config.js 20 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672
  1. module.exports = function(crowi) {
  2. const mongoose = require('mongoose')
  3. , debug = require('debug')('growi:models:config')
  4. , uglifycss = require('uglifycss')
  5. , recommendedXssWhiteList = require('@commons/service/xss/recommendedXssWhiteList')
  6. , SECURITY_RESTRICT_GUEST_MODE_DENY = 'Deny'
  7. , SECURITY_RESTRICT_GUEST_MODE_READONLY = 'Readonly'
  8. , SECURITY_REGISTRATION_MODE_OPEN = 'Open'
  9. , SECURITY_REGISTRATION_MODE_RESTRICTED = 'Resricted'
  10. , SECURITY_REGISTRATION_MODE_CLOSED = 'Closed'
  11. ;
  12. let configSchema;
  13. let Config;
  14. configSchema = new mongoose.Schema({
  15. ns: { type: String, required: true, index: true },
  16. key: { type: String, required: true, index: true },
  17. value: { type: String, required: true }
  18. });
  19. function validateCrowi() {
  20. if (crowi == null) {
  21. throw new Error('"crowi" is null. Init Config model with "crowi" argument first.');
  22. }
  23. }
  24. /**
  25. * default values when GROWI is cleanly installed
  26. */
  27. function getArrayForInstalling() {
  28. let config = getDefaultCrowiConfigs();
  29. // overwrite
  30. config['app:fileUpload'] = true;
  31. config['security:isEnabledPassport'] = true;
  32. config['customize:behavior'] = 'growi';
  33. config['customize:layout'] = 'growi';
  34. config['customize:isSavedStatesOfTabChanges'] = false;
  35. return config;
  36. }
  37. /**
  38. * default values when migrated from Official Crowi
  39. */
  40. function getDefaultCrowiConfigs() {
  41. /* eslint-disable key-spacing */
  42. return {
  43. //'app:installed' : "0.0.0",
  44. 'app:confidential' : '',
  45. 'app:fileUpload' : false,
  46. 'app:globalLang' : 'en-US',
  47. 'security:restrictGuestMode' : 'Deny',
  48. 'security:registrationMode' : 'Open',
  49. 'security:registrationWhiteList' : [],
  50. 'security:list-policy:hideRestrictedByOwner' : false,
  51. 'security:list-policy:hideRestrictedByGroup' : false,
  52. 'security:isEnabledPassport' : false,
  53. 'security:passport-ldap:isEnabled' : false,
  54. 'security:passport-ldap:serverUrl' : undefined,
  55. 'security:passport-ldap:isUserBind' : undefined,
  56. 'security:passport-ldap:bindDN' : undefined,
  57. 'security:passport-ldap:bindDNPassword' : undefined,
  58. 'security:passport-ldap:searchFilter' : undefined,
  59. 'security:passport-ldap:attrMapUsername' : undefined,
  60. 'security:passport-ldap:attrMapName' : undefined,
  61. 'security:passport-ldap:attrMapMail' : undefined,
  62. 'security:passport-ldap:groupSearchBase' : undefined,
  63. 'security:passport-ldap:groupSearchFilter' : undefined,
  64. 'security:passport-ldap:groupDnProperty' : undefined,
  65. 'security:passport-ldap:isSameUsernameTreatedAsIdenticalUser': false,
  66. 'security:passport-saml:isEnabled' : false,
  67. 'security:passport-saml:isSameEmailTreatedAsIdenticalUser': false,
  68. 'security:passport-google:isEnabled' : false,
  69. 'security:passport-github:isEnabled' : false,
  70. 'security:passport-twitter:isEnabled' : false,
  71. 'aws:bucket' : 'growi',
  72. 'aws:region' : 'ap-northeast-1',
  73. 'aws:accessKeyId' : '',
  74. 'aws:secretAccessKey' : '',
  75. 'mail:from' : '',
  76. 'mail:smtpHost' : '',
  77. 'mail:smtpPort' : '',
  78. 'mail:smtpUser' : '',
  79. 'mail:smtpPassword' : '',
  80. 'google:clientId' : '',
  81. 'google:clientSecret' : '',
  82. 'plugin:isEnabledPlugins' : true,
  83. 'customize:css' : '',
  84. 'customize:script' : '',
  85. 'customize:header' : '',
