page.js 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500
  1. import { body } from 'express-validator';
  2. import mongoose from 'mongoose';
  3. import loggerFactory from '~/utils/logger';
  4. import { GlobalNotificationSettingEvent } from '../models/GlobalNotificationSetting';
  5. import { PathAlreadyExistsError } from '../models/errors';
  6. import PageTagRelation from '../models/page-tag-relation';
  7. import UpdatePost from '../models/update-post';
  8. /**
  9. * @swagger
  10. * tags:
  11. * name: Pages
  12. */
  13. /**
  14. * @swagger
  15. *
  16. * components:
  17. * schemas:
  18. * Page:
  19. * description: Page
  20. * type: object
  21. * properties:
  22. * _id:
  23. * type: string
  24. * description: page ID
  25. * example: 5e07345972560e001761fa63
  26. * __v:
  27. * type: number
  28. * description: DB record version
  29. * example: 0
  30. * commentCount:
  31. * type: number
  32. * description: count of comments
  33. * example: 3
  34. * createdAt:
  35. * type: string
  36. * description: date created at
  37. * example: 2010-01-01T00:00:00.000Z
  38. * creator:
  39. * $ref: '#/components/schemas/User'
  40. * extended:
  41. * type: object
  42. * description: extend data
  43. * example: {}
  44. * grant:
  45. * type: number
  46. * description: grant
  47. * example: 1
  48. * grantedUsers:
  49. * type: array
  50. * description: granted users
  51. * items:
  52. * type: string
  53. * description: user ID
  54. * example: ["5ae5fccfc5577b0004dbd8ab"]
  55. * lastUpdateUser:
  56. * $ref: '#/components/schemas/User'
  57. * liker:
  58. * type: array
  59. * description: granted users
  60. * items:
  61. * type: string
  62. * description: user ID
  63. * example: []
  64. * path:
  65. * type: string
  66. * description: page path
  67. * example: /
  68. * revision:
  69. * $ref: '#/components/schemas/Revision'
  70. * status:
  71. * type: string
  72. * description: status
  73. * enum:
  74. * - 'wip'
  75. * - 'published'
  76. * - 'deleted'
  77. * - 'deprecated'
  78. * example: published
  79. * updatedAt:
  80. * type: string
  81. * description: date updated at
  82. * example: 2010-01-01T00:00:00.000Z
  83. *
  84. * UpdatePost:
  85. * description: UpdatePost
  86. * type: object
  87. * properties:
  88. * _id:
  89. * type: string
  90. * description: update post ID
  91. * example: 5e0734e472560e001761fa68
  92. * __v:
  93. * type: number
  94. * description: DB record version
  95. * example: 0
  96. * pathPattern:
  97. * type: string
  98. * description: path pattern
  99. * example: /test
  100. * patternPrefix:
  101. * type: string
  102. * description: patternPrefix prefix
  103. * example: /
  104. * patternPrefix2:
  105. * type: string
  106. * description: path
  107. * example: test
  108. * channel:
  109. * type: string
  110. * description: channel
  111. * example: general
  112. * provider:
  113. * type: string
  114. * description: provider
  115. * enum:
  116. * - slack
  117. * example: slack
  118. * creator:
  119. * $ref: '#/components/schemas/User'
  120. * createdAt:
  121. * type: string
  122. * description: date created at
  123. * example: 2010-01-01T00:00:00.000Z
  124. */
  125. /* eslint-disable no-use-before-define */
  126. /**
  127. * @type { (crowi: import('../crowi').default, app) => any }
  128. */
  129. module.exports = function(crowi, app) {
  130. const logger = loggerFactory('growi:routes:page');
  131. const { pagePathUtils } = require('@growi/core/dist/utils');
