync();
|
|
_logger.Debug("Request Processed: {@SecurityEvent}", securityEvent);
|
|
}
|
|
|
|
|
|
await _next(context);
|
|
}
|
|
}
|