api.js 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334
  1. const mime = require("mime-types");
  2. const fs = require('fs');
  3. const Path = require('path');
  4. const Security = require('../src/security.js');
  5. const MediaService = require('../model/mediaService.js');
  6. const MediaFileMetaModel = require('../model/mediaItemMeta.js').MediaFileMetaModel;
  7. const MediaFileTagModel = require('../model/mediaItemTag.js').MediaFileTagModel;
  8. const { AccessModel, ACCESS_TYPE, ACCESS_GRANT, ACCESS_TO } = require('../model/access.js');
  9. function MediaToJson(mediaData) {
  10. if (!mediaData)
  11. return null;
  12. if (mediaData.accessType === ACCESS_GRANT.readNoMeta)
  13. mediaData.meta = {
  14. height: mediaData.meta?.height,
  15. width: mediaData.meta?.width
  16. };
  17. return mediaData;
  18. }
  19. function accessToJson(access) {
  20. const typeStr = [ "unknown", "ldapAccount", "email", "link", "every one" ][access.type];
  21. const accessToStr = [ "unknown", "item", "tag", "meta", "everything", "admin"][access.accessTo];
  22. const grantStr = [ "none", "read", "write", "read without meta"][access.grant];
  23. return {
  24. id: access.id,
  25. type: typeStr,
  26. typeLabel: access.typeLabel,
  27. typeData: access.typeData,
  28. accessTo: accessToStr,
  29. accessToData: access.accessToData,
  30. grant: grantStr
  31. };
  32. }
  33. async function accessListToJson(app, req) {
  34. let result = {
  35. ...(req.sessionObj?.accessList || {})
  36. };
  37. result.isAdmin = await req.sessionObj?.accessList?.isAdmin?.(app, result) || false;
  38. delete result.isAdmin_;
  39. return result;
  40. }
  41. module.exports = { register: app => {
  42. app.router.post("/api/server/reboot", async (req, res) => {
  43. app.routerUtils.onApiRequest(req, res);
  44. if (!await req.sessionObj?.accessList?.isAdmin(app, req.sessionObj?.accessList))
  45. return app.routerUtils.onBadRequest(res);
  46. console.log("Starting reboot process, initiaed from ", res.sessionObj);
  47. app.server.close(() => {
  48. require("child_process").spawn(process.argv.shift(), process.argv, {
  49. cwd: process.cwd(),
  50. detached : true,
  51. stdio: "inherit"
  52. }).unref();
  53. setTimeout(() => process.exit(), 500);
  54. });
  55. app.routerUtils.jsonResponse(res, {});
  56. });
  57. app.router.post("/api/database/reload", async (req, res) => {
  58. app.routerUtils.onApiRequest(req, res);
  59. if (!await req.sessionObj?.accessList?.isAdmin(app, req.sessionObj?.accessList))
  60. return app.routerUtils.onBadRequest(res);
  61. app.libraryManager.forceReload(app);
  62. app.routerUtils.jsonResponse(res, {});
  63. });
  64. app.router.post("/api/database/scan", async (req, res) => {
  65. app.routerUtils.onApiRequest(req, res);
  66. if (!await req.sessionObj?.accessList?.isAdmin(app, req.sessionObj?.accessList))
  67. return app.routerUtils.onBadRequest(res);
  68. app.libraryManager.updateLibraries(app);
  69. app.routerUtils.jsonResponse(res, {});
  70. });
  71. app.router.get("/api/access/list", async (req, res) => {
  72. app.routerUtils.onApiRequest(req, res);
  73. app.routerUtils.jsonResponse(res, await accessListToJson(app, req));
  74. });
  75. app.router.post("/api/access/link", async (req, res) => { // /api/access/link, post: { linkIds: [string] (JSON) }
  76. app.routerUtils.onApiRequest(req, res);
  77. if (!req.post?.linkIds?.length)
  78. return app.routerUtils.httpResponse(res, 400, "Missing argument");
  79. try {
  80. for (let i of JSON.parse(req.post.linkIds)) {
  81. const access = await app.databaseHelper.findOne(AccessModel, { type: ACCESS_TYPE.link, typeData: i });
  82. if (access) {
