ApiV1Dot1Controller.php 45 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263
  1. <?php
  2. namespace App\Http\Controllers\Api;
  3. use App\AccountLog;
  4. use App\EmailVerification;
  5. use App\Http\Controllers\Controller;
  6. use App\Http\Controllers\StatusController;
  7. use App\Http\Resources\StatusStateless;
  8. use App\Jobs\ImageOptimizePipeline\ImageOptimize;
  9. use App\Jobs\ReportPipeline\ReportNotifyAdminViaEmail;
  10. use App\Jobs\StatusPipeline\NewStatusPipeline;
  11. use App\Jobs\StatusPipeline\RemoteStatusDelete;
  12. use App\Jobs\StatusPipeline\StatusDelete;
  13. use App\Jobs\VideoPipeline\VideoThumbnail;
  14. use App\Mail\ConfirmAppEmail;
  15. use App\Mail\PasswordChange;
  16. use App\Media;
  17. use App\Place;
  18. use App\Profile;
  19. use App\Report;
  20. use App\Services\AccountService;
  21. use App\Services\BouncerService;
  22. use App\Services\EmailService;
  23. use App\Services\FollowerService;
  24. use App\Services\MediaBlocklistService;
  25. use App\Services\MediaPathService;
  26. use App\Services\NetworkTimelineService;
  27. use App\Services\NotificationAppGatewayService;
  28. use App\Services\ProfileStatusService;
  29. use App\Services\PublicTimelineService;
  30. use App\Services\StatusService;
  31. use App\Services\UserStorageService;
  32. use App\Status;
  33. use App\StatusArchived;
  34. use App\User;
  35. use App\UserSetting;
  36. use App\Util\Lexer\Autolink;
  37. use App\Util\Lexer\RestrictedNames;
  38. use Cache;
  39. use DB;
  40. use Illuminate\Http\Request;
  41. use Illuminate\Support\Facades\Hash;
  42. use Illuminate\Support\Facades\RateLimiter;
  43. use Illuminate\Support\Str;
  44. use Jenssegers\Agent\Agent;
  45. use League\Fractal;
  46. use League\Fractal\Serializer\ArraySerializer;
  47. use Mail;
  48. use NotificationChannels\Expo\ExpoPushToken;
  49. class ApiV1Dot1Controller extends Controller
  50. {
  51. protected $fractal;
  52. public function __construct()
  53. {
  54. $this->fractal = new Fractal\Manager;
  55. $this->fractal->setSerializer(new ArraySerializer);
  56. }
  57. public function json($res, $code = 200, $headers = [])
  58. {
  59. return response()->json($res, $code, $headers, JSON_UNESCAPED_SLASHES);
  60. }
  61. public function error($msg, $code = 400, $extra = [], $headers = [])
  62. {
  63. $res = [
  64. 'msg' => $msg,
  65. 'code' => $code,
  66. ];
  67. return response()->json(array_merge($res, $extra), $code, $headers, JSON_UNESCAPED_SLASHES);
  68. }
  69. public function report(Request $request)
  70. {
  71. abort_if(! $request->user() || ! $request->user()->token(), 403);
  72. abort_unless($request->user()->tokenCan('write'), 403);
  73. $user = $request->user();
  74. abort_if($user->status != null, 403);
  75. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  76. abort_if(BouncerService::checkIp($request->ip()), 404);
  77. }
  78. $report_type = $request->input('report_type');
  79. $object_id = $request->input('object_id');
  80. $object_type = $request->input('object_type');
  81. $types = [
  82. 'spam',
  83. 'sensitive',
  84. 'abusive',
  85. 'underage',
  86. 'violence',
  87. 'copyright',
  88. 'impersonation',
  89. 'scam',
  90. 'terrorism',
  91. ];
  92. if (! $report_type || ! $object_id || ! $object_type) {
  93. return $this->error('Invalid or missing parameters', 400, ['error_code' => 'ERROR_INVALID_PARAMS']);
  94. }
  95. if (! in_array($report_type, $types)) {
  96. return $this->error('Invalid report type', 400, ['error_code' => 'ERROR_TYPE_INVALID']);
  97. }
  98. if ($object_type === 'user' && $object_id == $user->profile_id) {
  99. return $this->error('Cannot self report', 400, ['error_code' => 'ERROR_NO_SELF_REPORTS']);
  100. }
  101. $rpid = null;
  102. switch ($object_type) {
  103. case 'post':
