api.js 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304
  1. const mime = require("mime-types");
  2. const fs = require('fs');
  3. const Path = require('path');
  4. const Security = require('../src/security.js');
  5. const MediaService = require('../model/mediaService.js');
  6. const MediaFileMetaModel = require('../model/mediaItemMeta.js').MediaFileMetaModel;
  7. const MediaFileTagModel = require('../model/mediaItemTag.js').MediaFileTagModel;
  8. const { AccessModel, ACCESS_TYPE, ACCESS_GRANT, ACCESS_TO } = require('../model/access.js');
  9. function MediaToJson(mediaData) {
  10. if (!mediaData)
  11. return null;
  12. if (mediaData.accessType === ACCESS_GRANT.readNoMeta)
  13. mediaData.meta = {
  14. height: mediaData.meta?.height,
  15. width: mediaData.meta?.width
  16. };
  17. return mediaData;
  18. }
  19. function accessToJson(access) {
  20. const typeStr = [ "unknown", "ldapAccount", "email", "link", "every one" ][access.type];
  21. const accessToStr = [ "unknown", "item", "tag", "meta", "everything", "admin"][access.accessTo];
  22. const grantStr = [ "none", "read", "write", "read without meta"][access.grant];
  23. return {
  24. id: access.id,
  25. type: typeStr,
  26. typeData: access.typeData,
  27. accessTo: accessToStr,
  28. accessToData: access.accessToData,
  29. grant: grantStr
  30. };
  31. }
  32. module.exports = { register: app => {
  33. app.router.post("/api/database/reload", (req, res) => {
  34. app.routerUtils.onApiRequest(req, res);
  35. if (!req.sessionObj?.accessList?.isAdmin)
  36. return app.routerUtils.onBadRequest(res);
  37. app.libraryManager.updateLibraries(app.databaseHelper).finally(x => { require('../src/autotagBuilder').rebuildPathTags(app); });
  38. app.routerUtils.jsonResponse(res, {});
  39. });
  40. app.router.get("/api/access/list", (req, res) => {
  41. app.routerUtils.onApiRequest(req, res);
  42. app.routerUtils.jsonResponse(res, req.sessionObj?.accessList || {});
  43. });
  44. app.router.post("/api/access/link", async (req, res) => { // /api/access/link, post: { linkIds: [string] (JSON) }
  45. app.routerUtils.onApiRequest(req, res);
  46. if (!req.post?.linkIds?.length)
  47. return app.routerUtils.httpResponse(res, 400, "Missing argument");
  48. try {
  49. for (let i of JSON.parse(req.post.linkIds)) {
  50. const access = await app.databaseHelper.findOne(AccessModel, { type: ACCESS_TYPE.link, typeData: i });
  51. if (access) {
  52. Security.addLinkToSession(req, access.id, i);
  53. if (access.accessTo == ACCESS_TO.admin)
  54. Security.setAdmin(req, true);
  55. }
  56. }
  57. }
  58. catch (err) {
  59. console.error(err);
  60. return app.routerUtils.onBadRequest(res);
  61. }
  62. app.routerUtils.jsonResponse(res, req.sessionObj.accessList);
  63. });
  64. app.router.del("/api/access/:id", async (req, res) => {
  65. app.routerUtils.onApiRequest(req, res);
  66. Security.removeFromSession(req, req.params.id);
  67. const access = await app.databaseHelper.fetch(AccessModel, { id: Object.keys(req.sessionObj.accessList).map(i => req.sessionObj.accessList[i]).filter(x => x.dbId).map(x => x.dbId), accessTo: ACCESS_TO.admin });
  68. const result = Security.setAdmin(req, !!(access?.length || 0));
  69. app.routerUtils.jsonResponse(res, result);
  70. });
  71. app.router.post("/api/accessAdmin/create", async (req, res) => {
