AdminController.php 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559
  1. <?php
  2. namespace App\Http\Controllers;
  3. use App\{
  4. AccountInterstitial,
  5. Contact,
  6. Hashtag,
  7. Instance,
  8. Newsroom,
  9. OauthClient,
  10. Profile,
  11. Report,
  12. Status,
  13. StatusHashtag,
  14. Story,
  15. User
  16. };
  17. use DB, Cache, Storage;
  18. use Carbon\Carbon;
  19. use Illuminate\Http\Request;
  20. use Illuminate\Support\Facades\Redis;
  21. use App\Http\Controllers\Admin\{
  22. AdminDirectoryController,
  23. AdminDiscoverController,
  24. AdminHashtagsController,
  25. AdminInstanceController,
  26. AdminReportController,
  27. // AdminGroupsController,
  28. AdminMediaController,
  29. AdminSettingsController,
  30. // AdminStorageController,
  31. AdminSupportController,
  32. AdminUserController
  33. };
  34. use Illuminate\Validation\Rule;
  35. use App\Services\AdminStatsService;
  36. use App\Services\AccountService;
  37. use App\Services\StatusService;
  38. use App\Services\StoryService;
  39. use App\Models\CustomEmoji;
  40. class AdminController extends Controller
  41. {
  42. use AdminReportController,
  43. AdminDirectoryController,
  44. AdminDiscoverController,
  45. AdminHashtagsController,
  46. // AdminGroupsController,
  47. AdminMediaController,
  48. AdminSettingsController,
  49. AdminInstanceController,
  50. // AdminStorageController,
  51. AdminUserController;
  52. public function __construct()
  53. {
  54. $this->middleware('admin');
  55. $this->middleware('dangerzone');
  56. $this->middleware('twofactor');
  57. }
  58. public function home()
  59. {
  60. return view('admin.home');
  61. }
  62. public function stats()
  63. {
  64. $data = AdminStatsService::get();
  65. return view('admin.stats', compact('data'));
  66. }
  67. public function getStats()
  68. {
  69. return AdminStatsService::summary();
  70. }
  71. public function getAccounts()
  72. {
  73. $users = User::orderByDesc('id')->cursorPaginate(10);
  74. $res = [
  75. "next_page_url" => $users->nextPageUrl(),
  76. "data" => $users->map(function($user) {
  77. $account = AccountService::get($user->profile_id, true);
  78. if(!$account) {
  79. return [
  80. "id" => $user->profile_id,
  81. "username" => $user->username,
  82. "status" => "deleted",
  83. "avatar" => "/storage/avatars/default.jpg",
  84. "created_at" => $user->created_at
  85. ];
  86. }
  87. $account['user_id'] = $user->id;
  88. return $account;
  89. })
  90. ->filter(function($user) {
  91. return $user;
  92. })
  93. ];
  94. return $res;
  95. }
  96. public function getPosts()
  97. {
  98. $posts = DB::table('statuses')
  99. ->orderByDesc('id')
  100. ->cursorPaginate(10);
  101. $res = [
  102. "next_page_url" => $posts->nextPageUrl(),
  103. "data" => $posts->map(function($post) {
  104. $status = StatusService::get($post->id, false);
  105. if(!$status) {
  106. return ["id" => $post->id, "created_at" => $post->created_at];
  107. }
  108. return $status;
  109. })
  110. ];
  111. return $res;
  112. }
  113. public function getInstances()
  114. {
  115. return Instance::orderByDesc('id')->cursorPaginate(10);
  116. }
  117. public function statuses(Request $request)
  118. {
  119. $statuses = Status::orderBy('id', 'desc')->cursorPaginate(10);
  120. $data = $statuses->map(function($status) {
  121. return StatusService::get($status->id, false);
  122. })
  123. ->filter(function($s) {
  124. return $s;
  125. })
  126. ->toArray();
  127. return view('admin.statuses.home', compact('statuses', 'data'));
  128. }
  129. public function showStatus(Request $request, $id)
  130. {
  131. $status = Status::findOrFail($id);
  132. return view('admin.statuses.show', compact('status'));
  133. }
  134. public function profiles(Request $request)
  135. {
  136. $this->validate($request, [
  137. 'search' => 'nullable|string|max:250',
  138. 'filter' => [
  139. 'nullable',
  140. 'string',
  141. Rule::in(['all', 'local', 'remote'])
  142. ]
  143. ]);
  144. $search = $request->input('search');
  145. $filter = $request->input('filter');