  104. $object = Status::find($object_id);
  105. if (! $object) {
  106. return $this->error('Invalid object id', 400, ['error_code' => 'ERROR_INVALID_OBJECT_ID']);
  107. }
  108. $object_type = 'App\Status';
  109. $exists = Report::whereUserId($user->id)
  110. ->whereObjectId($object->id)
  111. ->whereObjectType('App\Status')
  112. ->count();
  113. $rpid = $object->profile_id;
  114. break;
  115. case 'user':
  116. $object = Profile::find($object_id);
  117. if (! $object) {
  118. return $this->error('Invalid object id', 400, ['error_code' => 'ERROR_INVALID_OBJECT_ID']);
  119. }
  120. $object_type = 'App\Profile';
  121. $exists = Report::whereUserId($user->id)
  122. ->whereObjectId($object->id)
  123. ->whereObjectType('App\Profile')
  124. ->count();
  125. $rpid = $object->id;
  126. break;
  127. default:
  128. return $this->error('Invalid report type', 400, ['error_code' => 'ERROR_REPORT_OBJECT_TYPE_INVALID']);
  129. break;
  130. }
  131. if ($exists !== 0) {
  132. return $this->error('Duplicate report', 400, ['error_code' => 'ERROR_REPORT_DUPLICATE']);
  133. }
  134. if ($object->profile_id == $user->profile_id) {
  135. return $this->error('Cannot self report', 400, ['error_code' => 'ERROR_NO_SELF_REPORTS']);
  136. }
  137. $report = new Report;
  138. $report->profile_id = $user->profile_id;
  139. $report->user_id = $user->id;
  140. $report->object_id = $object->id;
  141. $report->object_type = $object_type;
  142. $report->reported_profile_id = $rpid;
  143. $report->type = $report_type;
  144. $report->save();
  145. if (config('instance.reports.email.enabled')) {
  146. ReportNotifyAdminViaEmail::dispatch($report)->onQueue('default');
  147. }
  148. $res = [
  149. 'msg' => 'Successfully sent report',
  150. 'code' => 200,
  151. ];
  152. return $this->json($res);
  153. }
  154. /**
  155. * DELETE /api/v1.1/accounts/avatar
  156. *
  157. * @return \App\Transformer\Api\AccountTransformer
  158. */
  159. public function deleteAvatar(Request $request)
  160. {
  161. abort_if(! $request->user() || ! $request->user()->token(), 403);
  162. abort_unless($request->user()->tokenCan('write'), 403);
  163. $user = $request->user();
  164. abort_if($user->status != null, 403);
  165. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  166. abort_if(BouncerService::checkIp($request->ip()), 404);
  167. }
  168. $avatar = $user->profile->avatar;
  169. if ($avatar->media_path == 'public/avatars/default.png' ||
  170. $avatar->media_path == 'public/avatars/default.jpg'
  171. ) {
  172. return AccountService::get($user->profile_id);
  173. }
  174. if (is_file(storage_path('app/'.$avatar->media_path))) {
  175. @unlink(storage_path('app/'.$avatar->media_path));
  176. }
  177. $avatar->media_path = 'public/avatars/default.jpg';
  178. $avatar->change_count = $avatar->change_count + 1;
  179. $avatar->save();
  180. Cache::forget('avatar:'.$user->profile_id);
  181. Cache::forget("avatar:{$user->profile_id}");
  182. Cache::forget('user:account:id:'.$user->id);
  183. AccountService::del($user->profile_id);
  184. return AccountService::get($user->profile_id);
  185. }
  186. /**
  187. * GET /api/v1.1/accounts/{id}/posts
  188. *
  189. * @return \App\Transformer\Api\StatusTransformer
  190. */
  191. public function accountPosts(Request $request, $id)
  192. {
  193. abort_if(! $request->user() || ! $request->user()->token(), 403);
  194. abort_unless($request->user()->tokenCan('read'), 403);
  195. $user = $request->user();
  196. abort_if($user->status != null, 403);
  197. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  198. abort_if(BouncerService::checkIp($request->ip()), 404);
  199. }
  200. $account = AccountService::get($id);
  201. if (! $account || $account['username'] !== $request->input('username')) {
  202. return $this->json([]);
