index.js 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255
  1. import csrf from 'csurf';
  2. import express from 'express';
  3. import { generateAddActivityMiddleware } from '../middlewares/add-activity';
  4. import apiV1FormValidator from '../middlewares/apiv1-form-validator';
  5. import injectResetOrderByTokenMiddleware from '../middlewares/inject-reset-order-by-token-middleware';
  6. import injectUserRegistrationOrderByTokenMiddleware from '../middlewares/inject-user-registration-order-by-token-middleware';
  7. import * as loginFormValidator from '../middlewares/login-form-validator';
  8. import * as registerFormValidator from '../middlewares/register-form-validator';
  9. import {
  10. generateUnavailableWhenMaintenanceModeMiddleware, generateUnavailableWhenMaintenanceModeMiddlewareForApi,
  11. } from '../middlewares/unavailable-when-maintenance-mode';
  12. import * as allInAppNotifications from './all-in-app-notifications';
  13. import * as forgotPassword from './forgot-password';
  14. import nextFactory from './next';
  15. import * as privateLegacyPages from './private-legacy-pages';
  16. import * as userActivation from './user-activation';
  17. const multer = require('multer');
  18. const autoReap = require('multer-autoreap');
  19. const csrfProtection = csrf({ cookie: false });
  20. autoReap.options.reapOnError = true; // continue reaping the file even if an error occurs
  21. module.exports = function(crowi, app) {
  22. const autoReconnectToSearch = require('../middlewares/auto-reconnect-to-search')(crowi);
  23. const applicationNotInstalled = require('../middlewares/application-not-installed')(crowi);
  24. const applicationInstalled = require('../middlewares/application-installed')(crowi);
  25. const accessTokenParser = require('../middlewares/access-token-parser')(crowi);
  26. const loginRequiredStrictly = require('../middlewares/login-required')(crowi);
  27. const loginRequired = require('../middlewares/login-required')(crowi, true);
  28. const adminRequired = require('../middlewares/admin-required')(crowi);
  29. const certifySharedFile = require('../middlewares/certify-shared-file')(crowi);
  30. const injectUserUISettings = require('../middlewares/inject-user-ui-settings-to-localvars')();
  31. const rateLimiter = require('../middlewares/rate-limiter')();
  32. const addActivity = generateAddActivityMiddleware(crowi);
  33. const uploads = multer({ dest: `${crowi.tmpDir}uploads` });
  34. const page = require('./page')(crowi, app);
  35. const login = require('./login')(crowi, app);
  36. const loginPassport = require('./login-passport')(crowi, app);
  37. const me = require('./me')(crowi, app);
  38. const admin = require('./admin')(crowi, app);
  39. const user = require('./user')(crowi, app);
  40. const attachment = require('./attachment')(crowi, app);
  41. const comment = require('./comment')(crowi, app);
  42. const tag = require('./tag')(crowi, app);
  43. const search = require('./search')(crowi, app);
  44. // == TODO: Replace the code in hackmd.js getting the script path from manifest.json
  45. // const hackmd = require('./hackmd')(crowi, app);
  46. const ogp = require('./ogp')(crowi);
  47. const next = nextFactory(crowi);
  48. const unavailableWhenMaintenanceMode = generateUnavailableWhenMaintenanceModeMiddleware(crowi);
  49. const unavailableWhenMaintenanceModeForApi = generateUnavailableWhenMaintenanceModeMiddlewareForApi(crowi);
  50. const isInstalled = crowi.configManager.getConfig('crowi', 'app:installed');
  51. /* eslint-disable max-len, comma-spacing, no-multi-spaces */
  52. const [apiV3Router, apiV3AdminRouter, apiV3AuthRouter] = require('./apiv3')(crowi);
  53. app.use('/api-docs', require('./apiv3/docs')(crowi));
  54. // Rate limiter
  55. app.use(rateLimiter);
  56. // API v3 for admin
  57. app.use('/_api/v3', apiV3AdminRouter);
  58. // API v3 for auth
  59. app.use('/_api/v3', apiV3AuthRouter);
  60. app.get('/_next/*' , next.delegateToNext);
  61. app.get('/' , applicationInstalled, unavailableWhenMaintenanceMode, loginRequired, autoReconnectToSearch, next.delegateToNext);
  62. app.get('/login/error/:reason' , applicationInstalled, login.error);
  63. app.get('/login' , applicationInstalled, login.preLogin, next.delegateToNext);
