| 1 | /*!
|
|---|
| 2 | * Copyright (c) 2018, Salesforce.com, Inc.
|
|---|
| 3 | * All rights reserved.
|
|---|
| 4 | *
|
|---|
| 5 | * Redistribution and use in source and binary forms, with or without
|
|---|
| 6 | * modification, are permitted provided that the following conditions are met:
|
|---|
| 7 | *
|
|---|
| 8 | * 1. Redistributions of source code must retain the above copyright notice,
|
|---|
| 9 | * this list of conditions and the following disclaimer.
|
|---|
| 10 | *
|
|---|
| 11 | * 2. Redistributions in binary form must reproduce the above copyright notice,
|
|---|
| 12 | * this list of conditions and the following disclaimer in the documentation
|
|---|
| 13 | * and/or other materials provided with the distribution.
|
|---|
| 14 | *
|
|---|
| 15 | * 3. Neither the name of Salesforce.com nor the names of its contributors may
|
|---|
| 16 | * be used to endorse or promote products derived from this software without
|
|---|
| 17 | * specific prior written permission.
|
|---|
| 18 | *
|
|---|
| 19 | * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
|
|---|
| 20 | * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
|---|
| 21 | * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
|---|
| 22 | * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
|
|---|
| 23 | * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
|
|---|
| 24 | * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
|
|---|
| 25 | * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
|
|---|
| 26 | * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
|
|---|
| 27 | * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
|---|
| 28 | * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
|
|---|
| 29 | * POSSIBILITY OF SUCH DAMAGE.
|
|---|
| 30 | */
|
|---|
| 31 | "use strict";
|
|---|
| 32 | const psl = require("psl");
|
|---|
| 33 |
|
|---|
| 34 | // RFC 6761
|
|---|
| 35 | const SPECIAL_USE_DOMAINS = [
|
|---|
| 36 | "local",
|
|---|
| 37 | "example",
|
|---|
| 38 | "invalid",
|
|---|
| 39 | "localhost",
|
|---|
| 40 | "test"
|
|---|
| 41 | ];
|
|---|
| 42 |
|
|---|
| 43 | const SPECIAL_TREATMENT_DOMAINS = ["localhost", "invalid"];
|
|---|
| 44 |
|
|---|
| 45 | function getPublicSuffix(domain, options = {}) {
|
|---|
| 46 | const domainParts = domain.split(".");
|
|---|
| 47 | const topLevelDomain = domainParts[domainParts.length - 1];
|
|---|
| 48 | const allowSpecialUseDomain = !!options.allowSpecialUseDomain;
|
|---|
| 49 | const ignoreError = !!options.ignoreError;
|
|---|
| 50 |
|
|---|
| 51 | if (allowSpecialUseDomain && SPECIAL_USE_DOMAINS.includes(topLevelDomain)) {
|
|---|
| 52 | if (domainParts.length > 1) {
|
|---|
| 53 | const secondLevelDomain = domainParts[domainParts.length - 2];
|
|---|
| 54 | // In aforementioned example, the eTLD/pubSuf will be apple.localhost
|
|---|
| 55 | return `${secondLevelDomain}.${topLevelDomain}`;
|
|---|
| 56 | } else if (SPECIAL_TREATMENT_DOMAINS.includes(topLevelDomain)) {
|
|---|
| 57 | // For a single word special use domain, e.g. 'localhost' or 'invalid', per RFC 6761,
|
|---|
| 58 | // "Application software MAY recognize {localhost/invalid} names as special, or
|
|---|
| 59 | // MAY pass them to name resolution APIs as they would for other domain names."
|
|---|
| 60 | return `${topLevelDomain}`;
|
|---|
| 61 | }
|
|---|
| 62 | }
|
|---|
| 63 |
|
|---|
| 64 | if (!ignoreError && SPECIAL_USE_DOMAINS.includes(topLevelDomain)) {
|
|---|
| 65 | throw new Error(
|
|---|
| 66 | `Cookie has domain set to the public suffix "${topLevelDomain}" which is a special use domain. To allow this, configure your CookieJar with {allowSpecialUseDomain:true, rejectPublicSuffixes: false}.`
|
|---|
| 67 | );
|
|---|
| 68 | }
|
|---|
| 69 |
|
|---|
| 70 | return psl.get(domain);
|
|---|
| 71 | }
|
|---|
| 72 |
|
|---|
| 73 | exports.getPublicSuffix = getPublicSuffix;
|
|---|