mirror of
https://github.com/wassname/talk.git
synced 2026-07-20 12:40:47 +08:00
use wordlist service
This commit is contained in:
@@ -12,3 +12,4 @@ dump.rdb
|
||||
gaba.cfg
|
||||
.idea/
|
||||
coverage/
|
||||
yarn.lock
|
||||
|
||||
@@ -29,7 +29,12 @@ const handleResp = res => {
|
||||
throw new Error('Not Authorized to make this request');
|
||||
} else if (res.status > 399) {
|
||||
return res.json().then(err => {
|
||||
throw new Error(err.message || res.status);
|
||||
console.log(err);
|
||||
let message = err.message || res.status;
|
||||
if (err.error && err.error.translation_key) {
|
||||
message = err.error.translation_key;
|
||||
}
|
||||
throw new Error(message);
|
||||
});
|
||||
} else if (res.status === 204) {
|
||||
return res.text();
|
||||
|
||||
@@ -1,444 +0,0 @@
|
||||
[
|
||||
"4r5e",
|
||||
"5h1t",
|
||||
"5hit",
|
||||
"a55",
|
||||
"anal",
|
||||
"anus",
|
||||
"ar5e",
|
||||
"arrse",
|
||||
"arse",
|
||||
"ass",
|
||||
"ass-fucker",
|
||||
"asses",
|
||||
"assfucker",
|
||||
"assfukka",
|
||||
"asshole",
|
||||
"assholes",
|
||||
"asswhole",
|
||||
"a_s_s",
|
||||
"b!tch",
|
||||
"b00bs",
|
||||
"b17ch",
|
||||
"b1tch",
|
||||
"ballbag",
|
||||
"balls",
|
||||
"ballsack",
|
||||
"bastard",
|
||||
"beastial",
|
||||
"beastiality",
|
||||
"bellend",
|
||||
"bestial",
|
||||
"bestiality",
|
||||
"bi+ch",
|
||||
"biatch",
|
||||
"bitch",
|
||||
"bitcher",
|
||||
"bitchers",
|
||||
"bitches",
|
||||
"bitchin",
|
||||
"bitching",
|
||||
"blow job",
|
||||
"blowjob",
|
||||
"blowjobs",
|
||||
"boiolas",
|
||||
"bollock",
|
||||
"bollok",
|
||||
"boner",
|
||||
"boob",
|
||||
"boobs",
|
||||
"booobs",
|
||||
"boooobs",
|
||||
"booooobs",
|
||||
"booooooobs",
|
||||
"breasts",
|
||||
"buceta",
|
||||
"bugger",
|
||||
"bum",
|
||||
"bunny fucker",
|
||||
"butt",
|
||||
"butthole",
|
||||
"buttmuch",
|
||||
"buttplug",
|
||||
"c0ck",
|
||||
"c0cksucker",
|
||||
"carpet muncher",
|
||||
"cawk",
|
||||
"chink",
|
||||
"cipa",
|
||||
"cl1t",
|
||||
"clit",
|
||||
"clitoris",
|
||||
"clits",
|
||||
"cnut",
|
||||
"cock",
|
||||
"cock-sucker",
|
||||
"cockface",
|
||||
"cockhead",
|
||||
"cockmunch",
|
||||
"cockmuncher",
|
||||
"cocks",
|
||||
"cocksuck",
|
||||
"cocksucked",
|
||||
"cocksucker",
|
||||
"cocksucking",
|
||||
"cocksucks",
|
||||
"cocksuka",
|
||||
"cocksukka",
|
||||
"cok",
|
||||
"cokmuncher",
|
||||
"coksucka",
|
||||
"coon",
|
||||
"cox",
|
||||
"crap",
|
||||
"cum",
|
||||
"cummer",
|
||||
"cumming",
|
||||
"cums",
|
||||
"cumshot",
|
||||
"cunilingus",
|
||||
"cunillingus",
|
||||
