diff --git a/package-lock.json b/package-lock.json index 07f20e4..368c0e9 100644 --- a/package-lock.json +++ b/package-lock.json @@ -10,7 +10,8 @@ "hasInstallScript": true, "dependencies": { "@hackolade/fetch": "1.3.0", - "graphql": "16.10.0" + "graphql": "16.10.0", + "ip": "2.0.1" }, "devDependencies": { "@hackolade/hck-esbuild-plugins-pack": "0.0.1", @@ -3011,6 +3012,12 @@ "node": ">= 0.4" } }, + "node_modules/ip": { + "version": "2.0.1", + "resolved": "https://registry.npmjs.org/ip/-/ip-2.0.1.tgz", + "integrity": "sha512-lJUL9imLTNi1ZfXT+DU6rBBdbiKGBuay9B6xGSPVjUeQwaH1RIGqef8RZkUtHioLmSNpPR5M4HVKJGm1j8FWVQ==", + "license": "MIT" + }, "node_modules/is-array-buffer": { "version": "3.0.5", "resolved": "https://registry.npmjs.org/is-array-buffer/-/is-array-buffer-3.0.5.tgz", diff --git a/package.json b/package.json index 7b6f296..9a5d237 100644 --- a/package.json +++ b/package.json @@ -98,7 +98,8 @@ "disabled": false, "dependencies": { "@hackolade/fetch": "1.3.0", - "graphql": "16.10.0" + "graphql": "16.10.0", + "ip": "2.0.1" }, "lint-staged": { "*.{js,ts,json}": "prettier --write" diff --git a/reverse_engineering/helpers/escapeV6IpForURL.js b/reverse_engineering/helpers/escapeV6IpForURL.js new file mode 100644 index 0000000..f5c2ac9 --- /dev/null +++ b/reverse_engineering/helpers/escapeV6IpForURL.js @@ -0,0 +1,64 @@ +const ip = require('ip'); + +/** + * @param {{ + * host: string; + * }} param + * @returns {string} + * @see https://en.wikipedia.org/wiki/IPv6_address + * Literal IPv6 addresses in resources (URLs): + * ------------------------------------------------ + * Colon (:) characters in IPv6 addresses may conflict with the established syntax of resource identifiers, + * such as URIs and URLs. The colon is conventionally used to terminate the host path before a port number.[10] + * To alleviate this conflict, literal IPv6 addresses are enclosed in square brackets in such resource identifiers; + * When the URL doesn't conatoin the port the notation is http://[2001:db8:85a3:8d3:1319:8a2e:370:7348]/ + * When the URL also contains a port number the notation is: https://[2001:db8:85a3:8d3:1319:8a2e:370:7348]:443/ + */ +function escapeV6IpForURL({ host }) { + /** + * If the host is already URL compatible then the ip lib will return false > ip.isV6Format('[::1]') false If the host + * is a proper ipv6 ip then the `new URL(host)` will fail with Uncaught TypeError: Invalid URL code: + * 'ERR_INVALID_URL', !ip.isV4Format(host) check required because isV6Format returns true for ipv4 address because of + * backward compatibility + */ + if (ip.isV6Format(host) && !ip.isV4Format(host)) { + return `[${host}]`; + } + + const isUrlValid = isValidURL(host); + if (isUrlValid) { + return host; + } + + const urlWithIpV6HostRegExp = new RegExp(/^http(s)?:\/\/(:?([a-z0-9]{0,4}:?)+)/gim); + const [unescapedIpWithPort] = host.match(urlWithIpV6HostRegExp) ?? []; + + if (!unescapedIpWithPort) { + return host; + } + + const separatedIpPortionsAndPort = unescapedIpWithPort.split(':'); + const ipPortions = separatedIpPortionsAndPort.slice(0, separatedIpPortionsAndPort.length - 1); + const port = separatedIpPortionsAndPort.at(-1); + const escapedIpWithPort = `[${ipPortions.join(':')}]:${port}`; + + return host.replace(unescapedIpWithPort, escapedIpWithPort); +} + +/** + * @param {string} url + * @returns {boolean} + */ +function isValidURL(url) { + try { + new URL(url); + + return true; + } catch { + return false; + } +} + +module.exports = { + escapeV6IpForURL, +}; diff --git a/reverse_engineering/helpers/fetchIntrospectionSchema.js b/reverse_engineering/helpers/fetchIntrospectionSchema.js index a41c9ad..61612bb 100644 --- a/reverse_engineering/helpers/fetchIntrospectionSchema.js +++ b/reverse_engineering/helpers/fetchIntrospectionSchema.js @@ -6,6 +6,7 @@ const { getIntrospectionQuery } = require('graphql'); const { hckFetch } = require('@hackolade/fetch'); const { FetchIntrospectionSchemaError } = require('../errors/FetchIntrospectionSchemaError'); +const { escapeV6IpForURL } = require('./escapeV6IpForURL'); /** * Encode credentials to base64 for base authorization purposes @@ -78,7 +79,7 @@ async function fetchIntrospectionSchema({ connectionInfo }) { // If the URL is not provided, use the host keyword for backward compatibility with the less than 8.1.4 app version const url = connectionInfo.url || connectionInfo.host; - const response = await hckFetch(url, options); + const response = await hckFetch(escapeV6IpForURL({ host: url }), options); return await parseResponse(response); }