  83. Security.addLinkToSession(req, access.id, i, access.typeLabel);
  84. if (access.accessTo == ACCESS_TO.admin)
  85. Security.setAdmin(req, true);
  86. }
  87. }
  88. }
  89. catch (err) {
  90. console.error(err);
  91. return app.routerUtils.onBadRequest(res);
  92. }
  93. app.routerUtils.jsonResponse(res, await accessListToJson(app, req));
  94. });
  95. app.router.del("/api/access/:id", async (req, res) => {
  96. app.routerUtils.onApiRequest(req, res);
  97. Security.removeFromSession(req, req.params.id);
  98. const access = await app.databaseHelper.fetch(AccessModel, { id: Object.keys(req.sessionObj.accessList).map(i => req.sessionObj.accessList[i]).filter(x => x.dbId).map(x => x.dbId), accessTo: ACCESS_TO.admin });
  99. const result = Security.setAdmin(req, !!(access?.length || 0));
  100. app.routerUtils.jsonResponse(res, result);
  101. });
  102. app.router.post("/api/accessAdmin/create", async (req, res) => {
  103. app.routerUtils.onApiRequest(req, res);
  104. if (!await req.sessionObj?.accessList?.isAdmin(app, req.sessionObj?.accessList) || !req.body)
  105. return app.routerUtils.onBadRequest(res);
  106. let access = new AccessModel();
  107. access.type = parseInt(req.body.typeId);
  108. access.typeData = req.body.typeData;
  109. access.typeLabel = req.body.typeLabel;
  110. access.accessTo = parseInt(req.body.accessToId);
  111. access.accessToData = req.body.accessToData;
  112. access.grant = parseInt(req.body.grant);
  113. try {
  114. await app.databaseHelper.insertOne(access);
  115. }
  116. catch (err) {
  117. console.error(err);
  118. return app.routerUtils.onBadRequest(res);
  119. }
  120. app.routerUtils.jsonResponse(res, accessToJson(access));
  121. });
  122. app.router.del("/api/accessAdmin/:id", async (req, res) => {
  123. app.routerUtils.onApiRequest(req, res);
  124. if (!await req.sessionObj?.accessList?.isAdmin(app, req.sessionObj?.accessList) || !req.params.id)
  125. return app.routerUtils.onBadRequest(res);
  126. app.databaseHelper.remove(AccessModel, { id: parseInt(req.params.id) });
  127. app.routerUtils.jsonResponse(res, {});
  128. });
  129. app.router.post("/api/accessAdmin/:id", async (req, res) => {
  130. app.routerUtils.onApiRequest(req, res);
  131. if (!await req.sessionObj?.accessList?.isAdmin(app, req.sessionObj?.accessList) || !req.params.id || !req.body)
  132. return app.routerUtils.onBadRequest(res);
  133. const access = (await app.databaseHelper.fetch(AccessModel, { id: parseInt(req.params.id) }))?.[0];
  134. if (!access)
  135. return app.routerUtils.onBadRequest(res);
  136. access.typeLabel = req.body.typeLabel;
  137. access.typeData = req.body.typeData;
  138. access.accessTo = parseInt(req.body.accessToId);
  139. access.accessToData = req.body.accessToData;
  140. access.grant = parseInt(req.body.grant);
  141. try {
  142. app.databaseHelper.upsertOne(access);
  143. }
  144. catch (err) {
  145. console.error(err);
  146. return app.routerUtils.onBadRequest(res);
  147. }
  148. app.routerUtils.jsonResponse(res, accessToJson(access));
  149. });
  150. app.router.get("/api/accessAdmin/list", async (req, res) => {
  151. app.routerUtils.onApiRequest(req, res);
  152. if (!await req.sessionObj?.accessList?.isAdmin(app, req.sessionObj?.accessList))
  153. return app.routerUtils.onBadRequest(res);
  154. app.routerUtils.jsonResponse(res, (await app.databaseHelper.fetch(AccessModel)).map(accessToJson));
  155. });
  156. app.router.post("/api/media/:id/tag/del/:tag", async (req, res) => {
  157. app.routerUtils.onApiRequest(req, res);
  158. if (!req.params.id ||!req.params.tag)
  159. return app.routerUtils.onBadRequest(res);
  160. let checksum = [ req.params.id ];
  161. if (req.params.id === "list") {