  64. app.get('/login/invited' , applicationInstalled, login.invited);
  65. app.post('/login/activateInvited' , applicationInstalled, loginFormValidator.inviteRules(), loginFormValidator.inviteValidation, csrfProtection, login.invited);
  66. app.post('/login' , applicationInstalled, loginFormValidator.loginRules(), loginFormValidator.loginValidation, csrfProtection, addActivity, loginPassport.loginWithLocal, loginPassport.loginWithLdap, loginPassport.loginFailure);
  67. app.post('/register' , applicationInstalled, registerFormValidator.registerRules(), registerFormValidator.registerValidation, csrfProtection, addActivity, login.register);
  68. app.get('/register' , applicationInstalled, login.preLogin, login.register);
  69. app.get('/admin/*' , applicationInstalled, loginRequiredStrictly , adminRequired , next.delegateToNext);
  70. // app.get('/admin' , applicationInstalled, loginRequiredStrictly , adminRequired , admin.index);
  71. // app.get('/admin/app' , applicationInstalled, loginRequiredStrictly , adminRequired , admin.app.index);
  72. // installer
  73. if (!isInstalled) {
  74. const installer = require('./installer')(crowi);
  75. app.get('/installer' , applicationNotInstalled, next.delegateToNext);
  76. app.post('/installer' , applicationNotInstalled , registerFormValidator.registerRules(), registerFormValidator.registerValidation, csrfProtection, addActivity, installer.install);
  77. return;
  78. }
  79. // OAuth
  80. app.get('/passport/google' , loginPassport.loginWithGoogle, loginPassport.loginFailure);
  81. app.get('/passport/github' , loginPassport.loginWithGitHub, loginPassport.loginFailure);
  82. app.get('/passport/twitter' , loginPassport.loginWithTwitter, loginPassport.loginFailure);
  83. app.get('/passport/oidc' , loginPassport.loginWithOidc, loginPassport.loginFailure);
  84. app.get('/passport/saml' , loginPassport.loginWithSaml, loginPassport.loginFailure);
  85. app.get('/passport/basic' , loginPassport.loginWithBasic, loginPassport.loginFailure);
  86. app.get('/passport/google/callback' , loginPassport.loginPassportGoogleCallback , loginPassport.loginFailure);
  87. app.get('/passport/github/callback' , loginPassport.loginPassportGitHubCallback , loginPassport.loginFailure);
  88. app.get('/passport/twitter/callback' , loginPassport.loginPassportTwitterCallback , loginPassport.loginFailure);
  89. app.get('/passport/oidc/callback' , loginPassport.loginPassportOidcCallback , loginPassport.loginFailure);
  90. app.post('/passport/saml/callback' , addActivity, loginPassport.loginPassportSamlCallback, loginPassport.loginFailure);
  91. app.post('/_api/login/testLdap' , loginRequiredStrictly , loginFormValidator.loginRules() , loginFormValidator.loginValidation , loginPassport.testLdapCredentials);
  92. // security admin
  93. // app.get('/admin/security' , loginRequiredStrictly , adminRequired , admin.security.index);
  94. // markdown admin
  95. // app.get('/admin/markdown' , loginRequiredStrictly , adminRequired , admin.markdown.index);
  96. // customize admin
  97. // app.get('/admin/customize' , loginRequiredStrictly , adminRequired , admin.customize.index);
  98. // search admin
  99. // app.get('/admin/search' , loginRequiredStrictly , adminRequired , admin.search.index);
  100. // notification admin
  101. // app.get('/admin/notification' , loginRequiredStrictly , adminRequired , admin.notification.index);
  102. // app.get('/admin/notification/slackAuth' , loginRequiredStrictly , adminRequired , admin.notification.slackAuth);
  103. // app.get('/admin/notification/slackSetting/disconnect' , loginRequiredStrictly , adminRequired , admin.notification.disconnectFromSlack);
  104. // app.get('/admin/global-notification/new' , loginRequiredStrictly , adminRequired , admin.globalNotification.detail);
  105. // app.get('/admin/global-notification/:id' , loginRequiredStrictly , adminRequired , admin.globalNotification.detail);
  106. // app.get('/admin/slack-integration-legacy' , loginRequiredStrictly , adminRequired, admin.slackIntegrationLegacy);
  107. // app.get('/admin/slack-integration' , loginRequiredStrictly , adminRequired, admin.slackIntegration);
