config.js 20 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675
  1. // disable no-return-await for model functions
  2. /* eslint-disable no-return-await */
  3. /* eslint-disable no-use-before-define */
  4. module.exports = function(crowi) {
  5. const mongoose = require('mongoose');
  6. const debug = require('debug')('growi:models:config');
  7. const uglifycss = require('uglifycss');
  8. const recommendedWhitelist = require('@commons/service/xss/recommended-whitelist');
  9. const SECURITY_RESTRICT_GUEST_MODE_DENY = 'Deny';
  10. const SECURITY_RESTRICT_GUEST_MODE_READONLY = 'Readonly';
  11. const SECURITY_REGISTRATION_MODE_OPEN = 'Open';
  12. const SECURITY_REGISTRATION_MODE_RESTRICTED = 'Resricted';
  13. const SECURITY_REGISTRATION_MODE_CLOSED = 'Closed';
  14. let Config;
  15. const configSchema = new mongoose.Schema({
  16. ns: { type: String, required: true, index: true },
  17. key: { type: String, required: true, index: true },
  18. value: { type: String, required: true },
  19. });
  20. function validateCrowi() {
  21. if (crowi == null) {
  22. throw new Error('"crowi" is null. Init Config model with "crowi" argument first.');
  23. }
  24. }
  25. /**
  26. * default values when GROWI is cleanly installed
  27. */
  28. function getArrayForInstalling() {
  29. const config = getDefaultCrowiConfigs();
  30. // overwrite
  31. config['app:fileUpload'] = true;
  32. config['security:isEnabledPassport'] = true;
  33. config['customize:behavior'] = 'growi';
  34. config['customize:layout'] = 'growi';
  35. config['customize:isSavedStatesOfTabChanges'] = false;
  36. return config;
  37. }
  38. /**
  39. * default values when migrated from Official Crowi
  40. */
  41. function getDefaultCrowiConfigs() {
  42. /* eslint-disable key-spacing */
  43. return {
  44. // 'app:installed' : "0.0.0",
  45. 'app:confidential' : '',
  46. 'app:fileUpload' : false,
  47. 'app:globalLang' : 'en-US',
  48. 'security:restrictGuestMode' : 'Deny',
  49. 'security:registrationMode' : 'Open',
  50. 'security:registrationWhiteList' : [],
  51. 'security:list-policy:hideRestrictedByOwner' : false,
  52. 'security:list-policy:hideRestrictedByGroup' : false,
  53. 'security:isEnabledPassport' : false,
  54. 'security:passport-ldap:isEnabled' : false,
  55. 'security:passport-ldap:serverUrl' : undefined,
  56. 'security:passport-ldap:isUserBind' : undefined,
  57. 'security:passport-ldap:bindDN' : undefined,
  58. 'security:passport-ldap:bindDNPassword' : undefined,
  59. 'security:passport-ldap:searchFilter' : undefined,
  60. 'security:passport-ldap:attrMapUsername' : undefined,
  61. 'security:passport-ldap:attrMapName' : undefined,
  62. 'security:passport-ldap:attrMapMail' : undefined,
  63. 'security:passport-ldap:groupSearchBase' : undefined,
  64. 'security:passport-ldap:groupSearchFilter' : undefined,
  65. 'security:passport-ldap:groupDnProperty' : undefined,
  66. 'security:passport-ldap:isSameUsernameTreatedAsIdenticalUser': false,
  67. 'security:passport-saml:isEnabled' : false,
  68. 'security:passport-saml:isSameEmailTreatedAsIdenticalUser': false,
  69. 'security:passport-google:isEnabled' : false,
  70. 'security:passport-github:isEnabled' : false,
  71. 'security:passport-twitter:isEnabled' : false,
  72. 'aws:bucket' : 'growi',
  73. 'aws:region' : 'ap-northeast-1',
  74. 'aws:accessKeyId' : '',
  75. 'aws:secretAccessKey' : '',
  76. 'mail:from' : '',
  77. 'mail:smtpHost' : '',
  78. 'mail:smtpPort' : '',
  79. 'mail:smtpUser' : '',
  80. 'mail:smtpPassword' : '',
  81. 'google:clientId' : '',
