admin.js 8.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306
  1. import { SupportedAction } from '~/interfaces/activity';
  2. import UserGroup from '~/server/models/user-group';
  3. import loggerFactory from '~/utils/logger';
  4. const logger = loggerFactory('growi:routes:admin');
  5. const debug = require('debug')('growi:routes:admin');
  6. /* eslint-disable no-use-before-define */
  7. module.exports = function(crowi, app) {
  8. const models = crowi.models;
  9. const UserGroupRelation = models.UserGroupRelation;
  10. const GlobalNotificationSetting = models.GlobalNotificationSetting;
  11. const {
  12. configManager,
  13. aclService,
  14. slackIntegrationService,
  15. exportService,
  16. } = crowi;
  17. const ApiResponse = require('../util/apiResponse');
  18. const importer = require('../util/importer')(crowi);
  19. const MAX_PAGE_LIST = 50;
  20. const actions = {};
  21. const { check, param } = require('express-validator');
  22. const activityEvent = crowi.event('activity');
  23. const api = {};
  24. function createPager(total, limit, page, pagesCount, maxPageList) {
  25. const pager = {
  26. page,
  27. pagesCount,
  28. pages: [],
  29. total,
  30. previous: null,
  31. previousDots: false,
  32. next: null,
  33. nextDots: false,
  34. };
  35. if (page > 1) {
  36. pager.previous = page - 1;
  37. }
  38. if (page < pagesCount) {
  39. pager.next = page + 1;
  40. }
  41. let pagerMin = Math.max(1, Math.ceil(page - maxPageList / 2));
  42. let pagerMax = Math.min(pagesCount, Math.floor(page + maxPageList / 2));
  43. if (pagerMin === 1) {
  44. if (MAX_PAGE_LIST < pagesCount) {
  45. pagerMax = MAX_PAGE_LIST;
  46. }
  47. else {
  48. pagerMax = pagesCount;
  49. }
  50. }
  51. if (pagerMax === pagesCount) {
  52. if ((pagerMax - MAX_PAGE_LIST) < 1) {
  53. pagerMin = 1;
  54. }
  55. else {
  56. pagerMin = pagerMax - MAX_PAGE_LIST;
  57. }
  58. }
  59. pager.previousDots = null;
  60. if (pagerMin > 1) {
  61. pager.previousDots = true;
  62. }
  63. pager.nextDots = null;
  64. if (pagerMax < pagesCount) {
  65. pager.nextDots = true;
  66. }
  67. for (let i = pagerMin; i <= pagerMax; i++) {
  68. pager.pages.push(i);
  69. }
  70. return pager;
  71. }
  72. // Importer management
  73. actions.importer = {};
  74. actions.importer.api = api;
  75. api.validators = {};
  76. api.validators.importer = {};
  77. api.validators.importer.esa = function() {
  78. const validator = [
  79. check('importer:esa:team_name').not().isEmpty().withMessage('Error. Empty esa:team_name'),
  80. check('importer:esa:access_token').not().isEmpty().withMessage('Error. Empty esa:access_token'),
  81. ];
  82. return validator;
  83. };
  84. api.validators.importer.qiita = function() {
  85. const validator = [
  86. check('importer:qiita:team_name').not().isEmpty().withMessage('Error. Empty qiita:team_name'),
  87. check('importer:qiita:access_token').not().isEmpty().withMessage('Error. Empty qiita:access_token'),
  88. ];
  89. return validator;
  90. };
  91. // Export management
  92. actions.export = {};
  93. actions.export.api = api;
  94. api.validators.export = {};
  95. api.validators.export.download = function() {
  96. const validator = [
  97. // https://regex101.com/r/mD4eZs/6
  98. // prevent from pass traversal attack
  99. param('fileName').not().matches(/(\.\.\/|\.\.\\)/),
  100. ];
  101. return validator;
  102. };
  103. actions.export.download = (req, res) => {
  104. const { fileName } = req.params;
  105. const { validationResult } = require('express-validator');
  106. const errors = validationResult(req);
  107. if (!errors.isEmpty()) {
  108. return res.status(422).json({ errors: `${fileName} is invalid. Do not use path like '../'.` });
  109. }
  110. try {
  111. const zipFile = exportService.getFile(fileName);
  112. const parameters = {
  113. ip: req.ip,
  114. endpoint: req.originalUrl,
  115. action: SupportedAction.ACTION_ADMIN_ARCHIVE_DATA_DOWNLOAD,
  116. user: req.user?._id,
  117. snapshot: {
  118. username: req.user?.username,
  119. },
  120. };
  121. crowi.activityService.createActivity(parameters);
  122. return res.download(zipFile);
  123. }
  124. catch (err) {
  125. // TODO: use ApiV3Error
  126. logger.error(err);
  127. return res.json(ApiResponse.error());
  128. }
  129. };
  130. actions.api = {};
  131. /**
  132. * save esa settings, update config cache, and response json
  133. *
  134. * @param {*} req
  135. * @param {*} res
