InternalApiController.php 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336
  1. <?php
  2. namespace App\Http\Controllers;
  3. use Illuminate\Http\Request;
  4. use App\{
  5. DirectMessage,
  6. DiscoverCategory,
  7. Hashtag,
  8. Follower,
  9. Like,
  10. Media,
  11. Notification,
  12. Profile,
  13. StatusHashtag,
  14. Status,
  15. UserFilter,
  16. };
  17. use Auth,Cache;
  18. use Carbon\Carbon;
  19. use League\Fractal;
  20. use App\Transformer\Api\{
  21. AccountTransformer,
  22. StatusTransformer,
  23. };
  24. use App\Util\Media\Filter;
  25. use App\Jobs\StatusPipeline\NewStatusPipeline;
  26. use League\Fractal\Serializer\ArraySerializer;
  27. use League\Fractal\Pagination\IlluminatePaginatorAdapter;
  28. use Illuminate\Validation\Rule;
  29. use Illuminate\Support\Str;
  30. class InternalApiController extends Controller
  31. {
  32. protected $fractal;
  33. public function __construct()
  34. {
  35. $this->middleware('auth');
  36. $this->fractal = new Fractal\Manager();
  37. $this->fractal->setSerializer(new ArraySerializer());
  38. }
  39. // deprecated v2 compose api
  40. public function compose(Request $request)
  41. {
  42. return redirect('/');
  43. }
  44. // deprecated
  45. public function discover(Request $request)
  46. {
  47. return;
  48. }
  49. public function discoverPosts(Request $request)
  50. {
  51. $profile = Auth::user()->profile;
  52. $pid = $profile->id;
  53. $following = Cache::remember('feature:discover:following:'.$pid, now()->addMinutes(15), function() use ($pid) {
  54. return Follower::whereProfileId($pid)->pluck('following_id')->toArray();
  55. });
  56. $filters = Cache::remember("user:filter:list:$pid", now()->addMinutes(15), function() use($pid) {
  57. $private = Profile::whereIsPrivate(true)
  58. ->orWhere('unlisted', true)
  59. ->orWhere('status', '!=', null)
  60. ->pluck('id')
  61. ->toArray();
  62. $filters = UserFilter::whereUserId($pid)
  63. ->whereFilterableType('App\Profile')
  64. ->whereIn('filter_type', ['mute', 'block'])
  65. ->pluck('filterable_id')
  66. ->toArray();
  67. return array_merge($private, $filters);
  68. });
  69. $following = array_merge($following, $filters);
  70. $posts = Status::select(
  71. 'id',
  72. 'caption',
  73. 'profile_id',
  74. 'type'
  75. )
  76. ->whereNull('uri')
  77. ->whereIn('type', ['photo','photo:album', 'video'])
  78. ->whereIsNsfw(false)
  79. ->whereVisibility('public')
  80. ->whereNotIn('profile_id', $following)
  81. ->whereDate('created_at', '>', now()->subMonths(3))
  82. ->with('media')
  83. ->inRandomOrder()
  84. ->take(36)
  85. ->get();
  86. $res = [
  87. 'posts' => $posts->map(function($post) {
  88. return [
  89. 'type' => $post->type,
  90. 'url' => $post->url(),
  91. 'thumb' => $post->thumb(),
  92. ];
  93. })
  94. ];
  95. return response()->json($res);
  96. }
  97. public function directMessage(Request $request, $profileId, $threadId)
  98. {
  99. $profile = Auth::user()->profile;
  100. if($profileId != $profile->id) {
  101. abort(403);
  102. }
  103. $msg = DirectMessage::whereToId($profile->id)
  104. ->orWhere('from_id',$profile->id)
  105. ->findOrFail($threadId);
  106. $thread = DirectMessage::with('status')->whereIn('to_id', [$profile->id, $msg->from_id])
  107. ->whereIn('from_id', [$profile->id,$msg->from_id])
  108. ->orderBy('created_at', 'asc')
  109. ->paginate(30);
  110. return response()->json(compact('msg', 'profile', 'thread'), 200, [], JSON_PRETTY_PRINT);
  111. }
  112. public function statusReplies(Request $request, int $id)
  113. {
  114. $parent = Status::whereScope('public')->findOrFail($id);
  115. $children = Status::whereInReplyToId($parent->id)
  116. ->orderBy('created_at', 'desc')
  117. ->take(3)
  118. ->get();
  119. $resource = new Fractal\Resource\Collection($children, new StatusTransformer());
  120. $res = $this->fractal->createData($resource)->toArray();
  121. return response()->json($res);
  122. }
  123. public function stories(Request $request)
  124. {
  125. }
  126. public function discoverCategories(Request $request)
  127. {
  128. $categories = DiscoverCategory::whereActive(true)->orderBy('order')->take(10)->get();
  129. $res = $categories->map(function($item) {
  130. return [
  131. 'name' => $item->name,
  132. 'url' => $item->url(),
  133. 'thumb' => $item->thumb()
  134. ];
  135. });
  136. return response()->json($res);
  137. }
  138. public function modAction(Request $request)
  139. {
  140. abort_unless(Auth::user()->is_admin, 403);
  141. $this->validate($request, [
  142. 'action' => [
  143. 'required',
  144. 'string',
  145. Rule::in([
  146. 'autocw',
  147. 'noautolink',
  148. 'unlisted',
  149. 'disable',
  150. 'suspend'
  151. ])
  152. ],
  153. 'item_id' => 'required|integer|min:1',
  154. 'item_type' => [
  155. 'required',
  156. 'string',
  157. Rule::in(['status'])
  158. ]
  159. ]);
  160. $action = $request->input('action');
  161. $item_id = $request->input('item_id');
  162. $item_type = $request->input('item_type');
  163. switch($action) {
  164. case 'autocw':
  165. $profile = $item_type == 'status' ? Status::findOrFail($item_id)->profile : null;
  166. $profile->cw = true;
  167. $profile->save();
  168. break;
  169. case 'noautolink':
  170. $profile = $item_type == 'status' ? Status::findOrFail($item_id)->profile : null;
  171. $profile->no_autolink = true;
  172. $profile->save();
  173. break;
  174. case 'unlisted':
  175. $profile = $item_type == 'status' ? Status::findOrFail($item_id)->profile : null;
  176. $profile->unlisted = true;
  177. $profile->save();
  178. break;
  179. case 'disable':
  180. $profile = $item_type == 'status' ? Status::findOrFail($item_id)->profile : null;
  181. $user = $profile->user;
  182. $profile->status = 'disabled';
  183. $user->status = 'disabled';
  184. $profile->save();
  185. $user->save();
  186. break;
  187. case 'suspend':
  188. $profile = $item_type == 'status' ? Status::findOrFail($item_id)->profile : null;
  189. $user = $profile->user;
  190. $profile->status = 'suspended';
  191. $user->status = 'suspended';
  192. $profile->save();
  193. $user->save();
  194. break;
  195. default:
  196. # code...
