Add back checkBlacklist middleware

This commit is contained in:
MICHAEL JACKSON
2017-08-16 23:03:28 -07:00
parent 1173f91091
commit b9c6c0fc61
3 changed files with 28 additions and 7 deletions

View File

@ -0,0 +1,12 @@
function checkBlacklist(blacklist) {
return function (req, res, next) {
// Do not allow packages that have been blacklisted.
if (blacklist.includes(req.packageName)) {
res.status(403).type('text').send(`Package "${req.packageName}" is blacklisted`)
} else {
next()
}
}
}
module.exports = checkBlacklist

View File

@ -1,5 +1,4 @@
const validateNPMPackageName = require('validate-npm-package-name')
const PackageBlacklist = require('../PackageBlacklist').blacklist
const PackageURL = require('../PackageURL')
/**
@ -17,10 +16,6 @@ function parsePackageURL(req, res, next) {
if (nameErrors)
return res.status(403).type('text').send(`Invalid package name: ${url.packageName} (${nameErrors.join(', ')})`)
// Do not allow packages that have been blacklisted.
if (PackageBlacklist.includes(req.packageName))
return res.status(403).type('text').send(`Package ${req.packageName} is blacklisted`)
req.packageName = url.packageName
req.packageVersion = url.packageVersion
req.packageSpec = `${req.packageName}@${req.packageVersion}`