  82. 'google:clientSecret' : '',
  83. 'plugin:isEnabledPlugins' : true,
  84. 'customize:css' : '',
  85. 'customize:script' : '',
  86. 'customize:header' : '',
  87. 'customize:title' : '',
  88. 'customize:highlightJsStyle' : 'github',
  89. 'customize:highlightJsStyleBorder' : false,
  90. 'customize:theme' : 'default',
  91. 'customize:behavior' : 'crowi',
  92. 'customize:layout' : 'crowi',
  93. 'customize:isEnabledTimeline' : true,
  94. 'customize:isSavedStatesOfTabChanges' : true,
  95. 'customize:isEnabledAttachTitleHeader' : false,
  96. 'customize:showRecentCreatedNumber' : 10,
  97. 'importer:esa:team_name': '',
  98. 'importer:esa:access_token': '',
  99. 'importer:qiita:team_name': '',
  100. 'importer:qiita:access_token': '',
  101. };
  102. /* eslint-enable key-spacing */
  103. }
  104. function getDefaultMarkdownConfigs() {
  105. return {
  106. 'markdown:xss:isEnabledPrevention': true,
  107. 'markdown:xss:option': 2,
  108. 'markdown:xss:tagWhiteList': [],
  109. 'markdown:xss:attrWhiteList': [],
  110. 'markdown:isEnabledLinebreaks': false,
  111. 'markdown:isEnabledLinebreaksInComments': true,
  112. 'markdown:presentation:pageBreakSeparator': 1,
  113. 'markdown:presentation:pageBreakCustomSeparator': '',
  114. };
  115. }
  116. function getValueForCrowiNS(config, key) {
  117. // return the default value if undefined
  118. if (undefined === config.crowi || undefined === config.crowi[key]) {
  119. return getDefaultCrowiConfigs()[key];
  120. }
  121. return config.crowi[key];
  122. }
  123. function getValueForMarkdownNS(config, key) {
  124. // return the default value if undefined
  125. if (undefined === config.markdown || undefined === config.markdown[key]) {
  126. return getDefaultMarkdownConfigs()[key];
  127. }
  128. return config.markdown[key];
  129. }
  130. /**
  131. * It is deprecated to use this for anything other than ConfigLoader#load.
  132. */
  133. configSchema.statics.getDefaultCrowiConfigsObject = function() {
  134. return getDefaultCrowiConfigs();
  135. };
  136. /**
  137. * It is deprecated to use this for anything other than ConfigLoader#load.
  138. */
  139. configSchema.statics.getDefaultMarkdownConfigsObject = function() {
  140. return getDefaultMarkdownConfigs();
  141. };
  142. configSchema.statics.getRestrictGuestModeLabels = function() {
  143. const labels = {};
  144. labels[SECURITY_RESTRICT_GUEST_MODE_DENY] = 'security_setting.guest_mode.deny';
  145. labels[SECURITY_RESTRICT_GUEST_MODE_READONLY] = 'security_setting.guest_mode.readonly';
  146. return labels;
  147. };
  148. configSchema.statics.getRegistrationModeLabels = function() {
  149. const labels = {};
  150. labels[SECURITY_REGISTRATION_MODE_OPEN] = 'security_setting.registration_mode.open';
  151. labels[SECURITY_REGISTRATION_MODE_RESTRICTED] = 'security_setting.registration_mode.restricted';
  152. labels[SECURITY_REGISTRATION_MODE_CLOSED] = 'security_setting.registration_mode.closed';
  153. return labels;
  154. };
  155. configSchema.statics.updateConfigCache = function(ns, config) {
  156. validateCrowi();
  157. const originalConfig = crowi.getConfig();
  158. const newNSConfig = originalConfig[ns] || {};
  159. Object.keys(config).forEach((key) => {
  160. if (config[key] || config[key] === '' || config[key] === false) {
  161. newNSConfig[key] = config[key];
  162. }
  163. });
  164. originalConfig[ns] = newNSConfig;
  165. crowi.setConfig(originalConfig);
  166. // initialize custom css/script
  167. Config.initCustomCss(originalConfig);
  168. Config.initCustomScript(originalConfig);
