2017-03-08 18:45:51 +08:00
|
|
|
// response
|
|
|
|
// external modules
|
2021-06-12 06:59:01 +08:00
|
|
|
import * as request from "request";
|
2017-03-08 18:45:51 +08:00
|
|
|
// core
|
2021-06-12 06:59:01 +08:00
|
|
|
import * as config from "./config";
|
|
|
|
import * as logger from "./logger";
|
|
|
|
import * as models from "./models";
|
|
|
|
import * as utils from "./utils";
|
|
|
|
import * as history from "./history";
|
2019-08-05 10:21:20 +08:00
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
export function errorForbidden(req, res) {
|
2019-08-05 03:51:00 +08:00
|
|
|
if (req.user) {
|
|
|
|
responseError(res, '403', 'Forbidden', 'oh no.')
|
|
|
|
} else {
|
2020-08-03 10:53:21 +02:00
|
|
|
var nextURL = new URL('', config.serverURL)
|
2021-06-12 06:59:01 +08:00
|
|
|
nextURL.search = (new URLSearchParams({next: req.originalUrl})).toString()
|
2019-08-05 03:51:00 +08:00
|
|
|
req.flash('error', 'You are not allowed to access this page. Maybe try logging in?')
|
2020-08-03 10:53:21 +02:00
|
|
|
res.redirect(nextURL.toString())
|
2019-08-05 03:51:00 +08:00
|
|
|
}
|
|
|
|
}
|
2020-01-05 06:58:40 +08:00
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
export function errorNotFound(req, res) {
|
2019-08-05 03:51:00 +08:00
|
|
|
responseError(res, '404', 'Not Found', 'oops.')
|
2017-03-08 18:45:51 +08:00
|
|
|
}
|
2020-01-05 06:58:40 +08:00
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
export function errorBadRequest(req, res) {
|
2019-08-05 03:51:00 +08:00
|
|
|
responseError(res, '400', 'Bad Request', 'something not right.')
|
|
|
|
}
|
2020-01-05 06:58:40 +08:00
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
export function errorTooLong(req, res) {
|
2019-08-05 03:51:00 +08:00
|
|
|
responseError(res, '413', 'Payload Too Large', 'Shorten your note!')
|
|
|
|
}
|
2020-01-05 06:58:40 +08:00
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
export function errorInternalError(req, res) {
|
2019-08-05 03:51:00 +08:00
|
|
|
responseError(res, '500', 'Internal Error', 'wtf.')
|
|
|
|
}
|
2020-01-05 06:58:40 +08:00
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
export function errorServiceUnavailable(req, res) {
|
2020-01-05 06:58:40 +08:00
|
|
|
res.status(503).send('I\'m busy right now, try again later.')
|
2019-08-05 03:51:00 +08:00
|
|
|
}
|
2015-05-04 15:53:29 +08:00
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
export function responseError(res, code, detail, msg) {
|
2018-09-10 22:35:38 +02:00
|
|
|
res.status(code).render('error.ejs', {
|
2017-03-08 18:45:51 +08:00
|
|
|
title: code + ' ' + detail + ' ' + msg,
|
|
|
|
code: code,
|
|
|
|
detail: detail,
|
2018-09-13 21:26:39 +02:00
|
|
|
msg: msg
|
2017-03-08 18:45:51 +08:00
|
|
|
})
|
2015-05-04 15:53:29 +08:00
|
|
|
}
|
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
export function responseCodiMD(res, note) {
|
2017-03-08 18:45:51 +08:00
|
|
|
var body = note.content
|