  203. }
  204. $posts = ProfileStatusService::get($id);
  205. if (! $posts) {
  206. return $this->json([]);
  207. }
  208. $res = collect($posts)
  209. ->map(function ($id) {
  210. return StatusService::get($id);
  211. })
  212. ->filter(function ($post) {
  213. return $post && isset($post['account']);
  214. })
  215. ->toArray();
  216. return $this->json($res);
  217. }
  218. /**
  219. * POST /api/v1.1/accounts/change-password
  220. *
  221. * @return \App\Transformer\Api\AccountTransformer
  222. */
  223. public function accountChangePassword(Request $request)
  224. {
  225. abort_if(! $request->user() || ! $request->user()->token(), 403);
  226. abort_unless($request->user()->tokenCan('write'), 403);
  227. $user = $request->user();
  228. abort_if($user->status != null, 403);
  229. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  230. abort_if(BouncerService::checkIp($request->ip()), 404);
  231. }
  232. $this->validate($request, [
  233. 'current_password' => 'bail|required|current_password',
  234. 'new_password' => 'required|min:'.config('pixelfed.min_password_length', 8),
  235. 'confirm_password' => 'required|same:new_password',
  236. ], [
  237. 'current_password' => 'The password you entered is incorrect',
  238. ]);
  239. $user->password = bcrypt($request->input('new_password'));
  240. $user->save();
  241. $log = new AccountLog;
  242. $log->user_id = $user->id;
  243. $log->item_id = $user->id;
  244. $log->item_type = 'App\User';
  245. $log->action = 'account.edit.password';
  246. $log->message = 'Password changed';
  247. $log->link = null;
  248. $log->ip_address = $request->ip();
  249. $log->user_agent = $request->userAgent();
  250. $log->save();
  251. Mail::to($request->user())->send(new PasswordChange($user));
  252. return $this->json(AccountService::get($user->profile_id));
  253. }
  254. /**
  255. * GET /api/v1.1/accounts/login-activity
  256. *
  257. * @return array
  258. */
  259. public function accountLoginActivity(Request $request)
  260. {
  261. abort_if(! $request->user() || ! $request->user()->token(), 403);
  262. abort_unless($request->user()->tokenCan('read'), 403);
  263. $user = $request->user();
  264. abort_if($user->status != null, 403);
  265. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  266. abort_if(BouncerService::checkIp($request->ip()), 404);
  267. }
  268. $agent = new Agent;
  269. $currentIp = $request->ip();
  270. $activity = AccountLog::whereUserId($user->id)
  271. ->whereAction('auth.login')
  272. ->orderBy('created_at', 'desc')
  273. ->groupBy('ip_address')
  274. ->limit(10)
  275. ->get()
  276. ->map(function ($item) use ($agent, $currentIp) {
  277. $agent->setUserAgent($item->user_agent);
  278. return [
  279. 'id' => $item->id,
  280. 'action' => $item->action,
  281. 'ip' => $item->ip_address,
  282. 'ip_current' => $item->ip_address === $currentIp,
  283. 'is_mobile' => $agent->isMobile(),
  284. 'device' => $agent->device(),
  285. 'browser' => $agent->browser(),
  286. 'platform' => $agent->platform(),
  287. 'created_at' => $item->created_at->format('c'),
  288. ];
  289. });
  290. return $this->json($activity);
  291. }
  292. /**
  293. * GET /api/v1.1/accounts/two-factor
  294. *
  295. * @return array
  296. */
  297. public function accountTwoFactor(Request $request)
  298. {
  299. abort_if(! $request->user() || ! $request->user()->token(), 403);
  300. abort_unless($request->user()->tokenCan('read'), 403);
  301. $user = $request->user();
  302. abort_if($user->status != null, 403);
  303. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  304. abort_if(BouncerService::checkIp($request->ip()), 404);
  305. }
  306. $res = [
  307. 'active' => (bool) $user->{'2fa_enabled'},
  308. 'setup_at' => $user->{'2fa_setup_at'},
  309. ];
  310. return $this->json($res);