  169. };
  170. // Execute only once for installing application
  171. configSchema.statics.applicationInstall = function(callback) {
  172. const Config = this;
  173. Config.count({ ns: 'crowi' }, (err, count) => {
  174. if (count > 0) {
  175. return callback(new Error('Application already installed'), null);
  176. }
  177. Config.updateNamespaceByArray('crowi', getArrayForInstalling(), (err, configs) => {
  178. Config.updateConfigCache('crowi', configs);
  179. return callback(err, configs);
  180. });
  181. });
  182. };
  183. configSchema.statics.setupConfigFormData = function(ns, config) {
  184. let defaultConfig = {};
  185. // set Default Settings
  186. if (ns === 'crowi') {
  187. defaultConfig = getDefaultCrowiConfigs();
  188. }
  189. else if (ns === 'markdown') {
  190. defaultConfig = getDefaultMarkdownConfigs();
  191. }
  192. if (!defaultConfig[ns]) {
  193. defaultConfig[ns] = {};
  194. }
  195. Object.keys(config[ns] || {}).forEach((key) => {
  196. if (config[ns][key] !== undefined) {
  197. defaultConfig[key] = config[ns][key];
  198. }
  199. });
  200. return defaultConfig;
  201. };
  202. configSchema.statics.updateNamespaceByArray = function(ns, configs, callback) {
  203. const Config = this;
  204. if (configs.length < 0) {
  205. return callback(new Error('Argument #1 is not array.'), null);
  206. }
  207. Object.keys(configs).forEach((key) => {
  208. const value = configs[key];
  209. Config.findOneAndUpdate(
  210. { ns, key },
  211. { ns, key, value: JSON.stringify(value) },
  212. { upsert: true },
  213. (err, config) => {
  214. debug('Config.findAndUpdate', err, config);
  215. },
  216. );
  217. });
  218. return callback(null, configs);
  219. };
  220. configSchema.statics.findOneAndUpdateByNsAndKey = async function(ns, key, value) {
  221. return this.findOneAndUpdate(
  222. { ns, key },
  223. { ns, key, value: JSON.stringify(value) },
  224. { upsert: true },
  225. );
  226. };
  227. configSchema.statics.getConfig = function(callback) {
  228. };
  229. configSchema.statics.loadAllConfig = function(callback) {
  230. const Config = this;
  231. const config = {};
  232. config.crowi = {}; // crowi namespace
  233. Config.find()
  234. .sort({ ns: 1, key: 1 })
  235. .exec((err, doc) => {
  236. doc.forEach((el) => {
  237. if (!config[el.ns]) {
  238. config[el.ns] = {};
  239. }
  240. config[el.ns][el.key] = JSON.parse(el.value);
  241. });
  242. debug('Config loaded', config);
  243. // initialize custom css/script
  244. Config.initCustomCss(config);
  245. Config.initCustomScript(config);
  246. return callback(null, config);
  247. });
  248. };
  249. configSchema.statics.appTitle = function(config) {
  250. const key = 'app:title';
  251. return getValueForCrowiNS(config, key) || 'GROWI';
  252. };
  253. configSchema.statics.globalLang = function(config) {
  254. const key = 'app:globalLang';
  255. return getValueForCrowiNS(config, key);
  256. };
  257. configSchema.statics.isEnabledPassport = function(config) {
  258. // always true if growi installed cleanly
  259. if (Object.keys(config.crowi).length === 0) {
  260. return true;
  261. }
  262. const key = 'security:isEnabledPassport';
  263. return getValueForCrowiNS(config, key);
  264. };
  265. configSchema.statics.isEnabledPassportLdap = function(config) {
  266. const key = 'security:passport-ldap:isEnabled';
  267. return getValueForCrowiNS(config, key);
  268. };
  269. configSchema.statics.isEnabledPassportGoogle = function(config) {
  270. const key = 'security:passport-google:isEnabled';
