]> Untitled Git - lemmy.git/blob - src/api_routes.rs
Adding a captcha rate limit. Fixes #1755 (#1941)
[lemmy.git] / src / api_routes.rs
1 use actix_web::{error::ErrorBadRequest, *};
2 use lemmy_api::Perform;
3 use lemmy_api_common::{comment::*, community::*, person::*, post::*, site::*, websocket::*};
4 use lemmy_api_crud::PerformCrud;
5 use lemmy_utils::rate_limit::RateLimit;
6 use lemmy_websocket::{routes::chat_route, LemmyContext};
7 use serde::Deserialize;
8
9 pub fn config(cfg: &mut web::ServiceConfig, rate_limit: &RateLimit) {
10   cfg.service(
11     web::scope("/api/v3")
12       // Websocket
13       .service(web::resource("/ws").to(chat_route))
14       // Site
15       .service(
16         web::scope("/site")
17           .wrap(rate_limit.message())
18           .route("", web::get().to(route_get_crud::<GetSite>))
19           // Admin Actions
20           .route("", web::post().to(route_post_crud::<CreateSite>))
21           .route("", web::put().to(route_post_crud::<EditSite>))
22           .route("/transfer", web::post().to(route_post::<TransferSite>))
23           .route("/config", web::get().to(route_get::<GetSiteConfig>))
24           .route("/config", web::put().to(route_post::<SaveSiteConfig>)),
25       )
26       .service(
27         web::resource("/modlog")
28           .wrap(rate_limit.message())
29           .route(web::get().to(route_get::<GetModlog>)),
30       )
31       .service(
32         web::resource("/search")
33           .wrap(rate_limit.message())
34           .route(web::get().to(route_get::<Search>)),
35       )
36       .service(
37         web::resource("/resolve_object")
38           .wrap(rate_limit.message())
39           .route(web::get().to(route_get::<ResolveObject>)),
40       )
41       // Community
42       .service(
43         web::resource("/community")
44           .guard(guard::Post())
45           .wrap(rate_limit.register())
46           .route(web::post().to(route_post_crud::<CreateCommunity>)),
47       )
48       .service(
49         web::scope("/community")
50           .wrap(rate_limit.message())
51           .route("", web::get().to(route_get_crud::<GetCommunity>))
52           .route("", web::put().to(route_post_crud::<EditCommunity>))
53           .route("/list", web::get().to(route_get_crud::<ListCommunities>))
54           .route("/follow", web::post().to(route_post::<FollowCommunity>))
55           .route("/block", web::post().to(route_post::<BlockCommunity>))
56           .route(
57             "/delete",
58             web::post().to(route_post_crud::<DeleteCommunity>),
59           )
60           // Mod Actions
61           .route(
62             "/remove",
63             web::post().to(route_post_crud::<RemoveCommunity>),
64           )
65           .route("/transfer", web::post().to(route_post::<TransferCommunity>))
66           .route("/ban_user", web::post().to(route_post::<BanFromCommunity>))
67           .route("/mod", web::post().to(route_post::<AddModToCommunity>))
68           .route("/join", web::post().to(route_post::<CommunityJoin>))
69           .route("/mod/join", web::post().to(route_post::<ModJoin>)),
70       )
71       // Post
72       .service(
73         // Handle POST to /post separately to add the post() rate limitter
74         web::resource("/post")
75           .guard(guard::Post())
76           .wrap(rate_limit.post())
77           .route(web::post().to(route_post_crud::<CreatePost>)),
78       )
79       .service(
80         web::scope("/post")
81           .wrap(rate_limit.message())
82           .route("", web::get().to(route_get_crud::<GetPost>))
83           .route("", web::put().to(route_post_crud::<EditPost>))
84           .route("/delete", web::post().to(route_post_crud::<DeletePost>))
85           .route("/remove", web::post().to(route_post_crud::<RemovePost>))
86           .route(
87             "/mark_as_read",
88             web::post().to(route_post::<MarkPostAsRead>),
89           )
90           .route("/lock", web::post().to(route_post::<LockPost>))
91           .route("/sticky", web::post().to(route_post::<StickyPost>))
92           .route("/list", web::get().to(route_get_crud::<GetPosts>))
93           .route("/like", web::post().to(route_post::<CreatePostLike>))
94           .route("/save", web::put().to(route_post::<SavePost>))
95           .route("/join", web::post().to(route_post::<PostJoin>))
96           .route("/report", web::post().to(route_post::<CreatePostReport>))
97           .route(
98             "/report/resolve",
99             web::put().to(route_post::<ResolvePostReport>),
100           )
101           .route("/report/list", web::get().to(route_get::<ListPostReports>))
102           .route(
103             "/site_metadata",
104             web::get().to(route_get::<GetSiteMetadata>),
105           ),
106       )
107       // Comment
108       .service(
109         // Handle POST to /comment separately to add the comment() rate limitter
110         web::resource("/comment")
111           .guard(guard::Post())
112           .wrap(rate_limit.comment())
113           .route(web::post().to(route_post_crud::<CreateComment>)),
114       )
115       .service(
116         web::scope("/comment")
117           .wrap(rate_limit.message())
118           .route("", web::get().to(route_get_crud::<GetComment>))
119           .route("", web::put().to(route_post_crud::<EditComment>))
120           .route("/delete", web::post().to(route_post_crud::<DeleteComment>))
121           .route("/remove", web::post().to(route_post_crud::<RemoveComment>))
122           .route(
123             "/mark_as_read",
124             web::post().to(route_post::<MarkCommentAsRead>),
125           )
126           .route("/like", web::post().to(route_post::<CreateCommentLike>))
127           .route("/save", web::put().to(route_post::<SaveComment>))
