config.js 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489
  1. // disable no-return-await for model functions
  2. /* eslint-disable no-return-await */
  3. /* eslint-disable no-use-before-define */
  4. module.exports = function(crowi) {
  5. const mongoose = require('mongoose');
  6. const debug = require('debug')('growi:models:config');
  7. const recommendedWhitelist = require('@commons/service/xss/recommended-whitelist');
  8. const SECURITY_RESTRICT_GUEST_MODE_DENY = 'Deny';
  9. const SECURITY_RESTRICT_GUEST_MODE_READONLY = 'Readonly';
  10. const SECURITY_REGISTRATION_MODE_OPEN = 'Open';
  11. const SECURITY_REGISTRATION_MODE_RESTRICTED = 'Resricted';
  12. const SECURITY_REGISTRATION_MODE_CLOSED = 'Closed';
  13. let Config;
  14. const configSchema = new mongoose.Schema({
  15. ns: { type: String, required: true, index: true },
  16. key: { type: String, required: true, index: true },
  17. value: { type: String, required: true },
  18. });
  19. function validateCrowi() {
  20. if (crowi == null) {
  21. throw new Error('"crowi" is null. Init Config model with "crowi" argument first.');
  22. }
  23. }
  24. /**
  25. * default values when GROWI is cleanly installed
  26. */
  27. function getConfigsForInstalling() {
  28. const config = getDefaultCrowiConfigs();
  29. // overwrite
  30. config['app:installed'] = true;
  31. config['app:fileUpload'] = true;
  32. config['customize:behavior'] = 'growi';
  33. config['customize:layout'] = 'growi';
  34. config['customize:isSavedStatesOfTabChanges'] = false;
  35. return config;
  36. }
  37. /**
  38. * default values when migrated from Official Crowi
  39. */
  40. function getDefaultCrowiConfigs() {
  41. /* eslint-disable key-spacing */
  42. return {
  43. 'app:installed' : false,
  44. 'app:confidential' : undefined,
  45. 'app:fileUpload' : false,
  46. 'app:globalLang' : 'en-US',
  47. 'security:restrictGuestMode' : 'Deny',
  48. 'security:registrationMode' : 'Open',
  49. 'security:registrationWhiteList' : [],
  50. 'security:list-policy:hideRestrictedByOwner' : false,
  51. 'security:list-policy:hideRestrictedByGroup' : false,
  52. 'security:isEnabledPassport' : true,
  53. 'security:passport-ldap:isEnabled' : false,
  54. 'security:passport-ldap:serverUrl' : undefined,
  55. 'security:passport-ldap:isUserBind' : undefined,
  56. 'security:passport-ldap:bindDN' : undefined,
  57. 'security:passport-ldap:bindDNPassword' : undefined,
  58. 'security:passport-ldap:searchFilter' : undefined,
  59. 'security:passport-ldap:attrMapUsername' : undefined,
  60. 'security:passport-ldap:attrMapName' : undefined,
  61. 'security:passport-ldap:attrMapMail' : undefined,
  62. 'security:passport-ldap:groupSearchBase' : undefined,
  63. 'security:passport-ldap:groupSearchFilter' : undefined,
  64. 'security:passport-ldap:groupDnProperty' : undefined,
  65. 'security:passport-ldap:isSameUsernameTreatedAsIdenticalUser': false,
  66. 'security:passport-saml:isEnabled' : false,
  67. 'security:passport-saml:isSameEmailTreatedAsIdenticalUser': false,
  68. 'security:passport-google:isEnabled' : false,
  69. 'security:passport-github:isEnabled' : false,
  70. 'security:passport-twitter:isEnabled' : false,
  71. 'security:passport-oidc:isEnabled' : false,
  72. 'aws:bucket' : 'growi',
  73. 'aws:region' : 'ap-northeast-1',
  74. 'aws:accessKeyId' : undefined,
  75. 'aws:secretAccessKey' : undefined,
  76. 'mail:from' : undefined,
  77. 'mail:smtpHost' : undefined,
  78. 'mail:smtpPort' : undefined,
  79. 'mail:smtpUser' : undefined,
  80. 'mail:smtpPassword' : undefined,
  81. 'google:clientId' : undefined,
  82. 'google:clientSecret' : undefined,
  83. 'plugin:isEnabledPlugins' : true,
  84. 'customize:css' : undefined,
  85. 'customize:script' : undefined,
  86. 'customize:header' : undefined,
  87. 'customize:title' : undefined,
  88. 'customize:highlightJsStyle' : 'github',
  89. 'customize:highlightJsStyleBorder' : false,
  90. 'customize:theme' : 'default',
  91. 'customize:behavior' : 'crowi',
  92. 'customize:layout' : 'crowi',
  93. 'customize:isEnabledTimeline' : true,