  271. return getValueForCrowiNS(config, key);
  272. };
  273. configSchema.statics.isEnabledPassportGitHub = function(config) {
  274. const key = 'security:passport-github:isEnabled';
  275. return getValueForCrowiNS(config, key);
  276. };
  277. configSchema.statics.isEnabledPassportTwitter = function(config) {
  278. const key = 'security:passport-twitter:isEnabled';
  279. return getValueForCrowiNS(config, key);
  280. };
  281. configSchema.statics.isUploadable = function(config) {
  282. const method = process.env.FILE_UPLOAD || 'aws';
  283. if (method === 'aws' && (
  284. !config.crowi['aws:accessKeyId']
  285. || !config.crowi['aws:secretAccessKey']
  286. || !config.crowi['aws:region']
  287. || !config.crowi['aws:bucket'])) {
  288. return false;
  289. }
  290. return method !== 'none';
  291. };
  292. configSchema.statics.isGuestAllowedToRead = function(config) {
  293. // return true if puclic wiki mode
  294. if (Config.isPublicWikiOnly(config)) {
  295. return true;
  296. }
  297. // return false if undefined
  298. if (undefined === config.crowi || undefined === config.crowi['security:restrictGuestMode']) {
  299. return false;
  300. }
  301. return SECURITY_RESTRICT_GUEST_MODE_READONLY === config.crowi['security:restrictGuestMode'];
  302. };
  303. configSchema.statics.hidePagesRestrictedByOwnerInList = function(config) {
  304. const key = 'security:list-policy:hideRestrictedByOwner';
  305. return getValueForCrowiNS(config, key);
  306. };
  307. configSchema.statics.hidePagesRestrictedByGroupInList = function(config) {
  308. const key = 'security:list-policy:hideRestrictedByGroup';
  309. return getValueForCrowiNS(config, key);
  310. };
  311. configSchema.statics.isEnabledPlugins = function(config) {
  312. const key = 'plugin:isEnabledPlugins';
  313. return getValueForCrowiNS(config, key);
  314. };
  315. configSchema.statics.isEnabledLinebreaks = function(config) {
  316. const key = 'markdown:isEnabledLinebreaks';
  317. return getValueForMarkdownNS(config, key);
  318. };
  319. configSchema.statics.isEnabledLinebreaksInComments = function(config) {
  320. const key = 'markdown:isEnabledLinebreaksInComments';
  321. return getValueForMarkdownNS(config, key);
  322. };
  323. configSchema.statics.isPublicWikiOnly = function(config) {
  324. const publicWikiOnly = process.env.PUBLIC_WIKI_ONLY;
  325. if (publicWikiOnly === 'true' || publicWikiOnly === 1) {
  326. return true;
  327. }
  328. return false;
  329. };
  330. configSchema.statics.pageBreakSeparator = function(config) {
  331. const key = 'markdown:presentation:pageBreakSeparator';
  332. return getValueForMarkdownNS(config, key);
  333. };
  334. configSchema.statics.pageBreakCustomSeparator = function(config) {
  335. const key = 'markdown:presentation:pageBreakCustomSeparator';
  336. return getValueForMarkdownNS(config, key);
  337. };
  338. configSchema.statics.isEnabledXssPrevention = function(config) {
  339. const key = 'markdown:xss:isEnabledPrevention';
  340. return getValueForMarkdownNS(config, key);
  341. };
  342. configSchema.statics.xssOption = function(config) {
  343. const key = 'markdown:xss:option';
  344. return getValueForMarkdownNS(config, key);
  345. };
  346. configSchema.statics.tagWhiteList = function(config) {
  347. const key = 'markdown:xss:tagWhiteList';
  348. if (this.isEnabledXssPrevention(config)) {
  349. switch (this.xssOption(config)) {
  350. case 1: // ignore all: use default option
  351. return [];
  352. case 2: // recommended
  353. return recommendedWhitelist.tags;