|
|
|
var extracted = models.Note.extractMeta(body)
|
|
|
|
var meta = models.Note.parseMeta(extracted.meta)
|
|
|
|
var title = models.Note.decodeTitle(note.title)
|
|
|
|
title = models.Note.generateWebTitle(meta.title || title)
|
|
|
|
res.set({
|
|
|
|
'Cache-Control': 'private', // only cache by client
|
|
|
|
'X-Robots-Tag': 'noindex, nofollow' // prevent crawling
|
|
|
|
})
|
2018-09-10 22:35:38 +02:00
|
|
|
res.render('codimd.ejs', {
|
2018-09-13 21:26:39 +02:00
|
|
|
title: title
|
2017-03-08 18:45:51 +08:00
|
|
|
})
|
2015-05-04 15:53:29 +08:00
|
|
|
}
|
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
function updateHistory(userId, note, document, time?: any) {
|
2019-03-24 17:42:12 +01:00
|
|
|
var noteId = note.alias ? note.alias : models.Note.encodeNoteId(note.id)
|
|
|
|
history.updateHistory(userId, noteId, document, time)
|
2019-04-15 13:36:44 +08:00
|
|
|
logger.info('history updated')
|
2019-03-24 17:42:12 +01:00
|
|
|
}
|
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
export function newNote(req, res, next?: any) {
|
2017-03-08 18:45:51 +08:00
|
|
|
var owner = null
|
2018-09-26 16:00:01 +02:00
|
|
|
var body = ''
|
|
|
|
if (req.body && req.body.length > config.documentMaxLength) {
|
2020-02-26 11:23:55 +08:00
|
|
|
return errorTooLong(req, res)
|
2018-09-28 00:17:34 +02:00
|
|
|
} else if (req.body) {
|
2018-09-26 16:00:01 +02:00
|
|
|
body = req.body
|
|
|
|
}
|
2018-06-24 00:32:41 +02:00
|
|
|
body = body.replace(/[\r]/g, '')
|
2017-03-08 18:45:51 +08:00
|
|
|
if (req.isAuthenticated()) {
|
|
|
|
owner = req.user.id
|
2018-03-07 15:17:35 +01:00
|
|
|
} else if (!config.allowAnonymous) {
|
2020-02-26 11:13:45 +08:00
|
|
|
return errorForbidden(req, res)
|
2017-03-08 18:45:51 +08:00
|
|
|
}
|
|
|
|
models.Note.create({
|
|
|
|
ownerId: owner,
|
2018-01-11 00:51:22 +01:00
|
|
|
alias: req.alias ? req.alias : null,
|
2018-06-24 00:32:41 +02:00
|
|
|
content: body
|
2017-03-08 18:45:51 +08:00
|
|
|
}).then(function (note) {
|
2019-03-24 17:42:12 +01:00
|
|
|
if (req.isAuthenticated()) {
|
2019-04-15 13:36:44 +08:00
|
|
|
updateHistory(owner, note, body)
|
2019-03-24 17:42:12 +01:00
|
|
|
}
|
|
|
|
|
2018-03-07 15:17:35 +01:00
|
|
|
return res.redirect(config.serverURL + '/' + models.Note.encodeNoteId(note.id))
|
2017-03-08 18:45:51 +08:00
|
|
|
}).catch(function (err) {
|
|
|
|
logger.error(err)
|
2020-02-26 11:26:01 +08:00
|
|
|
return errorInternalError(req, res)
|
2017-03-08 18:45:51 +08:00
|
|
|
})
|
2015-05-04 15:53:29 +08:00
|
|
|
}
|
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
export function newCheckViewPermission(note, isLogin, userId) {
|
2020-01-05 06:58:40 +08:00
|
|
|
if (note.permission === 'private') {
|
|
|
|
return note.ownerId === userId
|
|
|
|
}
|
|
|
|
if (note.permission === 'limited' || note.permission === 'protected') {
|
|
|
|
return isLogin
|
|
|
|
}
|
|
|
|
return true
|
|
|
|
}
|
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
