Files
Multi-Hoster-Upload/lib/upload-confirmation.js
T
Sucukdeluxe b64cdd0ff3 fix: harden hoster confirmation and recovery
Require every successful upload to expose a validated HTTPS result and rebuild all Doodstream and DSVPlay output from the confirmed file code.

Keep failed baselines distinct from empty accounts, reject stale, foreign, and ambiguous recovery candidates across Doodstream, Byse, VOE, and Vidmoly, and preserve exact filename recovery with normalized extensions.

Emit bounded structured transport diagnostics without raw response bodies or tokenized URLs, and remove sensitive values from Doodstream debug traces.

Tests: node --test tests/upload-confirmation.test.js tests/hosters.test.js tests/doodstream-api-upload.test.js tests/doodstream-upload.test.js tests/byse-reject-recovery.test.js tests/hoster-recovery-provenance.test.js tests/suspect-reject-alternates.test.js

Lint: eslint lib/hoster-transport-error.js lib/hosters.js lib/doodstream-upload.js lib/voe-upload.js lib/vidmoly-upload.js lib/upload-confirmation.js
2026-08-13 20:43:48 +02:00

67 lines
2.2 KiB
JavaScript

const SUPPORTED_HOSTERS = new Set([
'doodstream.com',
'voe.sx',
'vidmoly.me',
'byse.sx',
'clouddrop.cc'
]);
const FILE_CODE_PATTERN = /^[A-Za-z0-9][A-Za-z0-9_-]{2,127}$/;
const HOSTER_RESULT_DOMAINS = {
'doodstream.com': ['doodstream.com', 'dood.to', 'dood.la', 'dood.so', 'dsvplay.com']
};
function isExpectedHostUrl(value, expectedHost, allowHttp = false) {
if (typeof value !== 'string' || value.trim() === '') return false;
try {
const url = new URL(value);
const hostname = url.hostname.toLowerCase();
const acceptedDomains = HOSTER_RESULT_DOMAINS[expectedHost] || [expectedHost];
return (url.protocol === 'https:' || (allowHttp && url.protocol === 'http:'))
&& acceptedDomains.some(domain => hostname === domain || hostname.endsWith(`.${domain}`));
} catch {
return false;
}
}
function getUrlHost(value) {
try {
return new URL(value).hostname.toLowerCase();
} catch {
return 'invalid';
}
}
function assertUploadConfirmation(result, hoster) {
const expectedHost = typeof hoster === 'string' ? hoster.trim().toLowerCase() : '';
const fileCode = typeof result?.file_code === 'string' ? result.file_code.trim() : '';
const urls = [result?.download_url, result?.embed_url].filter(value => (
value !== null
&& value !== undefined
&& !(typeof value === 'string' && value.trim() === '')
));
if (SUPPORTED_HOSTERS.has(expectedHost) && FILE_CODE_PATTERN.test(fileCode)) {
if (expectedHost === 'doodstream.com' && urls.every(value => isExpectedHostUrl(value, expectedHost, true))) {
return {
...result,
file_code: fileCode,
download_url: `https://doodstream.com/d/${fileCode}`,
embed_url: `https://doodstream.com/e/${fileCode}`
};
}
if (urls.length > 0 && urls.every(value => isExpectedHostUrl(value, expectedHost))) {
return fileCode === result.file_code ? result : { ...result, file_code: fileCode };
}
}
const error = new Error(`Upload zu ${hoster || 'unbekanntem Hoster'} wurde nicht bestätigt`);
error.diagnostic = {
payloadSnippet: JSON.stringify({
fileCodeLength: fileCode.length,
urlHosts: urls.map(getUrlHost)
})
};
throw error;
}
module.exports = { assertUploadConfirmation };