  311. }
  312. /**
  313. * GET /api/v1.1/accounts/emails-from-pixelfed
  314. *
  315. * @return array
  316. */
  317. public function accountEmailsFromPixelfed(Request $request)
  318. {
  319. abort_if(! $request->user() || ! $request->user()->token(), 403);
  320. abort_unless($request->user()->tokenCan('read'), 403);
  321. $user = $request->user();
  322. abort_if($user->status != null, 403);
  323. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  324. abort_if(BouncerService::checkIp($request->ip()), 404);
  325. }
  326. $from = config('mail.from.address');
  327. $emailVerifications = EmailVerification::whereUserId($user->id)
  328. ->orderByDesc('id')
  329. ->where('created_at', '>', now()->subDays(14))
  330. ->limit(10)
  331. ->get()
  332. ->map(function ($mail) use ($user, $from) {
  333. return [
  334. 'type' => 'Email Verification',
  335. 'subject' => 'Confirm Email',
  336. 'to_address' => $user->email,
  337. 'from_address' => $from,
  338. 'created_at' => str_replace('@', 'at', $mail->created_at->format('M j, Y @ g:i:s A')),
  339. ];
  340. })
  341. ->toArray();
  342. $passwordResets = DB::table('password_resets')
  343. ->whereEmail($user->email)
  344. ->where('created_at', '>', now()->subDays(14))
  345. ->orderByDesc('created_at')
  346. ->limit(10)
  347. ->get()
  348. ->map(function ($mail) use ($user, $from) {
  349. return [
  350. 'type' => 'Password Reset',
  351. 'subject' => 'Reset Password Notification',
  352. 'to_address' => $user->email,
  353. 'from_address' => $from,
  354. 'created_at' => str_replace('@', 'at', now()->parse($mail->created_at)->format('M j, Y @ g:i:s A')),
  355. ];
  356. })
  357. ->toArray();
  358. $passwordChanges = AccountLog::whereUserId($user->id)
  359. ->whereAction('account.edit.password')
  360. ->where('created_at', '>', now()->subDays(14))
  361. ->orderByDesc('created_at')
  362. ->limit(10)
  363. ->get()
  364. ->map(function ($mail) use ($user, $from) {
  365. return [
  366. 'type' => 'Password Change',
  367. 'subject' => 'Password Change',
  368. 'to_address' => $user->email,
  369. 'from_address' => $from,
  370. 'created_at' => str_replace('@', 'at', now()->parse($mail->created_at)->format('M j, Y @ g:i:s A')),
  371. ];
  372. })
  373. ->toArray();
  374. $res = collect([])
  375. ->merge($emailVerifications)
  376. ->merge($passwordResets)
  377. ->merge($passwordChanges)
  378. ->sortByDesc('created_at')
  379. ->values();
  380. return $this->json($res);
  381. }
  382. /**
  383. * GET /api/v1.1/accounts/apps-and-applications
  384. *
  385. * @return array
  386. */
  387. public function accountApps(Request $request)
  388. {
  389. abort_if(! $request->user() || ! $request->user()->token(), 403);
  390. abort_unless($request->user()->tokenCan('read'), 403);
  391. $user = $request->user();
  392. abort_if($user->status != null, 403);
  393. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  394. abort_if(BouncerService::checkIp($request->ip()), 404);
  395. }
  396. $res = $user->tokens->sortByDesc('created_at')->take(10)->map(function ($token, $key) use ($request) {
  397. return [
  398. 'id' => $token->id,
  399. 'current_session' => $request->user()->token()->id == $token->id,
  400. 'name' => $token->client->name,
  401. 'scopes' => $token->scopes,
  402. 'revoked' => $token->revoked,
  403. 'created_at' => str_replace('@', 'at', now()->parse($token->created_at)->format('M j, Y @ g:i:s A')),
  404. 'expires_at' => str_replace('@', 'at', now()->parse($token->expires_at)->format('M j, Y @ g:i:s A')),
  405. ];
  406. });
  407. return $this->json($res);
  408. }
  409. public function inAppRegistrationPreFlightCheck(Request $request)
  410. {
  411. return [
  412. 'open' => (bool) config_cache('pixelfed.open_registration'),
