index.js 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201
  1. import express from 'express';
  2. import injectResetOrderByTokenMiddleware from '../middlewares/inject-reset-order-by-token-middleware';
  3. import * as forgotPassword from './forgot-password';
  4. const multer = require('multer');
  5. const autoReap = require('multer-autoreap');
  6. const rateLimit = require('express-rate-limit');
  7. const apiLimiter = rateLimit({
  8. windowMs: 15 * 60 * 1000, // 15 minutes
  9. max: 5, // limit each IP to 5 requests per windowMs
  10. message:
  11. 'Too many requests sent from this IP, please try again after 15 minutes',
  12. });
  13. autoReap.options.reapOnError = true; // continue reaping the file even if an error occurs
  14. module.exports = function(crowi, app) {
  15. const autoReconnectToSearch = require('../middlewares/auto-reconnect-to-search')(crowi);
  16. const applicationNotInstalled = require('../middlewares/application-not-installed')(crowi);
  17. const applicationInstalled = require('../middlewares/application-installed')(crowi);
  18. const accessTokenParser = require('../middlewares/access-token-parser')(crowi);
  19. const loginRequiredStrictly = require('../middlewares/login-required')(crowi);
  20. const loginRequired = require('../middlewares/login-required')(crowi, true);
  21. const adminRequired = require('../middlewares/admin-required')(crowi);
  22. const certifySharedFile = require('../middlewares/certify-shared-file')(crowi);
  23. const csrf = require('../middlewares/csrf')(crowi);
  24. const uploads = multer({ dest: `${crowi.tmpDir}uploads` });
  25. const form = require('../form');
  26. const page = require('./page')(crowi, app);
  27. const login = require('./login')(crowi, app);
  28. const loginPassport = require('./login-passport')(crowi, app);
  29. const logout = require('./logout')(crowi, app);
  30. const me = require('./me')(crowi, app);
  31. const admin = require('./admin')(crowi, app);
  32. const user = require('./user')(crowi, app);
  33. const attachment = require('./attachment')(crowi, app);
  34. const comment = require('./comment')(crowi, app);
  35. const tag = require('./tag')(crowi, app);
  36. const search = require('./search')(crowi, app);
  37. const hackmd = require('./hackmd')(crowi, app);
  38. const isInstalled = crowi.configManager.getConfig('crowi', 'app:installed');
  39. /* eslint-disable max-len, comma-spacing, no-multi-spaces */
  40. // API v3
  41. app.use('/api-docs', require('./apiv3/docs')(crowi));
  42. app.use('/_api/v3', require('./apiv3')(crowi));
  43. app.get('/' , applicationInstalled, loginRequired , autoReconnectToSearch, page.showTopPage);
  44. app.get('/login/error/:reason' , applicationInstalled, login.error);
  45. app.get('/login' , applicationInstalled, login.preLogin, login.login);
  46. app.get('/login/invited' , applicationInstalled, login.invited);
  47. app.post('/login/activateInvited' , applicationInstalled, form.invited , csrf, login.invited);
  48. app.post('/login' , applicationInstalled, form.login , csrf, loginPassport.loginWithLocal, loginPassport.loginWithLdap, loginPassport.loginFailure);
  49. app.post('/register' , applicationInstalled, form.register , csrf, login.register);
  50. app.get('/register' , applicationInstalled, login.preLogin, login.register);
  51. app.get('/logout' , applicationInstalled, logout.logout);
  52. app.get('/admin' , applicationInstalled, loginRequiredStrictly , adminRequired , admin.index);
  53. app.get('/admin/app' , applicationInstalled, loginRequiredStrictly , adminRequired , admin.app.index);
  54. // installer
  55. if (!isInstalled) {
  56. const installer = require('./installer')(crowi);
  57. app.get('/installer' , applicationNotInstalled , installer.index);
  58. app.post('/installer' , applicationNotInstalled , form.register , csrf, installer.install);
  59. return;
  60. }
  61. // OAuth
  62. app.get('/passport/google' , loginPassport.loginWithGoogle, loginPassport.loginFailure);
  63. app.get('/passport/github' , loginPassport.loginWithGitHub, loginPassport.loginFailure);
  64. app.get('/passport/twitter' , loginPassport.loginWithTwitter, loginPassport.loginFailure);
  65. app.get('/passport/oidc' , loginPassport.loginWithOidc, loginPassport.loginFailure);
  66. app.get('/passport/saml' , loginPassport.loginWithSaml, loginPassport.loginFailure);
  67. app.get('/passport/basic' , loginPassport.loginWithBasic, loginPassport.loginFailure);