  86. 'customize:title' : '',
  87. 'customize:highlightJsStyle' : 'github',
  88. 'customize:highlightJsStyleBorder' : false,
  89. 'customize:theme' : 'default',
  90. 'customize:behavior' : 'crowi',
  91. 'customize:layout' : 'crowi',
  92. 'customize:isEnabledTimeline' : true,
  93. 'customize:isSavedStatesOfTabChanges' : true,
  94. 'customize:isEnabledAttachTitleHeader' : false,
  95. 'customize:showRecentCreatedNumber' : 10,
  96. 'importer:esa:team_name': '',
  97. 'importer:esa:access_token': '',
  98. 'importer:qiita:team_name': '',
  99. 'importer:qiita:access_token': '',
  100. };
  101. /* eslint-enable */
  102. }
  103. function getDefaultMarkdownConfigs() {
  104. return {
  105. 'markdown:xss:isEnabledPrevention': true,
  106. 'markdown:xss:option': 2,
  107. 'markdown:xss:tagWhiteList': [],
  108. 'markdown:xss:attrWhiteList': [],
  109. 'markdown:isEnabledLinebreaks': false,
  110. 'markdown:isEnabledLinebreaksInComments': true,
  111. 'markdown:presentation:pageBreakSeparator': 1,
  112. 'markdown:presentation:pageBreakCustomSeparator': '',
  113. };
  114. }
  115. function getValueForCrowiNS(config, key) {
  116. // return the default value if undefined
  117. if (undefined === config.crowi || undefined === config.crowi[key]) {
  118. return getDefaultCrowiConfigs()[key];
  119. }
  120. return config.crowi[key];
  121. }
  122. function getValueForMarkdownNS(config, key) {
  123. // return the default value if undefined
  124. if (undefined === config.markdown || undefined === config.markdown[key]) {
  125. return getDefaultMarkdownConfigs()[key];
  126. }
  127. return config.markdown[key];
  128. }
  129. /**
  130. * It is deprecated to use this for anything other than ConfigLoader#load.
  131. */
  132. configSchema.statics.getDefaultCrowiConfigsObject = function() {
  133. return getDefaultCrowiConfigs();
  134. };
  135. /**
  136. * It is deprecated to use this for anything other than ConfigLoader#load.
  137. */
  138. configSchema.statics.getDefaultMarkdownConfigsObject = function() {
  139. return getDefaultMarkdownConfigs();
  140. };
  141. configSchema.statics.getRestrictGuestModeLabels = function() {
  142. var labels = {};
  143. labels[SECURITY_RESTRICT_GUEST_MODE_DENY] = 'security_setting.guest_mode.deny';
  144. labels[SECURITY_RESTRICT_GUEST_MODE_READONLY] = 'security_setting.guest_mode.readonly';
  145. return labels;
  146. };
  147. configSchema.statics.getRegistrationModeLabels = function() {
  148. var labels = {};
  149. labels[SECURITY_REGISTRATION_MODE_OPEN] = 'security_setting.registration_mode.open';
  150. labels[SECURITY_REGISTRATION_MODE_RESTRICTED] = 'security_setting.registration_mode.restricted';
  151. labels[SECURITY_REGISTRATION_MODE_CLOSED] = 'security_setting.registration_mode.closed';
  152. return labels;
  153. };
  154. configSchema.statics.updateConfigCache = function(ns, config) {
  155. validateCrowi();
  156. const originalConfig = crowi.getConfig();
  157. const newNSConfig = originalConfig[ns] || {};
  158. Object.keys(config).forEach(function(key) {
  159. if (config[key] || config[key] === '' || config[key] === false) {
  160. newNSConfig[key] = config[key];
  161. }
  162. });
  163. originalConfig[ns] = newNSConfig;
  164. crowi.setConfig(originalConfig);
  165. // initialize custom css/script
  166. Config.initCustomCss(originalConfig);
  167. Config.initCustomScript(originalConfig);
  168. };
  169. // Execute only once for installing application
  170. configSchema.statics.applicationInstall = function(callback) {