export function checkViewPermission(req, note) {
|
2017-03-08 18:45:51 +08:00
|
|
|
if (note.permission === 'private') {
|
2021-06-12 06:59:01 +08:00
|
|
|
if (!req.isAuthenticated() || note.ownerId !== req.user.id) {
|
|
|
|
return false
|
|
|
|
} else {
|
|
|
|
return true
|
|
|
|
}
|
2017-03-08 18:45:51 +08:00
|
|
|
} else if (note.permission === 'limited' || note.permission === 'protected') {
|
2021-06-12 06:59:01 +08:00
|
|
|
if (!req.isAuthenticated()) {
|
|
|
|
return false
|
|
|
|
} else {
|
|
|
|
return true
|
|
|
|
}
|
2017-03-08 18:45:51 +08:00
|
|
|
} else {
|
|
|
|
return true
|
|
|
|
}
|
2015-05-04 15:53:29 +08:00
|
|
|
}
|
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
function findNote(req, res, callback, include?: any) {
|
2017-03-08 18:45:51 +08:00
|
|
|
var noteId = req.params.noteId
|
|
|
|
var id = req.params.noteId || req.params.shortid
|
|
|
|
models.Note.parseNoteId(id, function (err, _id) {
|
|
|
|
if (err) {
|
2018-02-17 00:47:50 +08:00
|
|
|
logger.error(err)
|
2020-02-26 11:26:01 +08:00
|
|
|
return errorInternalError(req, res)
|
2017-03-08 18:45:51 +08:00
|
|
|
}
|
|
|
|
models.Note.findOne({
|
|
|
|
where: {
|
|
|
|
id: _id
|
|
|
|
},
|
|
|
|
include: include || null
|
|
|
|
}).then(function (note) {
|
|
|
|
if (!note) {
|
2018-11-13 00:14:25 +01:00
|
|
|
if (config.allowFreeURL && noteId && !config.forbiddenNoteIDs.includes(noteId)) {
|
2017-03-08 18:45:51 +08:00
|
|
|
req.alias = noteId
|
|
|
|
return newNote(req, res)
|
|
|
|
} else {
|
2020-02-26 11:20:42 +08:00
|
|
|
return errorNotFound(req, res)
|
2017-03-08 18:45:51 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
if (!checkViewPermission(req, note)) {
|
2020-02-26 11:13:45 +08:00
|
|
|
return errorForbidden(req, res)
|
2017-03-08 18:45:51 +08:00
|
|
|
} else {
|
|
|
|
return callback(note)
|
|
|
|
}
|
|
|
|
}).catch(function (err) {
|
|
|
|
logger.error(err)
|
2020-02-26 11:26:01 +08:00
|
|
|
return errorInternalError(req, res)
|
2017-03-08 18:45:51 +08:00
|
|
|
})
|
|
|
|
})
|
2015-05-04 15:53:29 +08:00
|
|
|
}
|
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
function actionDownload(req, res, note) {
|
2017-03-08 18:45:51 +08:00
|
|
|
var body = note.content
|
|
|
|
var title = models.Note.decodeTitle(note.title)
|
|
|
|
var filename = title
|
|
|
|
filename = encodeURIComponent(filename)
|
|
|
|
res.set({
|
|
|
|
'Access-Control-Allow-Origin': '*', // allow CORS as API
|
|
|
|
'Access-Control-Allow-Headers': 'Range',
|
|
|
|
'Access-Control-Expose-Headers': 'Cache-Control, Content-Encoding, Content-Range',
|
|
|
|
'Content-Type': 'text/markdown; charset=UTF-8',
|
|
|
|
'Cache-Control': 'private',
|
|
|
|
'Content-disposition': 'attachment; filename=' + filename + '.md',
|
|
|
|
'X-Robots-Tag': 'noindex, nofollow' // prevent crawling
|
|
|
|
})
|
|
|
|
res.send(body)
|
2016-08-19 11:31:23 +08:00
|
|
|
}
|
2016-08-19 11:24:36 +08:00
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
