index.js 20 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224
  1. module.exports = function(crowi, app) {
  2. const middleware = require('../util/middlewares')
  3. , multer = require('multer')
  4. , uploads = multer({dest: crowi.tmpDir + 'uploads'})
  5. , form = require('../form')
  6. , page = require('./page')(crowi, app)
  7. , login = require('./login')(crowi, app)
  8. , loginPassport = require('./login-passport')(crowi, app)
  9. , logout = require('./logout')(crowi, app)
  10. , me = require('./me')(crowi, app)
  11. , admin = require('./admin')(crowi, app)
  12. , installer = require('./installer')(crowi, app)
  13. , user = require('./user')(crowi, app)
  14. , attachment= require('./attachment')(crowi, app)
  15. , comment = require('./comment')(crowi, app)
  16. , bookmark = require('./bookmark')(crowi, app)
  17. , revision = require('./revision')(crowi, app)
  18. , search = require('./search')(crowi, app)
  19. , hackmd = require('./hackmd')(crowi, app)
  20. , loginRequired = middleware.loginRequired
  21. , accessTokenParser = middleware.accessTokenParser(crowi, app)
  22. , csrf = middleware.csrfVerify(crowi, app)
  23. , config = crowi.getConfig()
  24. , Config = crowi.model('Config')
  25. ;
  26. /* eslint-disable comma-spacing */
  27. app.get('/' , middleware.applicationInstalled(), loginRequired(crowi, app, false) , page.pageListShow);
  28. app.get('/installer' , middleware.applicationNotInstalled() , middleware.checkSearchIndicesGenerated(crowi, app) , installer.index);
  29. app.post('/installer/createAdmin' , middleware.applicationNotInstalled() , form.register , csrf, installer.createAdmin);
  30. //app.post('/installer/user' , middleware.applicationNotInstalled() , installer.createFirstUser);
  31. app.get('/login/error/:reason' , login.error);
  32. app.get('/login' , middleware.applicationInstalled() , login.login);
  33. app.get('/login/invited' , login.invited);
  34. app.post('/login/activateInvited' , form.invited , csrf, login.invited);
  35. // switch POST /login route
  36. if (Config.isEnabledPassport(config)) {
  37. app.post('/login' , form.login , csrf, loginPassport.loginWithLocal, loginPassport.loginWithLdap, loginPassport.loginFailure);
  38. app.post('/_api/login/testLdap' , loginRequired(crowi, app) , form.login , loginPassport.testLdapCredentials);
  39. }
  40. else {
  41. app.post('/login' , form.login , csrf, login.login);
  42. }
  43. app.post('/register' , form.register , csrf, login.register);
  44. app.get('/register' , middleware.applicationInstalled() , login.register);
  45. app.post('/register/google' , login.registerGoogle);
  46. app.get('/google/callback' , login.googleCallback);
  47. app.get('/login/google' , login.loginGoogle);
  48. app.get('/logout' , logout.logout);
  49. app.get('/admin' , loginRequired(crowi, app) , middleware.adminRequired() , admin.index);
  50. app.get('/admin/app' , loginRequired(crowi, app) , middleware.adminRequired() , admin.app.index);
  51. app.post('/_api/admin/settings/app' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.app, admin.api.appSetting);
  52. app.post('/_api/admin/settings/mail' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.mail, admin.api.appSetting);
  53. app.post('/_api/admin/settings/aws' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.aws, admin.api.appSetting);
  54. app.post('/_api/admin/settings/plugin', loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.plugin, admin.api.appSetting);
  55. // security admin
  56. app.get('/admin/security' , loginRequired(crowi, app) , middleware.adminRequired() , admin.security.index);
  57. app.post('/_api/admin/security/general' , loginRequired(crowi, app) , middleware.adminRequired() , form.admin.securityGeneral, admin.api.securitySetting);