  171. var Config = this;
  172. Config.count({ ns: 'crowi' }, function(err, count) {
  173. if (count > 0) {
  174. return callback(new Error('Application already installed'), null);
  175. }
  176. Config.updateNamespaceByArray('crowi', getArrayForInstalling(), function(err, configs) {
  177. Config.updateConfigCache('crowi', configs);
  178. return callback(err, configs);
  179. });
  180. });
  181. };
  182. configSchema.statics.setupConfigFormData = function(ns, config) {
  183. var defaultConfig = {};
  184. // set Default Settings
  185. if (ns === 'crowi') {
  186. defaultConfig = getDefaultCrowiConfigs();
  187. }
  188. else if (ns === 'markdown') {
  189. defaultConfig = getDefaultMarkdownConfigs();
  190. }
  191. if (!defaultConfig[ns]) {
  192. defaultConfig[ns] = {};
  193. }
  194. Object.keys(config[ns] || {}).forEach(function(key) {
  195. if (config[ns][key] !== undefined) {
  196. defaultConfig[key] = config[ns][key];
  197. }
  198. });
  199. return defaultConfig;
  200. };
  201. configSchema.statics.updateNamespaceByArray = function(ns, configs, callback) {
  202. var Config = this;
  203. if (configs.length < 0) {
  204. return callback(new Error('Argument #1 is not array.'), null);
  205. }
  206. Object.keys(configs).forEach(function(key) {
  207. var value = configs[key];
  208. Config.findOneAndUpdate(
  209. { ns: ns, key: key },
  210. { ns: ns, key: key, value: JSON.stringify(value) },
  211. { upsert: true, },
  212. function(err, config) {
  213. debug('Config.findAndUpdate', err, config);
  214. });
  215. });
  216. return callback(null, configs);
  217. };
  218. configSchema.statics.findOneAndUpdateByNsAndKey = async function(ns, key, value) {
  219. return this.findOneAndUpdate(
  220. { ns: ns, key: key },
  221. { ns: ns, key: key, value: JSON.stringify(value) },
  222. { upsert: true, });
  223. };
  224. configSchema.statics.getConfig = function(callback) {
  225. };
  226. configSchema.statics.loadAllConfig = function(callback) {
  227. var Config = this
  228. , config = {};
  229. config.crowi = {}; // crowi namespace
  230. Config.find()
  231. .sort({ns: 1, key: 1})
  232. .exec(function(err, doc) {
  233. doc.forEach(function(el) {
  234. if (!config[el.ns]) {
  235. config[el.ns] = {};
  236. }
  237. config[el.ns][el.key] = JSON.parse(el.value);
  238. });
  239. debug('Config loaded', config);
  240. // initialize custom css/script
  241. Config.initCustomCss(config);
  242. Config.initCustomScript(config);
  243. return callback(null, config);
  244. });
  245. };
  246. configSchema.statics.appTitle = function(config) {
  247. const key = 'app:title';
  248. return getValueForCrowiNS(config, key) || 'GROWI';
  249. };
  250. configSchema.statics.globalLang = function(config) {
  251. const key = 'app:globalLang';
  252. return getValueForCrowiNS(config, key);
  253. };
  254. configSchema.statics.isEnabledPassport = function(config) {
  255. // always true if growi installed cleanly
  256. if (Object.keys(config.crowi).length == 0) {
  257. return true;
  258. }
  259. const key = 'security:isEnabledPassport';
  260. return getValueForCrowiNS(config, key);
  261. };
  262. configSchema.statics.isEnabledPassportLdap = function(config) {
  263. const key = 'security:passport-ldap:isEnabled';
  264. return getValueForCrowiNS(config, key);
  265. };
  266. configSchema.statics.isEnabledPassportGoogle = function(config) {
  267. const key = 'security:passport-google:isEnabled';
  268. return getValueForCrowiNS(config, key);
  269. };