  132. /** @type {import('../models/page').PageModel} */
  133. const Page = crowi.model('Page');
  134. const PageRedirect = mongoose.model('PageRedirect');
  135. const ApiResponse = require('../util/apiResponse');
  136. const globalNotificationService = crowi.getGlobalNotificationService();
  137. const actions = {};
  138. // async function showPageForPresentation(req, res, next) {
  139. // const id = req.params.id;
  140. // const { revisionId } = req.query;
  141. // let page = await Page.findByIdAndViewer(id, req.user, null, true, true);
  142. // if (page == null) {
  143. // next();
  144. // }
  145. // // empty page
  146. // if (page.isEmpty) {
  147. // // redirect to page (path) url
  148. // const url = new URL('https://dummy.origin');
  149. // url.pathname = page.path;
  150. // Object.entries(req.query).forEach(([key, value], i) => {
  151. // url.searchParams.append(key, value);
  152. // });
  153. // return res.safeRedirect(urljoin(url.pathname, url.search));
  154. // }
  155. // const renderVars = {};
  156. // // populate
  157. // page = await page.populateDataToMakePresentation(revisionId);
  158. // if (page != null) {
  159. // addRenderVarsForPresentation(renderVars, page);
  160. // }
  161. // return res.render('page_presentation', renderVars);
  162. // }
  163. /**
  164. * switch action
  165. * - presentation mode
  166. * - by behaviorType
  167. */
  168. // actions.showPage = async function(req, res, next) {
  169. // // presentation mode
  170. // if (req.query.presentation) {
  171. // return showPageForPresentation(req, res, next);
  172. // }
  173. // // delegate to showPageForGrowiBehavior
  174. // return showPageForGrowiBehavior(req, res, next);
  175. // };
  176. const api = {};
  177. const validator = {};
  178. actions.api = api;
  179. actions.validator = validator;
  180. /**
  181. * @swagger
  182. *
  183. * /pages.getPageTag:
  184. * get:
  185. * tags: [Pages]
  186. * operationId: getPageTag
  187. * summary: /pages.getPageTag
  188. * description: Get page tag
  189. * parameters:
  190. * - in: query
  191. * name: pageId
  192. * schema:
  193. * $ref: '#/components/schemas/Page/properties/_id'
  194. * responses:
  195. * 200:
  196. * description: Succeeded to get page tags.
  197. * content:
  198. * application/json:
  199. * schema:
  200. * properties:
  201. * ok:
  202. * $ref: '#/components/schemas/V1Response/properties/ok'
  203. * tags:
  204. * $ref: '#/components/schemas/Tags'
  205. * 403:
  206. * $ref: '#/components/responses/403'
  207. * 500:
  208. * $ref: '#/components/responses/500'
  209. */
  210. /**
  211. * @api {get} /pages.getPageTag get page tags
  212. * @apiName GetPageTag
  213. * @apiGroup Page
  214. *
  215. * @apiParam {String} pageId
  216. */
  217. api.getPageTag = async function(req, res) {
  218. const result = {};
  219. try {
  220. result.tags = await PageTagRelation.listTagNamesByPage(req.query.pageId);
  221. }
  222. catch (err) {
  223. return res.json(ApiResponse.error(err));
  224. }
  225. return res.json(ApiResponse.success(result));
  226. };
  227. /**
  228. * @swagger
  229. *
  230. * /pages.updatePost:
  231. * get:
  232. * tags: [Pages, CrowiCompatibles]
  233. * operationId: getUpdatePostPage
  234. * summary: /pages.updatePost
  235. * description: Get UpdatePost setting list
  236. * parameters:
  237. * - in: query
  238. * name: path
  239. * schema:
  240. * $ref: '#/components/schemas/Page/properties/path'
  241. * responses:
  242. * 200:
  243. * description: Succeeded to get UpdatePost setting list.