  58. app.post('/_api/admin/security/google' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.securityGoogle, admin.api.securitySetting);
  59. app.post('/_api/admin/security/mechanism' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.securityMechanism, admin.api.securitySetting);
  60. app.post('/_api/admin/security/passport-ldap' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.securityPassportLdap, admin.api.securityPassportLdapSetting);
  61. // OAuth
  62. app.post('/_api/admin/security/passport-google' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.securityPassportGoogle, admin.api.securityPassportGoogleSetting);
  63. app.post('/_api/admin/security/passport-github' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.securityPassportGitHub, admin.api.securityPassportGitHubSetting);
  64. app.get('/passport/google' , loginPassport.loginWithGoogle);
  65. app.get('/passport/github' , loginPassport.loginWithGitHub);
  66. app.get('/passport/google/callback' , loginPassport.loginPassportGoogleCallback);
  67. app.get('/passport/github/callback' , loginPassport.loginPassportGitHubCallback);
  68. // markdown admin
  69. app.get('/admin/markdown' , loginRequired(crowi, app) , middleware.adminRequired() , admin.markdown.index);
  70. app.post('/admin/markdown/lineBreaksSetting', loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.markdown, admin.markdown.lineBreaksSetting); //change form name
  71. app.post('/admin/markdown/xss-setting' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.markdownXss, admin.markdown.xssSetting);
  72. // markdown admin
  73. app.get('/admin/customize' , loginRequired(crowi, app) , middleware.adminRequired() , admin.customize.index);
  74. app.post('/_api/admin/customize/css' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.customcss, admin.api.customizeSetting);
  75. app.post('/_api/admin/customize/script' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.customscript, admin.api.customizeSetting);
  76. app.post('/_api/admin/customize/header' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.customheader, admin.api.customizeSetting);
  77. app.post('/_api/admin/customize/theme' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.customtheme, admin.api.customizeSetting);
  78. app.post('/_api/admin/customize/title' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.customtitle, admin.api.customizeSetting);
  79. app.post('/_api/admin/customize/behavior' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.custombehavior, admin.api.customizeSetting);
  80. app.post('/_api/admin/customize/layout' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.customlayout, admin.api.customizeSetting);
  81. app.post('/_api/admin/customize/features' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.customfeatures, admin.api.customizeSetting);
  82. app.post('/_api/admin/customize/highlightJsStyle' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.customhighlightJsStyle, admin.api.customizeSetting);
  83. // search admin
  84. app.get('/admin/search' , loginRequired(crowi, app) , middleware.adminRequired() , admin.search.index);
  85. app.post('/admin/search/build' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, admin.search.buildIndex);
  86. // notification admin
  87. app.get('/admin/notification' , loginRequired(crowi, app) , middleware.adminRequired() , admin.notification.index);
  88. app.post('/admin/notification/slackIwhSetting', loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.slackIwhSetting, admin.notification.slackIwhSetting);
  89. app.post('/admin/notification/slackSetting', loginRequired(crowi, app) , middleware.adminRequired() , csrf, form.admin.slackSetting, admin.notification.slackSetting);
  90. app.get('/admin/notification/slackAuth' , loginRequired(crowi, app) , middleware.adminRequired() , admin.notification.slackAuth);