  108. // app.get('/admin/users' , loginRequiredStrictly , adminRequired , admin.user.index);
  109. // app.get('/admin/users/external-accounts' , loginRequiredStrictly , adminRequired , admin.externalAccount.index);
  110. // user-groups admin
  111. // app.get('/admin/user-groups' , loginRequiredStrictly, adminRequired, admin.userGroup.index);
  112. // app.get('/admin/user-group-detail/:id' , loginRequiredStrictly, adminRequired, admin.userGroup.detail);
  113. // auditLog admin
  114. // app.get('/admin/audit-log' , loginRequiredStrictly, adminRequired, admin.auditLog.index);
  115. // importer management for admin
  116. // app.get('/admin/importer' , loginRequiredStrictly , adminRequired , admin.importer.index);
  117. app.post('/_api/admin/settings/importerEsa' , loginRequiredStrictly , adminRequired , csrfProtection, addActivity, admin.importer.api.validators.importer.esa(),admin.api.importerSettingEsa);
  118. app.post('/_api/admin/settings/importerQiita' , loginRequiredStrictly , adminRequired , csrfProtection, addActivity, admin.importer.api.validators.importer.qiita(), admin.api.importerSettingQiita);
  119. app.post('/_api/admin/import/esa' , loginRequiredStrictly , adminRequired , csrfProtection, addActivity, admin.api.importDataFromEsa);
  120. app.post('/_api/admin/import/testEsaAPI' , loginRequiredStrictly , adminRequired , csrfProtection, addActivity, admin.api.testEsaAPI);
  121. app.post('/_api/admin/import/qiita' , loginRequiredStrictly , adminRequired , csrfProtection, addActivity, admin.api.importDataFromQiita);
  122. app.post('/_api/admin/import/testQiitaAPI' , loginRequiredStrictly , adminRequired , csrfProtection, addActivity, admin.api.testQiitaAPI);
  123. // export management for admin
  124. // app.get('/admin/export' , loginRequiredStrictly , adminRequired ,admin.export.index);
  125. // app.get('/admin/export/:fileName' , loginRequiredStrictly , adminRequired ,admin.export.api.validators.export.download(), admin.export.download);
  126. // app.get('/admin/*' , loginRequiredStrictly ,adminRequired, admin.notFound.index);
  127. /*
  128. * Routes below are unavailable when maintenance mode
  129. */
  130. // API v3
  131. app.use('/_api/v3', unavailableWhenMaintenanceModeForApi, apiV3Router);
  132. const apiV1Router = express.Router();
  133. apiV1Router.get('/search' , accessTokenParser , loginRequired , search.api.search);
  134. apiV1Router.get('/me/user-group-relations' , accessTokenParser , loginRequiredStrictly , me.api.userGroupRelations);
  135. // HTTP RPC Styled API (に徐々に移行していいこうと思う)
  136. apiV1Router.get('/pages.list' , accessTokenParser , loginRequired , page.api.list);
  137. apiV1Router.post('/pages.update' , accessTokenParser , loginRequiredStrictly , addActivity, page.api.update);
  138. apiV1Router.get('/pages.exist' , accessTokenParser , loginRequired , page.api.exist);
  139. apiV1Router.get('/pages.updatePost' , accessTokenParser, loginRequired, page.api.getUpdatePost);
  140. apiV1Router.get('/pages.getPageTag' , accessTokenParser , loginRequired , page.api.getPageTag);
  141. // allow posting to guests because the client doesn't know whether the user logged in
  142. apiV1Router.post('/pages.remove' , loginRequiredStrictly , addActivity, page.validator.remove, apiV1FormValidator, page.api.remove); // (Avoid from API Token)
  143. apiV1Router.post('/pages.revertRemove' , loginRequiredStrictly , addActivity, page.validator.revertRemove, apiV1FormValidator, page.api.revertRemove); // (Avoid from API Token)
  144. apiV1Router.post('/pages.unlink' , loginRequiredStrictly , page.api.unlink); // (Avoid from API Token)
  145. apiV1Router.post('/pages.duplicate' , accessTokenParser, loginRequiredStrictly, page.api.duplicate);
  146. apiV1Router.get('/tags.list' , accessTokenParser, loginRequired, tag.api.list);
  147. apiV1Router.get('/tags.search' , accessTokenParser, loginRequired, tag.api.search);
  148. apiV1Router.post('/tags.update' , accessTokenParser, loginRequiredStrictly, addActivity, tag.api.update);
  149. apiV1Router.get('/comments.get' , accessTokenParser , loginRequired , comment.api.get);
  150. apiV1Router.post('/comments.add' , comment.api.validators.add(), accessTokenParser , loginRequiredStrictly , addActivity, comment.api.add);