"cunnilingus",
|
||||
"cunt",
|
||||
"cuntlick",
|
||||
"cuntlicker",
|
||||
"cuntlicking",
|
||||
"cunts",
|
||||
"cyalis",
|
||||
"cyberfuc",
|
||||
"cyberfuck",
|
||||
"cyberfucked",
|
||||
"cyberfucker",
|
||||
"cyberfuckers",
|
||||
"cyberfucking",
|
||||
"d1ck",
|
||||
"dick",
|
||||
"dickhead",
|
||||
"dildo",
|
||||
"dildos",
|
||||
"dink",
|
||||
"dinks",
|
||||
"dirsa",
|
||||
"dlck",
|
||||
"dog-fucker",
|
||||
"doggin",
|
||||
"dogging",
|
||||
"donkeyribber",
|
||||
"doosh",
|
||||
"duche",
|
||||
"dyke",
|
||||
"ejaculate",
|
||||
"ejaculated",
|
||||
"ejaculates",
|
||||
"ejaculating",
|
||||
"ejaculatings",
|
||||
"ejaculation",
|
||||
"ejakulate",
|
||||
"f u c k",
|
||||
"f u c k e r",
|
||||
"f4nny",
|
||||
"fag",
|
||||
"fagging",
|
||||
"faggitt",
|
||||
"faggot",
|
||||
"faggs",
|
||||
"fagot",
|
||||
"fagots",
|
||||
"fags",
|
||||
"fanny",
|
||||
"fannyflaps",
|
||||
"fannyfucker",
|
||||
"fanyy",
|
||||
"fatass",
|
||||
"fcuk",
|
||||
"fcuker",
|
||||
"fcuking",
|
||||
"feck",
|
||||
"fecker",
|
||||
"felching",
|
||||
"fellate",
|
||||
"fellatio",
|
||||
"fingerfuck",
|
||||
"fingerfucked",
|
||||
"fingerfucker",
|
||||
"fingerfuckers",
|
||||
"fingerfucking",
|
||||
"fingerfucks",
|
||||
"fistfuck",
|
||||
"fistfucked",
|
||||
"fistfucker",
|
||||
"fistfuckers",
|
||||
"fistfucking",
|
||||
"fistfuckings",
|
||||
"fistfucks",
|
||||
"flange",
|
||||
"fook",
|
||||
"fooker",
|
||||
"fuck",
|
||||
"fucka",
|
||||
"fucked",
|
||||
"fucker",
|
||||
"fuckers",
|
||||
"fuckhead",
|
||||
"fuckheads",
|
||||
"fuckin",
|
||||
"fucking",
|
||||
"fuckings",
|
||||
"fuckingshitmotherfucker",
|
||||
"fuckme",
|
||||
"fucks",
|
||||
"fuckwhit",
|
||||
"fuckwit",
|
||||
"fudge packer",
|
||||
"fudgepacker",
|
||||
"fuk",
|
||||
"fuker",
|
||||
"fukker",
|
||||
"fukkin",
|
||||
"fuks",
|
||||
"fukwhit",
|
||||
"fukwit",
|
||||
"fux",
|
||||
"fux0r",
|
||||
"f_u_c_k",
|
||||
"gangbang",
|
||||
"gangbanged",
|
||||
"gangbangs",
|
||||
"gaylord",
|
||||
"gaysex",
|
||||
"goatse",
|
||||
"hardcoresex",
|
||||
"heshe",
|
||||
"hoar",
|
||||
"hoare",
|
||||
"hoer",
|
||||
"homo",
|
||||
"hore",
|
||||
"horniest",
|
||||
"horny",
|
||||
"hotsex",
|
||||
"jack-off",
|
||||
"jackoff",
|
||||
"jap",
|
||||
"jerk-off",
|
||||
"jism",
|
||||
"jiz",
|
||||
"jizm",
|
||||
"jizz",
|
||||
"kawk",
|
||||
"knob",
|
||||
"knobead",
|
||||
"knobed",
|
||||
"knobend",
|
||||
"knobhead",
|
||||
"knobjocky",
|
||||
"knobjokey",
|
||||
"kock",
|
||||
"kondum",
|
||||
"kondums",
|
||||
"kum",
|
||||
"kummer",
|
||||
"kumming",