  91. app.get('/admin/notification/slackSetting/disconnect', loginRequired(crowi, app) , middleware.adminRequired() , admin.notification.disconnectFromSlack);
  92. app.post('/_api/admin/notification.add' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, admin.api.notificationAdd);
  93. app.post('/_api/admin/notification.remove' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, admin.api.notificationRemove);
  94. app.get('/_api/admin/users.search' , loginRequired(crowi, app) , middleware.adminRequired() , admin.api.usersSearch);
  95. app.get('/admin/global-notification/new' , loginRequired(crowi, app) , middleware.adminRequired() , admin.globalNotification.detail);
  96. app.get('/admin/global-notification/:id' , loginRequired(crowi, app) , middleware.adminRequired() , admin.globalNotification.detail);
  97. app.post('/admin/global-notification/new' , loginRequired(crowi, app) , middleware.adminRequired() , form.admin.notificationGlobal, admin.globalNotification.create);
  98. app.post('/_api/admin/global-notification/toggleIsEnabled', loginRequired(crowi, app) , middleware.adminRequired() , admin.api.toggleIsEnabledForGlobalNotification);
  99. app.post('/admin/global-notification/:id/update', loginRequired(crowi, app) , middleware.adminRequired() , form.admin.notificationGlobal, admin.globalNotification.update);
  100. app.post('/admin/global-notification/:id/remove', loginRequired(crowi, app) , middleware.adminRequired() , admin.globalNotification.remove);
  101. app.get('/admin/users' , loginRequired(crowi, app) , middleware.adminRequired() , admin.user.index);
  102. app.post('/admin/user/invite' , form.admin.userInvite , loginRequired(crowi, app) , middleware.adminRequired() , csrf, admin.user.invite);
  103. app.post('/admin/user/:id/makeAdmin' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, admin.user.makeAdmin);
  104. app.post('/admin/user/:id/removeFromAdmin', loginRequired(crowi, app) , middleware.adminRequired() , admin.user.removeFromAdmin);
  105. app.post('/admin/user/:id/activate' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, admin.user.activate);
  106. app.post('/admin/user/:id/suspend' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, admin.user.suspend);
  107. app.post('/admin/user/:id/remove' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, admin.user.remove);
  108. app.post('/admin/user/:id/removeCompletely' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, admin.user.removeCompletely);
  109. // new route patterns from here:
  110. app.post('/_api/admin/users.resetPassword' , loginRequired(crowi, app) , middleware.adminRequired() , csrf, admin.user.resetPassword);
  111. app.get('/admin/users/external-accounts' , loginRequired(crowi, app) , middleware.adminRequired() , admin.externalAccount.index);
  112. app.post('/admin/users/external-accounts/:id/remove' , loginRequired(crowi, app) , middleware.adminRequired() , admin.externalAccount.remove);
  113. // user-groups admin
  114. app.get('/admin/user-groups' , loginRequired(crowi, app), middleware.adminRequired(), admin.userGroup.index);
  115. app.get('/admin/user-group-detail/:id' , loginRequired(crowi, app), middleware.adminRequired(), admin.userGroup.detail);
  116. app.post('/admin/user-group/create' , form.admin.userGroupCreate, loginRequired(crowi, app), middleware.adminRequired(), csrf, admin.userGroup.create);
  117. app.post('/admin/user-group/:userGroupId/update', loginRequired(crowi, app), middleware.adminRequired(), csrf, admin.userGroup.update);
  118. app.post('/admin/user-group/:userGroupId/picture/delete', loginRequired(crowi, app), admin.userGroup.deletePicture);
  119. app.post('/admin/user-group.remove' , loginRequired(crowi, app), middleware.adminRequired(), csrf, admin.userGroup.removeCompletely);
  120. app.post('/_api/admin/user-group/:userGroupId/picture/upload', loginRequired(crowi, app), uploads.single('userGroupPicture'), admin.userGroup.uploadGroupPicture);
