AdminController.php 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563
  1. <?php
  2. namespace App\Http\Controllers;
  3. use App\{
  4. AccountInterstitial,
  5. Contact,
  6. Hashtag,
  7. Instance,
  8. Newsroom,
  9. OauthClient,
  10. Profile,
  11. Report,
  12. Status,
  13. StatusHashtag,
  14. Story,
  15. User
  16. };
  17. use DB, Cache, Storage;
  18. use Carbon\Carbon;
  19. use Illuminate\Http\Request;
  20. use Illuminate\Support\Facades\Redis;
  21. use App\Http\Controllers\Admin\{
  22. AdminAutospamController,
  23. AdminDirectoryController,
  24. AdminDiscoverController,
  25. AdminHashtagsController,
  26. AdminInstanceController,
  27. AdminReportController,
  28. // AdminGroupsController,
  29. AdminMediaController,
  30. AdminSettingsController,
  31. // AdminStorageController,
  32. AdminSupportController,
  33. AdminUserController
  34. };
  35. use Illuminate\Validation\Rule;
  36. use App\Services\AdminStatsService;
  37. use App\Services\AccountService;
  38. use App\Services\StatusService;
  39. use App\Services\StoryService;
  40. use App\Models\CustomEmoji;
  41. class AdminController extends Controller
  42. {
  43. use AdminReportController,
  44. AdminAutospamController,
  45. AdminDirectoryController,
  46. AdminDiscoverController,
  47. AdminHashtagsController,
  48. // AdminGroupsController,
  49. AdminMediaController,
  50. AdminSettingsController,
  51. AdminInstanceController,
  52. // AdminStorageController,
  53. AdminUserController;
  54. public function __construct()
  55. {
  56. $this->middleware('admin');
  57. $this->middleware('dangerzone');
  58. $this->middleware('twofactor');
  59. }
  60. public function home()
  61. {
  62. return view('admin.home');
  63. }
  64. public function stats()
  65. {
  66. $data = AdminStatsService::get();
  67. return view('admin.stats', compact('data'));
  68. }
  69. public function getStats()
  70. {
  71. return AdminStatsService::summary();
  72. }
  73. public function getAccounts()
  74. {
  75. $users = User::orderByDesc('id')->cursorPaginate(10);
  76. $res = [
  77. "next_page_url" => $users->nextPageUrl(),
  78. "data" => $users->map(function($user) {
  79. $account = AccountService::get($user->profile_id, true);
  80. if(!$account) {
  81. return [
  82. "id" => $user->profile_id,
  83. "username" => $user->username,
  84. "status" => "deleted",
  85. "avatar" => "/storage/avatars/default.jpg",
  86. "created_at" => $user->created_at
  87. ];
  88. }
  89. $account['user_id'] = $user->id;
  90. return $account;
  91. })
  92. ->filter(function($user) {
  93. return $user;
  94. })
  95. ];
  96. return $res;
  97. }
  98. public function getPosts()
  99. {
  100. $posts = DB::table('statuses')
  101. ->orderByDesc('id')
  102. ->cursorPaginate(10);
  103. $res = [
  104. "next_page_url" => $posts->nextPageUrl(),
  105. "data" => $posts->map(function($post) {
  106. $status = StatusService::get($post->id, false);
  107. if(!$status) {
  108. return ["id" => $post->id, "created_at" => $post->created_at];
  109. }
  110. return $status;
  111. })
  112. ];
  113. return $res;
  114. }
  115. public function getInstances()
  116. {
  117. return Instance::orderByDesc('id')->cursorPaginate(10);
  118. }
  119. public function statuses(Request $request)
  120. {
  121. $statuses = Status::orderBy('id', 'desc')->cursorPaginate(10);
  122. $data = $statuses->map(function($status) {
  123. return StatusService::get($status->id, false);
  124. })
  125. ->filter(function($s) {
  126. return $s;
  127. })
  128. ->toArray();
  129. return view('admin.statuses.home', compact('statuses', 'data'));
  130. }
  131. public function showStatus(Request $request, $id)
  132. {
  133. $status = Status::findOrFail($id);
  134. return view('admin.statuses.show', compact('status'));
  135. }
  136. public function profiles(Request $request)
  137. {
  138. $this->validate($request, [
  139. 'search' => 'nullable|string|max:250',
  140. 'filter' => [
  141. 'nullable',
  142. 'string',
  143. Rule::in(['all', 'local', 'remote'])
  144. ]
  145. ]);
  146. $search = $request->input('search');
