mirror of
https://github.com/anotherhadi/default-creds-web.git
synced 2026-10-05 10:58:24 +02:00
@@ -75,18 +75,6 @@
|
||||
results = data.results;
|
||||
totalPages = data.pagination.totalPages;
|
||||
totalResults = data.pagination.totalResults;
|
||||
if (typeof window !== "undefined" && (window as any).umami) {
|
||||
(window as any).umami.track("search", {
|
||||
query: lastQuery,
|
||||
results: totalResults,
|
||||
hasResults: totalResults > 0,
|
||||
});
|
||||
if (totalResults === 0) {
|
||||
(window as any).umami.track("search_no_results", {
|
||||
query: lastQuery,
|
||||
});
|
||||
}
|
||||
}
|
||||
} catch (e) {
|
||||
console.error("Search error:", e);
|
||||
results = [];
|
||||
|
||||
@@ -14,9 +14,6 @@ const {
|
||||
description = "Open-source database of default credentials for pentesters and researchers. Find factory-set passwords for any device or software.",
|
||||
ogImage = `${Astro.site ?? "https://default-creds.hadi.icu"}/og.png`
|
||||
} = Astro.props;
|
||||
|
||||
const umamiUrl = process.env.PUBLIC_UMAMI_URL;
|
||||
const umamiId = process.env.PUBLIC_UMAMI_WEBSITE_ID;
|
||||
---
|
||||
|
||||
<html lang="en">
|
||||
@@ -59,13 +56,4 @@ const umamiId = process.env.PUBLIC_UMAMI_WEBSITE_ID;
|
||||
<slot />
|
||||
</div>
|
||||
</body>
|
||||
|
||||
{umamiUrl && umamiId && (
|
||||
<script
|
||||
defer
|
||||
src={`${umamiUrl}/script.js`}
|
||||
data-website-id={umamiId}
|
||||
is:inline
|
||||
/>
|
||||
)}
|
||||
</html>
|
||||
|
||||
+2
-2
@@ -54,8 +54,8 @@ const SECURITY_HEADERS: Record<string, string> = {
|
||||
"default-src 'self'",
|
||||
"img-src 'self' cdn.jsdelivr.net data:",
|
||||
"style-src 'self' 'unsafe-inline'",
|
||||
"script-src 'self' 'unsafe-inline' static.cloudflareinsights.com umami.hadi.icu",
|
||||
"connect-src 'self' cloudflareinsights.com umami.hadi.icu",
|
||||
"script-src 'self' 'unsafe-inline' static.cloudflareinsights.com",
|
||||
"connect-src 'self' cloudflareinsights.com",
|
||||
"frame-ancestors 'none'",
|
||||
].join("; "),
|
||||
};
|
||||
|
||||
+1
-69
@@ -91,7 +91,7 @@ export function getAllData(): CredentialEntry[] {
|
||||
return allResults;
|
||||
}
|
||||
|
||||
export const GET: APIRoute = async ({ url, request }) => {
|
||||
export const GET: APIRoute = async ({ url }) => {
|
||||
const query = url.searchParams.get("q")?.trim().toLowerCase() || "";
|
||||
const page = Math.max(1, parseInt(url.searchParams.get("page") || "1"));
|
||||
const size = Math.min(
|
||||
@@ -99,9 +99,6 @@ export const GET: APIRoute = async ({ url, request }) => {
|
||||
Math.max(1, parseInt(url.searchParams.get("size") || "10")),
|
||||
);
|
||||
|
||||
const dnt = request.headers.get("DNT") === "1"
|
||||
|| request.headers.get("Sec-GPC") === "1";
|
||||
|
||||
const allEntries = getAllData();
|
||||
|
||||
let filtered = allEntries;
|
||||
@@ -112,15 +109,6 @@ export const GET: APIRoute = async ({ url, request }) => {
|
||||
);
|
||||
}
|
||||
|
||||
// NOTE: Server-side tracking is intentionally only triggered when DNT/GPC is active.
|
||||
// When DNT is off, the client handles tracking via Umami's JS snippet.
|
||||
// When DNT is on, the JS snippet is suppressed, so we fall back to server-side tracking
|
||||
// to log search queries (query string + result count only, no user data) in order to
|
||||
// identify missing manufacturers/products and improve the dataset.