  162. if (!req.body?.['list[]'])
  163. return app.routerUtils.onBadRequest(res);
  164. checksum = req.body['list[]'];
  165. }
  166. let data = await MediaService.fetchMultiple(app, checksum, req.sessionObj?.accessList, 0);
  167. data = Object.keys(data).map(x => data[x]).filter(x => x.ACCESS_TYPE != ACCESS_GRANT.write);
  168. await Promise.all(data.map(x => MediaService.updateVersionInDb(app, x.fixedSum)));
  169. await app.databaseHelper.remove(MediaFileTagModel, { md5sum: data.map(x => x.fixedSum), tag: decodeURIComponent(req.params.tag), fromMeta: 0 });
  170. const allMedias = await MediaService.fetchMultiple(app, checksum, req.sessionObj?.accessList, 0);
  171. app.routerUtils.jsonResponse(res, Object.keys(allMedias).map(x => allMedias[x]).map(x => MediaToJson(x)));
  172. });
  173. app.router.put("/api/media/:id/tag", async (req, res) => {
  174. app.routerUtils.onApiRequest(req, res);
  175. const requestedTag = req.body?.tag;
  176. if (!req.params.id ||!requestedTag)
  177. return app.routerUtils.onBadRequest(res);
  178. let checksum = [ req.params.id ];
  179. if (req.params.id === "list") {
  180. if (!req.body?.['list[]'])
  181. return app.routerUtils.onBadRequest(res);
  182. checksum = req.body['list[]'];
  183. }
  184. let data = await MediaService.fetchMultiple(app, checksum, req.sessionObj?.accessList, 0);
  185. data = Object.keys(data)
  186. .map(x => data[x])
  187. .filter(x => {
  188. if (x.ACCESS_TYPE != ACCESS_GRANT.write)
  189. return true;
  190. for (let existingTag of [...x.tags, ...x.fixedTags]) {
  191. if (existingTag === requestedTag || existingTag.startsWith(`${requestedTag}/`)) {
  192. return true;
  193. }
  194. }
  195. });
  196. await Promise.all(data.map(x => MediaService.updateVersionInDb(app, x.fixedSum)));
  197. let tag = data.map(x => new MediaFileTagModel(x.fixedSum, requestedTag, false));
  198. try {
  199. await app.databaseHelper.insertMultipleSameTable(tag);
  200. }
  201. catch (err) {
  202. console.error(err);
  203. return app.routerUtils.onBadRequest(res);
  204. }
  205. const allMedias = await MediaService.fetchMultiple(app, checksum, req.sessionObj?.accessList, 0);
  206. app.routerUtils.jsonResponse(res, Object.keys(allMedias).map(x => allMedias[x]).map(x => MediaToJson(x)));
  207. });
  208. app.router.patch("/api/media/:id/meta/:key", async (req, res) => {
  209. app.routerUtils.onApiRequest(req, res);
  210. if (!req.params.id ||!req.params.key || !Number.isInteger(req.body?.value?.length))
  211. return app.routerUtils.onBadRequest(res);
  212. let checksum = [ req.params.id ];
  213. if (req.params.id === "list") {
  214. if (!req.body?.['list[]'])
  215. return app.routerUtils.onBadRequest(res);
  216. checksum = req.body['list[]'];
  217. }
  218. let data = await MediaService.fetchMultiple(app, checksum, req.sessionObj?.accessList, 0);
  219. data = Object.keys(data)
  220. .map(x => data[x])
  221. .filter(x => x.ACCESS_TYPE != ACCESS_GRANT.write);
  222. if (!(await MediaService.updateMeta(app, data.map(x => x.fixedSum), req.params.key, req.body.value)))
  223. return app.routerUtils.onBadRequest(res);
  224. const allMedias = await MediaService.fetchMultiple(app, checksum, req.sessionObj?.accessList, 0);
  225. app.routerUtils.jsonResponse(res, Object.keys(allMedias).map(x => allMedias[x]).map(x => MediaToJson(x)));
  226. });
  227. app.router.get("/api/media/list", async (req, res) => {
  228. app.routerUtils.onApiRequest(req, res);
  229. let first = undefined,
  230. last = undefined,
  231. maxVersion = undefined;
  232. if (req.body?.chronology !== undefined) {
  233. let range = await MediaService.getMediaRange(app);
  234. first = range.min;
  235. last = range.max;
