]> Untitled Git - lemmy.git/blob - crates/api_crud/src/site/update.rs
6148d546eb22c6d15563197f81c44430aa5b14ef
[lemmy.git] / crates / api_crud / src / site / update.rs
1 use crate::site::{application_question_check, site_default_post_listing_type_check};
2 use actix_web::web::{Data, Json};
3 use lemmy_api_common::{
4   context::LemmyContext,
5   site::{EditSite, SiteResponse},
6   utils::{
7     is_admin,
8     local_site_rate_limit_to_rate_limit_config,
9     local_user_view_from_jwt,
10     sanitize_html_opt,
11   },
12 };
13 use lemmy_db_schema::{
14   source::{
15     actor_language::SiteLanguage,
16     federation_allowlist::FederationAllowList,
17     federation_blocklist::FederationBlockList,
18     local_site::{LocalSite, LocalSiteUpdateForm},
19     local_site_rate_limit::{LocalSiteRateLimit, LocalSiteRateLimitUpdateForm},
20     local_user::LocalUser,
21     site::{Site, SiteUpdateForm},
22     tagline::Tagline,
23   },
24   traits::Crud,
25   utils::{diesel_option_overwrite, diesel_option_overwrite_to_url, naive_now},
26   RegistrationMode,
27 };
28 use lemmy_db_views::structs::SiteView;
29 use lemmy_utils::{
30   error::{LemmyError, LemmyErrorExt, LemmyErrorType, LemmyResult},
31   utils::{
32     slurs::check_slurs_opt,
33     validation::{
34       build_and_check_regex,
35       check_site_visibility_valid,
36       is_valid_body_field,
37       site_description_length_check,
38       site_name_length_check,
39     },
40   },
41 };
42
43 #[tracing::instrument(skip(context))]
44 pub async fn update_site(
45   data: Json<EditSite>,
46   context: Data<LemmyContext>,
47 ) -> Result<Json<SiteResponse>, LemmyError> {
48   let local_user_view = local_user_view_from_jwt(&data.auth, &context).await?;
49   let site_view = SiteView::read_local(&mut context.pool()).await?;
50   let local_site = site_view.local_site;
51   let site = site_view.site;
52
53   // Make sure user is an admin; other types of users should not update site data...
54   is_admin(&local_user_view)?;
55
56   validate_update_payload(&local_site, &data)?;
57
58   if let Some(discussion_languages) = data.discussion_languages.clone() {
59     SiteLanguage::update(&mut context.pool(), discussion_languages.clone(), &site).await?;
60   }
61
62   let name = sanitize_html_opt(&data.name);
63   let sidebar = sanitize_html_opt(&data.sidebar);
64   let description = sanitize_html_opt(&data.description);
65
66   let site_form = SiteUpdateForm {
67     name,
68     sidebar: diesel_option_overwrite(sidebar),
69     description: diesel_option_overwrite(description),
70     icon: diesel_option_overwrite_to_url(&data.icon)?,
71     banner: diesel_option_overwrite_to_url(&data.banner)?,
72     updated: Some(Some(naive_now())),
73     ..Default::default()
74   };
75
76   Site::update(&mut context.pool(), site.id, &site_form)
77     .await
78     // Ignore errors for all these, so as to not throw errors if no update occurs
79     // Diesel will throw an error for empty update forms
80     .ok();
81
82   let application_question = sanitize_html_opt(&data.application_question);
83   let default_theme = sanitize_html_opt(&data.default_theme);
84   let legal_information = sanitize_html_opt(&data.legal_information);
85
86   let local_site_form = LocalSiteUpdateForm {
87     enable_downvotes: data.enable_downvotes,
88     registration_mode: data.registration_mode,
89     enable_nsfw: data.enable_nsfw,
90     community_creation_admin_only: data.community_creation_admin_only,
91     require_email_verification: data.require_email_verification,
92     application_question: diesel_option_overwrite(application_question),
93     private_instance: data.private_instance,
94     default_theme,
95     default_post_listing_type: data.default_post_listing_type,
96     legal_information: diesel_option_overwrite(legal_information),
97     application_email_admins: data.application_email_admins,