  94. 'customize:isSavedStatesOfTabChanges' : true,
  95. 'customize:isEnabledAttachTitleHeader' : false,
  96. 'customize:showRecentCreatedNumber' : 10,
  97. 'importer:esa:team_name': undefined,
  98. 'importer:esa:access_token': undefined,
  99. 'importer:qiita:team_name': undefined,
  100. 'importer:qiita:access_token': undefined,
  101. };
  102. /* eslint-enable key-spacing */
  103. }
  104. function getDefaultMarkdownConfigs() {
  105. return {
  106. 'markdown:xss:isEnabledPrevention': true,
  107. 'markdown:xss:option': 2,
  108. 'markdown:xss:tagWhiteList': [],
  109. 'markdown:xss:attrWhiteList': [],
  110. 'markdown:isEnabledLinebreaks': false,
  111. 'markdown:isEnabledLinebreaksInComments': true,
  112. 'markdown:presentation:pageBreakSeparator': 1,
  113. 'markdown:presentation:pageBreakCustomSeparator': undefined,
  114. };
  115. }
  116. function getDefaultNotificationConfigs() {
  117. return {
  118. 'slack:isIncomingWebhookPrioritized': false,
  119. 'slack:incomingWebhookUrl': undefined,
  120. 'slack:token': undefined,
  121. };
  122. }
  123. function getValueForMarkdownNS(config, key) {
  124. crowi.configManager.getConfig('markdown', key);
  125. // // return the default value if undefined
  126. // if (undefined === config.markdown || undefined === config.markdown[key]) {
  127. // return getDefaultMarkdownConfigs()[key];
  128. // }
  129. // return config.markdown[key];
  130. }
  131. /**
  132. * It is deprecated to use this for anything other than AppService#isDBInitialized.
  133. */
  134. configSchema.statics.getConfigsObjectForInstalling = function() {
  135. return getConfigsForInstalling();
  136. };
  137. /**
  138. * It is deprecated to use this for anything other than ConfigLoader#load.
  139. */
  140. configSchema.statics.getDefaultCrowiConfigsObject = function() {
  141. return getDefaultCrowiConfigs();
  142. };
  143. /**
  144. * It is deprecated to use this for anything other than ConfigLoader#load.
  145. */
  146. configSchema.statics.getDefaultMarkdownConfigsObject = function() {
  147. return getDefaultMarkdownConfigs();
  148. };
  149. /**
  150. * It is deprecated to use this for anything other than ConfigLoader#load.
  151. */
  152. configSchema.statics.getDefaultNotificationConfigsObject = function() {
  153. return getDefaultNotificationConfigs();
  154. };
  155. configSchema.statics.getRestrictGuestModeLabels = function() {
  156. const labels = {};
  157. labels[SECURITY_RESTRICT_GUEST_MODE_DENY] = 'security_setting.guest_mode.deny';
  158. labels[SECURITY_RESTRICT_GUEST_MODE_READONLY] = 'security_setting.guest_mode.readonly';
  159. return labels;
  160. };
  161. configSchema.statics.getRegistrationModeLabels = function() {
  162. const labels = {};
  163. labels[SECURITY_REGISTRATION_MODE_OPEN] = 'security_setting.registration_mode.open';
  164. labels[SECURITY_REGISTRATION_MODE_RESTRICTED] = 'security_setting.registration_mode.restricted';
  165. labels[SECURITY_REGISTRATION_MODE_CLOSED] = 'security_setting.registration_mode.closed';
  166. return labels;
  167. };
  168. configSchema.statics.updateConfigCache = function(ns, config) {
  169. validateCrowi();
  170. // const originalConfig = crowi.getConfig();
  171. // const newNSConfig = originalConfig[ns] || {};
  172. // Object.keys(config).forEach((key) => {
  173. // if (config[key] || config[key] === '' || config[key] === false) {
  174. // newNSConfig[key] = config[key];
  175. // }
  176. // });
  177. // originalConfig[ns] = newNSConfig;
  178. // crowi.setConfig(originalConfig);
  179. // // initialize custom css/script
  180. // Config.initCustomCss(originalConfig);
  181. // Config.initCustomScript(originalConfig);
  182. };
  183. // Execute only once for installing application
  184. // configSchema.statics.applicationInstall = function(callback) {
  185. // const Config = this;
  186. // Config.count({ ns: 'crowi' }, (err, count) => {
  187. // if (count > 0) {
  188. // return callback(new Error('Application already installed'), null);
  189. // }
  190. // Config.updateNamespaceByArray('crowi', getArrayForInstalling(), (err, configs) => {