  121. // user-group-relations admin
  122. app.post('/admin/user-group-relation/create', loginRequired(crowi, app), middleware.adminRequired(), csrf, admin.userGroupRelation.create);
  123. app.post('/admin/user-group-relation/:id/remove-relation/:relationId', loginRequired(crowi, app), middleware.adminRequired(), csrf, admin.userGroupRelation.remove);
  124. // importer management for admin
  125. app.get('/admin/importer' , loginRequired(crowi, app) , middleware.adminRequired() , admin.importer.index);
  126. app.post('/_api/admin/settings/importerEsa' , loginRequired(crowi, app) , middleware.adminRequired() , csrf , form.admin.importer , admin.api.importerSetting);
  127. app.post('/_api/admin/settings/importerQiita' , loginRequired(crowi, app) , middleware.adminRequired() , csrf , form.admin.importer , admin.api.importerSetting);
  128. app.post('/_api/admin/import/esa' , loginRequired(crowi, app) , middleware.adminRequired() , admin.api.importDataFromEsa);
  129. app.post('/_api/admin/import/testEsaAPI' , loginRequired(crowi, app) , middleware.adminRequired() , csrf , form.admin.importer , admin.api.testEsaAPI);
  130. app.post('/_api/admin/import/qiita' , loginRequired(crowi, app) , middleware.adminRequired() , admin.api.importDataFromQiita);
  131. app.post('/_api/admin/import/testQiitaAPI' , loginRequired(crowi, app) , middleware.adminRequired() , csrf , form.admin.importer , admin.api.testQiitaAPI);
  132. app.get('/me' , loginRequired(crowi, app) , me.index);
  133. app.get('/me/password' , loginRequired(crowi, app) , me.password);
  134. app.get('/me/apiToken' , loginRequired(crowi, app) , me.apiToken);
  135. app.post('/me' , form.me.user , loginRequired(crowi, app) , me.index);
  136. // external-accounts
  137. if (Config.isEnabledPassport(config)) {
  138. app.get('/me/external-accounts' , loginRequired(crowi, app) , me.externalAccounts.list);
  139. app.post('/me/external-accounts/disassociate' , loginRequired(crowi, app) , me.externalAccounts.disassociate);
  140. app.post('/me/external-accounts/associateLdap' , loginRequired(crowi, app) , form.login , me.externalAccounts.associateLdap);
  141. }
  142. app.post('/me/password' , form.me.password , loginRequired(crowi, app) , me.password);
  143. app.post('/me/imagetype' , form.me.imagetype , loginRequired(crowi, app) , me.imagetype);
  144. app.post('/me/apiToken' , form.me.apiToken , loginRequired(crowi, app) , me.apiToken);
  145. app.post('/me/picture/delete' , loginRequired(crowi, app) , me.deletePicture);
  146. app.post('/me/auth/google' , loginRequired(crowi, app) , me.authGoogle);
  147. app.get( '/me/auth/google/callback' , loginRequired(crowi, app) , me.authGoogleCallback);
  148. app.get( '/:id([0-9a-z]{24})' , loginRequired(crowi, app, false) , page.api.redirector);
  149. app.get( '/_r/:id([0-9a-z]{24})' , loginRequired(crowi, app, false) , page.api.redirector); // alias
  150. app.get( '/download/:id([0-9a-z]{24})' , loginRequired(crowi, app, false) , attachment.api.download);
  151. app.get( '/_search' , loginRequired(crowi, app, false) , search.searchPage);
  152. app.get( '/_api/search' , accessTokenParser , loginRequired(crowi, app, false) , search.api.search);
  153. app.get( '/_api/check_username' , user.api.checkUsername);
  154. app.post('/_api/me/picture/upload' , loginRequired(crowi, app) , uploads.single('userPicture'), me.api.uploadPicture);
  155. app.get( '/_api/me/user-group-relations' , accessTokenParser , loginRequired(crowi, app) , me.api.userGroupRelations);
  156. app.get( '/_api/user/bookmarks' , loginRequired(crowi, app, false) , user.api.bookmarks);
  157. // HTTP RPC Styled API (に徐々に移行していいこうと思う)
  158. app.get('/_api/users.list' , accessTokenParser , loginRequired(crowi, app, false) , user.api.list);