98     hide_modlog_mod_names: data.hide_modlog_mod_names,
99     updated: Some(Some(naive_now())),
100     slur_filter_regex: diesel_option_overwrite(data.slur_filter_regex.clone()),
101     actor_name_max_length: data.actor_name_max_length,
102     federation_enabled: data.federation_enabled,
103     captcha_enabled: data.captcha_enabled,
104     captcha_difficulty: data.captcha_difficulty.clone(),
105     reports_email_admins: data.reports_email_admins,
106     ..Default::default()
107   };
108
109   let update_local_site = LocalSite::update(&mut context.pool(), &local_site_form)
110     .await
111     .ok();
112
113   let local_site_rate_limit_form = LocalSiteRateLimitUpdateForm {
114     message: data.rate_limit_message,
115     message_per_second: data.rate_limit_message_per_second,
116     post: data.rate_limit_post,
117     post_per_second: data.rate_limit_post_per_second,
118     register: data.rate_limit_register,
119     register_per_second: data.rate_limit_register_per_second,
120     image: data.rate_limit_image,
121     image_per_second: data.rate_limit_image_per_second,
122     comment: data.rate_limit_comment,
123     comment_per_second: data.rate_limit_comment_per_second,
124     search: data.rate_limit_search,
125     search_per_second: data.rate_limit_search_per_second,
126     ..Default::default()
127   };
128
129   LocalSiteRateLimit::update(&mut context.pool(), &local_site_rate_limit_form)
130     .await
131     .ok();
132
133   // Replace the blocked and allowed instances
134   let allowed = data.allowed_instances.clone();
135   FederationAllowList::replace(&mut context.pool(), allowed).await?;
136   let blocked = data.blocked_instances.clone();
137   FederationBlockList::replace(&mut context.pool(), blocked).await?;
138
139   // TODO can't think of a better way to do this.
140   // If the server suddenly requires email verification, or required applications, no old users
141   // will be able to log in. It really only wants this to be a requirement for NEW signups.
142   // So if it was set from false, to true, you need to update all current users columns to be verified.
143
144   let old_require_application =
145     local_site.registration_mode == RegistrationMode::RequireApplication;
146   let new_require_application = update_local_site
147     .as_ref()
148     .map(|ols| ols.registration_mode == RegistrationMode::RequireApplication)
149     .unwrap_or(false);
150   if !old_require_application && new_require_application {
151     LocalUser::set_all_users_registration_applications_accepted(&mut context.pool())
152       .await
153       .with_lemmy_type(LemmyErrorType::CouldntSetAllRegistrationsAccepted)?;
154   }
155
156   let new_require_email_verification = update_local_site
157     .as_ref()
158     .map(|ols| ols.require_email_verification)
159     .unwrap_or(false);
160   if !local_site.require_email_verification && new_require_email_verification {
161     LocalUser::set_all_users_email_verified(&mut context.pool())
162       .await
163       .with_lemmy_type(LemmyErrorType::CouldntSetAllEmailVerified)?;
164   }
165
166   let new_taglines = data.taglines.clone();
167   let taglines = Tagline::replace(&mut context.pool(), local_site.id, new_taglines).await?;
168
169   let site_view = SiteView::read_local(&mut context.pool()).await?;
170
171   let rate_limit_config =
172     local_site_rate_limit_to_rate_limit_config(&site_view.local_site_rate_limit);
173   context
174     .settings_updated_channel()
175     .send(rate_limit_config)
176     .await?;
177
178   Ok(Json(SiteResponse {
179     site_view,
180     taglines,
181   }))
182 }
183
184 fn validate_update_payload(local_site: &LocalSite, edit_site: &EditSite) -> LemmyResult<()> {
185   // Check that the slur regex compiles, and return the regex if valid...
186   // Prioritize using new slur regex from the request; if not provided, use the existing regex.
