]> Untitled Git - lemmy.git/blob - crates/api/src/site.rs
01f7b45f19ce787845a4d888e3e82a73976b75ec
[lemmy.git] / crates / api / src / site.rs
1 use crate::Perform;
2 use actix_web::web::Data;
3 use anyhow::Context;
4 use diesel::NotFound;
5 use lemmy_api_common::{
6   blocking,
7   build_federated_instances,
8   get_local_user_view_from_jwt,
9   get_local_user_view_from_jwt_opt,
10   is_admin,
11   site::*,
12 };
13 use lemmy_apub::{
14   build_actor_id_from_shortname,
15   fetcher::search::{search_by_apub_id, SearchableObjects},
16   EndpointType,
17 };
18 use lemmy_db_queries::{
19   from_opt_str_to_opt_enum,
20   source::site::Site_,
21   Crud,
22   DbPool,
23   DeleteableOrRemoveable,
24   ListingType,
25   SearchType,
26   SortType,
27 };
28 use lemmy_db_schema::{
29   source::{moderator::*, site::Site},
30   PersonId,
31 };
32 use lemmy_db_views::{
33   comment_view::{CommentQueryBuilder, CommentView},
34   post_view::{PostQueryBuilder, PostView},
35   site_view::SiteView,
36 };
37 use lemmy_db_views_actor::{
38   community_view::{CommunityQueryBuilder, CommunityView},
39   person_view::{PersonQueryBuilder, PersonViewSafe},
40 };
41 use lemmy_db_views_moderator::{
42   mod_add_community_view::ModAddCommunityView,
43   mod_add_view::ModAddView,
44   mod_ban_from_community_view::ModBanFromCommunityView,
45   mod_ban_view::ModBanView,
46   mod_lock_post_view::ModLockPostView,
47   mod_remove_comment_view::ModRemoveCommentView,
48   mod_remove_community_view::ModRemoveCommunityView,
49   mod_remove_post_view::ModRemovePostView,
50   mod_sticky_post_view::ModStickyPostView,
51   mod_transfer_community_view::ModTransferCommunityView,
52 };
53 use lemmy_utils::{
54   location_info,
55   settings::structs::Settings,
56   version,
57   ApiError,
58   ConnectionId,
59   LemmyError,
60 };
61 use lemmy_websocket::LemmyContext;
62
63 #[async_trait::async_trait(?Send)]
64 impl Perform for GetModlog {
65   type Response = GetModlogResponse;
66
67   async fn perform(
68     &self,
69     context: &Data<LemmyContext>,
70     _websocket_id: Option<ConnectionId>,
71   ) -> Result<GetModlogResponse, LemmyError> {
72     let data: &GetModlog = self;
73
74     let community_id = data.community_id;
75     let mod_person_id = data.mod_person_id;
76     let page = data.page;
77     let limit = data.limit;
78     let removed_posts = blocking(context.pool(), move |conn| {
79       ModRemovePostView::list(conn, community_id, mod_person_id, page, limit)
80     })
81     .await??;
82
83     let locked_posts = blocking(context.pool(), move |conn| {
84       ModLockPostView::list(conn, community_id, mod_person_id, page, limit)
85     })
86     .await??;
87
88     let stickied_posts = blocking(context.pool(), move |conn| {
89       ModStickyPostView::list(conn, community_id, mod_person_id, page, limit)
90     })
91     .await??;
92
93     let removed_comments = blocking(context.pool(), move |conn| {
94       ModRemoveCommentView::list(conn, community_id, mod_person_id, page, limit)
95     })
96     .await??;
97
98     let banned_from_community = blocking(context.pool(), move |conn| {
99       ModBanFromCommunityView::list(conn, community_id, mod_person_id, page, limit)
100     })
101     .await??;
102
103     let added_to_community = blocking(context.pool(), move |conn| {
104       ModAddCommunityView::list(conn, community_id, mod_person_id, page, limit)
105     })
106     .await??;
107
108     let transferred_to_community = blocking(context.pool(), move |conn| {
109       ModTransferCommunityView::list(conn, community_id, mod_person_id, page, limit)
110     })
111     .await??;
112
113     // These arrays are only for the full modlog, when a community isn't given
114     let (removed_communities, banned, added) = if data.community_id.is_none() {
115       blocking(context.pool(), move |conn| {
116         Ok((
117           ModRemoveCommunityView::list(conn, mod_person_id, page, limit)?,
118           ModBanView::list(conn, mod_person_id, page, limit)?,
119           ModAddView::list(conn, mod_person_id, page, limit)?,
120         )) as Result<_, LemmyError>
121       })
122       .await??