  146. $limit = 12;
  147. $profiles = Profile::select('id','username')
  148. ->whereNull('status')
  149. ->when($search, function($q, $search) {
  150. return $q->where('username', 'like', "%$search%");
  151. })->when($filter, function($q, $filter) {
  152. if($filter == 'local') {
  153. return $q->whereNull('domain');
  154. }
  155. if($filter == 'remote') {
  156. return $q->whereNotNull('domain');
  157. }
  158. return $q;
  159. })->orderByDesc('id')
  160. ->simplePaginate($limit);
  161. return view('admin.profiles.home', compact('profiles'));
  162. }
  163. public function profileShow(Request $request, $id)
  164. {
  165. $profile = Profile::findOrFail($id);
  166. $user = $profile->user;
  167. return view('admin.profiles.edit', compact('profile', 'user'));
  168. }
  169. public function appsHome(Request $request)
  170. {
  171. $filter = $request->input('filter');
  172. if($filter == 'revoked') {
  173. $apps = OauthClient::with('user')
  174. ->whereNotNull('user_id')
  175. ->whereRevoked(true)
  176. ->orderByDesc('id')
  177. ->paginate(10);
  178. } else {
  179. $apps = OauthClient::with('user')
  180. ->whereNotNull('user_id')
  181. ->orderByDesc('id')
  182. ->paginate(10);
  183. }
  184. return view('admin.apps.home', compact('apps'));
  185. }
  186. public function messagesHome(Request $request)
  187. {
  188. $messages = Contact::orderByDesc('id')->paginate(10);
  189. return view('admin.messages.home', compact('messages'));
  190. }
  191. public function messagesShow(Request $request, $id)
  192. {
  193. $message = Contact::findOrFail($id);
  194. return view('admin.messages.show', compact('message'));
  195. }
  196. public function messagesMarkRead(Request $request)
  197. {
  198. $this->validate($request, [
  199. 'id' => 'required|integer|min:1'
  200. ]);
  201. $id = $request->input('id');
  202. $message = Contact::findOrFail($id);
  203. if($message->read_at) {
  204. return;
  205. }
  206. $message->read_at = now();
  207. $message->save();
  208. return;
  209. }
  210. public function newsroomHome(Request $request)
  211. {
  212. $newsroom = Newsroom::latest()->paginate(10);
  213. return view('admin.newsroom.home', compact('newsroom'));
  214. }
  215. public function newsroomCreate(Request $request)
  216. {
  217. return view('admin.newsroom.create');
  218. }
  219. public function newsroomEdit(Request $request, $id)
  220. {
  221. $news = Newsroom::findOrFail($id);
  222. return view('admin.newsroom.edit', compact('news'));
  223. }
  224. public function newsroomDelete(Request $request, $id)
  225. {
  226. $news = Newsroom::findOrFail($id);
  227. $news->delete();
  228. return redirect('/i/admin/newsroom');
  229. }
  230. public function newsroomUpdate(Request $request, $id)
  231. {
  232. $this->validate($request, [
  233. 'title' => 'required|string|min:1|max:100',
  234. 'summary' => 'nullable|string|max:200',
  235. 'body' => 'nullable|string'
  236. ]);
  237. $changed = false;
  238. $changedFields = [];
  239. $slug = str_slug($request->input('title'));
  240. if(Newsroom::whereSlug($slug)->exists()) {
  241. $slug = $slug . '-' . str_random(4);
  242. }
  243. $news = Newsroom::findOrFail($id);
  244. $fields = [
  245. 'title' => 'string',
  246. 'summary' => 'string',
  247. 'body' => 'string',
  248. 'category' => 'string',
  249. 'show_timeline' => 'boolean',
  250. 'auth_only' => 'boolean',
  251. 'show_link' => 'boolean',
  252. 'force_modal' => 'boolean',
  253. 'published' => 'published'
  254. ];
  255. foreach($fields as $field => $type) {
  256. switch ($type) {
  257. case 'string':
  258. if($request->{$field} != $news->{$field}) {
  259. if($field == 'title') {
  260. $news->slug = $slug;
  261. }
  262. $news->{$field} = $request->{$field};
  263. $changed = true;
  264. array_push($changedFields, $field);
  265. }
  266. break;
  267. case 'boolean':
  268. $state = $request->{$field} == 'on' ? true : false;
  269. if($state != $news->{$field}) {
  270. $news->{$field} = $state;
  271. $changed = true;
  272. array_push($changedFields, $field);
  273. }
  274. break;
  275. case 'published':