  270. configSchema.statics.isEnabledPassportGitHub = function(config) {
  271. const key = 'security:passport-github:isEnabled';
  272. return getValueForCrowiNS(config, key);
  273. };
  274. configSchema.statics.isEnabledPassportTwitter = function(config) {
  275. const key = 'security:passport-twitter:isEnabled';
  276. return getValueForCrowiNS(config, key);
  277. };
  278. configSchema.statics.isUploadable = function(config) {
  279. const method = process.env.FILE_UPLOAD || 'aws';
  280. if (method == 'aws' && (
  281. !config.crowi['aws:accessKeyId'] ||
  282. !config.crowi['aws:secretAccessKey'] ||
  283. !config.crowi['aws:region'] ||
  284. !config.crowi['aws:bucket'])) {
  285. return false;
  286. }
  287. return method != 'none';
  288. };
  289. configSchema.statics.isGuestAllowedToRead = function(config) {
  290. // return true if puclic wiki mode
  291. if (Config.isPublicWikiOnly(config)) {
  292. return true;
  293. }
  294. // return false if undefined
  295. if (undefined === config.crowi || undefined === config.crowi['security:restrictGuestMode']) {
  296. return false;
  297. }
  298. return SECURITY_RESTRICT_GUEST_MODE_READONLY === config.crowi['security:restrictGuestMode'];
  299. };
  300. configSchema.statics.hidePagesRestrictedByOwnerInList = function(config) {
  301. const key = 'security:list-policy:hideRestrictedByOwner';
  302. return getValueForCrowiNS(config, key);
  303. };
  304. configSchema.statics.hidePagesRestrictedByGroupInList = function(config) {
  305. const key = 'security:list-policy:hideRestrictedByGroup';
  306. return getValueForCrowiNS(config, key);
  307. };
  308. configSchema.statics.isEnabledPlugins = function(config) {
  309. const key = 'plugin:isEnabledPlugins';
  310. return getValueForCrowiNS(config, key);
  311. };
  312. configSchema.statics.isEnabledLinebreaks = function(config) {
  313. const key = 'markdown:isEnabledLinebreaks';
  314. return getValueForMarkdownNS(config, key);
  315. };
  316. configSchema.statics.isEnabledLinebreaksInComments = function(config) {
  317. const key = 'markdown:isEnabledLinebreaksInComments';
  318. return getValueForMarkdownNS(config, key);
  319. };
  320. configSchema.statics.isPublicWikiOnly = function(config) {
  321. const publicWikiOnly = process.env.PUBLIC_WIKI_ONLY;
  322. if ( publicWikiOnly === 'true' || publicWikiOnly == 1) {
  323. return true;
  324. }
  325. return false;
  326. };
  327. configSchema.statics.pageBreakSeparator = function(config) {
  328. const key = 'markdown:presentation:pageBreakSeparator';
  329. return getValueForMarkdownNS(config, key);
  330. };
  331. configSchema.statics.pageBreakCustomSeparator = function(config) {
  332. const key = 'markdown:presentation:pageBreakCustomSeparator';
  333. return getValueForMarkdownNS(config, key);
  334. };
  335. configSchema.statics.isEnabledXssPrevention = function(config) {
  336. const key = 'markdown:xss:isEnabledPrevention';
  337. return getValueForMarkdownNS(config, key);
  338. };
  339. configSchema.statics.xssOption = function(config) {
  340. const key = 'markdown:xss:option';
  341. return getValueForMarkdownNS(config, key);
  342. };
  343. configSchema.statics.tagWhiteList = function(config) {
  344. const key = 'markdown:xss:tagWhiteList';
  345. if (this.isEnabledXssPrevention(config)) {
  346. switch (this.xssOption(config)) {
  347. case 1: // ignore all: use default option
  348. return [];
  349. case 2: // recommended
  350. return recommendedXssWhiteList.tags;
  351. case 3: // custom white list
  352. return config.markdown[key];