  244. * content:
  245. * application/json:
  246. * schema:
  247. * properties:
  248. * ok:
  249. * $ref: '#/components/schemas/V1Response/properties/ok'
  250. * updatePost:
  251. * $ref: '#/components/schemas/UpdatePost'
  252. * 403:
  253. * $ref: '#/components/responses/403'
  254. * 500:
  255. * $ref: '#/components/responses/500'
  256. */
  257. /**
  258. * @api {get} /pages.updatePost
  259. * @apiName Get UpdatePost setting list
  260. * @apiGroup Page
  261. *
  262. * @apiParam {String} path
  263. */
  264. api.getUpdatePost = function(req, res) {
  265. const path = req.query.path;
  266. if (!path) {
  267. return res.json(ApiResponse.error({}));
  268. }
  269. UpdatePost.findSettingsByPath(path)
  270. .then((data) => {
  271. // eslint-disable-next-line no-param-reassign
  272. data = data.map((e) => {
  273. return e.channel;
  274. });
  275. logger.debug('Found updatePost data', data);
  276. const result = { updatePost: data };
  277. return res.json(ApiResponse.success(result));
  278. })
  279. .catch((err) => {
  280. logger.debug('Error occured while get setting', err);
  281. return res.json(ApiResponse.error({}));
  282. });
  283. };
  284. validator.remove = [
  285. body('completely')
  286. .custom(v => v === 'true' || v === true || v == null)
  287. .withMessage('The body property "completely" must be "true" or true. (Omit param for false)'),
  288. body('recursively')
  289. .custom(v => v === 'true' || v === true || v == null)
  290. .withMessage('The body property "recursively" must be "true" or true. (Omit param for false)'),
  291. ];
  292. /**
  293. * @api {post} /pages.remove Remove page
  294. * @apiName RemovePage
  295. * @apiGroup Page
  296. *
  297. * @apiParam {String} page_id Page Id.
  298. * @apiParam {String} revision_id
  299. */
  300. api.remove = async function(req, res) {
  301. const pageId = req.body.page_id;
  302. const previousRevision = req.body.revision_id || null;
  303. const { recursively: isRecursively, completely: isCompletely } = req.body;
  304. const options = {};
  305. const activityParameters = {
  306. ip: req.ip,
  307. endpoint: req.originalUrl,
  308. };
  309. /** @type {import('../models/page').PageDocument | undefined} */
  310. const page = await Page.findByIdAndViewer(pageId, req.user, null, true);
  311. if (page == null) {
  312. return res.json(ApiResponse.error(`Page '${pageId}' is not found or forbidden`, 'notfound_or_forbidden'));
  313. }
  314. if (page.isEmpty && !isRecursively) {
  315. return res.json(ApiResponse.error('Empty pages cannot be single deleted', 'single_deletion_empty_pages'));
  316. }
  317. const creatorId = await crowi.pageService.getCreatorIdForCanDelete(page);
  318. logger.debug('Delete page', page._id, page.path);
  319. try {
  320. if (isCompletely) {
  321. const userRelatedGroups = await crowi.pageGrantService.getUserRelatedGroups(req.user);
  322. const canDeleteCompletely = crowi.pageService.canDeleteCompletely(page, creatorId, req.user, isRecursively, userRelatedGroups);
  323. if (!canDeleteCompletely) {
  324. return res.json(ApiResponse.error('You cannot delete this page completely', 'complete_deletion_not_allowed_for_user'));
  325. }
  326. if (pagePathUtils.isUsersHomepage(page.path)) {
  327. if (!crowi.pageService.canDeleteUserHomepageByConfig()) {
  328. return res.json(ApiResponse.error('Could not delete user homepage'));
  329. }
  330. if (!await crowi.pageService.isUsersHomepageOwnerAbsent(page.path)) {
  331. return res.json(ApiResponse.error('Could not delete user homepage'));
  332. }
  333. }
  334. await crowi.pageService.deleteCompletely(page, req.user, options, isRecursively, false, activityParameters);
  335. }
  336. else {
  337. // behave like not found
  338. const notRecursivelyAndEmpty = page.isEmpty && !isRecursively;
  339. if (notRecursivelyAndEmpty) {
  340. return res.json(ApiResponse.error(`Page '${pageId}' is not found.`, 'notfound'));