  159. app.get('/_api/pages.list' , accessTokenParser , loginRequired(crowi, app, false) , page.api.list);
  160. app.post('/_api/pages.create' , accessTokenParser , loginRequired(crowi, app) , csrf, page.api.create);
  161. app.post('/_api/pages.update' , accessTokenParser , loginRequired(crowi, app) , csrf, page.api.update);
  162. app.get('/_api/pages.get' , accessTokenParser , loginRequired(crowi, app, false) , page.api.get);
  163. app.get('/_api/pages.updatePost' , accessTokenParser , loginRequired(crowi, app, false) , page.api.getUpdatePost);
  164. // allow posting to guests because the client doesn't know whether the user logged in
  165. app.post('/_api/pages.seen' , accessTokenParser , loginRequired(crowi, app, false) , page.api.seen);
  166. app.post('/_api/pages.rename' , accessTokenParser , loginRequired(crowi, app) , csrf, page.api.rename);
  167. app.post('/_api/pages.remove' , loginRequired(crowi, app) , csrf, page.api.remove); // (Avoid from API Token)
  168. app.post('/_api/pages.revertRemove' , loginRequired(crowi, app) , csrf, page.api.revertRemove); // (Avoid from API Token)
  169. app.post('/_api/pages.unlink' , loginRequired(crowi, app) , csrf, page.api.unlink); // (Avoid from API Token)
  170. app.post('/_api/pages.duplicate' , accessTokenParser, loginRequired(crowi, app), csrf, page.api.duplicate);
  171. app.get('/_api/comments.get' , accessTokenParser , loginRequired(crowi, app, false) , comment.api.get);
  172. app.post('/_api/comments.add' , form.comment, accessTokenParser , loginRequired(crowi, app) , csrf, comment.api.add);
  173. app.post('/_api/comments.remove' , accessTokenParser , loginRequired(crowi, app) , csrf, comment.api.remove);
  174. app.get( '/_api/bookmarks.get' , accessTokenParser , loginRequired(crowi, app, false) , bookmark.api.get);
  175. app.post('/_api/bookmarks.add' , accessTokenParser , loginRequired(crowi, app) , csrf, bookmark.api.add);
  176. app.post('/_api/bookmarks.remove' , accessTokenParser , loginRequired(crowi, app) , csrf, bookmark.api.remove);
  177. app.post('/_api/likes.add' , accessTokenParser , loginRequired(crowi, app) , csrf, page.api.like);
  178. app.post('/_api/likes.remove' , accessTokenParser , loginRequired(crowi, app) , csrf, page.api.unlike);
  179. app.get( '/_api/attachments.list' , accessTokenParser , loginRequired(crowi, app, false) , attachment.api.list);
  180. app.post('/_api/attachments.add' , uploads.single('file'), accessTokenParser, loginRequired(crowi, app) ,csrf, attachment.api.add);
  181. app.post('/_api/attachments.remove' , accessTokenParser , loginRequired(crowi, app) , csrf, attachment.api.remove);
  182. app.get( '/_api/revisions.get' , accessTokenParser , loginRequired(crowi, app, false) , revision.api.get);
  183. app.get( '/_api/revisions.ids' , accessTokenParser , loginRequired(crowi, app, false) , revision.api.ids);
  184. app.get( '/_api/revisions.list' , accessTokenParser , loginRequired(crowi, app, false) , revision.api.list);
  185. //app.get('/_api/revision/:id' , user.useUserData() , revision.api.get);
  186. //app.get('/_api/r/:revisionId' , user.useUserData() , page.api.get);
  187. app.post('/_/edit' , form.revision , loginRequired(crowi, app) , csrf, page.pageEdit);
  188. app.get('/trash$' , loginRequired(crowi, app, false) , page.trashPageShowWrapper);
  189. app.get('/trash/$' , loginRequired(crowi, app, false) , page.trashPageListShowWrapper);
  190. app.get('/trash/*/$' , loginRequired(crowi, app, false) , page.deletedPageListShowWrapper);
  191. app.get('/_hackmd/load-agent' , hackmd.loadAgent);
  192. app.post('/_api/hackmd/integrate' , accessTokenParser , loginRequired(crowi, app) , csrf, hackmd.integrate);
  193. app.get('/*/$' , loginRequired(crowi, app, false) , page.pageListShowWrapper);
  194. app.get('/*' , loginRequired(crowi, app, false) , page.pageShowWrapper);
  195. };