  236. maxVersion = range.maxVersion;
  237. }
  238. let fromDate = parseInt(req.body?.from);
  239. let count = parseInt(req.body?.count);
  240. app.routerUtils.jsonResponse(res, {
  241. data: (await MediaService.fetchMediasWithAccess(
  242. app,
  243. isNaN(fromDate) ? 0 : fromDate,
  244. isNaN(count) ? 25 : Math.min(350, count),
  245. req.sessionObj?.accessList,
  246. req.body?.version || 0)).map(MediaToJson),
  247. first: first,
  248. last: last,
  249. maxVersion: maxVersion
  250. });
  251. });
  252. app.router.get("/api/media/sumlist", async (req, res) => {
  253. app.routerUtils.onApiRequest(req, res);
  254. app.routerUtils.jsonResponse(res, {
  255. data: await MediaService.fetchMediasSumWithAccess(
  256. app,
  257. req.sessionObj?.accessList)
  258. });
  259. });
  260. app.router.del("/api/media/:md5sum", async (req, res) => {
  261. app.routerUtils.onApiRequest(req, res);
  262. let data = MediaToJson(await MediaService.fetchOne(app, req.params.md5sum, req.sessionObj?.accessList, 0));
  263. if (!data)
  264. return app.routerUtils.onPageNotFound(res);
  265. await MediaService.removeMedia(app, data);
  266. app.routerUtils.jsonResponse(res, {});
  267. });
  268. app.router.get("/api/media/:md5sum", async (req, res) => {
  269. app.routerUtils.onApiRequest(req, res);
  270. let data = MediaToJson(await MediaService.fetchOne(app, req.params.md5sum, req.sessionObj?.accessList, 0));
  271. if (!data)
  272. return app.routerUtils.onPageNotFound(res);
  273. app.routerUtils.jsonResponse(res, data);
  274. });
  275. app.router.get("/api/media/thumbnail/:md5sum.jpg", async (req, res) => {
  276. app.routerUtils.onApiRequest(req, res);
  277. let data = await MediaService.fetchOne(app, req.params.md5sum, req.sessionObj?.accessList, 0);
  278. if (!data)
  279. return app.routerUtils.onPageNotFound(res);
  280. try {
  281. let thumbnail = null;
  282. req.body = req.body || {};
  283. req.body.w = parseInt(req.body.w || 0);
  284. req.body.h = parseInt(req.body.h || 0);
  285. req.body.q = parseInt(req.body.q || 6);
  286. try {
  287. thumbnail = await (await app.libraryManager.findMedia(data.path))?.createThumbnail(req.body.w, req.body.h, req.body.q);
  288. } catch (err) {
  289. return app.routerUtils.apiError(res);
  290. }
  291. if (!thumbnail)
  292. return app.routerUtils.onPageNotFound(res);
  293. res.setHeader("Content-Type", "image/jpeg");
  294. res.setHeader("Content-Length", fs.statSync(thumbnail.name)?.size || undefined);
  295. res.setHeader("Cache-Control", "private, max-age=2630000"); // 1 month cache
  296. let rd = fs.createReadStream(thumbnail.name);
  297. rd.once('end', () => thumbnail.removeCallback());
  298. rd.pipe(res);
  299. }
  300. catch (err) {
  301. console.error(err);
  302. app.routerUtils.onPageNotFound(res);
  303. }
  304. });
  305. app.router.get("/api/media/original/:md5sum", async (req, res) => {
  306. app.routerUtils.onApiRequest(req, res);
  307. let data = await MediaService.fetchOne(app, req.params.md5sum, req.sessionObj?.accessList, 0);
  308. if (!data)
  309. return app.routerUtils.onPageNotFound(res);
  310. const fileName = Path.basename(data.path);
  311. res.setHeader("Cache-Control", "private, max-age=2630000"); // 1 month cache
  312. if (data.accessType === ACCESS_GRANT.readNoMeta || req.body?.trim !== undefined) {
  313. console.log("remove meta");//-> trim metadata
  314. }
  315. res.setHeader("Content-Disposition", `attachment; filename="${fileName}"`);
  316. res.setHeader("Content-Type", mime.lookup(data.path));
  317. res.setHeader("Content-Length", fs.statSync(data.path)?.size || undefined);
  318. fs.createReadStream(data.path).pipe(res);
  319. });
  320. }};