link_token.html 21 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270
  1. <!DOCTYPE html>
  2. <html lang="en" data-content_root="../../../">
  3. <head>
  4. <meta charset="utf-8" />
  5. <meta name="viewport" content="width=device-width, initial-scale=1.0" />
  6. <meta name="viewport" content="width=device-width, initial-scale=1">
  7. <title>searx.botdetection.link_token &#8212; SearXNG Documentation (2025.4.30+fd33559cf)</title>
  8. <link rel="stylesheet" type="text/css" href="../../../_static/pygments.css?v=6625fa76" />
  9. <link rel="stylesheet" type="text/css" href="../../../_static/searxng.css?v=52e4ff28" />
  10. <script src="../../../_static/documentation_options.js?v=b12b0e12"></script>
  11. <script src="../../../_static/doctools.js?v=9a2dae69"></script>
  12. <script src="../../../_static/sphinx_highlight.js?v=dc90522c"></script>
  13. <script data-project="searxng" data-version="2025.4.30+fd33559cf" src="../../../_static/describe_version.js?v=fa7f30d0"></script>
  14. <link rel="index" title="Index" href="../../../genindex.html" />
  15. <link rel="search" title="Search" href="../../../search.html" />
  16. </head><body>
  17. <div class="related" role="navigation" aria-label="Related">
  18. <h3>Navigation</h3>
  19. <ul>
  20. <li class="right" style="margin-right: 10px">
  21. <a href="../../../genindex.html" title="General Index"
  22. accesskey="I">index</a></li>
  23. <li class="right" >
  24. <a href="../../../py-modindex.html" title="Python Module Index"
  25. >modules</a> |</li>
  26. <li class="nav-item nav-item-0"><a href="../../../index.html">SearXNG Documentation (2025.4.30+fd33559cf)</a> &#187;</li>
  27. <li class="nav-item nav-item-1"><a href="../../index.html" accesskey="U">Module code</a> &#187;</li>
  28. <li class="nav-item nav-item-this"><a href="">searx.botdetection.link_token</a></li>
  29. </ul>
  30. </div>
  31. <div class="document">
  32. <div class="documentwrapper">
  33. <div class="bodywrapper">
  34. <div class="body" role="main">
  35. <h1>Source code for searx.botdetection.link_token</h1><div class="highlight"><pre>
  36. <span></span><span class="c1"># SPDX-License-Identifier: AGPL-3.0-or-later</span>
  37. <span class="sd">&quot;&quot;&quot;</span>
  38. <span class="sd">Method ``link_token``</span>
  39. <span class="sd">---------------------</span>
  40. <span class="sd">The ``link_token`` method evaluates a request as :py:obj:`suspicious</span>
  41. <span class="sd">&lt;is_suspicious&gt;` if the URL ``/client&lt;token&gt;.css`` is not requested by the</span>
  42. <span class="sd">client. By adding a random component (the token) in the URL, a bot can not send</span>
  43. <span class="sd">a ping by request a static URL.</span>
  44. <span class="sd">.. note::</span>
  45. <span class="sd"> This method requires a redis DB and needs a HTTP X-Forwarded-For_ header.</span>
  46. <span class="sd">To get in use of this method a flask URL route needs to be added:</span>
  47. <span class="sd">.. code:: python</span>
  48. <span class="sd"> @app.route(&#39;/client&lt;token&gt;.css&#39;, methods=[&#39;GET&#39;, &#39;POST&#39;])</span>
  49. <span class="sd"> def client_token(token=None):</span>
  50. <span class="sd"> link_token.ping(request, token)</span>
  51. <span class="sd"> return Response(&#39;&#39;, mimetype=&#39;text/css&#39;)</span>
  52. <span class="sd">And in the HTML template from flask a stylesheet link is needed (the value of</span>
  53. <span class="sd">``link_token`` comes from :py:obj:`get_token`):</span>
  54. <span class="sd">.. code:: html</span>
  55. <span class="sd"> &lt;link rel=&quot;stylesheet&quot;</span>
  56. <span class="sd"> href=&quot;{{ url_for(&#39;client_token&#39;, token=link_token) }}&quot;</span>
  57. <span class="sd"> type=&quot;text/css&quot; &gt;</span>
  58. <span class="sd">.. _X-Forwarded-For:</span>
  59. <span class="sd"> https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Forwarded-For</span>
  60. <span class="sd">&quot;&quot;&quot;</span>
  61. <span class="kn">from</span><span class="w"> </span><span class="nn">__future__</span><span class="w"> </span><span class="kn">import</span> <span class="n">annotations</span>
  62. <span class="kn">from</span><span class="w"> </span><span class="nn">ipaddress</span><span class="w"> </span><span class="kn">import</span> <span class="p">(</span>
  63. <span class="n">IPv4Network</span><span class="p">,</span>