|
||||
"kums",
|
||||
"kunilingus",
|
||||
"l3i+ch",
|
||||
"l3itch",
|
||||
"labia",
|
||||
"lmfao",
|
||||
"lust",
|
||||
"lusting",
|
||||
"m0f0",
|
||||
"m0fo",
|
||||
"m45terbate",
|
||||
"ma5terb8",
|
||||
"ma5terbate",
|
||||
"masochist",
|
||||
"master-bate",
|
||||
"masterb8",
|
||||
"masterbat*",
|
||||
"masterbat3",
|
||||
"masterbate",
|
||||
"masterbation",
|
||||
"masterbations",
|
||||
"masturbate",
|
||||
"mo-fo",
|
||||
"mof0",
|
||||
"mofo",
|
||||
"mothafuck",
|
||||
"mothafucka",
|
||||
"mothafuckas",
|
||||
"mothafuckaz",
|
||||
"mothafucked",
|
||||
"mothafucker",
|
||||
"mothafuckers",
|
||||
"mothafuckin",
|
||||
"mothafucking",
|
||||
"mothafuckings",
|
||||
"mothafucks",
|
||||
"mother fucker",
|
||||
"motherfuck",
|
||||
"motherfucked",
|
||||
"motherfucker",
|
||||
"motherfuckers",
|
||||
"motherfuckin",
|
||||
"motherfucking",
|
||||
"motherfuckings",
|
||||
"motherfuckka",
|
||||
"motherfucks",
|
||||
"muff",
|
||||
"mutha",
|
||||
"muthafecker",
|
||||
"muthafuckker",
|
||||
"muther",
|
||||
"mutherfucker",
|
||||
"n1gga",
|
||||
"n1gger",
|
||||
"nazi",
|
||||
"nigg3r",
|
||||
"nigg4h",
|
||||
"nigga",
|
||||
"niggah",
|
||||
"niggas",
|
||||
"niggaz",
|
||||
"nigger",
|
||||
"niggers",
|
||||
"nob",
|
||||
"nob jokey",
|
||||
"nobhead",
|
||||
"nobjocky",
|
||||
"nobjokey",
|
||||
"numbnuts",
|
||||
"nutsack",
|
||||
"orgasim",
|
||||
"orgasims",
|
||||
"orgasm",
|
||||
"orgasms",
|
||||
"p0rn",
|
||||
"pecker",
|
||||
"penis",
|
||||
"penisfucker",
|
||||
"phonesex",
|
||||
"phuck",
|
||||
"phuk",
|
||||
"phuked",
|
||||
"phuking",
|
||||
"phukked",
|
||||
"phukking",
|
||||
"phuks",
|
||||
"phuq",
|
||||
"pigfucker",
|
||||
"pimpis",
|
||||
"piss",
|
||||
"pissed",
|
||||
"pisser",
|
||||
"pissers",
|
||||
"pisses",
|
||||
"pissflaps",
|
||||
"pissin",
|
||||
"pissing",
|
||||
"pissoff",
|
||||
"poop",
|
||||
"porn",
|
||||
"porno",
|
||||
"pornography",
|
||||
"pornos",
|
||||
"prick",
|
||||
"pricks",
|
||||
"pron",
|
||||
"pube",
|
||||
"pusse",
|
||||
"pussi",
|
||||
"pussies",
|
||||
"pussy",
|
||||
"pussys",
|
||||
"rectum",
|
||||
"retard",
|
||||
"rimjaw",
|
||||
"rimming",
|
||||
"s hit",
|
||||
"s.o.b.",
|
||||
"sadist",
|
||||
"schlong",
|
||||
"screwing",
|
||||
"scroat",
|
||||
"scrote",
|
||||
"scrotum",
|
||||
"semen",
|
||||
"sex",
|
||||
"sh!+",
|
||||
"sh!t",
|
||||
"sh1t",
|
||||
"shag",
|
||||
"shagger",
|
||||
"shaggin",
|
||||
"shagging",
|
||||
"shemale",
|
||||
"shi+",
|
||||
"shit",
|
||||
"shitdick",
|
||||
"shite",
|
||||
"shited",
|
||||
"shitey",
|