  354. case 3: // custom white list
  355. return config.markdown[key];
  356. default:
  357. return [];
  358. }
  359. }
  360. else {
  361. return [];
  362. }
  363. };
  364. configSchema.statics.attrWhiteList = function(config) {
  365. const key = 'markdown:xss:attrWhiteList';
  366. if (this.isEnabledXssPrevention(config)) {
  367. switch (this.xssOption(config)) {
  368. case 1: // ignore all: use default option
  369. return [];
  370. case 2: // recommended
  371. return recommendedWhitelist.attrs;
  372. case 3: // custom white list
  373. return config.markdown[key];
  374. default:
  375. return [];
  376. }
  377. }
  378. else {
  379. return [];
  380. }
  381. };
  382. /**
  383. * initialize custom css strings
  384. */
  385. configSchema.statics.initCustomCss = function(config) {
  386. const key = 'customize:css';
  387. const rawCss = getValueForCrowiNS(config, key);
  388. // uglify and store
  389. this._customCss = uglifycss.processString(rawCss);
  390. };
  391. configSchema.statics.customCss = function(config) {
  392. return this._customCss;
  393. };
  394. configSchema.statics.initCustomScript = function(config) {
  395. const key = 'customize:script';
  396. const rawScript = getValueForCrowiNS(config, key);
  397. // store as is
  398. this._customScript = rawScript;
  399. };
  400. configSchema.statics.customScript = function(config) {
  401. return this._customScript;
  402. };
  403. configSchema.statics.customHeader = function(config) {
  404. const key = 'customize:header';
  405. return getValueForCrowiNS(config, key);
  406. };
  407. configSchema.statics.theme = function(config) {
  408. const key = 'customize:theme';
  409. return getValueForCrowiNS(config, key);
  410. };
  411. configSchema.statics.customTitle = function(config, page) {
  412. validateCrowi();
  413. const key = 'customize:title';
  414. let customTitle = getValueForCrowiNS(config, key);
  415. if (customTitle == null || customTitle.trim().length === 0) {
  416. customTitle = '{{page}} - {{sitename}}';
  417. }
  418. // replace
  419. customTitle = customTitle
  420. .replace('{{sitename}}', this.appTitle(config))
  421. .replace('{{page}}', page);
  422. return crowi.xss.process(customTitle);
  423. };
  424. configSchema.statics.behaviorType = function(config) {
  425. const key = 'customize:behavior';
  426. return getValueForCrowiNS(config, key);
  427. };
  428. configSchema.statics.layoutType = function(config) {
  429. const key = 'customize:layout';
  430. return getValueForCrowiNS(config, key);
  431. };
  432. configSchema.statics.highlightJsStyle = function(config) {
  433. const key = 'customize:highlightJsStyle';
  434. return getValueForCrowiNS(config, key);
  435. };
  436. configSchema.statics.highlightJsStyleBorder = function(config) {
  437. const key = 'customize:highlightJsStyleBorder';
  438. return getValueForCrowiNS(config, key);
  439. };
  440. configSchema.statics.isEnabledTimeline = function(config) {
  441. const key = 'customize:isEnabledTimeline';
  442. return getValueForCrowiNS(config, key);
  443. };
  444. configSchema.statics.isSavedStatesOfTabChanges = function(config) {
  445. const key = 'customize:isSavedStatesOfTabChanges';
  446. return getValueForCrowiNS(config, key);
  447. };
  448. configSchema.statics.isEnabledAttachTitleHeader = function(config) {
  449. const key = 'customize:isEnabledAttachTitleHeader';
  450. return getValueForCrowiNS(config, key);
  451. };
  452. configSchema.statics.showRecentCreatedNumber = function(config) {