  413. 'iara' => (bool) config_cache('pixelfed.allow_app_registration'),
  414. ];
  415. }
  416. public function inAppRegistration(Request $request)
  417. {
  418. abort_if($request->user(), 404);
  419. abort_unless((bool) config_cache('pixelfed.open_registration'), 404);
  420. abort_unless((bool) config_cache('pixelfed.allow_app_registration'), 404);
  421. abort_unless($request->hasHeader('X-PIXELFED-APP'), 403);
  422. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  423. abort_if(BouncerService::checkIp($request->ip()), 404);
  424. }
  425. $rl = RateLimiter::attempt('pf:apiv1.1:iar:'.$request->ip(), config('pixelfed.app_registration_rate_limit_attempts', 3), function () {}, config('pixelfed.app_registration_rate_limit_decay', 1800));
  426. abort_if(! $rl, 400, 'Too many requests');
  427. $this->validate($request, [
  428. 'email' => [
  429. 'required',
  430. 'string',
  431. 'email',
  432. 'max:255',
  433. 'unique:users',
  434. function ($attribute, $value, $fail) {
  435. $banned = EmailService::isBanned($value);
  436. if ($banned) {
  437. return $fail('Email is invalid.');
  438. }
  439. },
  440. ],
  441. 'username' => [
  442. 'required',
  443. 'min:2',
  444. 'max:15',
  445. 'unique:users',
  446. function ($attribute, $value, $fail) {
  447. $dash = substr_count($value, '-');
  448. $underscore = substr_count($value, '_');
  449. $period = substr_count($value, '.');
  450. if (ends_with($value, ['.php', '.js', '.css'])) {
  451. return $fail('Username is invalid.');
  452. }
  453. if (($dash + $underscore + $period) > 1) {
  454. return $fail('Username is invalid. Can only contain one dash (-), period (.) or underscore (_).');
  455. }
  456. if (! ctype_alnum($value[0])) {
  457. return $fail('Username is invalid. Must start with a letter or number.');
  458. }
  459. if (! ctype_alnum($value[strlen($value) - 1])) {
  460. return $fail('Username is invalid. Must end with a letter or number.');
  461. }
  462. $val = str_replace(['_', '.', '-'], '', $value);
  463. if (! ctype_alnum($val)) {
  464. return $fail('Username is invalid. Username must be alpha-numeric and may contain dashes (-), periods (.) and underscores (_).');
  465. }
  466. $restricted = RestrictedNames::get();
  467. if (in_array(strtolower($value), array_map('strtolower', $restricted))) {
  468. return $fail('Username cannot be used.');
  469. }
  470. },
  471. ],
  472. 'password' => 'required|string|min:8',
  473. ]);
  474. $email = $request->input('email');
  475. $username = $request->input('username');
  476. $password = $request->input('password');
  477. if (config('database.default') == 'pgsql') {
  478. $username = strtolower($username);
  479. $email = strtolower($email);
  480. }
  481. $user = new User;
  482. $user->name = $username;
  483. $user->username = $username;
  484. $user->email = $email;
  485. $user->password = Hash::make($password);
  486. $user->register_source = 'app';
  487. $user->app_register_ip = $request->ip();
  488. $user->app_register_token = Str::random(40);
  489. $user->save();
  490. $rtoken = Str::random(64);
  491. $verify = new EmailVerification;
  492. $verify->user_id = $user->id;
  493. $verify->email = $user->email;
  494. $verify->user_token = $user->app_register_token;
  495. $verify->random_token = $rtoken;
  496. $verify->save();
  497. $params = http_build_query([
  498. 'ut' => $user->app_register_token,
  499. 'rt' => $rtoken,
  500. 'ea' => base64_encode($user->email),
  501. ]);
  502. $appUrl = url('/api/v1.1/auth/iarer?'.$params);
  503. Mail::to($user->email)->send(new ConfirmAppEmail($verify, $appUrl));
  504. return response()->json([
  505. 'success' => true,
  506. ]);
  507. }
  508. public function inAppRegistrationEmailRedirect(Request $request)
  509. {
  510. $this->validate($request, [
  511. 'ut' => 'required',
  512. 'rt' => 'required',