  147. $filter = $request->input('filter');
  148. $limit = 12;
  149. $profiles = Profile::select('id','username')
  150. ->whereNull('status')
  151. ->when($search, function($q, $search) {
  152. return $q->where('username', 'like', "%$search%");
  153. })->when($filter, function($q, $filter) {
  154. if($filter == 'local') {
  155. return $q->whereNull('domain');
  156. }
  157. if($filter == 'remote') {
  158. return $q->whereNotNull('domain');
  159. }
  160. return $q;
  161. })->orderByDesc('id')
  162. ->simplePaginate($limit);
  163. return view('admin.profiles.home', compact('profiles'));
  164. }
  165. public function profileShow(Request $request, $id)
  166. {
  167. $profile = Profile::findOrFail($id);
  168. $user = $profile->user;
  169. return view('admin.profiles.edit', compact('profile', 'user'));
  170. }
  171. public function appsHome(Request $request)
  172. {
  173. $filter = $request->input('filter');
  174. if($filter == 'revoked') {
  175. $apps = OauthClient::with('user')
  176. ->whereNotNull('user_id')
  177. ->whereRevoked(true)
  178. ->orderByDesc('id')
  179. ->paginate(10);
  180. } else {
  181. $apps = OauthClient::with('user')
  182. ->whereNotNull('user_id')
  183. ->orderByDesc('id')
  184. ->paginate(10);
  185. }
  186. return view('admin.apps.home', compact('apps'));
  187. }
  188. public function messagesHome(Request $request)
  189. {
  190. $messages = Contact::orderByDesc('id')->paginate(10);
  191. return view('admin.messages.home', compact('messages'));
  192. }
  193. public function messagesShow(Request $request, $id)
  194. {
  195. $message = Contact::findOrFail($id);
  196. return view('admin.messages.show', compact('message'));
  197. }
  198. public function messagesMarkRead(Request $request)
  199. {
  200. $this->validate($request, [
  201. 'id' => 'required|integer|min:1'
  202. ]);
  203. $id = $request->input('id');
  204. $message = Contact::findOrFail($id);
  205. if($message->read_at) {
  206. return;
  207. }
  208. $message->read_at = now();
  209. $message->save();
  210. return;
  211. }
  212. public function newsroomHome(Request $request)
  213. {
  214. $newsroom = Newsroom::latest()->paginate(10);
  215. return view('admin.newsroom.home', compact('newsroom'));
  216. }
  217. public function newsroomCreate(Request $request)
  218. {
  219. return view('admin.newsroom.create');
  220. }
  221. public function newsroomEdit(Request $request, $id)
  222. {
  223. $news = Newsroom::findOrFail($id);
  224. return view('admin.newsroom.edit', compact('news'));
  225. }
  226. public function newsroomDelete(Request $request, $id)
  227. {
  228. $news = Newsroom::findOrFail($id);
  229. $news->delete();
  230. return redirect('/i/admin/newsroom');
  231. }
  232. public function newsroomUpdate(Request $request, $id)
  233. {
  234. $this->validate($request, [
  235. 'title' => 'required|string|min:1|max:100',
  236. 'summary' => 'nullable|string|max:200',
  237. 'body' => 'nullable|string'
  238. ]);
  239. $changed = false;
  240. $changedFields = [];
  241. $slug = str_slug($request->input('title'));
  242. if(Newsroom::whereSlug($slug)->exists()) {
  243. $slug = $slug . '-' . str_random(4);
  244. }
  245. $news = Newsroom::findOrFail($id);
  246. $fields = [
  247. 'title' => 'string',
  248. 'summary' => 'string',
  249. 'body' => 'string',
  250. 'category' => 'string',
  251. 'show_timeline' => 'boolean',
  252. 'auth_only' => 'boolean',
  253. 'show_link' => 'boolean',
  254. 'force_modal' => 'boolean',
  255. 'published' => 'published'
  256. ];
  257. foreach($fields as $field => $type) {
  258. switch ($type) {
  259. case 'string':
  260. if($request->{$field} != $news->{$field}) {
  261. if($field == 'title') {
  262. $news->slug = $slug;
  263. }
  264. $news->{$field} = $request->{$field};
  265. $changed = true;
  266. array_push($changedFields, $field);
  267. }
  268. break;
  269. case 'boolean':
  270. $state = $request->{$field} == 'on' ? true : false;
  271. if($state != $news->{$field}) {
  272. $news->{$field} = $state;
  273. $changed = true;
  274. array_push($changedFields, $field);
  275. }
  276. break;