128           .route("/list", web::get().to(route_get_crud::<GetComments>))
129           .route("/report", web::post().to(route_post::<CreateCommentReport>))
130           .route(
131             "/report/resolve",
132             web::put().to(route_post::<ResolveCommentReport>),
133           )
134           .route(
135             "/report/list",
136             web::get().to(route_get::<ListCommentReports>),
137           ),
138       )
139       // Private Message
140       .service(
141         web::scope("/private_message")
142           .wrap(rate_limit.message())
143           .route("/list", web::get().to(route_get_crud::<GetPrivateMessages>))
144           .route("", web::post().to(route_post_crud::<CreatePrivateMessage>))
145           .route("", web::put().to(route_post_crud::<EditPrivateMessage>))
146           .route(
147             "/delete",
148             web::post().to(route_post_crud::<DeletePrivateMessage>),
149           )
150           .route(
151             "/mark_as_read",
152             web::post().to(route_post::<MarkPrivateMessageAsRead>),
153           ),
154       )
155       // User
156       .service(
157         // Account action, I don't like that it's in /user maybe /accounts
158         // Handle /user/register separately to add the register() rate limitter
159         web::resource("/user/register")
160           .guard(guard::Post())
161           .wrap(rate_limit.register())
162           .route(web::post().to(route_post_crud::<Register>)),
163       )
164       .service(
165         // Handle captcha separately
166         web::resource("/user/get_captcha")
167           .wrap(rate_limit.post())
168           .route(web::get().to(route_get::<GetCaptcha>)),
169       )
170       // User actions
171       .service(
172         web::scope("/user")
173           .wrap(rate_limit.message())
174           .route("", web::get().to(route_get_crud::<GetPersonDetails>))
175           .route("/mention", web::get().to(route_get::<GetPersonMentions>))
176           .route(
177             "/mention/mark_as_read",
178             web::post().to(route_post::<MarkPersonMentionAsRead>),
179           )
180           .route("/replies", web::get().to(route_get::<GetReplies>))
181           .route("/join", web::post().to(route_post::<UserJoin>))
182           // Admin action. I don't like that it's in /user
183           .route("/ban", web::post().to(route_post::<BanPerson>))
184           .route("/block", web::post().to(route_post::<BlockPerson>))
185           // Account actions. I don't like that they're in /user maybe /accounts
186           .route("/login", web::post().to(route_post::<Login>))
187           .route(
188             "/delete_account",
189             web::post().to(route_post_crud::<DeleteAccount>),
190           )
191           .route(
192             "/password_reset",
193             web::post().to(route_post::<PasswordReset>),
194           )
195           .route(
196             "/password_change",
197             web::post().to(route_post::<PasswordChange>),
198           )
199           // mark_all_as_read feels off being in this section as well
200           .route(
201             "/mark_all_as_read",
202             web::post().to(route_post::<MarkAllAsRead>),
203           )
204           .route(
205             "/save_user_settings",
206             web::put().to(route_post::<SaveUserSettings>),
207           )
208           .route(
209             "/change_password",
210             web::put().to(route_post::<ChangePassword>),
211           )
212           .route("/report_count", web::get().to(route_get::<GetReportCount>))
213           .route("/unread_count", web::get().to(route_get::<GetUnreadCount>)),
214       )
215       // Admin Actions
216       .service(
217         web::resource("/admin/add")
218           .wrap(rate_limit.message())
219           .route(web::post().to(route_post::<AddAdmin>)),
220       ),
221   );
222 }
223
224 async fn perform<Request>(
225   data: Request,
226   context: web::Data<LemmyContext>,
227 ) -> Result<HttpResponse, Error>
228 where
229   Request: Perform,
230   Request: Send + 'static,
231 {
232   let res = data
233     .perform(&context, None)
234     .await
235     .map(|json| HttpResponse::Ok().json(json))
236     .map_err(ErrorBadRequest)?;
237   Ok(res)
238 }
239
240 async fn route_get<'a, Data>(
241   data: web::Query<Data>,
242   context: web::Data<LemmyContext>,
243 ) -> Result<HttpResponse, Error>
244 where
245   Data: Deserialize<'a> + Send + 'static + Perform,
246 {
247   perform::<Data>(data.0, context).await
248 }
249
250 async fn route_post<'a, Data>(
251   data: web::Json<Data>,
252   context: web::Data<LemmyContext>,
253 ) -> Result<HttpResponse, Error>
254 where
255   Data: Deserialize<'a> + Send + 'static + Perform,
256 {
257   perform::<Data>(data.0, context).await
258 }
259
260 async fn perform_crud<Request>(
261   data: Request,
262   context: web::Data<LemmyContext>,
263 ) -> Result<HttpResponse, Error>
264 where
265   Request: PerformCrud,
266   Request: Send + 'static,
267 {
268   let res = data
269     .perform(&context, None)
270     .await
271     .map(|json| HttpResponse::Ok().json(json))
272     .map_err(ErrorBadRequest)?;
273   Ok(res)
274 }
275
276 async fn route_get_crud<'a, Data>(
277   data: web::Query<Data>,
278   context: web::Data<LemmyContext>,
279 ) -> Result<HttpResponse, Error>
280 where
281   Data: Deserialize<'a> + Send + 'static + PerformCrud,
282 {
283   perform_crud::<Data>(data.0, context).await
284 }
285
286 async fn route_post_crud<'a, Data>(
287   data: web::Json<Data>,
288   context: web::Data<LemmyContext>,
289 ) -> Result<HttpResponse, Error>
290 where
291   Data: Deserialize<'a> + Send + 'static + PerformCrud,
292 {
293   perform_crud::<Data>(data.0, context).await
294 }