index.js 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445
  1. import { SCOPE } from '@growi/core/dist/interfaces';
  2. import express from 'express';
  3. import { middlewareFactory as rateLimiterFactory } from '~/features/rate-limiter';
  4. import { accessTokenParser } from '../middlewares/access-token-parser';
  5. import { generateAddActivityMiddleware } from '../middlewares/add-activity';
  6. import apiV1FormValidator from '../middlewares/apiv1-form-validator';
  7. import * as applicationNotInstalled from '../middlewares/application-not-installed';
  8. import {
  9. excludeReadOnlyUser,
  10. excludeReadOnlyUserIfCommentNotAllowed,
  11. } from '../middlewares/exclude-read-only-user';
  12. import injectResetOrderByTokenMiddleware from '../middlewares/inject-reset-order-by-token-middleware';
  13. import injectUserRegistrationOrderByTokenMiddleware from '../middlewares/inject-user-registration-order-by-token-middleware';
  14. import * as loginFormValidator from '../middlewares/login-form-validator';
  15. import {
  16. generateUnavailableWhenMaintenanceModeMiddleware,
  17. generateUnavailableWhenMaintenanceModeMiddlewareForApi,
  18. } from '../middlewares/unavailable-when-maintenance-mode';
  19. import * as attachment from './attachment';
  20. import { routesFactory as attachmentApiRoutesFactory } from './attachment/api';
  21. import * as forgotPassword from './forgot-password';
  22. import nextFactory from './next';
  23. import * as userActivation from './user-activation';
  24. const multer = require('multer');
  25. const autoReap = require('multer-autoreap');
  26. autoReap.options.reapOnError = true; // continue reaping the file even if an error occurs
  27. /** @param {import('~/server/crowi').default} crowi Crowi instance */
  28. module.exports = (crowi, app) => {
  29. const autoReconnectToSearch =
  30. require('../middlewares/auto-reconnect-to-search')(crowi);
  31. const applicationInstalled = require('../middlewares/application-installed')(
  32. crowi,
  33. );
  34. const loginRequiredStrictly = require('../middlewares/login-required')(crowi);
  35. const loginRequired = require('../middlewares/login-required')(crowi, true);
  36. const adminRequired = require('../middlewares/admin-required')(crowi);
  37. const addActivity = generateAddActivityMiddleware(crowi);
  38. const uploads = multer({ dest: `${crowi.tmpDir}uploads` });
  39. const page = require('./page')(crowi, app);
  40. const login = require('./login')(crowi, app);
  41. const loginPassport = require('./login-passport')(crowi, app);
  42. const admin = require('./admin')(crowi, app);
  43. const attachmentApi = attachmentApiRoutesFactory(crowi).api;
  44. const comment = require('./comment')(crowi, app);
  45. const tag = require('./tag')(crowi, app);
  46. const search = require('./search')(crowi, app);
  47. const ogp = require('./ogp')(crowi);
  48. const { createApiRouter } = require('~/server/util/createApiRouter');
  49. const next = nextFactory(crowi);
  50. const unavailableWhenMaintenanceMode =
  51. generateUnavailableWhenMaintenanceModeMiddleware(crowi);
  52. const unavailableWhenMaintenanceModeForApi =
  53. generateUnavailableWhenMaintenanceModeMiddlewareForApi(crowi);
  54. /* eslint-disable max-len, comma-spacing, no-multi-spaces */
  55. const [apiV3Router, apiV3AdminRouter, apiV3AuthRouter] = require('./apiv3')(
  56. crowi,
  57. app,
  58. );
  59. // Rate limiter
  60. app.use(rateLimiterFactory());
  61. // API v3 for admin
  62. app.use('/_api/v3', apiV3AdminRouter);
  63. // API v3 for auth
  64. app.use('/_api/v3', apiV3AuthRouter);
  65. app.get('/_next/*', next.delegateToNext);
  66. app.get(
