]> Untitled Git - lemmy.git/blob - crates/api_crud/src/site/update.rs
Prevent making an instance private if federation is enabled. (#3074)
[lemmy.git] / crates / api_crud / src / site / update.rs
1 use crate::{site::check_application_question, PerformCrud};
2 use actix_web::web::Data;
3 use lemmy_api_common::{
4   context::LemmyContext,
5   site::{EditSite, SiteResponse},
6   utils::{
7     is_admin,
8     local_site_rate_limit_to_rate_limit_config,
9     local_site_to_slur_regex,
10     local_user_view_from_jwt,
11     site_description_length_check,
12   },
13 };
14 use lemmy_db_schema::{
15   source::{
16     actor_language::SiteLanguage,
17     federation_allowlist::FederationAllowList,
18     federation_blocklist::FederationBlockList,
19     local_site::{LocalSite, LocalSiteUpdateForm},
20     local_site_rate_limit::{LocalSiteRateLimit, LocalSiteRateLimitUpdateForm},
21     local_user::LocalUser,
22     site::{Site, SiteUpdateForm},
23     tagline::Tagline,
24   },
25   traits::Crud,
26   utils::{diesel_option_overwrite, diesel_option_overwrite_to_url, naive_now},
27   ListingType,
28   RegistrationMode,
29 };
30 use lemmy_db_views::structs::SiteView;
31 use lemmy_utils::{
32   error::LemmyError,
33   utils::{slurs::check_slurs_opt, validation::is_valid_body_field},
34 };
35
36 #[async_trait::async_trait(?Send)]
37 impl PerformCrud for EditSite {
38   type Response = SiteResponse;
39
40   #[tracing::instrument(skip(context))]
41   async fn perform(&self, context: &Data<LemmyContext>) -> Result<SiteResponse, LemmyError> {
42     let data: &EditSite = self;
43     let local_user_view = local_user_view_from_jwt(&data.auth, context).await?;
44     let site_view = SiteView::read_local(context.pool()).await?;
45     let local_site = site_view.local_site;
46     let site = site_view.site;
47
48     // Make sure user is an admin
49     is_admin(&local_user_view)?;
50
51     let slur_regex = local_site_to_slur_regex(&local_site);
52
53     check_slurs_opt(&data.name, &slur_regex)?;
54     check_slurs_opt(&data.description, &slur_regex)?;
55
56     if let Some(desc) = &data.description {
57       site_description_length_check(desc)?;
58     }
59
60     is_valid_body_field(&data.sidebar)?;
61
62     let application_question = diesel_option_overwrite(&data.application_question);
63     check_application_question(
64       &application_question,
65       data
66         .registration_mode
67         .unwrap_or(local_site.registration_mode),
68     )?;
69
70     if let Some(listing_type) = &data.default_post_listing_type {
71       // only allow all or local as default listing types
72       if listing_type != &ListingType::All && listing_type != &ListingType::Local {
73         return Err(LemmyError::from_message(
74           "invalid_default_post_listing_type",
75         ));
76       }
77     }
78
79     let enabled_private_instance_with_federation = data.private_instance == Some(true)
80       && data
81         .federation_enabled
82         .unwrap_or(local_site.federation_enabled);
83     let enabled_federation_with_private_instance = data.federation_enabled == Some(true)
84       && data.private_instance.unwrap_or(local_site.private_instance);
85
86     if enabled_private_instance_with_federation || enabled_federation_with_private_instance {
87       return Err(LemmyError::from_message(
88         "cant_enable_private_instance_and_federation_together",
89       ));
90     }
91
92     if let Some(discussion_languages) = data.discussion_languages.clone() {
93       SiteLanguage::update(context.pool(), discussion_languages.clone(), &site).await?;
94     }
95
96     let name = data.name.clone();
97     let site_form = SiteUpdateForm::builder()
98       .name(name)
99       .sidebar(diesel_option_overwrite(&data.sidebar))
100       .description(diesel_option_overwrite(&data.description))
101       .icon(diesel_option_overwrite_to_url(&data.icon)?)
102       .banner(diesel_option_overwrite_to_url(&data.banner)?)