  353. default:
  354. return [];
  355. }
  356. }
  357. else {
  358. return [];
  359. }
  360. };
  361. configSchema.statics.attrWhiteList = function(config) {
  362. const key = 'markdown:xss:attrWhiteList';
  363. if (this.isEnabledXssPrevention(config)) {
  364. switch (this.xssOption(config)) {
  365. case 1: // ignore all: use default option
  366. return [];
  367. case 2: // recommended
  368. return recommendedXssWhiteList.attrs;
  369. case 3: // custom white list
  370. return config.markdown[key];
  371. default:
  372. return [];
  373. }
  374. }
  375. else {
  376. return [];
  377. }
  378. };
  379. /**
  380. * initialize custom css strings
  381. */
  382. configSchema.statics.initCustomCss = function(config) {
  383. const key = 'customize:css';
  384. const rawCss = getValueForCrowiNS(config, key);
  385. // uglify and store
  386. this._customCss = uglifycss.processString(rawCss);
  387. };
  388. configSchema.statics.customCss = function(config) {
  389. return this._customCss;
  390. };
  391. configSchema.statics.initCustomScript = function(config) {
  392. const key = 'customize:script';
  393. const rawScript = getValueForCrowiNS(config, key);
  394. // store as is
  395. this._customScript = rawScript;
  396. };
  397. configSchema.statics.customScript = function(config) {
  398. return this._customScript;
  399. };
  400. configSchema.statics.customHeader = function(config) {
  401. const key = 'customize:header';
  402. return getValueForCrowiNS(config, key);
  403. };
  404. configSchema.statics.theme = function(config) {
  405. const key = 'customize:theme';
  406. return getValueForCrowiNS(config, key);
  407. };
  408. configSchema.statics.customTitle = function(config, page) {
  409. validateCrowi();
  410. const key = 'customize:title';
  411. let customTitle = getValueForCrowiNS(config, key);
  412. if (customTitle == null || customTitle.trim().length == 0) {
  413. customTitle = '{{page}} - {{sitename}}';
  414. }
  415. // replace
  416. customTitle = customTitle
  417. .replace('{{sitename}}', this.appTitle(config))
  418. .replace('{{page}}', page);
  419. return crowi.xss.process(customTitle);
  420. };
  421. configSchema.statics.behaviorType = function(config) {
  422. const key = 'customize:behavior';
  423. return getValueForCrowiNS(config, key);
  424. };
  425. configSchema.statics.layoutType = function(config) {
  426. const key = 'customize:layout';
  427. return getValueForCrowiNS(config, key);
  428. };
  429. configSchema.statics.highlightJsStyle = function(config) {
  430. const key = 'customize:highlightJsStyle';
  431. return getValueForCrowiNS(config, key);
  432. };
  433. configSchema.statics.highlightJsStyleBorder = function(config) {
  434. const key = 'customize:highlightJsStyleBorder';
  435. return getValueForCrowiNS(config, key);
  436. };
  437. configSchema.statics.isEnabledTimeline = function(config) {
  438. const key = 'customize:isEnabledTimeline';
  439. return getValueForCrowiNS(config, key);
  440. };
  441. configSchema.statics.isSavedStatesOfTabChanges = function(config) {
  442. const key = 'customize:isSavedStatesOfTabChanges';
  443. return getValueForCrowiNS(config, key);
  444. };
  445. configSchema.statics.isEnabledAttachTitleHeader = function(config) {
  446. const key = 'customize:isEnabledAttachTitleHeader';
  447. return getValueForCrowiNS(config, key);
  448. };
  449. configSchema.statics.showRecentCreatedNumber = function(config) {
  450. const key = 'customize:showRecentCreatedNumber';
  451. return getValueForCrowiNS(config, key);