  72. app.routerUtils.onApiRequest(req, res);
  73. if (!req.sessionObj?.accessList?.isAdmin || !req.body)
  74. return app.routerUtils.onBadRequest(res);
  75. let access = new AccessModel();
  76. access.type = parseInt(req.body.typeId);
  77. access.typeData = req.body.typeData;
  78. access.accessTo = parseInt(req.body.accessToId);
  79. access.accessToData = req.body.accessToData;
  80. access.grant = parseInt(req.body.grant);
  81. try {
  82. await app.databaseHelper.insertOne(access);
  83. }
  84. catch (err) {
  85. console.error(err);
  86. return app.routerUtils.onBadRequest(res);
  87. }
  88. app.routerUtils.jsonResponse(res, accessToJson(access));
  89. });
  90. app.router.del("/api/accessAdmin/:id", async (req, res) => {
  91. app.routerUtils.onApiRequest(req, res);
  92. if (!req.sessionObj?.accessList?.isAdmin || !req.params.id)
  93. return app.routerUtils.onBadRequest(res);
  94. app.databaseHelper.remove(AccessModel, { id: parseInt(req.params.id) });
  95. app.routerUtils.jsonResponse(res, {});
  96. });
  97. app.router.post("/api/accessAdmin/:id", async (req, res) => {
  98. app.routerUtils.onApiRequest(req, res);
  99. if (!req.sessionObj?.accessList?.isAdmin || !req.params.id || !req.body)
  100. return app.routerUtils.onBadRequest(res);
  101. const access = (await app.databaseHelper.fetch(AccessModel, { id: parseInt(req.params.id) }))?.[0];
  102. if (!access)
  103. return app.routerUtils.onBadRequest(res);
  104. access.typeData = req.body.typeData;
  105. access.accessTo = parseInt(req.body.accessToId);
  106. access.accessToData = req.body.accessToData;
  107. access.grant = parseInt(req.body.grant);
  108. try {
  109. app.databaseHelper.upsertOne(access);
  110. }
  111. catch (err) {
  112. console.error(err);
  113. return app.routerUtils.onBadRequest(res);
  114. }
  115. app.routerUtils.jsonResponse(res, accessToJson(access));
  116. });
  117. app.router.get("/api/accessAdmin/list", async (req, res) => {
  118. app.routerUtils.onApiRequest(req, res);
  119. if (!req.sessionObj?.accessList?.isAdmin)
  120. return app.routerUtils.onBadRequest(res);
  121. app.routerUtils.jsonResponse(res, (await app.databaseHelper.fetch(AccessModel)).map(accessToJson));
  122. });
  123. app.router.post("/api/media/:id/tag/del/:tag", async (req, res) => {
  124. app.routerUtils.onApiRequest(req, res);
  125. if (!req.params.id ||!req.params.tag)
  126. return app.routerUtils.onBadRequest(res);
  127. let checksum = [ req.params.id ];
  128. if (req.params.id === "list") {
  129. if (!req.body?.['list[]'])
  130. return app.routerUtils.onBadRequest(res);
  131. checksum = req.body['list[]'];
  132. }
  133. let data = await MediaService.fetchMultiple(app, checksum, req.sessionObj?.accessList, 0);
  134. data = Object.keys(data).map(x => data[x]).filter(x => x.ACCESS_TYPE != ACCESS_GRANT.write);
  135. await Promise.all(data.map(x => MediaService.updateVersionInDb(app, x.fixedSum)));
  136. await app.databaseHelper.remove(MediaFileTagModel, { md5sum: data.map(x => x.fixedSum), tag: decodeURIComponent(req.params.tag), fromMeta: 0 });
  137. const allMedias = await MediaService.fetchMultiple(app, checksum, req.sessionObj?.accessList, 0);
  138. app.routerUtils.jsonResponse(res, Object.keys(allMedias).map(x => allMedias[x]).map(x => MediaToJson(x)));
  139. });
  140. app.router.put("/api/media/:id/tag", async (req, res) => {