  341. }
  342. if (!page.isEmpty && !page.isUpdatable(previousRevision)) {
  343. return res.json(ApiResponse.error('Someone could update this page, so couldn\'t delete.', 'outdated'));
  344. }
  345. if (!crowi.pageService.canDelete(page, creatorId, req.user, isRecursively)) {
  346. return res.json(ApiResponse.error('You cannot delete this page', 'user_not_admin'));
  347. }
  348. if (pagePathUtils.isUsersHomepage(page.path)) {
  349. if (!crowi.pageService.canDeleteUserHomepageByConfig()) {
  350. return res.json(ApiResponse.error('Could not delete user homepage'));
  351. }
  352. if (!await crowi.pageService.isUsersHomepageOwnerAbsent(page.path)) {
  353. return res.json(ApiResponse.error('Could not delete user homepage'));
  354. }
  355. }
  356. await crowi.pageService.deletePage(page, req.user, options, isRecursively, activityParameters);
  357. }
  358. }
  359. catch (err) {
  360. logger.error('Error occured while get setting', err);
  361. return res.json(ApiResponse.error('Failed to delete page.', err.message));
  362. }
  363. logger.debug('Page deleted', page.path);
  364. const result = {};
  365. result.path = page.path;
  366. result.isRecursively = isRecursively;
  367. result.isCompletely = isCompletely;
  368. res.json(ApiResponse.success(result));
  369. try {
  370. // global notification
  371. await globalNotificationService.fire(GlobalNotificationSettingEvent.PAGE_DELETE, page, req.user);
  372. }
  373. catch (err) {
  374. logger.error('Delete notification failed', err);
  375. }
  376. };
  377. validator.revertRemove = [
  378. body('recursively')
  379. .optional()
  380. .custom(v => v === 'true' || v === true || v == null)
  381. .withMessage('The body property "recursively" must be "true" or true. (Omit param for false)'),
  382. ];
  383. /**
  384. * @api {post} /pages.revertRemove Revert removed page
  385. * @apiName RevertRemovePage
  386. * @apiGroup Page
  387. *
  388. * @apiParam {String} page_id Page Id.
  389. */
  390. api.revertRemove = async function(req, res, options) {
  391. const pageId = req.body.page_id;
  392. // get recursively flag
  393. const isRecursively = req.body.recursively;
  394. const activityParameters = {
  395. ip: req.ip,
  396. endpoint: req.originalUrl,
  397. };
  398. let page;
  399. try {
  400. page = await Page.findByIdAndViewer(pageId, req.user);
  401. if (page == null) {
  402. throw new Error(`Page '${pageId}' is not found or forbidden`, 'notfound_or_forbidden');
  403. }
  404. page = await crowi.pageService.revertDeletedPage(page, req.user, {}, isRecursively, activityParameters);
  405. }
  406. catch (err) {
  407. if (err instanceof PathAlreadyExistsError) {
  408. logger.error('Path already exists', err);
  409. return res.json(ApiResponse.error(err, 'already_exists', err.targetPath));
  410. }
  411. logger.error('Error occured while get setting', err);
  412. return res.json(ApiResponse.error(err));
  413. }
  414. const result = {};
  415. result.page = page; // TODO consider to use serializePageSecurely method -- 2018.08.06 Yuki Takei
  416. return res.json(ApiResponse.success(result));
  417. };
  418. /**
  419. * @api {post} /pages.unlink Remove the redirecting page
  420. * @apiName UnlinkPage
  421. * @apiGroup Page
  422. *
  423. * @apiParam {String} page_id Page Id.
  424. * @apiParam {String} revision_id
  425. */
  426. api.unlink = async function(req, res) {
  427. const path = req.body.path;
  428. try {
  429. await PageRedirect.removePageRedirectsByToPath(path);
  430. logger.debug('Redirect Page deleted', path);
  431. }
  432. catch (err) {
  433. logger.error('Error occured while get setting', err);
  434. return res.json(ApiResponse.error('Failed to delete redirect page.'));
  435. }
  436. const result = { path };
  437. return res.json(ApiResponse.success(result));
  438. };
  439. return actions;
  440. };