187   let slur_regex = build_and_check_regex(
188     &edit_site
189       .slur_filter_regex
190       .as_deref()
191       .or(local_site.slur_filter_regex.as_deref()),
192   )?;
193
194   if let Some(name) = &edit_site.name {
195     // The name doesn't need to be updated, but if provided it cannot be blanked out...
196     site_name_length_check(name)?;
197     check_slurs_opt(&edit_site.name, &slur_regex)?;
198   }
199
200   if let Some(desc) = &edit_site.description {
201     site_description_length_check(desc)?;
202     check_slurs_opt(&edit_site.description, &slur_regex)?;
203   }
204
205   site_default_post_listing_type_check(&edit_site.default_post_listing_type)?;
206
207   check_site_visibility_valid(
208     local_site.private_instance,
209     local_site.federation_enabled,
210     &edit_site.private_instance,
211     &edit_site.federation_enabled,
212   )?;
213
214   // Ensure that the sidebar has fewer than the max num characters...
215   is_valid_body_field(&edit_site.sidebar, false)?;
216
217   application_question_check(
218     &local_site.application_question,
219     &edit_site.application_question,
220     edit_site
221       .registration_mode
222       .unwrap_or(local_site.registration_mode),
223   )
224 }
225
226 #[cfg(test)]
227 mod tests {
228   #![allow(clippy::unwrap_used)]
229   #![allow(clippy::indexing_slicing)]
230
231   use crate::site::update::validate_update_payload;
232   use lemmy_api_common::site::EditSite;
233   use lemmy_db_schema::{source::local_site::LocalSite, ListingType, RegistrationMode};
234   use lemmy_utils::error::LemmyErrorType;
235
236   #[test]
237   fn test_validate_invalid_update_payload() {
238     let invalid_payloads = [
239       (
240         "EditSite name matches LocalSite slur filter",
241         LemmyErrorType::Slurs,
242         &generate_local_site(
243           Some(String::from("(foo|bar)")),
244           true,
245           false,
246           None::<String>,
247           RegistrationMode::Open,
248         ),
249         &generate_edit_site(
250           Some(String::from("foo site_name")),
251           None::<String>,
252           None::<String>,
253           None::<ListingType>,
254           None::<String>,
255           None::<bool>,
256           None::<bool>,
257           None::<String>,
258           None::<RegistrationMode>,
259         ),
260       ),
261       (
262         "EditSite name matches new slur filter",
263         LemmyErrorType::Slurs,
264         &generate_local_site(
265           Some(String::from("(foo|bar)")),
266           true,
267           false,
268           None::<String>,
269           RegistrationMode::Open,
270         ),
271         &generate_edit_site(
272           Some(String::from("zeta site_name")),
273           None::<String>,
274           None::<String>,
275           None::<ListingType>,
276           Some(String::from("(zeta|alpha)")),
277           None::<bool>,
278           None::<bool>,
279           None::<String>,
280           None::<RegistrationMode>,
281         ),
282       ),
283       (
284         "EditSite listing type is Subscribed, which is invalid",
285         LemmyErrorType::InvalidDefaultPostListingType,
286         &generate_local_site(
287           None::<String>,
288           true,
289           false,
290           None::<String>,
291           RegistrationMode::Open,
292         ),
293         &generate_edit_site(
294           Some(String::from("site_name")),
295           None::<String>,
296           None::<String>,
297           Some(ListingType::Subscribed),
298           None::<String>,
299           None::<bool>,
300           None::<bool>,
301           None::<String>,
302           None::<RegistrationMode>,
303         ),
304       ),
305       (
306         "EditSite is both private and federated",
307         LemmyErrorType::CantEnablePrivateInstanceAndFederationTogether,
308         &generate_local_site(
309           None::<String>,
310           true,
311           false,
312           None::<String>,
313           RegistrationMode::Open,
314         ),
315         &generate_edit_site(
316           Some(String::from("site_name")),
317           None::<String>,
318           None::<String>,
319           None::<ListingType>,
320           None::<String>,
321           Some(true),
322           Some(true),
323           None::<String>,
324           None::<RegistrationMode>,
325         ),
326       ),
327       (