export function publishNoteActions(req, res, next) {
|
2017-03-08 18:45:51 +08:00
|
|
|
findNote(req, res, function (note) {
|
|
|
|
var action = req.params.action
|
|
|
|
switch (action) {
|
2018-10-27 16:55:14 -07:00
|
|
|
case 'download':
|
|
|
|
actionDownload(req, res, note)
|
2018-10-27 17:54:01 -07:00
|
|
|
break
|
2017-03-08 18:45:51 +08:00
|
|
|
case 'edit':
|
2018-03-07 15:17:35 +01:00
|
|
|
res.redirect(config.serverURL + '/' + (note.alias ? note.alias : models.Note.encodeNoteId(note.id)))
|
2017-03-08 18:45:51 +08:00
|
|
|
break
|
|
|
|
default:
|
2018-03-07 15:17:35 +01:00
|
|
|
res.redirect(config.serverURL + '/s/' + note.shortid)
|
2017-03-08 18:45:51 +08:00
|
|
|
break
|
|
|
|
}
|
|
|
|
})
|
2015-07-02 00:10:20 +08:00
|
|
|
}
|
2016-01-31 15:42:26 -06:00
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
export function publishSlideActions(req, res, next) {
|
2017-03-08 18:45:51 +08:00
|
|
|
findNote(req, res, function (note) {
|
|
|
|
var action = req.params.action
|
|
|
|
switch (action) {
|
|
|
|
case 'edit':
|
2018-03-07 15:17:35 +01:00
|
|
|
res.redirect(config.serverURL + '/' + (note.alias ? note.alias : models.Note.encodeNoteId(note.id)))
|
2017-03-08 18:45:51 +08:00
|
|
|
break
|
|
|
|
default:
|
2018-03-07 15:17:35 +01:00
|
|
|
res.redirect(config.serverURL + '/p/' + note.shortid)
|
2017-03-08 18:45:51 +08:00
|
|
|
break
|
|
|
|
}
|
|
|
|
})
|
2016-08-15 11:25:27 +08:00
|
|
|
}
|
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
export function githubActions(req, res, next) {
|
2017-03-08 18:45:51 +08:00
|
|
|
var noteId = req.params.noteId
|
|
|
|
findNote(req, res, function (note) {
|
|
|
|
var action = req.params.action
|
|
|
|
switch (action) {
|
|
|
|
case 'gist':
|
|
|
|
githubActionGist(req, res, note)
|
|
|
|
break
|
|
|
|
default:
|
2018-03-07 15:17:35 +01:00
|
|
|
res.redirect(config.serverURL + '/' + noteId)
|
2017-03-08 18:45:51 +08:00
|
|
|
break
|
|
|
|
}
|
|
|
|
})
|
2016-01-31 15:42:26 -06:00
|
|
|
}
|
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
function githubActionGist(req, res, note) {
|
2017-03-08 18:45:51 +08:00
|
|
|
var code = req.query.code
|
|
|
|
var state = req.query.state
|
|
|
|
if (!code || !state) {
|
2020-02-26 11:13:45 +08:00
|
|
|
return errorForbidden(req, res)
|
2017-03-08 18:45:51 +08:00
|
|
|
} else {
|
|
|
|
var data = {
|
|
|
|
client_id: config.github.clientID,
|
|
|
|
client_secret: config.github.clientSecret,
|
|
|
|
code: code,
|
|
|
|
state: state
|
|
|
|
}
|
|
|
|
var authUrl = 'https://github.com/login/oauth/access_token'
|
|
|
|
request({
|
|
|
|
url: authUrl,
|
|
|
|
method: 'POST',
|
|
|
|
json: data
|
|
|
|
}, function (error, httpResponse, body) {
|
|
|
|
if (!error && httpResponse.statusCode === 200) {
|
|
|
|
var accessToken = body.access_token
|
|
|
|
if (accessToken) {
|
|
|
|
var content = note.content
|
|
|
|
var title = models.Note.decodeTitle(note.title)
|
|