  141. app.routerUtils.onApiRequest(req, res);
  142. const requestedTag = req.body?.tag;
  143. if (!req.params.id ||!requestedTag)
  144. return app.routerUtils.onBadRequest(res);
  145. let checksum = [ req.params.id ];
  146. if (req.params.id === "list") {
  147. if (!req.body?.['list[]'])
  148. return app.routerUtils.onBadRequest(res);
  149. checksum = req.body['list[]'];
  150. }
  151. let data = await MediaService.fetchMultiple(app, checksum, req.sessionObj?.accessList, 0);
  152. data = Object.keys(data)
  153. .map(x => data[x])
  154. .filter(x => {
  155. if (x.ACCESS_TYPE != ACCESS_GRANT.write)
  156. return true;
  157. for (let existingTag of [...x.tags, ...x.fixedTags]) {
  158. if (existingTag === requestedTag || existingTag.startsWith(`${requestedTag}/`)) {
  159. return true;
  160. }
  161. }
  162. });
  163. await Promise.all(data.map(x => MediaService.updateVersionInDb(app, x.fixedSum)));
  164. let tag = data.map(x => new MediaFileTagModel(x.fixedSum, requestedTag, false));
  165. try {
  166. await app.databaseHelper.insertMultipleSameTable(tag);
  167. }
  168. catch (err) {
  169. console.error(err);
  170. return app.routerUtils.onBadRequest(res);
  171. }
  172. const allMedias = await MediaService.fetchMultiple(app, checksum, req.sessionObj?.accessList, 0);
  173. app.routerUtils.jsonResponse(res, Object.keys(allMedias).map(x => allMedias[x]).map(x => MediaToJson(x)));
  174. });
  175. app.router.patch("/api/media/:id/meta/:key", async (req, res) => {
  176. app.routerUtils.onApiRequest(req, res);
  177. if (!req.params.id ||!req.params.key || !Number.isInteger(req.body?.value?.length))
  178. return app.routerUtils.onBadRequest(res);
  179. let checksum = [ req.params.id ];
  180. if (req.params.id === "list") {
  181. if (!req.body?.['list[]'])
  182. return app.routerUtils.onBadRequest(res);
  183. checksum = req.body['list[]'];
  184. }
  185. let data = await MediaService.fetchMultiple(app, checksum, req.sessionObj?.accessList, 0);
  186. data = Object.keys(data)
  187. .map(x => data[x])
  188. .filter(x => x.ACCESS_TYPE != ACCESS_GRANT.write);
  189. await Promise.all(data.map(x => MediaService.updateVersionInDb(app, x.fixedSum)));
  190. if (!req.body.value) {
  191. await app.databaseHelper.remove(MediaFileMetaModel, { md5sum: data.map(x => x.fixedSum), key: req.params.key, fromFile: 0 });
  192. } else {
  193. let newMediaItemMedia = data.map(x => new MediaFileMetaModel(x.fixedSum, req.params.key, req.body.value, false));
  194. await app.databaseHelper.remove(MediaFileMetaModel, { md5sum: data.map(x => x.fixedSum), key: req.params.key, fromFile: 0 });
  195. try {
  196. await app.databaseHelper.insertMultipleSameTable(newMediaItemMedia);
  197. }
  198. catch (err) {
  199. console.error(err);
  200. return app.routerUtils.onBadRequest(res);
  201. }
  202. }
  203. const allMedias = await MediaService.fetchMultiple(app, checksum, req.sessionObj?.accessList);
  204. app.routerUtils.jsonResponse(res, Object.keys(allMedias).map(x => allMedias[x]).map(x => MediaToJson(x)));
  205. });
  206. app.router.get("/api/media/list", async (req, res) => {
  207. app.routerUtils.onApiRequest(req, res);
  208. let first = undefined,
  209. last = undefined,
  210. maxVersion = undefined;
  211. if (req.body?.chronology !== undefined) {
  212. let range = await MediaService.getMediaRange(app);