  151. apiV1Router.post('/comments.update' , comment.api.validators.add(), accessTokenParser , loginRequiredStrictly , addActivity, comment.api.update);
  152. apiV1Router.post('/comments.remove' , accessTokenParser , loginRequiredStrictly , addActivity, comment.api.remove);
  153. apiV1Router.post('/attachments.add' , uploads.single('file'), autoReap, accessTokenParser, loginRequiredStrictly ,addActivity ,attachment.api.add);
  154. apiV1Router.post('/attachments.uploadProfileImage' , uploads.single('file'), autoReap, accessTokenParser, loginRequiredStrictly ,attachment.api.uploadProfileImage);
  155. apiV1Router.post('/attachments.remove' , accessTokenParser , loginRequiredStrictly , addActivity ,attachment.api.remove);
  156. apiV1Router.post('/attachments.removeProfileImage' , accessTokenParser , loginRequiredStrictly , attachment.api.removeProfileImage);
  157. apiV1Router.get('/attachments.limit' , accessTokenParser , loginRequiredStrictly, attachment.api.limit);
  158. // API v1
  159. app.use('/_api', unavailableWhenMaintenanceModeForApi, apiV1Router);
  160. app.use(unavailableWhenMaintenanceMode);
  161. // app.get('/tags' , loginRequired, tag.showPage);
  162. app.get('/tags', loginRequired, next.delegateToNext);
  163. app.get('/me' , loginRequiredStrictly, injectUserUISettings, next.delegateToNext);
  164. // external-accounts
  165. // my in-app-notifications
  166. app.get('/me/all-in-app-notifications' , loginRequiredStrictly, allInAppNotifications.list);
  167. app.get('/me/external-accounts' , loginRequiredStrictly, injectUserUISettings, me.externalAccounts.list);
  168. // my drafts
  169. app.get('/me/drafts' , loginRequiredStrictly, injectUserUISettings, me.drafts.list);
  170. app.get('/attachment/:id([0-9a-z]{24})' , certifySharedFile , loginRequired, attachment.api.get);
  171. app.get('/attachment/profile/:id([0-9a-z]{24})' , loginRequired, attachment.api.get);
  172. app.get('/attachment/:pageId/:fileName' , loginRequired, attachment.api.obsoletedGetForMongoDB); // DEPRECATED: remains for backward compatibility for v3.3.x or below
  173. app.get('/download/:id([0-9a-z]{24})' , loginRequired, attachment.api.download);
  174. app.get('/_search' , loginRequired, next.delegateToNext);
  175. app.get('/trash$' , loginRequired, injectUserUISettings, page.trashPageShowWrapper);
  176. app.get('/trash/$' , loginRequired, (req, res) => res.redirect('/trash'));
  177. app.get('/trash/*/$' , loginRequired, injectUserUISettings, page.deletedPageListShowWrapper);
  178. // == TODO: Replace the code in hackmd.js getting the script path from manifest.json
  179. // app.get('/_hackmd/load-agent' , hackmd.loadAgent);
  180. // app.get('/_hackmd/load-styles' , hackmd.loadStyles);
  181. // app.post('/_api/hackmd.integrate' , accessTokenParser , loginRequiredStrictly , hackmd.validateForApi, hackmd.integrate);
  182. // app.post('/_api/hackmd.discard' , accessTokenParser , loginRequiredStrictly , hackmd.validateForApi, hackmd.discard);
  183. // app.post('/_api/hackmd.saveOnHackmd' , accessTokenParser , loginRequiredStrictly , hackmd.validateForApi, hackmd.saveOnHackmd);
  184. app.use('/forgot-password', express.Router()
  185. .use(forgotPassword.checkForgotPasswordEnabledMiddlewareFactory(crowi))
  186. .get('/', forgotPassword.forgotPassword)
  187. .get('/:token', injectResetOrderByTokenMiddleware, forgotPassword.resetPassword)
  188. .use(forgotPassword.handleErrosMiddleware));
  189. app.get('/_private-legacy-pages', next.delegateToNext);
  190. app.use('/user-activation', express.Router()
  191. .get('/:token', applicationInstalled, injectUserRegistrationOrderByTokenMiddleware, userActivation.form)
  192. .use(userActivation.tokenErrorHandlerMiddeware));
  193. app.post('/user-activation/register', applicationInstalled, csrfProtection, userActivation.registerRules(), userActivation.validateRegisterForm, userActivation.registerAction(crowi));
  194. app.get('/share/:linkId', page.showSharedPage);
  195. app.use('/ogp', express.Router().get('/:pageId([0-9a-z]{0,})', loginRequired, ogp.pageIdRequired, ogp.ogpValidator, ogp.renderOgp));
  196. app.get('/*/$' , loginRequired, next.delegateToNext);
  197. app.get('/*' , loginRequired, autoReconnectToSearch, next.delegateToNext);
  198. };