328         "LocalSite is private, but EditSite also makes it federated",
329         LemmyErrorType::CantEnablePrivateInstanceAndFederationTogether,
330         &generate_local_site(
331           None::<String>,
332           true,
333           false,
334           None::<String>,
335           RegistrationMode::Open,
336         ),
337         &generate_edit_site(
338           Some(String::from("site_name")),
339           None::<String>,
340           None::<String>,
341           None::<ListingType>,
342           None::<String>,
343           None::<bool>,
344           Some(true),
345           None::<String>,
346           None::<RegistrationMode>,
347         ),
348       ),
349       (
350         "EditSite requires application, but neither it nor LocalSite has an application question",
351         LemmyErrorType::ApplicationQuestionRequired,
352         &generate_local_site(
353           None::<String>,
354           true,
355           false,
356           None::<String>,
357           RegistrationMode::Open,
358         ),
359         &generate_edit_site(
360           Some(String::from("site_name")),
361           None::<String>,
362           None::<String>,
363           None::<ListingType>,
364           None::<String>,
365           None::<bool>,
366           None::<bool>,
367           None::<String>,
368           Some(RegistrationMode::RequireApplication),
369         ),
370       ),
371     ];
372
373     invalid_payloads.iter().enumerate().for_each(
374       |(
375          idx,
376          &(reason, ref expected_err, local_site, edit_site),
377        )| {
378         match validate_update_payload(local_site, edit_site) {
379           Ok(_) => {
380             panic!(
381               "Got Ok, but validation should have failed with error: {} for reason: {}. invalid_payloads.nth({})",
382               expected_err, reason, idx
383             )
384           }
385           Err(error) => {
386             assert!(
387               error.error_type.eq(&expected_err.clone()),
388               "Got Err {:?}, but should have failed with message: {} for reason: {}. invalid_payloads.nth({})",
389               error.error_type,
390               expected_err,
391               reason,
392               idx
393             )
394           }
395         }
396       },
397     );
398   }
399
400   #[test]
401   fn test_validate_valid_update_payload() {
402     let valid_payloads = [
403       (
404         "No changes between LocalSite and EditSite",
405         &generate_local_site(
406           None::<String>,
407           true,
408           false,
409           None::<String>,
410           RegistrationMode::Open,
411         ),
412         &generate_edit_site(
413           None::<String>,
414           None::<String>,
415           None::<String>,
416           None::<ListingType>,
417           None::<String>,
418           None::<bool>,
419           None::<bool>,
420           None::<String>,
421           None::<RegistrationMode>,
422         ),
423       ),
424       (
425         "EditSite allows clearing and changing values",
426         &generate_local_site(
427           None::<String>,
428           true,
429           false,
430           None::<String>,
431           RegistrationMode::Open,
432         ),
433         &generate_edit_site(
434           Some(String::from("site_name")),
435           Some(String::new()),
436           Some(String::new()),
437           Some(ListingType::All),
438           Some(String::new()),
439           Some(false),
440           Some(true),
441           Some(String::new()),
442           Some(RegistrationMode::Open),
443         ),
444       ),
445       (
446         "EditSite name passes slur filter regex",
447         &generate_local_site(
448           Some(String::from("(foo|bar)")),
449           true,
450           false,
451           None::<String>,
452           RegistrationMode::Open,
453         ),
454         &generate_edit_site(
455           Some(String::from("foo site_name")),
456           None::<String>,
457           None::<String>,
458           None::<ListingType>,
459           Some(String::new()),
460           None::<bool>,
461           None::<bool>,
462           None::<String>,
463           None::<RegistrationMode>,
464         ),
465       ),
466       (
467         "LocalSite has application question and EditSite now requires applications,",
468         &generate_local_site(
469           None::<String>,