  68. app.get('/passport/google/callback' , loginPassport.loginPassportGoogleCallback , loginPassport.loginFailure);
  69. app.get('/passport/github/callback' , loginPassport.loginPassportGitHubCallback , loginPassport.loginFailure);
  70. app.get('/passport/twitter/callback' , loginPassport.loginPassportTwitterCallback , loginPassport.loginFailure);
  71. app.get('/passport/oidc/callback' , loginPassport.loginPassportOidcCallback , loginPassport.loginFailure);
  72. app.post('/passport/saml/callback' , loginPassport.loginPassportSamlCallback , loginPassport.loginFailure);
  73. app.post('/_api/login/testLdap' , loginRequiredStrictly , form.login , loginPassport.testLdapCredentials);
  74. // security admin
  75. app.get('/admin/security' , loginRequiredStrictly , adminRequired , admin.security.index);
  76. // markdown admin
  77. app.get('/admin/markdown' , loginRequiredStrictly , adminRequired , admin.markdown.index);
  78. // customize admin
  79. app.get('/admin/customize' , loginRequiredStrictly , adminRequired , admin.customize.index);
  80. // search admin
  81. app.get('/admin/search' , loginRequiredStrictly , adminRequired , admin.search.index);
  82. // notification admin
  83. app.get('/admin/notification' , loginRequiredStrictly , adminRequired , admin.notification.index);
  84. app.get('/admin/notification/slackAuth' , loginRequiredStrictly , adminRequired , admin.notification.slackAuth);
  85. app.get('/admin/notification/slackSetting/disconnect' , loginRequiredStrictly , adminRequired , admin.notification.disconnectFromSlack);
  86. app.get('/admin/global-notification/new' , loginRequiredStrictly , adminRequired , admin.globalNotification.detail);
  87. app.get('/admin/global-notification/:id' , loginRequiredStrictly , adminRequired , admin.globalNotification.detail);
  88. app.get('/admin/slack-integration-legacy' , loginRequiredStrictly , adminRequired, admin.slackIntegrationLegacy);
  89. app.get('/admin/slack-integration' , loginRequiredStrictly , adminRequired, admin.slackIntegration);
  90. app.get('/admin/users' , loginRequiredStrictly , adminRequired , admin.user.index);
  91. app.get('/admin/users/external-accounts' , loginRequiredStrictly , adminRequired , admin.externalAccount.index);
  92. // user-groups admin
  93. app.get('/admin/user-groups' , loginRequiredStrictly, adminRequired, admin.userGroup.index);
  94. app.get('/admin/user-group-detail/:id' , loginRequiredStrictly, adminRequired, admin.userGroup.detail);
  95. // importer management for admin
  96. app.get('/admin/importer' , loginRequiredStrictly , adminRequired , admin.importer.index);
  97. app.post('/_api/admin/settings/importerEsa' , loginRequiredStrictly , adminRequired , csrf, admin.importer.api.validators.importer.esa(),admin.api.importerSettingEsa);
  98. app.post('/_api/admin/settings/importerQiita' , loginRequiredStrictly , adminRequired , csrf , admin.importer.api.validators.importer.qiita(), admin.api.importerSettingQiita);
  99. app.post('/_api/admin/import/esa' , loginRequiredStrictly , adminRequired , admin.api.importDataFromEsa);
  100. app.post('/_api/admin/import/testEsaAPI' , loginRequiredStrictly , adminRequired , csrf, admin.api.testEsaAPI);
  101. app.post('/_api/admin/import/qiita' , loginRequiredStrictly , adminRequired , admin.api.importDataFromQiita);
  102. app.post('/_api/admin/import/testQiitaAPI' , loginRequiredStrictly , adminRequired , csrf, admin.api.testQiitaAPI);
  103. // export management for admin
  104. app.get('/admin/export' , loginRequiredStrictly , adminRequired ,admin.export.index);
  105. app.get('/admin/export/:fileName' , loginRequiredStrictly , adminRequired ,admin.export.api.validators.export.download(), admin.export.download);
  106. app.get('/admin/*' , loginRequiredStrictly ,adminRequired, admin.notFound.index);
  107. app.get('/me' , loginRequiredStrictly , me.index);
  108. // external-accounts
  109. app.get('/me/external-accounts' , loginRequiredStrictly , me.externalAccounts.list);
  110. // my drafts
  111. app.get('/me/drafts' , loginRequiredStrictly, me.drafts.list);
  112. app.get('/:id([0-9a-z]{24})' , loginRequired , page.redirector);
  113. app.get('/_r/:id([0-9a-z]{24})' , loginRequired , page.redirector); // alias
  114. app.get('/attachment/:id([0-9a-z]{24})' , certifySharedFile , loginRequired, attachment.api.get);
  115. app.get('/attachment/profile/:id([0-9a-z]{24})' , loginRequired, attachment.api.get);