  64. <span class="n">IPv6Network</span><span class="p">,</span>
  65. <span class="n">ip_address</span><span class="p">,</span>
  66. <span class="p">)</span>
  67. <span class="kn">import</span><span class="w"> </span><span class="nn">string</span>
  68. <span class="kn">import</span><span class="w"> </span><span class="nn">random</span>
  69. <span class="kn">from</span><span class="w"> </span><span class="nn">searx</span><span class="w"> </span><span class="kn">import</span> <span class="n">logger</span>
  70. <span class="kn">from</span><span class="w"> </span><span class="nn">searx</span><span class="w"> </span><span class="kn">import</span> <span class="n">redisdb</span>
  71. <span class="kn">from</span><span class="w"> </span><span class="nn">searx.redislib</span><span class="w"> </span><span class="kn">import</span> <span class="n">secret_hash</span>
  72. <span class="kn">from</span><span class="w"> </span><span class="nn">searx.extended_types</span><span class="w"> </span><span class="kn">import</span> <span class="n">SXNG_Request</span>
  73. <span class="kn">from</span><span class="w"> </span><span class="nn">._helpers</span><span class="w"> </span><span class="kn">import</span> <span class="p">(</span>
  74. <span class="n">get_network</span><span class="p">,</span>
  75. <span class="n">get_real_ip</span><span class="p">,</span>
  76. <span class="p">)</span>
  77. <span class="n">TOKEN_LIVE_TIME</span> <span class="o">=</span> <span class="mi">600</span>
  78. <span class="sd">&quot;&quot;&quot;Lifetime (sec) of limiter&#39;s CSS token.&quot;&quot;&quot;</span>
  79. <span class="n">PING_LIVE_TIME</span> <span class="o">=</span> <span class="mi">3600</span>
  80. <span class="sd">&quot;&quot;&quot;Lifetime (sec) of the ping-key from a client (request)&quot;&quot;&quot;</span>
  81. <span class="n">PING_KEY</span> <span class="o">=</span> <span class="s1">&#39;SearXNG_limiter.ping&#39;</span>
  82. <span class="sd">&quot;&quot;&quot;Prefix of all ping-keys generated by :py:obj:`get_ping_key`&quot;&quot;&quot;</span>
  83. <span class="n">TOKEN_KEY</span> <span class="o">=</span> <span class="s1">&#39;SearXNG_limiter.token&#39;</span>
  84. <span class="sd">&quot;&quot;&quot;Key for which the current token is stored in the DB&quot;&quot;&quot;</span>
  85. <span class="n">logger</span> <span class="o">=</span> <span class="n">logger</span><span class="o">.</span><span class="n">getChild</span><span class="p">(</span><span class="s1">&#39;botdetection.link_token&#39;</span><span class="p">)</span>
  86. <div class="viewcode-block" id="is_suspicious">
  87. <a class="viewcode-back" href="../../../src/searx.botdetection.html#searx.botdetection.link_token.is_suspicious">[docs]</a>
  88. <span class="k">def</span><span class="w"> </span><span class="nf">is_suspicious</span><span class="p">(</span><span class="n">network</span><span class="p">:</span> <span class="n">IPv4Network</span> <span class="o">|</span> <span class="n">IPv6Network</span><span class="p">,</span> <span class="n">request</span><span class="p">:</span> <span class="n">SXNG_Request</span><span class="p">,</span> <span class="n">renew</span><span class="p">:</span> <span class="nb">bool</span> <span class="o">=</span> <span class="kc">False</span><span class="p">):</span>
  89. <span class="w"> </span><span class="sd">&quot;&quot;&quot;Checks whether a valid ping is exists for this (client) network, if not</span>
  90. <span class="sd"> this request is rated as *suspicious*. If a valid ping exists and argument</span>
  91. <span class="sd"> ``renew`` is ``True`` the expire time of this ping is reset to</span>
  92. <span class="sd"> :py:obj:`PING_LIVE_TIME`.</span>
  93. <span class="sd"> &quot;&quot;&quot;</span>
  94. <span class="n">redis_client</span> <span class="o">=</span> <span class="n">redisdb</span><span class="o">.</span><span class="n">client</span><span class="p">()</span>
  95. <span class="k">if</span> <span class="ow">not</span> <span class="n">redis_client</span><span class="p">:</span>
  96. <span class="k">return</span> <span class="kc">False</span>
  97. <span class="n">ping_key</span> <span class="o">=</span> <span class="n">get_ping_key</span><span class="p">(</span><span class="n">network</span><span class="p">,</span> <span class="n">request</span><span class="p">)</span>