  67. '/',
  68. applicationInstalled,
  69. unavailableWhenMaintenanceMode,
  70. loginRequired,
  71. autoReconnectToSearch,
  72. next.delegateToNext,
  73. );
  74. app.get('/login/error/:reason', applicationInstalled, next.delegateToNext);
  75. app.get('/login', applicationInstalled, login.preLogin, next.delegateToNext);
  76. app.get('/invited', applicationInstalled, next.delegateToNext);
  77. // app.post('/login' , applicationInstalled, loginFormValidator.loginRules(), loginFormValidator.loginValidation, csrfProtection, addActivity, loginPassport.loginWithLocal, loginPassport.loginWithLdap, loginPassport.loginFailure);
  78. // NOTE: get method "/admin/export/:fileName" should be loaded before "/admin/*"
  79. app.get(
  80. '/admin/export/:fileName',
  81. accessTokenParser([SCOPE.READ.ADMIN.EXPORT_DATA]),
  82. loginRequiredStrictly,
  83. adminRequired,
  84. admin.export.api.validators.export.download(),
  85. admin.export.download,
  86. );
  87. // TODO: If you want to use accessTokenParser, you need to add scope ANY e.g. accessTokenParser([SCOPE.READ.ADMIN.ANY])
  88. app.get(
  89. '/admin/*',
  90. applicationInstalled,
  91. loginRequiredStrictly,
  92. adminRequired,
  93. next.delegateToNext,
  94. );
  95. app.get(
  96. '/admin',
  97. applicationInstalled,
  98. loginRequiredStrictly,
  99. adminRequired,
  100. next.delegateToNext,
  101. );
  102. // installer
  103. app.get(
  104. '/installer',
  105. applicationNotInstalled.generateCheckerMiddleware(crowi),
  106. next.delegateToNext,
  107. applicationNotInstalled.redirectToTopOnError,
  108. );
  109. // OAuth
  110. app.get(
  111. '/passport/google',
  112. loginPassport.loginWithGoogle,
  113. loginPassport.loginFailureForExternalAccount,
  114. );
  115. app.get(
  116. '/passport/github',
  117. loginPassport.loginWithGitHub,
  118. loginPassport.loginFailureForExternalAccount,
  119. );
  120. app.get(
  121. '/passport/oidc',
  122. loginPassport.loginWithOidc,
  123. loginPassport.loginFailureForExternalAccount,
  124. );
  125. app.get(
  126. '/passport/saml',
  127. loginPassport.loginWithSaml,
  128. loginPassport.loginFailureForExternalAccount,
  129. );
  130. app.get(
  131. '/passport/google/callback',
  132. loginPassport.injectRedirectTo,
  133. loginPassport.loginPassportGoogleCallback,
  134. loginPassport.loginFailureForExternalAccount,
  135. );
  136. app.get(
  137. '/passport/github/callback',
  138. loginPassport.injectRedirectTo,
  139. loginPassport.loginPassportGitHubCallback,
  140. loginPassport.loginFailureForExternalAccount,
  141. );
  142. app.get(
  143. '/passport/oidc/callback',
  144. loginPassport.injectRedirectTo,
  145. loginPassport.loginPassportOidcCallback,
  146. loginPassport.loginFailureForExternalAccount,
  147. );
  148. app.post(
  149. '/passport/saml/callback',
  150. addActivity,
  151. loginPassport.injectRedirectTo,
  152. loginPassport.loginPassportSamlCallback,
  153. loginPassport.loginFailureForExternalAccount,
  154. );
  155. app.post(
  156. '/_api/login/testLdap',
  157. accessTokenParser([SCOPE.WRITE.USER_SETTINGS.EXTERNAL_ACCOUNT]),
  158. loginRequiredStrictly,
  159. loginFormValidator.loginRules(),
  160. loginFormValidator.loginValidation,
  161. loginPassport.testLdapCredentials,
  162. );
  163. // importer management for admin
  164. app.post(
  165. '/_api/admin/settings/importerEsa',
  166. accessTokenParser([SCOPE.WRITE.ADMIN.IMPORT_DATA]),
  167. loginRequiredStrictly,
  168. adminRequired,
  169. addActivity,
  170. admin.importer.api.validators.importer.esa(),
  171. admin.api.importerSettingEsa,
  172. );
  173. app.post(
  174. '/_api/admin/settings/importerQiita',