  513. 'ea' => 'required',
  514. ]);
  515. $ut = $request->input('ut');
  516. $rt = $request->input('rt');
  517. $ea = $request->input('ea');
  518. $params = http_build_query([
  519. 'ut' => $ut,
  520. 'rt' => $rt,
  521. 'domain' => config('pixelfed.domain.app'),
  522. 'ea' => $ea,
  523. ]);
  524. $url = 'pixelfed://confirm-account/'.$ut.'?'.$params;
  525. return redirect()->away($url);
  526. }
  527. public function inAppRegistrationConfirm(Request $request)
  528. {
  529. abort_if($request->user(), 404);
  530. abort_unless((bool) config_cache('pixelfed.open_registration'), 404);
  531. abort_unless((bool) config_cache('pixelfed.allow_app_registration'), 404);
  532. abort_unless($request->hasHeader('X-PIXELFED-APP'), 403);
  533. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  534. abort_if(BouncerService::checkIp($request->ip()), 404);
  535. }
  536. $rl = RateLimiter::attempt('pf:apiv1.1:iarc:'.$request->ip(), config('pixelfed.app_registration_confirm_rate_limit_attempts', 20), function () {}, config('pixelfed.app_registration_confirm_rate_limit_decay', 1800));
  537. abort_if(! $rl, 429, 'Too many requests');
  538. $request->validate([
  539. 'user_token' => 'required',
  540. 'random_token' => 'required',
  541. 'email' => 'required',
  542. ]);
  543. $verify = EmailVerification::whereEmail($request->input('email'))
  544. ->whereUserToken($request->input('user_token'))
  545. ->whereRandomToken($request->input('random_token'))
  546. ->first();
  547. if (! $verify) {
  548. return response()->json(['error' => 'Invalid tokens'], 403);
  549. }
  550. if ($verify->created_at->lt(now()->subHours(24))) {
  551. $verify->delete();
  552. return response()->json(['error' => 'Invalid tokens'], 403);
  553. }
  554. $user = User::findOrFail($verify->user_id);
  555. $user->email_verified_at = now();
  556. $user->last_active_at = now();
  557. $user->save();
  558. $token = $user->createToken('Pixelfed', ['read', 'write', 'follow', 'admin:read', 'admin:write', 'push']);
  559. return response()->json([
  560. 'access_token' => $token->accessToken,
  561. ]);
  562. }
  563. public function archive(Request $request, $id)
  564. {
  565. abort_if(! $request->user() || ! $request->user()->token(), 403);
  566. abort_unless($request->user()->tokenCan('write'), 403);
  567. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  568. abort_if(BouncerService::checkIp($request->ip()), 404);
  569. }
  570. $status = Status::whereNull('in_reply_to_id')
  571. ->whereNull('reblog_of_id')
  572. ->whereProfileId($request->user()->profile_id)
  573. ->findOrFail($id);
  574. if ($status->scope === 'archived') {
  575. return [200];
  576. }
  577. $archive = new StatusArchived;
  578. $archive->status_id = $status->id;
  579. $archive->profile_id = $status->profile_id;
  580. $archive->original_scope = $status->scope;
  581. $archive->save();
  582. $status->scope = 'archived';
  583. $status->visibility = 'draft';
  584. $status->save();
  585. StatusService::del($status->id, true);
  586. AccountService::syncPostCount($status->profile_id);
  587. return [200];
  588. }
  589. public function unarchive(Request $request, $id)
  590. {
  591. abort_if(! $request->user() || ! $request->user()->token(), 403);
  592. abort_unless($request->user()->tokenCan('write'), 403);
  593. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  594. abort_if(BouncerService::checkIp($request->ip()), 404);
  595. }
  596. $status = Status::whereNull('in_reply_to_id')
  597. ->whereNull('reblog_of_id')
  598. ->whereProfileId($request->user()->profile_id)
  599. ->findOrFail($id);
  600. if ($status->scope !== 'archived') {
  601. return [200];
  602. }
  603. $archive = StatusArchived::whereStatusId($status->id)
  604. ->whereProfileId($status->profile_id)