|
|
var filename = title.replace('/', ' ') + '.md'
|
|
|
|
var gist = {
|
2019-08-02 01:01:46 +08:00
|
|
|
files: {}
|
2017-03-08 18:45:51 +08:00
|
|
|
}
|
|
|
|
gist.files[filename] = {
|
2019-08-02 01:01:46 +08:00
|
|
|
content: content
|
2017-03-08 18:45:51 +08:00
|
|
|
}
|
|
|
|
var gistUrl = 'https://api.github.com/gists'
|
|
|
|
request({
|
|
|
|
url: gistUrl,
|
|
|
|
headers: {
|
2018-06-24 14:13:38 +02:00
|
|
|
'User-Agent': 'CodiMD',
|
2019-08-02 01:01:46 +08:00
|
|
|
Authorization: 'token ' + accessToken
|
2017-03-08 18:45:51 +08:00
|
|
|
},
|
|
|
|
method: 'POST',
|
|
|
|
json: gist
|
|
|
|
}, function (error, httpResponse, body) {
|
|
|
|
if (!error && httpResponse.statusCode === 201) {
|
|
|
|
res.setHeader('referer', '')
|
|
|
|
res.redirect(body.html_url)
|
2016-04-20 18:03:55 +08:00
|
|
|
} else {
|
2020-02-26 11:13:45 +08:00
|
|
|
return errorForbidden(req, res)
|
2016-04-20 18:03:55 +08:00
|
|
|
}
|
2017-03-08 18:45:51 +08:00
|
|
|
})
|
|
|
|
} else {
|
2020-02-26 11:13:45 +08:00
|
|
|
return errorForbidden(req, res)
|
2017-03-08 18:45:51 +08:00
|
|
|
}
|
|
|
|
} else {
|
2020-02-26 11:13:45 +08:00
|
|
|
return errorForbidden(req, res)
|
2017-03-08 18:45:51 +08:00
|
|
|
}
|
|
|
|
})
|
|
|
|
}
|
2016-01-31 15:42:26 -06:00
|
|
|
}
|
2015-07-02 00:10:20 +08:00
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
export function gitlabActions(req, res, next) {
|
2017-03-08 18:45:51 +08:00
|
|
|
var noteId = req.params.noteId
|
|
|
|
findNote(req, res, function (note) {
|
|
|
|
var action = req.params.action
|
|
|
|
switch (action) {
|
|
|
|
case 'projects':
|
|
|
|
gitlabActionProjects(req, res, note)
|
|
|
|
break
|
|
|
|
default:
|
2018-03-07 15:17:35 +01:00
|
|
|
res.redirect(config.serverURL + '/' + noteId)
|
2017-03-08 18:45:51 +08:00
|
|
|
break
|
|
|
|
}
|
|
|
|
})
|
2016-05-16 18:16:45 +08:00
|
|
|
}
|
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
function gitlabActionProjects(req, res, note) {
|
2017-03-08 18:45:51 +08:00
|
|
|
if (req.isAuthenticated()) {
|
|
|
|
models.User.findOne({
|
|
|
|
where: {
|
|
|
|
id: req.user.id
|
|
|
|
}
|
|
|
|
}).then(function (user) {
|
2021-06-12 06:59:01 +08:00
|
|
|
if (!user) {
|
|
|
|
return errorNotFound(req, res)
|
|
|
|
}
|
|
|
|
var ret: any = {baseURL: config.gitlab.baseURL, version: config.gitlab.version}
|
2017-03-08 18:45:51 +08:00
|
|
|
ret.accesstoken = user.accessToken
|
|
|
|
ret.profileid = user.profileid
|
|
|
|
request(
|
2019-04-12 17:56:36 +08:00
|
|
|
config.gitlab.baseURL + '/api/' + config.gitlab.version + '/projects?membership=yes&per_page=100&access_token=' + user.accessToken,
|
|
|
|
function (error, httpResponse, body) {
|
|
|
|
if (!error && httpResponse.statusCode === 200) {
|
|
|
|
ret.projects = JSON.parse(body)
|
|
|
|
return res.send(ret)
|
|
|
|
} else {
|
|
|
|
return res.send(ret)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
)
|
2017-03-08 18:45:51 +08:00
|
|
|