123     } else {
124       (Vec::new(), Vec::new(), Vec::new())
125     };
126
127     // Return the jwt
128     Ok(GetModlogResponse {
129       removed_posts,
130       locked_posts,
131       stickied_posts,
132       removed_comments,
133       removed_communities,
134       banned_from_community,
135       banned,
136       added_to_community,
137       added,
138       transferred_to_community,
139     })
140   }
141 }
142
143 #[async_trait::async_trait(?Send)]
144 impl Perform for Search {
145   type Response = SearchResponse;
146
147   async fn perform(
148     &self,
149     context: &Data<LemmyContext>,
150     _websocket_id: Option<ConnectionId>,
151   ) -> Result<SearchResponse, LemmyError> {
152     let data: &Search = self;
153
154     let local_user_view =
155       get_local_user_view_from_jwt_opt(&data.auth, context.pool(), context.secret()).await?;
156
157     let show_nsfw = local_user_view.as_ref().map(|t| t.local_user.show_nsfw);
158     let show_bot_accounts = local_user_view
159       .as_ref()
160       .map(|t| t.local_user.show_bot_accounts);
161     let show_read_posts = local_user_view
162       .as_ref()
163       .map(|t| t.local_user.show_read_posts);
164
165     let person_id = local_user_view.map(|u| u.person.id);
166
167     let mut posts = Vec::new();
168     let mut comments = Vec::new();
169     let mut communities = Vec::new();
170     let mut users = Vec::new();
171
172     // TODO no clean / non-nsfw searching rn
173
174     let q = data.q.to_owned();
175     let page = data.page;
176     let limit = data.limit;
177     let sort: Option<SortType> = from_opt_str_to_opt_enum(&data.sort);
178     let listing_type: Option<ListingType> = from_opt_str_to_opt_enum(&data.listing_type);
179     let search_type: SearchType = from_opt_str_to_opt_enum(&data.type_).unwrap_or(SearchType::All);
180     let community_id = data.community_id;
181     let community_actor_id = data
182       .community_name
183       .as_ref()
184       .map(|t| build_actor_id_from_shortname(EndpointType::Community, t, &context.settings()).ok())
185       .unwrap_or(None);
186     let creator_id = data.creator_id;
187     match search_type {
188       SearchType::Posts => {
189         posts = blocking(context.pool(), move |conn| {
190           PostQueryBuilder::create(conn)
191             .sort(sort)
192             .show_nsfw(show_nsfw)
193             .show_bot_accounts(show_bot_accounts)
194             .show_read_posts(show_read_posts)
195             .listing_type(listing_type)
196             .community_id(community_id)
197             .community_actor_id(community_actor_id)
198             .creator_id(creator_id)
199             .my_person_id(person_id)
200             .search_term(q)
201             .page(page)
202             .limit(limit)
203             .list()
204         })
205         .await??;
206       }
207       SearchType::Comments => {
208         comments = blocking(context.pool(), move |conn| {
209           CommentQueryBuilder::create(conn)
210             .sort(sort)
211             .listing_type(listing_type)
212             .search_term(q)
213             .show_bot_accounts(show_bot_accounts)
214             .community_id(community_id)
215             .community_actor_id(community_actor_id)
216             .creator_id(creator_id)
217             .my_person_id(person_id)
218             .page(page)
219             .limit(limit)
220             .list()
221         })
222         .await??;
223       }
224       SearchType::Communities => {
225         communities = blocking(context.pool(), move |conn| {
226           CommunityQueryBuilder::create(conn)
227             .sort(sort)
228             .listing_type(listing_type)
229             .search_term(q)
230             .my_person_id(person_id)
231             .page(page)
232             .limit(limit)
233             .list()
234         })
235         .await??;
236       }
237       SearchType::Users => {
238         users = blocking(context.pool(), move |conn| {
239           PersonQueryBuilder::create(conn)
240             .sort(sort)
241             .search_term(q)
242             .page(page)
243             .limit(limit)
244             .list()
245         })
246         .await??;
247       }
248       SearchType::All => {
249         // If the community or creator is included, dont search communities or users
250         let community_or_creator_included =
251           data.community_id.is_some() || data.community_name.is_some() || data.creator_id.is_some();
252         let community_actor_id_2 = community_actor_id.to_owned();
253
254         posts = blocking(context.pool(), move |conn| {
255           PostQueryBuilder::create(conn)
256             .sort(sort)
257             .show_nsfw(show_nsfw)
258             .show_bot_accounts(show_bot_accounts)
259             .show_read_posts(show_read_posts)
260             .listing_type(listing_type)
261             .community_id(community_id)
262             .community_actor_id(community_actor_id_2)
263             .creator_id(creator_id)
264             .my_person_id(person_id)
265             .search_term(q)
266             .page(page)
267             .limit(limit)
268             .list()
269         })
270         .await??;
271
272         let q = data.q.to_owned();
273         let community_actor_id = community_actor_id.to_owned();
274
275         comments = blocking(context.pool(), move |conn| {
276           CommentQueryBuilder::create(conn)
277             .sort(sort)
278             .listing_type(listing_type)
279             .search_term(q)
280             .show_bot_accounts(show_bot_accounts)
281             .community_id(community_id)
282             .community_actor_id(community_actor_id)
283             .creator_id(creator_id)
284             .my_person_id(person_id)
285             .page(page)
286             .limit(limit)
287             .list()
288         })
289         .await??;
290
291         let q = data.q.to_owned();
292
293         communities = if community_or_creator_included {
294           vec![]
295         } else {
296           blocking(context.pool(), move |conn| {
297             CommunityQueryBuilder::create(conn)
298               .sort(sort)
299               .listing_type(listing_type)
300               .search_term(q)
301               .my_person_id(person_id)
302               .page(page)
303               .limit(limit)
304               .list()
305           })
306           .await??