  98. <span class="k">if</span> <span class="ow">not</span> <span class="n">redis_client</span><span class="o">.</span><span class="n">get</span><span class="p">(</span><span class="n">ping_key</span><span class="p">):</span>
  99. <span class="n">logger</span><span class="o">.</span><span class="n">info</span><span class="p">(</span><span class="s2">&quot;missing ping (IP: </span><span class="si">%s</span><span class="s2">) / request: </span><span class="si">%s</span><span class="s2">&quot;</span><span class="p">,</span> <span class="n">network</span><span class="o">.</span><span class="n">compressed</span><span class="p">,</span> <span class="n">ping_key</span><span class="p">)</span>
  100. <span class="k">return</span> <span class="kc">True</span>
  101. <span class="k">if</span> <span class="n">renew</span><span class="p">:</span>
  102. <span class="n">redis_client</span><span class="o">.</span><span class="n">set</span><span class="p">(</span><span class="n">ping_key</span><span class="p">,</span> <span class="mi">1</span><span class="p">,</span> <span class="n">ex</span><span class="o">=</span><span class="n">PING_LIVE_TIME</span><span class="p">)</span>
  103. <span class="n">logger</span><span class="o">.</span><span class="n">debug</span><span class="p">(</span><span class="s2">&quot;found ping for (client) network </span><span class="si">%s</span><span class="s2"> -&gt; </span><span class="si">%s</span><span class="s2">&quot;</span><span class="p">,</span> <span class="n">network</span><span class="o">.</span><span class="n">compressed</span><span class="p">,</span> <span class="n">ping_key</span><span class="p">)</span>
  104. <span class="k">return</span> <span class="kc">False</span></div>
  105. <div class="viewcode-block" id="ping">
  106. <a class="viewcode-back" href="../../../src/searx.botdetection.html#searx.botdetection.link_token.ping">[docs]</a>
  107. <span class="k">def</span><span class="w"> </span><span class="nf">ping</span><span class="p">(</span><span class="n">request</span><span class="p">:</span> <span class="n">SXNG_Request</span><span class="p">,</span> <span class="n">token</span><span class="p">:</span> <span class="nb">str</span><span class="p">):</span>
  108. <span class="w"> </span><span class="sd">&quot;&quot;&quot;This function is called by a request to URL ``/client&lt;token&gt;.css``. If</span>
  109. <span class="sd"> ``token`` is valid a :py:obj:`PING_KEY` for the client is stored in the DB.</span>
  110. <span class="sd"> The expire time of this ping-key is :py:obj:`PING_LIVE_TIME`.</span>
  111. <span class="sd"> &quot;&quot;&quot;</span>
  112. <span class="kn">from</span><span class="w"> </span><span class="nn">.</span><span class="w"> </span><span class="kn">import</span> <span class="n">redis_client</span><span class="p">,</span> <span class="n">cfg</span> <span class="c1"># pylint: disable=import-outside-toplevel, cyclic-import</span>
  113. <span class="k">if</span> <span class="ow">not</span> <span class="n">redis_client</span><span class="p">:</span>
  114. <span class="k">return</span>
  115. <span class="k">if</span> <span class="ow">not</span> <span class="n">token_is_valid</span><span class="p">(</span><span class="n">token</span><span class="p">):</span>
  116. <span class="k">return</span>
  117. <span class="n">real_ip</span> <span class="o">=</span> <span class="n">ip_address</span><span class="p">(</span><span class="n">get_real_ip</span><span class="p">(</span><span class="n">request</span><span class="p">))</span>
  118. <span class="n">network</span> <span class="o">=</span> <span class="n">get_network</span><span class="p">(</span><span class="n">real_ip</span><span class="p">,</span> <span class="n">cfg</span><span class="p">)</span>
  119. <span class="n">ping_key</span> <span class="o">=</span> <span class="n">get_ping_key</span><span class="p">(</span><span class="n">network</span><span class="p">,</span> <span class="n">request</span><span class="p">)</span>
  120. <span class="n">logger</span><span class="o">.</span><span class="n">debug</span><span class="p">(</span><span class="s2">&quot;store ping_key for (client) network </span><span class="si">%s</span><span class="s2"> (IP </span><span class="si">%s</span><span class="s2">) -&gt; </span><span class="si">%s</span><span class="s2">&quot;</span><span class="p">,</span> <span class="n">network</span><span class="o">.</span><span class="n">compressed</span><span class="p">,</span> <span class="n">real_ip</span><span class="p">,</span> <span class="n">ping_key</span><span class="p">)</span>