|
||||
if (query && dnt) {
|
||||
await trackSearchServerSide(query, filtered.length);
|
||||
}
|
||||
|
||||
const totalResults = filtered.length;
|
||||
const totalPages = Math.ceil(totalResults / size);
|
||||
const start = (page - 1) * size;
|
||||
@@ -146,59 +134,3 @@ export const GET: APIRoute = async ({ url, request }) => {
|
||||
},
|
||||
);
|
||||
};
|
||||
|
||||
async function trackSearchServerSide(query: string, results: number) {
|
||||
const umamiUrl = process.env.UMAMI_URL;
|
||||
const umamiId = process.env.UMAMI_WEBSITE_ID;
|
||||
|
||||
if (!umamiUrl || !umamiId) return;
|
||||
|
||||
try {
|
||||
await fetch(`${umamiUrl}/api/send`, {
|
||||
method: "POST",
|
||||
headers: {
|
||||
"Content-Type": "application/json",
|
||||
"User-Agent": "Mozilla/5.0 (compatible; default-creds-server/1.0)",
|
||||
},
|
||||
body: JSON.stringify({
|
||||
type: "event",
|
||||
payload: {
|
||||
website: umamiId,
|
||||
hostname: "default-creds.hadi.icu",
|
||||
url: "/api/search",
|
||||
name: "search",
|
||||
data: {
|
||||
query,
|
||||
results,
|
||||
hasResults: results > 0,
|
||||
source: "server",
|
||||
},
|
||||
},
|
||||
}),
|
||||
});
|
||||
if (results === 0) {
|
||||
await fetch(`${umamiUrl}/api/send`, {
|
||||
method: "POST",
|
||||
headers: {
|
||||
"Content-Type": "application/json",
|
||||
"User-Agent": "Mozilla/5.0 (compatible; default-creds-server/1.0)",
|
||||
},
|
||||
body: JSON.stringify({
|
||||
type: "event",
|
||||
payload: {
|
||||
website: umamiId,
|
||||
hostname: "default-creds.hadi.icu",
|
||||
url: "/api/search",
|
||||
name: "search_no_results",
|
||||
data: {
|
||||
query,
|
||||
source: "server",
|
||||
},
|
||||
},
|
||||
}),
|
||||
});
|
||||
}
|
||||
} catch (e) {
|
||||
console.error("Umami server-side tracking failed:", e);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -5,7 +5,7 @@ import Layout from "../layouts/Layout.astro";
|
||||
<Layout title="Privacy Policy">
|
||||
<main class="prose prose-invert max-w-3xl mx-auto">
|
||||
<h1 class="text-4xl font-black uppercase tracking-tighter text-primary">Privacy Policy</h1>
|
||||
<p class="text-base-content/50 text-sm">Last updated: March 2026</p>
|
||||
<p class="text-base-content/50 text-sm">Last updated: August 2026</p>
|
||||
|
||||
<p>
|
||||
Default Creds is a free, open-source tool for security researchers and pentesters. This page explains
|
||||
@@ -14,18 +14,8 @@ import Layout from "../layouts/Layout.astro";
|
||||
|
||||
<h2>What we collect</h2>
|
||||
<p>
|
||||
This site uses <a href="https://umami.is" target="_blank" class="link link-primary">Umami</a>,
|
||||
a privacy-focused analytics tool. Umami collects the following anonymized data:
|
||||
We don't run any analytics or tracking on this site.
|
||||
</p>
|
||||
<ul>
|
||||
<li>Pages visited</li>
|
||||
<li>Referrer URL (where you came from)</li>
|
||||
<li>Browser and operating system (aggregated)</li>
|
||||
<li>Country (derived from IP, not stored)</li>
|
||||
<li>Search queries submitted through the search interface</li>
|
||||
</ul>
|
||||
|
||||
<h2>What we do NOT collect</h2>
|
||||
<ul>
|
||||
<li>No cookies are set — ever</li>
|
||||
<li>No IP addresses are stored</li>
|
||||
@@ -34,17 +24,11 @@ import Layout from "../layouts/Layout.astro";
|
||||
<li>No data is sold or shared with third parties</li>
|
||||
</ul>
|
||||
|
||||
<h2>How anonymization works</h2>
|
||||
<h2>Server logs</h2>
|
||||
<p>
|
||||
Umami does not store IP addresses. Instead, it generates a daily rotating hash from your IP,
|
||||
browser, and a server-side secret. This hash is used solely to distinguish unique visits within
|
||||
a single day and cannot be reversed or linked back to you.
|
||||
</p>
|
||||
|
||||
<h2>Data storage</h2>
|
||||
<p>
|
||||
All analytics data is stored on our own self-hosted server. No data is sent to third-party
|
||||
analytics providers. The Umami instance is hosted at <code>umami.hadi.icu</code>.
|
||||
Like any web server, ours may retain standard access logs (e.g. request timestamps, IP addresses,
|
||||
user agents) for a short period for security and abuse-prevention purposes. These logs are not used
|
||||
for analytics and are not retained long-term.
|
||||
</p>
|
||||
|
||||
<h2>Your rights</h2>
|
||||
@@ -54,18 +38,6 @@ import Layout from "../layouts/Layout.astro";
|
||||
<a href="/.well-known/security.txt" class="link link-primary">security.txt</a>.
|
||||
</p>
|
||||
|
||||
<h2>Do Not Track</h2>
|
||||
<p>
|
||||
Umami respects the <code>DNT</code> (Do Not Track) header. If your browser has DNT enabled,
|
||||
no client-side analytics will be collected for your session.
|
||||
</p>
|
||||
<p>
|
||||
However, when a search is performed, the query and whether it returned results are logged
|
||||
server-side, with no user information attached (no IP, no browser, no session identifier).
|
||||
This is used solely to identify missing manufacturers or products in the database and improve
|
||||
the dataset.
|
||||
</p>
|
||||
|
||||
<h2>Changes to this policy</h2>
|
||||
<p>
|
||||
If anything changes, this page will be updated with a new date at the top.
|
||||
|
||||
Reference in New Issue
Block a user