307         };
308
309         let q = data.q.to_owned();
310
311         users = if community_or_creator_included {
312           vec![]
313         } else {
314           blocking(context.pool(), move |conn| {
315             PersonQueryBuilder::create(conn)
316               .sort(sort)
317               .search_term(q)
318               .page(page)
319               .limit(limit)
320               .list()
321           })
322           .await??
323         };
324       }
325       SearchType::Url => {
326         posts = blocking(context.pool(), move |conn| {
327           PostQueryBuilder::create(conn)
328             .sort(sort)
329             .show_nsfw(show_nsfw)
330             .show_bot_accounts(show_bot_accounts)
331             .show_read_posts(show_read_posts)
332             .listing_type(listing_type)
333             .my_person_id(person_id)
334             .community_id(community_id)
335             .community_actor_id(community_actor_id)
336             .creator_id(creator_id)
337             .url_search(q)
338             .page(page)
339             .limit(limit)
340             .list()
341         })
342         .await??;
343       }
344     };
345
346     // Blank out deleted or removed info
347     for cv in comments
348       .iter_mut()
349       .filter(|cv| cv.comment.deleted || cv.comment.removed)
350     {
351       cv.comment = cv.to_owned().comment.blank_out_deleted_or_removed_info();
352     }
353
354     for cv in communities
355       .iter_mut()
356       .filter(|cv| cv.community.deleted || cv.community.removed)
357     {
358       cv.community = cv.to_owned().community.blank_out_deleted_or_removed_info();
359     }
360
361     for pv in posts
362       .iter_mut()
363       .filter(|p| p.post.deleted || p.post.removed)
364     {
365       pv.post = pv.to_owned().post.blank_out_deleted_or_removed_info();
366     }
367
368     // Return the jwt
369     Ok(SearchResponse {
370       type_: search_type.to_string(),
371       comments,
372       posts,
373       communities,
374       users,
375     })
376   }
377 }
378
379 #[async_trait::async_trait(?Send)]
380 impl Perform for ResolveObject {
381   type Response = ResolveObjectResponse;
382
383   async fn perform(
384     &self,
385     context: &Data<LemmyContext>,
386     _websocket_id: Option<ConnectionId>,
387   ) -> Result<ResolveObjectResponse, LemmyError> {
388     let local_user_view =
389       get_local_user_view_from_jwt_opt(&self.auth, context.pool(), context.secret()).await?;
390     let res = search_by_apub_id(&self.q, context)
391       .await
392       .map_err(|_| ApiError::err("couldnt_find_object"))?;
393     convert_response(res, local_user_view.map(|l| l.person.id), context.pool())
394       .await
395       .map_err(|_| ApiError::err("couldnt_find_object").into())
396   }
397 }
398
399 async fn convert_response(
400   object: SearchableObjects,
401   user_id: Option<PersonId>,
402   pool: &DbPool,
403 ) -> Result<ResolveObjectResponse, LemmyError> {
404   let removed_or_deleted;
405   let mut res = ResolveObjectResponse {
406     comment: None,
407     post: None,
408     community: None,
409     person: None,
410   };
411   use SearchableObjects::*;
412   match object {
413     Person(p) => {
414       removed_or_deleted = p.deleted;
415       res.person = Some(blocking(pool, move |conn| PersonViewSafe::read(conn, p.id)).await??)