  197. break;
  198. }
  199. Cache::forget('profiles:private');
  200. return ['msg' => 200];
  201. }
  202. public function composePost(Request $request)
  203. {
  204. $this->validate($request, [
  205. 'caption' => 'nullable|string|max:'.config('pixelfed.max_caption_length', 500),
  206. 'media.*' => 'required',
  207. 'media.*.id' => 'required|integer|min:1',
  208. 'media.*.filter_class' => 'nullable|alpha_dash|max:30',
  209. 'media.*.license' => 'nullable|string|max:80',
  210. 'cw' => 'nullable|boolean',
  211. 'visibility' => 'required|string|in:public,private,unlisted|min:2|max:10',
  212. 'place' => 'nullable',
  213. 'comments_disabled' => 'nullable|boolean'
  214. ]);
  215. if(config('costar.enabled') == true) {
  216. $blockedKeywords = config('costar.keyword.block');
  217. if($blockedKeywords !== null && $request->caption) {
  218. $keywords = config('costar.keyword.block');
  219. foreach($keywords as $kw) {
  220. if(Str::contains($request->caption, $kw) == true) {
  221. abort(400, 'Invalid object');
  222. }
  223. }
  224. }
  225. }
  226. $user = Auth::user();
  227. $profile = $user->profile;
  228. $visibility = $request->input('visibility');
  229. $medias = $request->input('media');
  230. $attachments = [];
  231. $status = new Status;
  232. $mimes = [];
  233. $cw = $request->input('cw');
  234. foreach($medias as $k => $media) {
  235. if($k + 1 > config('pixelfed.max_album_length')) {
  236. continue;
  237. }
  238. $m = Media::findOrFail($media['id']);
  239. if($m->profile_id !== $profile->id || $m->status_id) {
  240. abort(403, 'Invalid media id');
  241. }
  242. $m->filter_class = in_array($media['filter_class'], Filter::classes()) ? $media['filter_class'] : null;
  243. $m->license = $media['license'];
  244. $m->caption = isset($media['alt']) ? strip_tags($media['alt']) : null;
  245. $m->order = isset($media['cursor']) && is_int($media['cursor']) ? (int) $media['cursor'] : $k;
  246. if($cw == true || $profile->cw == true) {
  247. $m->is_nsfw = $cw;
  248. $status->is_nsfw = $cw;
  249. }
  250. $m->save();
  251. $attachments[] = $m;
  252. array_push($mimes, $m->mime);
  253. }
  254. if($request->filled('place')) {
  255. $status->place_id = $request->input('place')['id'];
  256. }
  257. if($request->filled('comments_disabled')) {
  258. $status->comments_disabled = $request->input('comments_disabled');
  259. }
  260. $status->caption = strip_tags($request->caption);
  261. $status->scope = 'draft';
  262. $status->profile_id = $profile->id;
  263. $status->save();
  264. foreach($attachments as $media) {
  265. $media->status_id = $status->id;
  266. $media->save();
  267. }
  268. $visibility = $profile->unlisted == true && $visibility == 'public' ? 'unlisted' : $visibility;
  269. $cw = $profile->cw == true ? true : $cw;
  270. $status->is_nsfw = $cw;
  271. $status->visibility = $visibility;
  272. $status->scope = $visibility;
  273. $status->type = StatusController::mimeTypeCheck($mimes);
  274. $status->save();
  275. NewStatusPipeline::dispatch($status);
  276. Cache::forget('user:account:id:'.$profile->user_id);
  277. Cache::forget('profile:status_count:'.$profile->id);
  278. Cache::forget($user->storageUsedKey());
  279. return $status->url();
  280. }
  281. public function bookmarks(Request $request)
  282. {
  283. $statuses = Auth::user()->profile
  284. ->bookmarks()
  285. ->withCount(['likes','comments'])
  286. ->orderBy('created_at', 'desc')
  287. ->simplePaginate(10);
  288. $resource = new Fractal\Resource\Collection($statuses, new StatusTransformer());
  289. $res = $this->fractal->createData($resource)->toArray();
  290. return response()->json($res);
  291. }
  292. }