  191. // Config.updateConfigCache('crowi', configs);
  192. // return callback(err, configs);
  193. // });
  194. // });
  195. // };
  196. configSchema.statics.updateNamespaceByArray = function(ns, configs, callback) {
  197. const Config = this;
  198. if (configs.length < 0) {
  199. return callback(new Error('Argument #1 is not array.'), null);
  200. }
  201. Object.keys(configs).forEach((key) => {
  202. const value = configs[key];
  203. Config.findOneAndUpdate(
  204. { ns, key },
  205. { ns, key, value: JSON.stringify(value) },
  206. { upsert: true },
  207. (err, config) => {
  208. debug('Config.findAndUpdate', err, config);
  209. },
  210. );
  211. });
  212. return callback(null, configs);
  213. };
  214. configSchema.statics.findOneAndUpdateByNsAndKey = async function(ns, key, value) {
  215. return this.findOneAndUpdate(
  216. { ns, key },
  217. { ns, key, value: JSON.stringify(value) },
  218. { upsert: true },
  219. );
  220. };
  221. configSchema.statics.getConfig = function(callback) {
  222. };
  223. // configSchema.statics.loadAllConfig = function(callback) {
  224. // const Config = this;
  225. // const config = {};
  226. // config.crowi = {}; // crowi namespace
  227. // Config.find()
  228. // .sort({ ns: 1, key: 1 })
  229. // .exec((err, doc) => {
  230. // doc.forEach((el) => {
  231. // if (!config[el.ns]) {
  232. // config[el.ns] = {};
  233. // }
  234. // config[el.ns][el.key] = JSON.parse(el.value);
  235. // });
  236. // debug('Config loaded', config);
  237. // // initialize custom css/script
  238. // Config.initCustomCss(config);
  239. // Config.initCustomScript(config);
  240. // return callback(null, config);
  241. // });
  242. // };
  243. configSchema.statics.isGuestAllowedToRead = function(config) {
  244. // return true if puclic wiki mode
  245. if (crowi.aclService.getIsPublicWikiOnly()) {
  246. return true;
  247. }
  248. const restrictGuestMode = crowi.configManager.getConfig('crowi', 'security:restrictGuestMode');
  249. // return false if undefined
  250. if (undefined === config.crowi || undefined === restrictGuestMode) {
  251. return false;
  252. }
  253. return SECURITY_RESTRICT_GUEST_MODE_READONLY === restrictGuestMode;
  254. };
  255. configSchema.statics.isEnabledLinebreaks = function(config) {
  256. const key = 'markdown:isEnabledLinebreaks';
  257. return getValueForMarkdownNS(config, key);
  258. };
  259. configSchema.statics.isEnabledLinebreaksInComments = function(config) {
  260. const key = 'markdown:isEnabledLinebreaksInComments';
  261. return getValueForMarkdownNS(config, key);
  262. };
  263. configSchema.statics.isPublicWikiOnly = function(config) {
  264. const publicWikiOnly = process.env.PUBLIC_WIKI_ONLY;
  265. if (publicWikiOnly === 'true' || publicWikiOnly === 1) {
  266. return true;
  267. }
  268. return false;
  269. };
  270. configSchema.statics.pageBreakSeparator = function(config) {
  271. const key = 'markdown:presentation:pageBreakSeparator';
  272. return getValueForMarkdownNS(config, key);
  273. };
  274. configSchema.statics.pageBreakCustomSeparator = function(config) {
  275. const key = 'markdown:presentation:pageBreakCustomSeparator';
  276. return getValueForMarkdownNS(config, key);
  277. };
  278. configSchema.statics.isEnabledXssPrevention = function(config) {
  279. const key = 'markdown:xss:isEnabledPrevention';
  280. return getValueForMarkdownNS(config, key);
  281. };
  282. configSchema.statics.xssOption = function(config) {
  283. const key = 'markdown:xss:option';
  284. return getValueForMarkdownNS(config, key);
  285. };
  286. configSchema.statics.tagWhiteList = function(config) {
  287. const key = 'markdown:xss:tagWhiteList';
  288. if (this.isEnabledXssPrevention(config)) {
  289. switch (this.xssOption(config)) {
  290. case 1: // ignore all: use default option
  291. return [];
  292. case 2: // recommended
  293. return recommendedWhitelist.tags;
  294. case 3: // custom white list
  295. return config.markdown[key];
  296. default:
  297. return [];