||||
"shitfuck",
|
||||
"shitfull",
|
||||
"shithead",
|
||||
"shiting",
|
||||
"shitings",
|
||||
"shits",
|
||||
"shitted",
|
||||
"shitter",
|
||||
"shitters",
|
||||
"shitting",
|
||||
"shittings",
|
||||
"shitty",
|
||||
"skank",
|
||||
"slut",
|
||||
"sluts",
|
||||
"smegma",
|
||||
"smut",
|
||||
"snatch",
|
||||
"son-of-a-bitch",
|
||||
"spac",
|
||||
"spunk",
|
||||
"s_h_i_t",
|
||||
"t1tt1e5",
|
||||
"t1tties",
|
||||
"teets",
|
||||
"teez",
|
||||
"testical",
|
||||
"testicle",
|
||||
"tit",
|
||||
"titfuck",
|
||||
"tits",
|
||||
"titt",
|
||||
"tittie5",
|
||||
"tittiefucker",
|
||||
"titties",
|
||||
"tittyfuck",
|
||||
"tittywank",
|
||||
"titwank",
|
||||
"tosser",
|
||||
"turd",
|
||||
"tw4t",
|
||||
"twat",
|
||||
"twathead",
|
||||
"twatty",
|
||||
"twunt",
|
||||
"twunter",
|
||||
"v14gra",
|
||||
"v1gra",
|
||||
"vagina",
|
||||
"viagra",
|
||||
"vulva",
|
||||
"w00se",
|
||||
"wang",
|
||||
"wank",
|
||||
"wanker",
|
||||
"wanky",
|
||||
"whoar",
|
||||
"whore",
|
||||
"willies",
|
||||
"willy",
|
||||
"xrated",
|
||||
"xxx"
|
||||
]
|
||||
+7
-17
@@ -5,8 +5,7 @@ const bcrypt = require('bcrypt');
|
||||
const jwt = require('jsonwebtoken');
|
||||
const Action = require('./action');
|
||||
const Comment = require('./comment');
|
||||
|
||||
const naughtyWords = require('./naughty-words.json');
|
||||
const Wordlist = require('../services/wordlist');
|
||||
|
||||
// SALT_ROUNDS is the number of rounds that the bcrypt algorithm will run
|
||||
// through during the salting process.
|
||||
@@ -305,30 +304,21 @@ const isValidDisplayName = (displayName) => {
|
||||
const onlyLettersNumbersUnderscore = /^[a-z0-9_]+$/;
|
||||
|
||||
if (!displayName) {
|
||||
const ErrMissingDisplay = new Error('DISPLAY_NAME_REQUIRED');
|
||||
const ErrMissingDisplay = new Error('A display name is required to create a user');
|
||||
ErrMissingDisplay.translation_key = 'DISPLAY_NAME_REQUIRED';
|
||||
ErrMissingDisplay.status = 400;
|
||||
return Promise.reject(ErrMissingDisplay);
|
||||
}
|
||||
|
||||
if (!onlyLettersNumbersUnderscore.test(displayName)) {
|
||||
const ErrSpecialChars = new Error('NO_SPECIAL_CHARACTERS');
|
||||
const ErrSpecialChars = new Error('No special characters are allowed in a display name');
|
||||
ErrSpecialChars.translation_key = 'NO_SPECIAL_CHARACTERS';
|
||||
ErrSpecialChars.status = 400;
|
||||
return Promise.reject(ErrSpecialChars);
|
||||
}
|
||||
|
||||
const hasBadWords = naughtyWords.some(badWord => {
|
||||
|
||||
// test the word AFTER the interspersed _ characters are removed.