  213. first = range.min;
  214. last = range.max;
  215. maxVersion = range.maxVersion;
  216. }
  217. let fromDate = parseInt(req.body?.from);
  218. let count = parseInt(req.body?.count);
  219. app.routerUtils.jsonResponse(res, {
  220. data: (await MediaService.fetchMediasWithAccess(
  221. app,
  222. isNaN(fromDate) ? 0 : fromDate,
  223. isNaN(count) ? 25 : Math.min(350, count),
  224. req.sessionObj?.accessList,
  225. req.body?.version || 0)).map(MediaToJson),
  226. first: first,
  227. last: last,
  228. maxVersion: maxVersion
  229. });
  230. });
  231. app.router.get("/api/media/sumlist", async (req, res) => {
  232. app.routerUtils.onApiRequest(req, res);
  233. app.routerUtils.jsonResponse(res, {
  234. data: await MediaService.fetchMediasSumWithAccess(
  235. app,
  236. req.sessionObj?.accessList)
  237. });
  238. });
  239. app.router.get("/api/media/:md5sum", async (req, res) => {
  240. app.routerUtils.onApiRequest(req, res);
  241. let data = MediaToJson(await MediaService.fetchOne(app, req.params.md5sum, req.sessionObj?.accessList, 0));
  242. if (!data)
  243. return app.routerUtils.onPageNotFound(res);
  244. app.routerUtils.jsonResponse(res, data);
  245. });
  246. app.router.get("/api/media/thumbnail/:md5sum.jpg", async (req, res) => {
  247. app.routerUtils.onApiRequest(req, res);
  248. let data = await MediaService.fetchOne(app, req.params.md5sum, req.sessionObj?.accessList, 0);
  249. if (!data)
  250. return app.routerUtils.onPageNotFound(res);
  251. try {
  252. let thumbnail = null;
  253. req.body = req.body || {};
  254. req.body.w = parseInt(req.body.w || 0);
  255. req.body.h = parseInt(req.body.h || 0);
  256. req.body.q = parseInt(req.body.q || 6);
  257. try {
  258. thumbnail = await (await app.libraryManager.findMedia(data.path))?.createThumbnail(req.body.w, req.body.h, req.body.q);
  259. } catch (err) {
  260. return app.routerUtils.apiError(res);
  261. }
  262. if (!thumbnail)
  263. return app.routerUtils.onPageNotFound(res);
  264. res.setHeader("Content-Type", "image/jpeg");
  265. res.setHeader("Content-Length", fs.statSync(thumbnail.name)?.size || undefined);
  266. res.setHeader("Cache-Control", "private, max-age=2630000"); // 1 month cache
  267. let rd = fs.createReadStream(thumbnail.name);
  268. rd.once('end', () => thumbnail.removeCallback());
  269. rd.pipe(res);
  270. }
  271. catch (err) {
  272. console.error(err);
  273. app.routerUtils.onPageNotFound(res);
  274. }
  275. });
  276. app.router.get("/api/media/original/:md5sum", async (req, res) => {
  277. app.routerUtils.onApiRequest(req, res);
  278. let data = await MediaService.fetchOne(app, req.params.md5sum, req.sessionObj?.accessList, 0);
  279. if (!data)
  280. return app.routerUtils.onPageNotFound(res);
  281. const fileName = Path.basename(data.path);
  282. res.setHeader("Cache-Control", "private, max-age=2630000"); // 1 month cache
  283. if (data.accessType === ACCESS_GRANT.readNoMeta || req.body?.trim !== undefined) {
  284. console.log("remove meta");//-> trim metadata
  285. }
  286. res.setHeader("Content-Disposition", `attachment; filename="${fileName}"`);
  287. res.setHeader("Content-Type", mime.lookup(data.path));
  288. res.setHeader("Content-Length", fs.statSync(data.path)?.size || undefined);
  289. fs.createReadStream(data.path).pipe(res);
  290. });
  291. }};