  605. ->firstOrFail();
  606. $status->scope = $archive->original_scope;
  607. $status->visibility = $archive->original_scope;
  608. $status->save();
  609. $archive->delete();
  610. StatusService::del($status->id, true);
  611. AccountService::syncPostCount($status->profile_id);
  612. return [200];
  613. }
  614. public function archivedPosts(Request $request)
  615. {
  616. abort_if(! $request->user() || ! $request->user()->token(), 403);
  617. abort_unless($request->user()->tokenCan('read'), 403);
  618. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  619. abort_if(BouncerService::checkIp($request->ip()), 404);
  620. }
  621. $statuses = Status::whereProfileId($request->user()->profile_id)
  622. ->whereScope('archived')
  623. ->orderByDesc('id')
  624. ->cursorPaginate(10);
  625. return StatusStateless::collection($statuses);
  626. }
  627. public function placesById(Request $request, $id, $slug)
  628. {
  629. abort_if(! $request->user() || ! $request->user()->token(), 403);
  630. abort_unless($request->user()->tokenCan('read'), 403);
  631. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  632. abort_if(BouncerService::checkIp($request->ip()), 404);
  633. }
  634. $place = Place::whereSlug($slug)->findOrFail($id);
  635. $posts = Cache::remember('pf-api:v1.1:places-by-id:'.$place->id, 3600, function () use ($place) {
  636. return Status::wherePlaceId($place->id)
  637. ->whereNull('uri')
  638. ->whereScope('public')
  639. ->orderByDesc('created_at')
  640. ->limit(60)
  641. ->pluck('id');
  642. });
  643. $posts = $posts->map(function ($id) {
  644. return StatusService::get($id);
  645. })
  646. ->filter()
  647. ->values();
  648. return [
  649. 'place' => [
  650. 'id' => $place->id,
  651. 'name' => $place->name,
  652. 'slug' => $place->slug,
  653. 'country' => $place->country,
  654. 'lat' => $place->lat,
  655. 'long' => $place->long,
  656. ],
  657. 'posts' => $posts];
  658. }
  659. public function moderatePost(Request $request, $id)
  660. {
  661. abort_if(! $request->user() || ! $request->user()->token(), 403);
  662. abort_if($request->user()->is_admin != true, 403);
  663. abort_unless($request->user()->tokenCan('admin:write'), 403);
  664. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  665. abort_if(BouncerService::checkIp($request->ip()), 404);
  666. }
  667. $this->validate($request, [
  668. 'action' => 'required|in:cw,mark-public,mark-unlisted,mark-private,mark-spammer,delete',
  669. ]);
  670. $action = $request->input('action');
  671. $status = Status::find($id);
  672. if (! $status) {
  673. return response()->json(['error' => 'Cannot find status'], 400);
  674. }
  675. if ($status->uri == null) {
  676. if ($status->profile->user && $status->profile->user->is_admin) {
  677. return response()->json(['error' => 'Cannot moderate admin accounts'], 400);
  678. }
  679. }
  680. if ($action == 'mark-spammer') {
  681. $status->profile->update([
  682. 'unlisted' => true,
  683. 'cw' => true,
  684. 'no_autolink' => true,
  685. ]);
  686. Status::whereProfileId($status->profile_id)
  687. ->get()
  688. ->each(function ($s) {
  689. if (in_array($s->scope, ['public', 'unlisted'])) {
  690. $s->scope = 'private';
  691. $s->visibility = 'private';
  692. }
  693. $s->is_nsfw = true;
  694. $s->save();
  695. StatusService::del($s->id, true);
  696. });
  697. Cache::forget('pf:bouncer_v0:exemption_by_pid:'.$status->profile_id);
  698. Cache::forget('pf:bouncer_v0:recent_by_pid:'.$status->profile_id);
  699. Cache::forget('admin-dash:reports:spam-count');
  700. } elseif ($action == 'cw') {
  701. $state = $status->is_nsfw;
  702. $status->is_nsfw = ! $state;
  703. $status->save();
  704. StatusService::del($status->id);
  705. } elseif ($action == 'mark-public') {
  706. $state = $status->scope;