470           true,
471           false,
472           Some(String::from("question")),
473           RegistrationMode::Open,
474         ),
475         &generate_edit_site(
476           Some(String::from("site_name")),
477           None::<String>,
478           None::<String>,
479           None::<ListingType>,
480           None::<String>,
481           None::<bool>,
482           None::<bool>,
483           None::<String>,
484           Some(RegistrationMode::RequireApplication),
485         ),
486       ),
487     ];
488
489     valid_payloads
490       .iter()
491       .enumerate()
492       .for_each(|(idx, &(reason, local_site, edit_site))| {
493         assert!(
494           validate_update_payload(local_site, edit_site).is_ok(),
495           "Got Err, but should have got Ok for reason: {}. valid_payloads.nth({})",
496           reason,
497           idx
498         );
499       })
500   }
501
502   fn generate_local_site(
503     site_slur_filter_regex: Option<String>,
504     site_is_private: bool,
505     site_is_federated: bool,
506     site_application_question: Option<String>,
507     site_registration_mode: RegistrationMode,
508   ) -> LocalSite {
509     LocalSite {
510       id: Default::default(),
511       site_id: Default::default(),
512       site_setup: true,
513       enable_downvotes: false,
514       enable_nsfw: false,
515       community_creation_admin_only: false,
516       require_email_verification: false,
517       application_question: site_application_question,
518       private_instance: site_is_private,
519       default_theme: String::new(),
520       default_post_listing_type: ListingType::All,
521       legal_information: None,
522       hide_modlog_mod_names: false,
523       application_email_admins: false,
524       slur_filter_regex: site_slur_filter_regex,
525       actor_name_max_length: 0,
526       federation_enabled: site_is_federated,
527       captcha_enabled: false,
528       captcha_difficulty: String::new(),
529       published: Default::default(),
530       updated: None,
531       registration_mode: site_registration_mode,
532       reports_email_admins: false,
533     }
534   }
535
536   // Allow the test helper function to have too many arguments.
537   // It's either this or generate the entire struct each time for testing.
538   #[allow(clippy::too_many_arguments)]
539   fn generate_edit_site(
540     site_name: Option<String>,
541     site_description: Option<String>,
542     site_sidebar: Option<String>,
543     site_listing_type: Option<ListingType>,
544     site_slur_filter_regex: Option<String>,
545     site_is_private: Option<bool>,
546     site_is_federated: Option<bool>,
547     site_application_question: Option<String>,
548     site_registration_mode: Option<RegistrationMode>,
549   ) -> EditSite {
550     EditSite {
551       name: site_name,
552       sidebar: site_sidebar,
553       description: site_description,
554       icon: None,
555       banner: None,
556       enable_downvotes: None,
557       enable_nsfw: None,
558       community_creation_admin_only: None,
559       require_email_verification: None,
560       application_question: site_application_question,
561       private_instance: site_is_private,
562       default_theme: None,
563       default_post_listing_type: site_listing_type,
564       legal_information: None,
565       application_email_admins: None,
566       hide_modlog_mod_names: None,
567       discussion_languages: None,
568       slur_filter_regex: site_slur_filter_regex,
569       actor_name_max_length: None,
570       rate_limit_message: None,
571       rate_limit_message_per_second: None,
572       rate_limit_post: None,
573       rate_limit_post_per_second: None,
574       rate_limit_register: None,
575       rate_limit_register_per_second: None,
576       rate_limit_image: None,
577       rate_limit_image_per_second: None,
578       rate_limit_comment: None,
579       rate_limit_comment_per_second: None,
580       rate_limit_search: None,
581       rate_limit_search_per_second: None,
582       federation_enabled: site_is_federated,
583       federation_debug: None,
584       captcha_enabled: None,
585       captcha_difficulty: None,
586       allowed_instances: None,
587       blocked_instances: None,
588       taglines: None,
589       registration_mode: site_registration_mode,
590       reports_email_admins: None,
591       auth: Default::default(),
592     }
593   }
594 }