  121. <span class="n">redis_client</span><span class="o">.</span><span class="n">set</span><span class="p">(</span><span class="n">ping_key</span><span class="p">,</span> <span class="mi">1</span><span class="p">,</span> <span class="n">ex</span><span class="o">=</span><span class="n">PING_LIVE_TIME</span><span class="p">)</span></div>
  122. <div class="viewcode-block" id="get_ping_key">
  123. <a class="viewcode-back" href="../../../src/searx.botdetection.html#searx.botdetection.link_token.get_ping_key">[docs]</a>
  124. <span class="k">def</span><span class="w"> </span><span class="nf">get_ping_key</span><span class="p">(</span><span class="n">network</span><span class="p">:</span> <span class="n">IPv4Network</span> <span class="o">|</span> <span class="n">IPv6Network</span><span class="p">,</span> <span class="n">request</span><span class="p">:</span> <span class="n">SXNG_Request</span><span class="p">)</span> <span class="o">-&gt;</span> <span class="nb">str</span><span class="p">:</span>
  125. <span class="w"> </span><span class="sd">&quot;&quot;&quot;Generates a hashed key that fits (more or less) to a *WEB-browser</span>
  126. <span class="sd"> session* in a network.&quot;&quot;&quot;</span>
  127. <span class="k">return</span> <span class="p">(</span>
  128. <span class="n">PING_KEY</span>
  129. <span class="o">+</span> <span class="s2">&quot;[&quot;</span>
  130. <span class="o">+</span> <span class="n">secret_hash</span><span class="p">(</span>
  131. <span class="n">network</span><span class="o">.</span><span class="n">compressed</span> <span class="o">+</span> <span class="n">request</span><span class="o">.</span><span class="n">headers</span><span class="o">.</span><span class="n">get</span><span class="p">(</span><span class="s1">&#39;Accept-Language&#39;</span><span class="p">,</span> <span class="s1">&#39;&#39;</span><span class="p">)</span> <span class="o">+</span> <span class="n">request</span><span class="o">.</span><span class="n">headers</span><span class="o">.</span><span class="n">get</span><span class="p">(</span><span class="s1">&#39;User-Agent&#39;</span><span class="p">,</span> <span class="s1">&#39;&#39;</span><span class="p">)</span>
  132. <span class="p">)</span>
  133. <span class="o">+</span> <span class="s2">&quot;]&quot;</span>
  134. <span class="p">)</span></div>
  135. <span class="k">def</span><span class="w"> </span><span class="nf">token_is_valid</span><span class="p">(</span><span class="n">token</span><span class="p">)</span> <span class="o">-&gt;</span> <span class="nb">bool</span><span class="p">:</span>
  136. <span class="n">valid</span> <span class="o">=</span> <span class="n">token</span> <span class="o">==</span> <span class="n">get_token</span><span class="p">()</span>
  137. <span class="n">logger</span><span class="o">.</span><span class="n">debug</span><span class="p">(</span><span class="s2">&quot;token is valid --&gt; </span><span class="si">%s</span><span class="s2">&quot;</span><span class="p">,</span> <span class="n">valid</span><span class="p">)</span>
  138. <span class="k">return</span> <span class="n">valid</span>
  139. <div class="viewcode-block" id="get_token">
  140. <a class="viewcode-back" href="../../../src/searx.botdetection.html#searx.botdetection.link_token.get_token">[docs]</a>
  141. <span class="k">def</span><span class="w"> </span><span class="nf">get_token</span><span class="p">()</span> <span class="o">-&gt;</span> <span class="nb">str</span><span class="p">:</span>
  142. <span class="w"> </span><span class="sd">&quot;&quot;&quot;Returns current token. If there is no currently active token a new token</span>
  143. <span class="sd"> is generated randomly and stored in the redis DB.</span>
  144. <span class="sd"> - :py:obj:`TOKEN_LIVE_TIME`</span>
  145. <span class="sd"> - :py:obj:`TOKEN_KEY`</span>
  146. <span class="sd"> &quot;&quot;&quot;</span>
  147. <span class="n">redis_client</span> <span class="o">=</span> <span class="n">redisdb</span><span class="o">.</span><span class="n">client</span><span class="p">()</span>
  148. <span class="k">if</span> <span class="ow">not</span> <span class="n">redis_client</span><span class="p">:</span>
  149. <span class="c1"># This function is also called when limiter is inactive / no redis DB</span>