  276. $state = $request->{$field} == 'on' ? true : false;
  277. $published = $news->published_at != null;
  278. if($state != $published) {
  279. $news->published_at = $state ? now() : null;
  280. $changed = true;
  281. array_push($changedFields, $field);
  282. }
  283. break;
  284. }
  285. }
  286. if($changed) {
  287. $news->save();
  288. }
  289. $redirect = $news->published_at ? $news->permalink() : $news->editUrl();
  290. return redirect($redirect);
  291. }
  292. public function newsroomStore(Request $request)
  293. {
  294. $this->validate($request, [
  295. 'title' => 'required|string|min:1|max:100',
  296. 'summary' => 'nullable|string|max:200',
  297. 'body' => 'nullable|string'
  298. ]);
  299. $changed = false;
  300. $changedFields = [];
  301. $slug = str_slug($request->input('title'));
  302. if(Newsroom::whereSlug($slug)->exists()) {
  303. $slug = $slug . '-' . str_random(4);
  304. }
  305. $news = new Newsroom();
  306. $fields = [
  307. 'title' => 'string',
  308. 'summary' => 'string',
  309. 'body' => 'string',
  310. 'category' => 'string',
  311. 'show_timeline' => 'boolean',
  312. 'auth_only' => 'boolean',
  313. 'show_link' => 'boolean',
  314. 'force_modal' => 'boolean',
  315. 'published' => 'published'
  316. ];
  317. foreach($fields as $field => $type) {
  318. switch ($type) {
  319. case 'string':
  320. if($request->{$field} != $news->{$field}) {
  321. if($field == 'title') {
  322. $news->slug = $slug;
  323. }
  324. $news->{$field} = $request->{$field};
  325. $changed = true;
  326. array_push($changedFields, $field);
  327. }
  328. break;
  329. case 'boolean':
  330. $state = $request->{$field} == 'on' ? true : false;
  331. if($state != $news->{$field}) {
  332. $news->{$field} = $state;
  333. $changed = true;
  334. array_push($changedFields, $field);
  335. }
  336. break;
  337. case 'published':
  338. $state = $request->{$field} == 'on' ? true : false;
  339. $published = $news->published_at != null;
  340. if($state != $published) {
  341. $news->published_at = $state ? now() : null;
  342. $changed = true;
  343. array_push($changedFields, $field);
  344. }
  345. break;
  346. }
  347. }
  348. if($changed) {
  349. $news->save();
  350. }
  351. $redirect = $news->published_at ? $news->permalink() : $news->editUrl();
  352. return redirect($redirect);
  353. }
  354. public function diagnosticsHome(Request $request)
  355. {
  356. return view('admin.diagnostics.home');
  357. }
  358. public function diagnosticsDecrypt(Request $request)
  359. {
  360. $this->validate($request, [
  361. 'payload' => 'required'
  362. ]);
  363. $key = 'exception_report:';
  364. $decrypted = decrypt($request->input('payload'));
  365. if(!starts_with($decrypted, $key)) {
  366. abort(403, 'Can only decrypt error diagnostics');
  367. }
  368. $res = [
  369. 'decrypted' => substr($decrypted, strlen($key))
  370. ];
  371. return response()->json($res);
  372. }
  373. public function stories(Request $request)
  374. {
  375. $stories = Story::with('profile')->latest()->paginate(10);
  376. $stats = StoryService::adminStats();
  377. return view('admin.stories.home', compact('stories', 'stats'));
  378. }
  379. public function customEmojiHome(Request $request)
  380. {
  381. if(!config('federation.custom_emoji.enabled')) {
  382. return view('admin.custom-emoji.not-enabled');
  383. }
  384. $this->validate($request, [
  385. 'sort' => 'sometimes|in:all,local,remote,duplicates,disabled,search'
  386. ]);
  387. if($request->has('cc')) {
  388. Cache::forget('pf:admin:custom_emoji:stats');
  389. Cache::forget('pf:custom_emoji');
  390. return redirect(route('admin.custom-emoji'));
  391. }
  392. $sort = $request->input('sort') ?? 'all';
  393. if($sort == 'search' && empty($request->input('q'))) {
  394. return redirect(route('admin.custom-emoji'));
  395. }
  396. $pg = config('database.default') == 'pgsql';
  397. $emojis = CustomEmoji::when($sort, function($query, $sort) use($request, $pg) {
  398. if($sort == 'all') {
  399. if($pg) {
  400. return $query->latest();
  401. } else {