}).catch(function (err) {
|
|
|
|
logger.error('gitlab action projects failed: ' + err)
|
2020-02-26 11:26:01 +08:00
|
|
|
return errorInternalError(req, res)
|
2017-03-08 18:45:51 +08:00
|
|
|
})
|
|
|
|
} else {
|
2020-02-26 11:13:45 +08:00
|
|
|
return errorForbidden(req, res)
|
2017-03-08 18:45:51 +08:00
|
|
|
}
|
2016-05-16 18:16:45 +08:00
|
|
|
}
|
|
|
|
|
2021-06-12 06:59:01 +08:00
|
|
|
export function showPublishSlide(req, res, next) {
|
2017-03-08 18:45:51 +08:00
|
|
|
var include = [{
|
|
|
|
model: models.User,
|
|
|
|
as: 'owner'
|
|
|
|
}, {
|
|
|
|
model: models.User,
|
|
|
|
as: 'lastchangeuser'
|
|
|
|
}]
|
|
|
|
findNote(req, res, function (note) {
|
|
|
|
// force to use short id
|
|
|
|
var shortid = req.params.shortid
|
2021-06-12 06:59:01 +08:00
|
|
|
if ((note.alias && shortid !== note.alias) || (!note.alias && shortid !== note.shortid)) {
|
|
|
|
return res.redirect(config.serverURL + '/p/' + (note.alias || note.shortid))
|
|
|
|
}
|
2017-03-08 18:45:51 +08:00
|
|
|
note.increment('viewcount').then(function (note) {
|
|
|
|
if (!note) {
|
2020-02-26 11:20:42 +08:00
|
|
|
return errorNotFound(req, res)
|
2017-03-08 18:45:51 +08:00
|
|
|
}
|
|
|
|
var body = note.content
|
|
|
|
var extracted = models.Note.extractMeta(body)
|
|
|
|
var markdown = extracted.markdown
|
|
|
|
var meta = models.Note.parseMeta(extracted.meta)
|
|
|
|
var createtime = note.createdAt
|
|
|
|
var updatetime = note.lastchangeAt
|
|
|
|
var title = models.Note.decodeTitle(note.title)
|
|
|
|
title = models.Note.generateWebTitle(meta.title || title)
|
|
|
|
var data = {
|
|
|
|
title: title,
|
|
|
|
description: meta.description || (markdown ? models.Note.generateDescription(markdown) : null),
|
|
|
|
viewcount: note.viewcount,
|
|
|
|
createtime: createtime,
|
|
|
|
updatetime: updatetime,
|
|
|
|
body: markdown,
|
2017-06-05 01:12:40 +08:00
|
|
|
theme: meta.slideOptions && utils.isRevealTheme(meta.slideOptions.theme),
|
2017-03-08 18:45:51 +08:00
|
|
|
meta: JSON.stringify(extracted.meta),
|
|
|
|
owner: note.owner ? note.owner.id : null,
|
|
|
|
ownerprofile: note.owner ? models.User.getProfile(note.owner) : null,
|
|
|
|
lastchangeuser: note.lastchangeuser ? note.lastchangeuser.id : null,
|
|
|
|
lastchangeuserprofile: note.lastchangeuser ? models.User.getProfile(note.lastchangeuser) : null,
|
|
|
|
robots: meta.robots || false, // default allow robots
|
|
|
|
GA: meta.GA,
|
2017-10-18 17:48:53 +02:00
|
|
|
disqus: meta.disqus,
|
|
|
|
cspNonce: res.locals.nonce
|
2017-03-08 18:45:51 +08:00
|
|
|
}
|
2020-01-05 07:43:01 +08:00
|
|
|
res.set({
|
|
|
|
'Cache-Control': 'private' // only cache by client
|
|
|
|
})
|
|
|
|
res.render('slide.ejs', data)
|
2017-03-08 18:45:51 +08:00
|
|
|
}).catch(function (err) {
|
|
|
|
logger.error(err)
|
2020-02-26 11:26:01 +08:00
|
|
|
return errorInternalError(req, res)
|
2017-03-08 18:45:51 +08:00
|
|
|
})
|
|
|
|
}, include)
|
2015-11-23 20:38:26 +08:00
|
|
|
}
|