  136. */
  137. actions.api.importerSettingEsa = async(req, res) => {
  138. const form = req.body;
  139. const { validationResult } = require('express-validator');
  140. const errors = validationResult(req);
  141. if (!errors.isEmpty()) {
  142. return res.json(ApiResponse.error('esa.io form is blank'));
  143. }
  144. await configManager.updateConfigsInTheSameNamespace('crowi', form);
  145. importer.initializeEsaClient(); // let it run in the back aftert res
  146. const parameters = { action: SupportedAction.ACTION_ADMIN_ESA_DATA_UPDATED };
  147. activityEvent.emit('update', res.locals.activity._id, parameters);
  148. return res.json(ApiResponse.success());
  149. };
  150. /**
  151. * save qiita settings, update config cache, and response json
  152. *
  153. * @param {*} req
  154. * @param {*} res
  155. */
  156. actions.api.importerSettingQiita = async(req, res) => {
  157. const form = req.body;
  158. const { validationResult } = require('express-validator');
  159. const errors = validationResult(req);
  160. if (!errors.isEmpty()) {
  161. return res.json(ApiResponse.error('Qiita form is blank'));
  162. }
  163. await configManager.updateConfigsInTheSameNamespace('crowi', form);
  164. importer.initializeQiitaClient(); // let it run in the back aftert res
  165. const parameters = { action: SupportedAction.ACTION_ADMIN_QIITA_DATA_UPDATED };
  166. activityEvent.emit('update', res.locals.activity._id, parameters);
  167. return res.json(ApiResponse.success());
  168. };
  169. /**
  170. * Import all posts from esa
  171. *
  172. * @param {*} req
  173. * @param {*} res
  174. */
  175. actions.api.importDataFromEsa = async(req, res) => {
  176. const user = req.user;
  177. let errors;
  178. try {
  179. errors = await importer.importDataFromEsa(user);
  180. const parameters = { action: SupportedAction.ACTION_ADMIN_ESA_DATA_IMPORTED };
  181. activityEvent.emit('update', res.locals.activity._id, parameters);
  182. }
  183. catch (err) {
  184. errors = [err];
  185. }
  186. if (errors.length > 0) {
  187. return res.json(ApiResponse.error(`<br> - ${errors.join('<br> - ')}`));
  188. }
  189. return res.json(ApiResponse.success());
  190. };
  191. /**
  192. * Import all posts from qiita
  193. *
  194. * @param {*} req
  195. * @param {*} res
  196. */
  197. actions.api.importDataFromQiita = async(req, res) => {
  198. const user = req.user;
  199. let errors;
  200. try {
  201. errors = await importer.importDataFromQiita(user);
  202. const parameters = { action: SupportedAction.ACTION_ADMIN_QIITA_DATA_IMPORTED };
  203. activityEvent.emit('update', res.locals.activity._id, parameters);
  204. }
  205. catch (err) {
  206. errors = [err];
  207. }
  208. if (errors.length > 0) {
  209. return res.json(ApiResponse.error(`<br> - ${errors.join('<br> - ')}`));
  210. }
  211. return res.json(ApiResponse.success());
  212. };
  213. /**
  214. * Test connection to esa and response result with json
  215. *
  216. * @param {*} req
  217. * @param {*} res
  218. */
  219. actions.api.testEsaAPI = async(req, res) => {
  220. try {
  221. await importer.testConnectionToEsa();
  222. const parameters = { action: SupportedAction.ACTION_ADMIN_CONNECTION_TEST_OF_ESA_DATA };
  223. activityEvent.emit('update', res.locals.activity._id, parameters);
  224. return res.json(ApiResponse.success());
  225. }
  226. catch (err) {
  227. return res.json(ApiResponse.error(err));
  228. }
  229. };
  230. /**
  231. * Test connection to qiita and response result with json
  232. *
  233. * @param {*} req
  234. * @param {*} res
  235. */
  236. actions.api.testQiitaAPI = async(req, res) => {
  237. try {
  238. await importer.testConnectionToQiita();
  239. const parameters = { action: SupportedAction.ACTION_ADMIN_CONNECTION_TEST_OF_QIITA_DATA };
  240. activityEvent.emit('update', res.locals.activity._id, parameters);
  241. return res.json(ApiResponse.success());
  242. }
  243. catch (err) {
  244. return res.json(ApiResponse.error(err));
  245. }
  246. };
  247. actions.api.searchBuildIndex = async function(req, res) {
  248. const search = crowi.getSearcher();
  249. if (!search) {
  250. return res.json(ApiResponse.error('ElasticSearch Integration is not set up.'));
  251. }
  252. try {
  253. search.buildIndex();
  254. }
  255. catch (err) {
  256. return res.json(ApiResponse.error(err));
  257. }
  258. return res.json(ApiResponse.success());
  259. };
  260. return actions;
  261. };