  277. case 'published':
  278. $state = $request->{$field} == 'on' ? true : false;
  279. $published = $news->published_at != null;
  280. if($state != $published) {
  281. $news->published_at = $state ? now() : null;
  282. $changed = true;
  283. array_push($changedFields, $field);
  284. }
  285. break;
  286. }
  287. }
  288. if($changed) {
  289. $news->save();
  290. }
  291. $redirect = $news->published_at ? $news->permalink() : $news->editUrl();
  292. return redirect($redirect);
  293. }
  294. public function newsroomStore(Request $request)
  295. {
  296. $this->validate($request, [
  297. 'title' => 'required|string|min:1|max:100',
  298. 'summary' => 'nullable|string|max:200',
  299. 'body' => 'nullable|string'
  300. ]);
  301. $changed = false;
  302. $changedFields = [];
  303. $slug = str_slug($request->input('title'));
  304. if(Newsroom::whereSlug($slug)->exists()) {
  305. $slug = $slug . '-' . str_random(4);
  306. }
  307. $news = new Newsroom();
  308. $fields = [
  309. 'title' => 'string',
  310. 'summary' => 'string',
  311. 'body' => 'string',
  312. 'category' => 'string',
  313. 'show_timeline' => 'boolean',
  314. 'auth_only' => 'boolean',
  315. 'show_link' => 'boolean',
  316. 'force_modal' => 'boolean',
  317. 'published' => 'published'
  318. ];
  319. foreach($fields as $field => $type) {
  320. switch ($type) {
  321. case 'string':
  322. if($request->{$field} != $news->{$field}) {
  323. if($field == 'title') {
  324. $news->slug = $slug;
  325. }
  326. $news->{$field} = $request->{$field};
  327. $changed = true;
  328. array_push($changedFields, $field);
  329. }
  330. break;
  331. case 'boolean':
  332. $state = $request->{$field} == 'on' ? true : false;
  333. if($state != $news->{$field}) {
  334. $news->{$field} = $state;
  335. $changed = true;
  336. array_push($changedFields, $field);
  337. }
  338. break;
  339. case 'published':
  340. $state = $request->{$field} == 'on' ? true : false;
  341. $published = $news->published_at != null;
  342. if($state != $published) {
  343. $news->published_at = $state ? now() : null;
  344. $changed = true;
  345. array_push($changedFields, $field);
  346. }
  347. break;
  348. }
  349. }
  350. if($changed) {
  351. $news->save();
  352. }
  353. $redirect = $news->published_at ? $news->permalink() : $news->editUrl();
  354. return redirect($redirect);
  355. }
  356. public function diagnosticsHome(Request $request)
  357. {
  358. return view('admin.diagnostics.home');
  359. }
  360. public function diagnosticsDecrypt(Request $request)
  361. {
  362. $this->validate($request, [
  363. 'payload' => 'required'
  364. ]);
  365. $key = 'exception_report:';
  366. $decrypted = decrypt($request->input('payload'));
  367. if(!starts_with($decrypted, $key)) {
  368. abort(403, 'Can only decrypt error diagnostics');
  369. }
  370. $res = [
  371. 'decrypted' => substr($decrypted, strlen($key))
  372. ];
  373. return response()->json($res);
  374. }
  375. public function stories(Request $request)
  376. {
  377. $stories = Story::with('profile')->latest()->paginate(10);
  378. $stats = StoryService::adminStats();
  379. return view('admin.stories.home', compact('stories', 'stats'));
  380. }
  381. public function customEmojiHome(Request $request)
  382. {
  383. if(!config('federation.custom_emoji.enabled')) {
  384. return view('admin.custom-emoji.not-enabled');
  385. }
  386. $this->validate($request, [
  387. 'sort' => 'sometimes|in:all,local,remote,duplicates,disabled,search'
  388. ]);
  389. if($request->has('cc')) {
  390. Cache::forget('pf:admin:custom_emoji:stats');
  391. Cache::forget('pf:custom_emoji');
  392. return redirect(route('admin.custom-emoji'));
  393. }
  394. $sort = $request->input('sort') ?? 'all';
  395. if($sort == 'search' && empty($request->input('q'))) {
  396. return redirect(route('admin.custom-emoji'));
  397. }
  398. $pg = config('database.default') == 'pgsql';
  399. $emojis = CustomEmoji::when($sort, function($query, $sort) use($request, $pg) {
  400. if($sort == 'all') {
  401. if($pg) {
  402. return $query->latest();
  403. } else {