103       .updated(Some(Some(naive_now())))
104       .build();
105
106     Site::update(context.pool(), site.id, &site_form)
107       .await
108       // Ignore errors for all these, so as to not throw errors if no update occurs
109       // Diesel will throw an error for empty update forms
110       .ok();
111
112     let local_site_form = LocalSiteUpdateForm::builder()
113       .enable_downvotes(data.enable_downvotes)
114       .registration_mode(data.registration_mode)
115       .enable_nsfw(data.enable_nsfw)
116       .community_creation_admin_only(data.community_creation_admin_only)
117       .require_email_verification(data.require_email_verification)
118       .application_question(application_question)
119       .private_instance(data.private_instance)
120       .default_theme(data.default_theme.clone())
121       .default_post_listing_type(data.default_post_listing_type)
122       .legal_information(diesel_option_overwrite(&data.legal_information))
123       .application_email_admins(data.application_email_admins)
124       .hide_modlog_mod_names(data.hide_modlog_mod_names)
125       .updated(Some(Some(naive_now())))
126       .slur_filter_regex(diesel_option_overwrite(&data.slur_filter_regex))
127       .actor_name_max_length(data.actor_name_max_length)
128       .federation_enabled(data.federation_enabled)
129       .federation_worker_count(data.federation_worker_count)
130       .captcha_enabled(data.captcha_enabled)
131       .captcha_difficulty(data.captcha_difficulty.clone())
132       .reports_email_admins(data.reports_email_admins)
133       .build();
134
135     let update_local_site = LocalSite::update(context.pool(), &local_site_form)
136       .await
137       .ok();
138
139     let local_site_rate_limit_form = LocalSiteRateLimitUpdateForm::builder()
140       .message(data.rate_limit_message)
141       .message_per_second(data.rate_limit_message_per_second)
142       .post(data.rate_limit_post)
143       .post_per_second(data.rate_limit_post_per_second)
144       .register(data.rate_limit_register)
145       .register_per_second(data.rate_limit_register_per_second)
146       .image(data.rate_limit_image)
147       .image_per_second(data.rate_limit_image_per_second)
148       .comment(data.rate_limit_comment)
149       .comment_per_second(data.rate_limit_comment_per_second)
150       .search(data.rate_limit_search)
151       .search_per_second(data.rate_limit_search_per_second)
152       .build();
153
154     LocalSiteRateLimit::update(context.pool(), &local_site_rate_limit_form)
155       .await
156       .ok();
157
158     // Replace the blocked and allowed instances
159     let allowed = data.allowed_instances.clone();
160     FederationAllowList::replace(context.pool(), allowed).await?;
161     let blocked = data.blocked_instances.clone();
162     FederationBlockList::replace(context.pool(), blocked).await?;
163
164     // TODO can't think of a better way to do this.
165     // If the server suddenly requires email verification, or required applications, no old users
166     // will be able to log in. It really only wants this to be a requirement for NEW signups.
167     // So if it was set from false, to true, you need to update all current users columns to be verified.
168
169     let old_require_application =
170       local_site.registration_mode == RegistrationMode::RequireApplication;
171     let new_require_application = update_local_site
172       .as_ref()
173       .map(|ols| ols.registration_mode == RegistrationMode::RequireApplication)
174       .unwrap_or(false);
175     if !old_require_application && new_require_application {
176       LocalUser::set_all_users_registration_applications_accepted(context.pool())
177         .await
178         .map_err(|e| LemmyError::from_error_message(e, "couldnt_set_all_registrations_accepted"))?;
179     }
180
181     let new_require_email_verification = update_local_site
182       .as_ref()
183       .map(|ols| ols.require_email_verification)
184       .unwrap_or(false);
185     if !local_site.require_email_verification && new_require_email_verification {
186       LocalUser::set_all_users_email_verified(context.pool())
187         .await
188         .map_err(|e| LemmyError::from_error_message(e, "couldnt_set_all_email_verified"))?;
189     }
190
191     let new_taglines = data.taglines.clone();
192     let taglines = Tagline::replace(context.pool(), local_site.id, new_taglines).await?;
193
194     let site_view = SiteView::read_local(context.pool()).await?;
195
196     let rate_limit_config =
197       local_site_rate_limit_to_rate_limit_config(&site_view.local_site_rate_limit);
198     context
199       .settings_updated_channel()
200       .send(rate_limit_config)
201       .await?;
202
203     let res = SiteResponse {
204       site_view,
205       taglines,
206     };
207
208     Ok(res)
209   }
210 }