  116. app.get('/attachment/:pageId/:fileName', loginRequired, attachment.api.obsoletedGetForMongoDB); // DEPRECATED: remains for backward compatibility for v3.3.x or below
  117. app.get('/download/:id([0-9a-z]{24})' , loginRequired, attachment.api.download);
  118. app.get('/_search' , loginRequired , search.searchPage);
  119. app.get('/_api/search' , accessTokenParser , loginRequired , search.api.search);
  120. app.get('/_api/check_username' , user.api.checkUsername);
  121. app.get('/_api/me/user-group-relations' , accessTokenParser , loginRequiredStrictly , me.api.userGroupRelations);
  122. // HTTP RPC Styled API (に徐々に移行していいこうと思う)
  123. app.get('/_api/users.list' , accessTokenParser , loginRequired , user.api.list);
  124. app.get('/_api/pages.list' , accessTokenParser , loginRequired , page.api.list);
  125. app.post('/_api/pages.update' , accessTokenParser , loginRequiredStrictly , csrf, page.api.update);
  126. app.get('/_api/pages.exist' , accessTokenParser , loginRequired , page.api.exist);
  127. app.get('/_api/pages.updatePost' , accessTokenParser, loginRequired, page.api.getUpdatePost);
  128. app.get('/_api/pages.getPageTag' , accessTokenParser , loginRequired , page.api.getPageTag);
  129. // allow posting to guests because the client doesn't know whether the user logged in
  130. app.post('/_api/pages.remove' , loginRequiredStrictly , csrf, page.api.remove); // (Avoid from API Token)
  131. app.post('/_api/pages.revertRemove' , loginRequiredStrictly , csrf, page.api.revertRemove); // (Avoid from API Token)
  132. app.post('/_api/pages.unlink' , loginRequiredStrictly , csrf, page.api.unlink); // (Avoid from API Token)
  133. app.post('/_api/pages.duplicate' , accessTokenParser, loginRequiredStrictly, csrf, page.api.duplicate);
  134. app.get('/tags' , loginRequired, tag.showPage);
  135. app.get('/_api/tags.list' , accessTokenParser, loginRequired, tag.api.list);
  136. app.get('/_api/tags.search' , accessTokenParser, loginRequired, tag.api.search);
  137. app.post('/_api/tags.update' , accessTokenParser, loginRequiredStrictly, tag.api.update);
  138. app.get('/_api/comments.get' , accessTokenParser , loginRequired , comment.api.get);
  139. app.post('/_api/comments.add' , comment.api.validators.add(), accessTokenParser , loginRequiredStrictly , csrf, comment.api.add);
  140. app.post('/_api/comments.update' , comment.api.validators.add(), accessTokenParser , loginRequiredStrictly , csrf, comment.api.update);
  141. app.post('/_api/comments.remove' , accessTokenParser , loginRequiredStrictly , csrf, comment.api.remove);
  142. app.post('/_api/attachments.add' , uploads.single('file'), autoReap, accessTokenParser, loginRequiredStrictly ,csrf, attachment.api.add);
  143. app.post('/_api/attachments.uploadProfileImage' , uploads.single('file'), autoReap, accessTokenParser, loginRequiredStrictly ,csrf, attachment.api.uploadProfileImage);
  144. app.post('/_api/attachments.remove' , accessTokenParser , loginRequiredStrictly , csrf, attachment.api.remove);
  145. app.post('/_api/attachments.removeProfileImage' , accessTokenParser , loginRequiredStrictly , csrf, attachment.api.removeProfileImage);
  146. app.get('/_api/attachments.limit' , accessTokenParser , loginRequiredStrictly, attachment.api.limit);
  147. app.get('/trash$' , loginRequired , page.trashPageShowWrapper);
  148. app.get('/trash/$' , loginRequired , page.trashPageListShowWrapper);
  149. app.get('/trash/*/$' , loginRequired , page.deletedPageListShowWrapper);
  150. app.get('/_hackmd/load-agent' , hackmd.loadAgent);
  151. app.get('/_hackmd/load-styles' , hackmd.loadStyles);
  152. app.post('/_api/hackmd.integrate' , accessTokenParser , loginRequiredStrictly , csrf, hackmd.validateForApi, hackmd.integrate);
  153. app.post('/_api/hackmd.discard' , accessTokenParser , loginRequiredStrictly , csrf, hackmd.validateForApi, hackmd.discard);
  154. app.post('/_api/hackmd.saveOnHackmd' , accessTokenParser , loginRequiredStrictly , csrf, hackmd.validateForApi, hackmd.saveOnHackmd);
  155. app.use('/forgot-password', express.Router()
  156. .get('/', forgotPassword.forgotPassword)
  157. .get('/:token', apiLimiter, injectResetOrderByTokenMiddleware, forgotPassword.resetPassword)
  158. .use(forgotPassword.handleHttpErrosMiddleware));
  159. app.get('/share/:linkId', page.showSharedPage);
  160. app.get('/*/$' , loginRequired , page.showPageWithEndOfSlash, page.notFound);
  161. app.get('/*' , loginRequired , autoReconnectToSearch, page.showPage, page.notFound);
  162. };