  175. accessTokenParser([SCOPE.WRITE.ADMIN.IMPORT_DATA]),
  176. loginRequiredStrictly,
  177. adminRequired,
  178. addActivity,
  179. admin.importer.api.validators.importer.qiita(),
  180. admin.api.importerSettingQiita,
  181. );
  182. app.post(
  183. '/_api/admin/import/esa',
  184. accessTokenParser([SCOPE.WRITE.ADMIN.IMPORT_DATA]),
  185. loginRequiredStrictly,
  186. adminRequired,
  187. addActivity,
  188. admin.api.importDataFromEsa,
  189. );
  190. app.post(
  191. '/_api/admin/import/testEsaAPI',
  192. accessTokenParser([SCOPE.WRITE.ADMIN.IMPORT_DATA]),
  193. loginRequiredStrictly,
  194. adminRequired,
  195. addActivity,
  196. admin.api.testEsaAPI,
  197. );
  198. app.post(
  199. '/_api/admin/import/qiita',
  200. accessTokenParser([SCOPE.WRITE.ADMIN.IMPORT_DATA]),
  201. loginRequiredStrictly,
  202. adminRequired,
  203. addActivity,
  204. admin.api.importDataFromQiita,
  205. );
  206. app.post(
  207. '/_api/admin/import/testQiitaAPI',
  208. accessTokenParser([SCOPE.WRITE.ADMIN.IMPORT_DATA]),
  209. loginRequiredStrictly,
  210. adminRequired,
  211. addActivity,
  212. admin.api.testQiitaAPI,
  213. );
  214. // brand logo
  215. app.use('/attachment', attachment.getBrandLogoRouterFactory(crowi));
  216. /*
  217. * Routes below are unavailable when maintenance mode
  218. */
  219. // API v3
  220. app.use('/_api/v3', unavailableWhenMaintenanceModeForApi, apiV3Router);
  221. const apiV1Router = createApiRouter();
  222. apiV1Router.get(
  223. '/search',
  224. accessTokenParser([SCOPE.READ.FEATURES.PAGE], { acceptLegacy: true }),
  225. loginRequired,
  226. search.api.search,
  227. );
  228. // HTTP RPC Styled API (に徐々に移行していいこうと思う)
  229. apiV1Router.get(
  230. '/pages.updatePost',
  231. accessTokenParser([SCOPE.READ.FEATURES.PAGE], { acceptLegacy: true }),
  232. loginRequired,
  233. page.api.getUpdatePost,
  234. );
  235. apiV1Router.get(
  236. '/pages.getPageTag',
  237. accessTokenParser([SCOPE.READ.FEATURES.PAGE], { acceptLegacy: true }),
  238. loginRequired,
  239. page.api.getPageTag,
  240. );
  241. // allow posting to guests because the client doesn't know whether the user logged in
  242. apiV1Router.post(
  243. '/pages.remove',
  244. accessTokenParser([SCOPE.WRITE.FEATURES.PAGE]),
  245. loginRequiredStrictly,
  246. excludeReadOnlyUser,
  247. page.validator.remove,
  248. apiV1FormValidator,
  249. page.api.remove,
  250. ); // (Avoid from API Token)
  251. apiV1Router.post(
  252. '/pages.revertRemove',
  253. accessTokenParser([SCOPE.WRITE.FEATURES.PAGE]),
  254. loginRequiredStrictly,
  255. excludeReadOnlyUser,
  256. page.validator.revertRemove,
  257. apiV1FormValidator,
  258. page.api.revertRemove,
  259. ); // (Avoid from API Token)
  260. apiV1Router.post(
  261. '/pages.unlink',
  262. accessTokenParser([SCOPE.WRITE.FEATURES.PAGE]),
  263. loginRequiredStrictly,
  264. excludeReadOnlyUser,
  265. page.api.unlink,
  266. ); // (Avoid from API Token)
  267. apiV1Router.get(
  268. '/tags.list',
  269. accessTokenParser([SCOPE.READ.FEATURES.PAGE], { acceptLegacy: true }),
  270. loginRequired,
  271. tag.api.list,
  272. );
  273. apiV1Router.get(
  274. '/tags.search',
  275. accessTokenParser([SCOPE.READ.FEATURES.PAGE], { acceptLegacy: true }),
  276. loginRequired,
  277. tag.api.search,
  278. );
  279. apiV1Router.post(
  280. '/tags.update',
  281. accessTokenParser([SCOPE.WRITE.FEATURES.PAGE], { acceptLegacy: true }),
  282. loginRequiredStrictly,
  283. excludeReadOnlyUser,
  284. addActivity,
  285. tag.api.update,
  286. );
  287. apiV1Router.get(
  288. '/comments.get',
  289. accessTokenParser([SCOPE.READ.FEATURES.PAGE], { acceptLegacy: true }),