  402. return $query->groupBy('shortcode')->latest();
  403. }
  404. } else if($sort == 'local') {
  405. return $query->latest()->where('domain', '=', config('pixelfed.domain.app'));
  406. } else if($sort == 'remote') {
  407. return $query->latest()->where('domain', '!=', config('pixelfed.domain.app'));
  408. } else if($sort == 'duplicates') {
  409. return $query->latest()->groupBy('shortcode')->havingRaw('count(*) > 1');
  410. } else if($sort == 'disabled') {
  411. return $query->latest()->whereDisabled(true);
  412. } else if($sort == 'search') {
  413. $q = $query
  414. ->latest()
  415. ->where('shortcode', 'like', '%' . $request->input('q') . '%')
  416. ->orWhere('domain', 'like', '%' . $request->input('q') . '%');
  417. if(!$request->has('dups')) {
  418. $q = $q->groupBy('shortcode');
  419. }
  420. return $q;
  421. }
  422. })
  423. ->simplePaginate(10)
  424. ->withQueryString();
  425. $stats = Cache::remember('pf:admin:custom_emoji:stats', 43200, function() use($pg) {
  426. $res = [
  427. 'total' => CustomEmoji::count(),
  428. 'active' => CustomEmoji::whereDisabled(false)->count(),
  429. 'remote' => CustomEmoji::where('domain', '!=', config('pixelfed.domain.app'))->count(),
  430. ];
  431. if($pg) {
  432. $res['duplicate'] = CustomEmoji::select('shortcode')->groupBy('shortcode')->havingRaw('count(*) > 1')->count();
  433. } else {
  434. $res['duplicate'] = CustomEmoji::groupBy('shortcode')->havingRaw('count(*) > 1')->count();
  435. }
  436. return $res;
  437. });
  438. return view('admin.custom-emoji.home', compact('emojis', 'sort', 'stats'));
  439. }
  440. public function customEmojiToggleActive(Request $request, $id)
  441. {
  442. abort_unless(config('federation.custom_emoji.enabled'), 404);
  443. $emoji = CustomEmoji::findOrFail($id);
  444. $emoji->disabled = !$emoji->disabled;
  445. $emoji->save();
  446. $key = CustomEmoji::CACHE_KEY . str_replace(':', '', $emoji->shortcode);
  447. Cache::forget($key);
  448. return redirect()->back();
  449. }
  450. public function customEmojiAdd(Request $request)
  451. {
  452. abort_unless(config('federation.custom_emoji.enabled'), 404);
  453. return view('admin.custom-emoji.add');
  454. }
  455. public function customEmojiStore(Request $request)
  456. {
  457. abort_unless(config('federation.custom_emoji.enabled'), 404);
  458. $this->validate($request, [
  459. 'shortcode' => [
  460. 'required',
  461. 'min:3',
  462. 'max:80',
  463. 'starts_with::',
  464. 'ends_with::',
  465. Rule::unique('custom_emoji')->where(function ($query) use($request) {
  466. return $query->whereDomain(config('pixelfed.domain.app'))
  467. ->whereShortcode($request->input('shortcode'));
  468. })
  469. ],
  470. 'emoji' => 'required|file|mimes:jpg,png|max:' . (config('federation.custom_emoji.max_size') / 1000)
  471. ]);
  472. $emoji = new CustomEmoji;
  473. $emoji->shortcode = $request->input('shortcode');
  474. $emoji->domain = config('pixelfed.domain.app');
  475. $emoji->save();
  476. $fileName = $emoji->id . '.' . $request->emoji->extension();
  477. $request->emoji->storePubliclyAs('public/emoji', $fileName);
  478. $emoji->media_path = 'emoji/' . $fileName;
  479. $emoji->save();
  480. Cache::forget('pf:custom_emoji');
  481. return redirect(route('admin.custom-emoji'));
  482. }
  483. public function customEmojiDelete(Request $request, $id)
  484. {
  485. abort_unless(config('federation.custom_emoji.enabled'), 404);
  486. $emoji = CustomEmoji::findOrFail($id);
  487. Storage::delete("public/{$emoji->media_path}");
  488. Cache::forget('pf:custom_emoji');
  489. $emoji->delete();
  490. return redirect(route('admin.custom-emoji'));
  491. }
  492. public function customEmojiShowDuplicates(Request $request, $id)
  493. {
  494. abort_unless(config('federation.custom_emoji.enabled'), 404);
  495. $emoji = CustomEmoji::orderBy('id')->whereDisabled(false)->whereShortcode($id)->firstOrFail();
  496. $emojis = CustomEmoji::whereShortcode($id)->where('id', '!=', $emoji->id)->cursorPaginate(10);
  497. return view('admin.custom-emoji.duplicates', compact('emoji', 'emojis'));
  498. }
  499. }