  404. return $query->groupBy('shortcode')->latest();
  405. }
  406. } else if($sort == 'local') {
  407. return $query->latest()->where('domain', '=', config('pixelfed.domain.app'));
  408. } else if($sort == 'remote') {
  409. return $query->latest()->where('domain', '!=', config('pixelfed.domain.app'));
  410. } else if($sort == 'duplicates') {
  411. return $query->latest()->groupBy('shortcode')->havingRaw('count(*) > 1');
  412. } else if($sort == 'disabled') {
  413. return $query->latest()->whereDisabled(true);
  414. } else if($sort == 'search') {
  415. $q = $query
  416. ->latest()
  417. ->where('shortcode', 'like', '%' . $request->input('q') . '%')
  418. ->orWhere('domain', 'like', '%' . $request->input('q') . '%');
  419. if(!$request->has('dups')) {
  420. if(!$pg) {
  421. $q = $q->groupBy('shortcode');
  422. }
  423. }
  424. return $q;
  425. }
  426. })
  427. ->simplePaginate(10)
  428. ->withQueryString();
  429. $stats = Cache::remember('pf:admin:custom_emoji:stats', 43200, function() use($pg) {
  430. $res = [
  431. 'total' => CustomEmoji::count(),
  432. 'active' => CustomEmoji::whereDisabled(false)->count(),
  433. 'remote' => CustomEmoji::where('domain', '!=', config('pixelfed.domain.app'))->count(),
  434. ];
  435. if($pg) {
  436. $res['duplicate'] = CustomEmoji::select('shortcode')->groupBy('shortcode')->havingRaw('count(*) > 1')->count();
  437. } else {
  438. $res['duplicate'] = CustomEmoji::groupBy('shortcode')->havingRaw('count(*) > 1')->count();
  439. }
  440. return $res;
  441. });
  442. return view('admin.custom-emoji.home', compact('emojis', 'sort', 'stats'));
  443. }
  444. public function customEmojiToggleActive(Request $request, $id)
  445. {
  446. abort_unless(config('federation.custom_emoji.enabled'), 404);
  447. $emoji = CustomEmoji::findOrFail($id);
  448. $emoji->disabled = !$emoji->disabled;
  449. $emoji->save();
  450. $key = CustomEmoji::CACHE_KEY . str_replace(':', '', $emoji->shortcode);
  451. Cache::forget($key);
  452. return redirect()->back();
  453. }
  454. public function customEmojiAdd(Request $request)
  455. {
  456. abort_unless(config('federation.custom_emoji.enabled'), 404);
  457. return view('admin.custom-emoji.add');
  458. }
  459. public function customEmojiStore(Request $request)
  460. {
  461. abort_unless(config('federation.custom_emoji.enabled'), 404);
  462. $this->validate($request, [
  463. 'shortcode' => [
  464. 'required',
  465. 'min:3',
  466. 'max:80',
  467. 'starts_with::',
  468. 'ends_with::',
  469. Rule::unique('custom_emoji')->where(function ($query) use($request) {
  470. return $query->whereDomain(config('pixelfed.domain.app'))
  471. ->whereShortcode($request->input('shortcode'));
  472. })
  473. ],
  474. 'emoji' => 'required|file|mimes:jpg,png|max:' . (config('federation.custom_emoji.max_size') / 1000)
  475. ]);
  476. $emoji = new CustomEmoji;
  477. $emoji->shortcode = $request->input('shortcode');
  478. $emoji->domain = config('pixelfed.domain.app');
  479. $emoji->save();
  480. $fileName = $emoji->id . '.' . $request->emoji->extension();
  481. $request->emoji->storePubliclyAs('public/emoji', $fileName);
  482. $emoji->media_path = 'emoji/' . $fileName;
  483. $emoji->save();
  484. Cache::forget('pf:custom_emoji');
  485. return redirect(route('admin.custom-emoji'));
  486. }
  487. public function customEmojiDelete(Request $request, $id)
  488. {
  489. abort_unless(config('federation.custom_emoji.enabled'), 404);
  490. $emoji = CustomEmoji::findOrFail($id);
  491. Storage::delete("public/{$emoji->media_path}");
  492. Cache::forget('pf:custom_emoji');
  493. $emoji->delete();
  494. return redirect(route('admin.custom-emoji'));
  495. }
  496. public function customEmojiShowDuplicates(Request $request, $id)
  497. {
  498. abort_unless(config('federation.custom_emoji.enabled'), 404);
  499. $emoji = CustomEmoji::orderBy('id')->whereDisabled(false)->whereShortcode($id)->firstOrFail();
  500. $emojis = CustomEmoji::whereShortcode($id)->where('id', '!=', $emoji->id)->cursorPaginate(10);
  501. return view('admin.custom-emoji.duplicates', compact('emoji', 'emojis'));
  502. }
  503. }