  452. };
  453. configSchema.statics.fileUploadEnabled = function(config) {
  454. const Config = this;
  455. if (!Config.isUploadable(config)) {
  456. return false;
  457. }
  458. // convert to boolean
  459. return !!config.crowi['app:fileUpload'];
  460. };
  461. configSchema.statics.hasSlackConfig = function(config) {
  462. return Config.hasSlackToken(config) || Config.hasSlackIwhUrl(config);
  463. };
  464. /**
  465. * for Slack Incoming Webhooks
  466. */
  467. configSchema.statics.hasSlackIwhUrl = function(config) {
  468. if (!config.notification) {
  469. return false;
  470. }
  471. return (config.notification['slack:incomingWebhookUrl'] ? true : false);
  472. };
  473. configSchema.statics.isIncomingWebhookPrioritized = function(config) {
  474. if (!config.notification) {
  475. return false;
  476. }
  477. return (config.notification['slack:isIncomingWebhookPrioritized'] ? true : false);
  478. };
  479. configSchema.statics.hasSlackToken = function(config) {
  480. if (!config.notification) {
  481. return false;
  482. }
  483. return (config.notification['slack:token'] ? true : false);
  484. };
  485. configSchema.statics.getLocalconfig = function(config) {
  486. const Config = this;
  487. const env = process.env;
  488. const local_config = {
  489. crowi: {
  490. title: Config.appTitle(crowi),
  491. url: config.crowi['app:siteUrl:fixed'] || '',
  492. },
  493. upload: {
  494. image: Config.isUploadable(config),
  495. file: Config.fileUploadEnabled(config),
  496. },
  497. behaviorType: Config.behaviorType(config),
  498. layoutType: Config.layoutType(config),
  499. isEnabledLinebreaks: Config.isEnabledLinebreaks(config),
  500. isEnabledLinebreaksInComments: Config.isEnabledLinebreaksInComments(config),
  501. isEnabledXssPrevention: Config.isEnabledXssPrevention(config),
  502. xssOption: Config.xssOption(config),
  503. tagWhiteList: Config.tagWhiteList(config),
  504. attrWhiteList: Config.attrWhiteList(config),
  505. highlightJsStyleBorder: Config.highlightJsStyleBorder(config),
  506. isSavedStatesOfTabChanges: Config.isSavedStatesOfTabChanges(config),
  507. hasSlackConfig: Config.hasSlackConfig(config),
  508. env: {
  509. PLANTUML_URI: env.PLANTUML_URI || null,
  510. BLOCKDIAG_URI: env.BLOCKDIAG_URI || null,
  511. HACKMD_URI: env.HACKMD_URI || null,
  512. MATHJAX: env.MATHJAX || null,
  513. NO_CDN: env.NO_CDN || null,
  514. },
  515. recentCreatedLimit: Config.showRecentCreatedNumber(config),
  516. isAclEnabled: !Config.isPublicWikiOnly(config),
  517. globalLang: Config.globalLang(config),
  518. };
  519. return local_config;
  520. };
  521. configSchema.statics.userUpperLimit = function(crowi) {
  522. const key = 'USER_UPPER_LIMIT';
  523. const env = crowi.env[key];
  524. if (undefined === crowi.env || undefined === crowi.env[key]) {
  525. return 0;
  526. }
  527. return Number(env);
  528. };
  529. /*
  530. configSchema.statics.isInstalled = function(config)
  531. {
  532. if (!config.crowi) {
  533. return false;
  534. }
  535. if (config.crowi['app:installed']
  536. && config.crowi['app:installed'] !== '0.0.0') {
  537. return true;
  538. }
  539. return false;
  540. }
  541. */
  542. Config = mongoose.model('Config', configSchema);
  543. Config.SECURITY_REGISTRATION_MODE_OPEN = SECURITY_REGISTRATION_MODE_OPEN;
  544. Config.SECURITY_REGISTRATION_MODE_RESTRICTED = SECURITY_REGISTRATION_MODE_RESTRICTED;
  545. Config.SECURITY_REGISTRATION_MODE_CLOSED = SECURITY_REGISTRATION_MODE_CLOSED;
  546. return Config;
  547. };