  150. <span class="c1"># (see render function in webapp.py)</span>
  151. <span class="k">return</span> <span class="s1">&#39;12345678&#39;</span>
  152. <span class="n">token</span> <span class="o">=</span> <span class="n">redis_client</span><span class="o">.</span><span class="n">get</span><span class="p">(</span><span class="n">TOKEN_KEY</span><span class="p">)</span>
  153. <span class="k">if</span> <span class="n">token</span><span class="p">:</span>
  154. <span class="n">token</span> <span class="o">=</span> <span class="n">token</span><span class="o">.</span><span class="n">decode</span><span class="p">(</span><span class="s1">&#39;UTF-8&#39;</span><span class="p">)</span>
  155. <span class="k">else</span><span class="p">:</span>
  156. <span class="n">token</span> <span class="o">=</span> <span class="s1">&#39;&#39;</span><span class="o">.</span><span class="n">join</span><span class="p">(</span><span class="n">random</span><span class="o">.</span><span class="n">choice</span><span class="p">(</span><span class="n">string</span><span class="o">.</span><span class="n">ascii_lowercase</span> <span class="o">+</span> <span class="n">string</span><span class="o">.</span><span class="n">digits</span><span class="p">)</span> <span class="k">for</span> <span class="n">_</span> <span class="ow">in</span> <span class="nb">range</span><span class="p">(</span><span class="mi">16</span><span class="p">))</span>
  157. <span class="n">redis_client</span><span class="o">.</span><span class="n">set</span><span class="p">(</span><span class="n">TOKEN_KEY</span><span class="p">,</span> <span class="n">token</span><span class="p">,</span> <span class="n">ex</span><span class="o">=</span><span class="n">TOKEN_LIVE_TIME</span><span class="p">)</span>
  158. <span class="k">return</span> <span class="n">token</span></div>
  159. </pre></div>
  160. <div class="clearer"></div>
  161. </div>
  162. </div>
  163. </div>
  164. <span id="sidebar-top"></span>
  165. <div class="sphinxsidebar" role="navigation" aria-label="Main">
  166. <div class="sphinxsidebarwrapper">
  167. <p class="logo"><a href="../../../index.html">
  168. <img class="logo" src="../../../_static/searxng-wordmark.svg" alt="Logo of SearXNG"/>
  169. </a></p>
  170. <h3><a href="../../../index.html">Table of Contents</a></h3>
  171. <ul>
  172. <li class="toctree-l1"><a class="reference internal" href="../../../user/index.html">User information</a></li>
  173. <li class="toctree-l1"><a class="reference internal" href="../../../own-instance.html">Why use a private instance?</a></li>
  174. <li class="toctree-l1"><a class="reference internal" href="../../../admin/index.html">Administrator documentation</a></li>
  175. <li class="toctree-l1"><a class="reference internal" href="../../../dev/index.html">Developer documentation</a></li>
  176. <li class="toctree-l1"><a class="reference internal" href="../../../utils/index.html">DevOps tooling box</a></li>
  177. <li class="toctree-l1"><a class="reference internal" href="../../../src/index.html">Source-Code</a></li>
  178. </ul>
  179. <h3>Project Links</h3>
  180. <ul>
  181. <li><a href="https://github.com/searxng/searxng/tree/master">Source</a>
  182. <li><a href="https://github.com/searxng/searxng/wiki">Wiki</a>
  183. <li><a href="https://searx.space">Public instances</a>
  184. <li><a href="https://github.com/searxng/searxng/issues">Issue Tracker</a>
  185. </ul><h3>Navigation</h3>
  186. <ul>
  187. <li><a href="../../../index.html">Overview</a>
  188. <ul>
  189. <li><a href="../../index.html">Module code</a>
  190. </ul>
  191. </li>
  192. </ul>
  193. </li>
  194. </ul>
  195. <search id="searchbox" style="display: none" role="search">
  196. <h3 id="searchlabel">Quick search</h3>
  197. <div class="searchformwrapper">
  198. <form class="search" action="../../../search.html" method="get">
  199. <input type="text" name="q" aria-labelledby="searchlabel" autocomplete="off" autocorrect="off" autocapitalize="off" spellcheck="false"/>
  200. <input type="submit" value="Go" />
  201. </form>
  202. </div>
  203. </search>
  204. <script>document.getElementById('searchbox').style.display = "block"</script>
  205. </div>
  206. </div>
  207. <div class="clearer"></div>
  208. </div>
  209. <div class="footer" role="contentinfo">
  210. &#169; Copyright SearXNG team.
  211. </div>
  212. </body>
  213. </html>