  453. const key = 'customize:showRecentCreatedNumber';
  454. return getValueForCrowiNS(config, key);
  455. };
  456. configSchema.statics.fileUploadEnabled = function(config) {
  457. const Config = this;
  458. if (!Config.isUploadable(config)) {
  459. return false;
  460. }
  461. // convert to boolean
  462. return !!config.crowi['app:fileUpload'];
  463. };
  464. configSchema.statics.hasSlackConfig = function(config) {
  465. return Config.hasSlackToken(config) || Config.hasSlackIwhUrl(config);
  466. };
  467. /**
  468. * for Slack Incoming Webhooks
  469. */
  470. configSchema.statics.hasSlackIwhUrl = function(config) {
  471. if (!config.notification) {
  472. return false;
  473. }
  474. return (!!config.notification['slack:incomingWebhookUrl']);
  475. };
  476. configSchema.statics.isIncomingWebhookPrioritized = function(config) {
  477. if (!config.notification) {
  478. return false;
  479. }
  480. return (!!config.notification['slack:isIncomingWebhookPrioritized']);
  481. };
  482. configSchema.statics.hasSlackToken = function(config) {
  483. if (!config.notification) {
  484. return false;
  485. }
  486. return (!!config.notification['slack:token']);
  487. };
  488. configSchema.statics.getLocalconfig = function(config) {
  489. const Config = this;
  490. const env = process.env;
  491. const localConfig = {
  492. crowi: {
  493. title: Config.appTitle(crowi),
  494. url: crowi.configManager.getSiteUrl(),
  495. },
  496. upload: {
  497. image: Config.isUploadable(config),
  498. file: Config.fileUploadEnabled(config),
  499. },
  500. behaviorType: Config.behaviorType(config),
  501. layoutType: Config.layoutType(config),
  502. isEnabledLinebreaks: Config.isEnabledLinebreaks(config),
  503. isEnabledLinebreaksInComments: Config.isEnabledLinebreaksInComments(config),
  504. isEnabledXssPrevention: Config.isEnabledXssPrevention(config),
  505. xssOption: Config.xssOption(config),
  506. tagWhiteList: Config.tagWhiteList(config),
  507. attrWhiteList: Config.attrWhiteList(config),
  508. highlightJsStyleBorder: Config.highlightJsStyleBorder(config),
  509. isSavedStatesOfTabChanges: Config.isSavedStatesOfTabChanges(config),
  510. hasSlackConfig: Config.hasSlackConfig(config),
  511. env: {
  512. PLANTUML_URI: env.PLANTUML_URI || null,
  513. BLOCKDIAG_URI: env.BLOCKDIAG_URI || null,
  514. HACKMD_URI: env.HACKMD_URI || null,
  515. MATHJAX: env.MATHJAX || null,
  516. NO_CDN: env.NO_CDN || null,
  517. },
  518. recentCreatedLimit: Config.showRecentCreatedNumber(config),
  519. isAclEnabled: !Config.isPublicWikiOnly(config),
  520. globalLang: Config.globalLang(config),
  521. };
  522. return localConfig;
  523. };
  524. configSchema.statics.userUpperLimit = function(crowi) {
  525. const key = 'USER_UPPER_LIMIT';
  526. const env = crowi.env[key];
  527. if (undefined === crowi.env || undefined === crowi.env[key]) {
  528. return 0;
  529. }
  530. return Number(env);
  531. };
  532. /*
  533. configSchema.statics.isInstalled = function(config)
  534. {
  535. if (!config.crowi) {
  536. return false;
  537. }
  538. if (config.crowi['app:installed']
  539. && config.crowi['app:installed'] !== '0.0.0') {
  540. return true;
  541. }
  542. return false;
  543. }
  544. */
  545. Config = mongoose.model('Config', configSchema);
  546. Config.SECURITY_REGISTRATION_MODE_OPEN = SECURITY_REGISTRATION_MODE_OPEN;
  547. Config.SECURITY_REGISTRATION_MODE_RESTRICTED = SECURITY_REGISTRATION_MODE_RESTRICTED;
  548. Config.SECURITY_REGISTRATION_MODE_CLOSED = SECURITY_REGISTRATION_MODE_CLOSED;
  549. return Config;
  550. };