  290. loginRequired,
  291. comment.api.get,
  292. );
  293. apiV1Router.post(
  294. '/comments.add',
  295. accessTokenParser([SCOPE.WRITE.FEATURES.PAGE], { acceptLegacy: true }),
  296. comment.api.validators.add(),
  297. loginRequiredStrictly,
  298. excludeReadOnlyUserIfCommentNotAllowed,
  299. addActivity,
  300. comment.api.add,
  301. );
  302. apiV1Router.post(
  303. '/comments.update',
  304. accessTokenParser([SCOPE.WRITE.FEATURES.PAGE], { acceptLegacy: true }),
  305. comment.api.validators.add(),
  306. loginRequiredStrictly,
  307. excludeReadOnlyUserIfCommentNotAllowed,
  308. addActivity,
  309. comment.api.update,
  310. );
  311. apiV1Router.post(
  312. '/comments.remove',
  313. accessTokenParser([SCOPE.WRITE.FEATURES.PAGE], { acceptLegacy: true }),
  314. loginRequiredStrictly,
  315. excludeReadOnlyUserIfCommentNotAllowed,
  316. addActivity,
  317. comment.api.remove,
  318. );
  319. apiV1Router.post(
  320. '/attachments.uploadProfileImage',
  321. accessTokenParser([SCOPE.WRITE.FEATURES.ATTACHMENT], {
  322. acceptLegacy: true,
  323. }),
  324. loginRequiredStrictly,
  325. uploads.single('file'),
  326. autoReap,
  327. attachmentApi.uploadProfileImage,
  328. );
  329. apiV1Router.post(
  330. '/attachments.remove',
  331. accessTokenParser([SCOPE.WRITE.FEATURES.ATTACHMENT], {
  332. acceptLegacy: true,
  333. }),
  334. loginRequiredStrictly,
  335. excludeReadOnlyUser,
  336. addActivity,
  337. attachmentApi.remove,
  338. );
  339. apiV1Router.post(
  340. '/attachments.removeProfileImage',
  341. accessTokenParser([SCOPE.WRITE.FEATURES.ATTACHMENT], {
  342. acceptLegacy: true,
  343. }),
  344. loginRequiredStrictly,
  345. attachmentApi.removeProfileImage,
  346. );
  347. // API v1
  348. app.use('/_api', unavailableWhenMaintenanceModeForApi, apiV1Router);
  349. app.use(unavailableWhenMaintenanceMode);
  350. app.get('/me', loginRequiredStrictly, next.delegateToNext);
  351. app.get('/me/*', loginRequiredStrictly, next.delegateToNext);
  352. app.use(
  353. '/attachment',
  354. accessTokenParser([SCOPE.READ.FEATURES.ATTACHMENT]),
  355. attachment.getRouterFactory(crowi),
  356. );
  357. app.use(
  358. '/download',
  359. accessTokenParser([SCOPE.READ.FEATURES.ATTACHMENT]),
  360. attachment.downloadRouterFactory(crowi),
  361. );
  362. app.get('/_search', loginRequired, next.delegateToNext);
  363. app.use(
  364. '/forgot-password',
  365. express
  366. .Router()
  367. .use(forgotPassword.checkForgotPasswordEnabledMiddlewareFactory(crowi))
  368. .get('/', forgotPassword.renderForgotPassword(crowi))
  369. .get(
  370. '/:token',
  371. injectResetOrderByTokenMiddleware,
  372. forgotPassword.renderResetPassword(crowi),
  373. )
  374. .use(forgotPassword.handleErrorsMiddleware(crowi)),
  375. );
  376. app.get('/_private-legacy-pages', next.delegateToNext);
  377. app.use(
  378. '/user-activation',
  379. express
  380. .Router()
  381. .get(
  382. '/:token',
  383. applicationInstalled,
  384. injectUserRegistrationOrderByTokenMiddleware,
  385. userActivation.renderUserActivationPage(crowi),
  386. )
  387. .use(userActivation.tokenErrorHandlerMiddeware(crowi)),
  388. );
  389. app.get('/share$', (req, res) => res.redirect('/'));
  390. app.get('/share/:linkId', next.delegateToNext);
  391. app.use(
  392. '/ogp',
  393. express
  394. .Router()
  395. .get(
  396. '/:pageId([0-9a-z]{0,})',
  397. loginRequired,
  398. ogp.pageIdRequired,
  399. ogp.ogpValidator,
  400. ogp.renderOgp,
  401. ),
  402. );
  403. app.get('/*/$', loginRequired, next.delegateToNext);
  404. app.get('/*', loginRequired, autoReconnectToSearch, next.delegateToNext);
  405. };