416     }
417     Community(c) => {
418       removed_or_deleted = c.deleted || c.removed;
419       res.community =
420         Some(blocking(pool, move |conn| CommunityView::read(conn, c.id, user_id)).await??)
421     }
422     Post(p) => {
423       removed_or_deleted = p.deleted || p.removed;
424       res.post = Some(blocking(pool, move |conn| PostView::read(conn, p.id, user_id)).await??)
425     }
426     Comment(c) => {
427       removed_or_deleted = c.deleted || c.removed;
428       res.comment = Some(blocking(pool, move |conn| CommentView::read(conn, c.id, user_id)).await??)
429     }
430   };
431   // if the object was deleted from database, dont return it
432   if removed_or_deleted {
433     return Err(NotFound {}.into());
434   }
435   Ok(res)
436 }
437
438 #[async_trait::async_trait(?Send)]
439 impl Perform for TransferSite {
440   type Response = GetSiteResponse;
441
442   async fn perform(
443     &self,
444     context: &Data<LemmyContext>,
445     _websocket_id: Option<ConnectionId>,
446   ) -> Result<GetSiteResponse, LemmyError> {
447     let data: &TransferSite = self;
448     let local_user_view =
449       get_local_user_view_from_jwt(&data.auth, context.pool(), context.secret()).await?;
450
451     is_admin(&local_user_view)?;
452
453     let read_site = blocking(context.pool(), move |conn| Site::read_simple(conn)).await??;
454
455     // Make sure user is the creator
456     if read_site.creator_id != local_user_view.person.id {
457       return Err(ApiError::err("not_an_admin").into());
458     }
459
460     let new_creator_id = data.person_id;
461     let transfer_site = move |conn: &'_ _| Site::transfer(conn, new_creator_id);
462     if blocking(context.pool(), transfer_site).await?.is_err() {
463       return Err(ApiError::err("couldnt_update_site").into());
464     };
465
466     // Mod tables
467     let form = ModAddForm {
468       mod_person_id: local_user_view.person.id,
469       other_person_id: data.person_id,
470       removed: Some(false),
471     };
472
473     blocking(context.pool(), move |conn| ModAdd::create(conn, &form)).await??;
474
475     let site_view = blocking(context.pool(), move |conn| SiteView::read(conn)).await??;
476
477     let mut admins = blocking(context.pool(), move |conn| PersonViewSafe::admins(conn)).await??;
478     let creator_index = admins
479       .iter()
480       .position(|r| r.person.id == site_view.creator.id)
481       .context(location_info!())?;
482     let creator_person = admins.remove(creator_index);
483     admins.insert(0, creator_person);
484
485     let banned = blocking(context.pool(), move |conn| PersonViewSafe::banned(conn)).await??;
486     let federated_instances = build_federated_instances(
487       context.pool(),
488       &context.settings().federation,
489       &context.settings().hostname,
490     )
491     .await?;
492
493     Ok(GetSiteResponse {
494       site_view: Some(site_view),
495       admins,
496       banned,
497       online: 0,
498       version: version::VERSION.to_string(),
499       my_user: None,
500       federated_instances,
501     })
502   }
503 }
504
505 #[async_trait::async_trait(?Send)]
506 impl Perform for GetSiteConfig {
507   type Response = GetSiteConfigResponse;
508
509   async fn perform(
510     &self,
511     context: &Data<LemmyContext>,
512     _websocket_id: Option<ConnectionId>,
513   ) -> Result<GetSiteConfigResponse, LemmyError> {
514     let data: &GetSiteConfig = self;
515     let local_user_view =
516       get_local_user_view_from_jwt(&data.auth, context.pool(), context.secret()).await?;
517
518     // Only let admins read this
519     is_admin(&local_user_view)?;
520
521     let config_hjson = Settings::read_config_file()?;
522
523     Ok(GetSiteConfigResponse { config_hjson })
524   }
525 }
526
527 #[async_trait::async_trait(?Send)]
528 impl Perform for SaveSiteConfig {
529   type Response = GetSiteConfigResponse;
530
531   async fn perform(
532     &self,
533     context: &Data<LemmyContext>,
534     _websocket_id: Option<ConnectionId>,
535   ) -> Result<GetSiteConfigResponse, LemmyError> {
536     let data: &SaveSiteConfig = self;
537     let local_user_view =
538       get_local_user_view_from_jwt(&data.auth, context.pool(), context.secret()).await?;
539
540     // Only let admins read this
541     is_admin(&local_user_view)?;
542
543     // Make sure docker doesn't have :ro at the end of the volume, so its not a read-only filesystem
544     let config_hjson = Settings::save_config_file(&data.config_hjson)
545       .map_err(|_| ApiError::err("couldnt_update_site"))?;
546
547     Ok(GetSiteConfigResponse { config_hjson })
548   }
549 }