  298. }
  299. }
  300. else {
  301. return [];
  302. }
  303. };
  304. configSchema.statics.attrWhiteList = function(config) {
  305. const key = 'markdown:xss:attrWhiteList';
  306. if (this.isEnabledXssPrevention(config)) {
  307. switch (this.xssOption(config)) {
  308. case 1: // ignore all: use default option
  309. return [];
  310. case 2: // recommended
  311. return recommendedWhitelist.attrs;
  312. case 3: // custom white list
  313. return config.markdown[key];
  314. default:
  315. return [];
  316. }
  317. }
  318. else {
  319. return [];
  320. }
  321. };
  322. /**
  323. * for Slack Incoming Webhooks
  324. */
  325. configSchema.statics.hasSlackIwhUrl = function(config) {
  326. if (!config.notification) {
  327. return false;
  328. }
  329. return (!!config.notification['slack:incomingWebhookUrl']);
  330. };
  331. configSchema.statics.isIncomingWebhookPrioritized = function(config) {
  332. if (!config.notification) {
  333. return false;
  334. }
  335. return (!!config.notification['slack:isIncomingWebhookPrioritized']);
  336. };
  337. configSchema.statics.hasSlackToken = function(config) {
  338. if (!config.notification) {
  339. return false;
  340. }
  341. return (!!config.notification['slack:token']);
  342. };
  343. configSchema.statics.getLocalconfig = function() { // CONF.RF: これも別のメソッドにする
  344. const env = process.env;
  345. const localConfig = {
  346. crowi: {
  347. title: crowi.appService.getAppTitle(),
  348. url: crowi.appService.getSiteUrl(),
  349. },
  350. upload: {
  351. image: crowi.fileUploadService.getIsUploadable(),
  352. file: crowi.fileUploadService.getFileUploadEnabled(),
  353. },
  354. behaviorType: crowi.configManager.getConfig('crowi', 'customize:behavior'),
  355. layoutType: crowi.configManager.getConfig('crowi', 'customize:layout'),
  356. isEnabledLinebreaks: crowi.configManager.getConfig('markdown', 'markdown:isEnabledLinebreaks'),
  357. isEnabledLinebreaksInComments: crowi.configManager.getConfig('markdown', 'markdown:isEnabledLinebreaksInComments'),
  358. isEnabledXssPrevention: crowi.configManager.getConfig('markdown', 'markdown:xss:isEnabledPrevention'),
  359. xssOption: crowi.configManager.getConfig('markdown', 'markdown:xss:option'),
  360. tagWhiteList: crowi.xssService.getTagWhiteList(),
  361. attrWhiteList: crowi.xssService.getAttrWhiteList(),
  362. highlightJsStyleBorder: crowi.configManager.getConfig('crowi', 'customize:highlightJsStyleBorder'),
  363. isSavedStatesOfTabChanges: crowi.configManager.getConfig('crowi', 'customize:isSavedStatesOfTabChanges'),
  364. hasSlackConfig: crowi.slackNotificationService.hasSlackConfig(),
  365. env: {
  366. PLANTUML_URI: env.PLANTUML_URI || null,
  367. BLOCKDIAG_URI: env.BLOCKDIAG_URI || null,
  368. HACKMD_URI: env.HACKMD_URI || null,
  369. MATHJAX: env.MATHJAX || null,
  370. NO_CDN: env.NO_CDN || null,
  371. },
  372. recentCreatedLimit: crowi.configManager.getConfig('crowi', 'customize:showRecentCreatedNumber'),
  373. isAclEnabled: !crowi.aclService.getIsPublicWikiOnly(),
  374. globalLang: crowi.configManager.getConfig('crowi', 'app:globalLang'),
  375. };
  376. return localConfig;
  377. };
  378. configSchema.statics.userUpperLimit = function(crowi) {
  379. const key = 'USER_UPPER_LIMIT';
  380. const env = crowi.env[key];
  381. if (undefined === crowi.env || undefined === crowi.env[key]) {
  382. return 0;
  383. }
  384. return Number(env);
  385. };
  386. /*
  387. configSchema.statics.isInstalled = function(config)
  388. {
  389. if (!config.crowi) {
  390. return false;
  391. }
  392. if (config.crowi['app:installed']
  393. && config.crowi['app:installed'] !== '0.0.0') {
  394. return true;
  395. }
  396. return false;
  397. }
  398. */
  399. Config = mongoose.model('Config', configSchema);
  400. Config.SECURITY_REGISTRATION_MODE_OPEN = SECURITY_REGISTRATION_MODE_OPEN;
  401. Config.SECURITY_REGISTRATION_MODE_RESTRICTED = SECURITY_REGISTRATION_MODE_RESTRICTED;
  402. Config.SECURITY_REGISTRATION_MODE_CLOSED = SECURITY_REGISTRATION_MODE_CLOSED;
  403. return Config;
  404. };