|
||||
return new RegExp(badWord, 'ig').test(displayName.replace(/_/g, ''));
|
||||
});
|
||||
|
||||
if (hasBadWords) {
|
||||
const ErrProfanity = new Error('PROFANITY_ERROR');
|
||||
ErrProfanity.status = 400;
|
||||
return Promise.reject(ErrProfanity);
|
||||
} else {
|
||||
return Promise.resolve(displayName);
|
||||
}
|
||||
// check for profanity
|
||||
return Wordlist.displayNameCheck(displayName);
|
||||
};
|
||||
|
||||
/**
|
||||
|
||||
+23
-1
@@ -165,6 +165,27 @@ class Wordlist {
|
||||
return errors;
|
||||
}
|
||||
|
||||
/**
|
||||
* check potential username for banned words, special characters
|
||||
*/
|
||||
static displayNameCheck(displayName) {
|
||||
const wl = new Wordlist();
|
||||
return wl.load()
|
||||
.then(() => {
|
||||
displayName = displayName.replace(/_/g, '');
|
||||
// test each word, and fail if we find a match
|
||||
const hasBadWords = wl.lists.banned.some(word => {
|
||||
return new RegExp(word, 'ig').test(displayName);
|
||||
});
|
||||
|
||||
if (hasBadWords) {
|
||||
throw ErrContainsProfanity;
|
||||
} else {
|
||||
return Promise.resolve(displayName);
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
/**
|
||||
* Connect middleware for scanning request bodies for wordlisted words and
|
||||
* attaching a ErrContainsProfanity to the req.wordlisted parameter, otherwise
|
||||
@@ -196,7 +217,8 @@ class Wordlist {
|
||||
|
||||
// ErrContainsProfanity is returned in the event that the middleware detects
|
||||
// profanity/wordlisted words in the payload.
|
||||
const ErrContainsProfanity = new Error('contains profanity');
|
||||
const ErrContainsProfanity = new Error('Suspected profanity. If you think this in error, please let us know!');
|
||||
ErrContainsProfanity.translation_key = 'PROFANITY_ERROR';
|
||||
ErrContainsProfanity.status = 400;
|
||||
|
||||
module.exports = Wordlist;
|
||||
|
||||
@@ -9,15 +9,15 @@ describe('models.User', () => {
|
||||
return User.createLocalUsers([{
|
||||
email: 'stampi@gmail.com',
|
||||
displayName: 'Stampi',
|
||||
password: '1Coral!'
|
||||
password: '1Coral!-'
|
||||
}, {
|
||||
email: 'sockmonster@gmail.com',
|
||||
displayName: 'Sockmonster',
|
||||
password: '2Coral!'
|
||||
password: '2Coral!2'
|
||||
}, {
|
||||
email: 'marvel@gmail.com',
|
||||
displayName: 'Marvel',
|
||||
password: '3Coral!'
|
||||
password: '3Coral!3'
|
||||
}]).then((users) => {
|
||||
mockUsers = users;
|
||||
});
|
||||
@@ -29,7 +29,7 @@ describe('models.User', () => {
|
||||
.findById(mockUsers[0].id)
|
||||
.then((user) => {
|
||||
expect(user).to.have.property('displayName')
|
||||
.and.to.equal('Stampi');
|
||||
.and.to.equal('stampi');
|
||||
});
|
||||
});
|
||||
});
|
||||
@@ -54,7 +54,7 @@ describe('models.User', () => {
|
||||
return 0;
|
||||
});
|
||||
expect(sorted[0]).to.have.property('displayName')
|
||||
.and.to.equal('Marvel');
|
||||
.and.to.equal('marvel');
|
||||
});
|
||||
});
|
||||
});
|
||||
@@ -63,16 +63,16 @@ describe('models.User', () => {
|
||||
|
||||
it('should find a user when we give the right credentials', () => {
|
||||
return User
|
||||
.findLocalUser(mockUsers[0].profiles[0].id, '1Coral!')
|
||||
.findLocalUser(mockUsers[0].profiles[0].id, '1Coral!-')
|
||||
.then((user) => {
|
||||
expect(user).to.have.property('displayName')
|
||||
.and.to.equal(mockUsers[0].displayName);
|
||||
.and.to.equal(mockUsers[0].displayName.toLowerCase());
|
||||
});
|
||||
});
|
||||
|
||||
it('should not find the user when we give the wrong credentials', () => {
|
||||
return User
|
||||
.findLocalUser(mockUsers[0].profiles[0].id, '1Coral!<nope>')
|
||||
.findLocalUser(mockUsers[0].profiles[0].id, '1Coral!-<nope>')
|
||||
.then((user) => {
|
||||
expect(user).to.equal(false);
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user