  707. $status->scope = 'public';
  708. $status->visibility = 'public';
  709. $status->save();
  710. StatusService::del($status->id, true);
  711. if ($state !== 'public') {
  712. if ($status->uri) {
  713. if ($status->in_reply_to_id == null && $status->reblog_of_id == null) {
  714. NetworkTimelineService::add($status->id);
  715. }
  716. } else {
  717. if ($status->in_reply_to_id == null && $status->reblog_of_id == null) {
  718. PublicTimelineService::add($status->id);
  719. }
  720. }
  721. }
  722. } elseif ($action == 'mark-unlisted') {
  723. $state = $status->scope;
  724. $status->scope = 'unlisted';
  725. $status->visibility = 'unlisted';
  726. $status->save();
  727. StatusService::del($status->id);
  728. if ($state == 'public') {
  729. PublicTimelineService::del($status->id);
  730. NetworkTimelineService::del($status->id);
  731. }
  732. } elseif ($action == 'mark-private') {
  733. $state = $status->scope;
  734. $status->scope = 'private';
  735. $status->visibility = 'private';
  736. $status->save();
  737. StatusService::del($status->id);
  738. if ($state == 'public') {
  739. PublicTimelineService::del($status->id);
  740. NetworkTimelineService::del($status->id);
  741. }
  742. } elseif ($action == 'delete') {
  743. PublicTimelineService::del($status->id);
  744. NetworkTimelineService::del($status->id);
  745. Cache::forget('_api:statuses:recent_9:'.$status->profile_id);
  746. Cache::forget('profile:status_count:'.$status->profile_id);
  747. Cache::forget('profile:embed:'.$status->profile_id);
  748. StatusService::del($status->id, true);
  749. Cache::forget('profile:status_count:'.$status->profile_id);
  750. $status->uri ? RemoteStatusDelete::dispatch($status) : StatusDelete::dispatch($status);
  751. return [];
  752. }
  753. Cache::forget('_api:statuses:recent_9:'.$status->profile_id);
  754. return StatusService::get($status->id, false);
  755. }
  756. public function getWebSettings(Request $request)
  757. {
  758. abort_if(! $request->user() || ! $request->user()->token(), 403);
  759. abort_unless($request->user()->tokenCan('read'), 403);
  760. $uid = $request->user()->id;
  761. $settings = UserSetting::firstOrCreate([
  762. 'user_id' => $uid,
  763. ]);
  764. if (! $settings->other) {
  765. return [];
  766. }
  767. return $settings->other;
  768. }
  769. public function setWebSettings(Request $request)
  770. {
  771. abort_if(! $request->user() || ! $request->user()->token(), 403);
  772. abort_unless($request->user()->tokenCan('write'), 403);
  773. $this->validate($request, [
  774. 'field' => 'required|in:enable_reblogs,hide_reblog_banner',
  775. 'value' => 'required',
  776. ]);
  777. $field = $request->input('field');
  778. $value = $request->input('value');
  779. $settings = UserSetting::firstOrCreate([
  780. 'user_id' => $request->user()->id,
  781. ]);
  782. if (! $settings->other) {
  783. $other = [];
  784. } else {
  785. $other = $settings->other;
  786. }
  787. $other[$field] = $value;
  788. $settings->other = $other;
  789. $settings->save();
  790. return [200];
  791. }
  792. public function getMutualAccounts(Request $request, $id)
  793. {
  794. abort_if(! $request->user() || ! $request->user()->token(), 403);
  795. abort_unless($request->user()->tokenCan('follow'), 403);
  796. $account = AccountService::get($id, true);
  797. if (! $account || ! isset($account['id'])) {
  798. return [];
  799. }
  800. $res = collect(FollowerService::mutualAccounts($request->user()->profile_id, $id))
  801. ->map(function ($accountId) {
  802. return AccountService::get($accountId, true);
  803. })
  804. ->filter()
  805. ->take(24)
  806. ->values();
  807. return $this->json($res);
  808. }
  809. public function accountUsernameToId(Request $request, $username)
  810. {
  811. abort_if(! $request->user() || ! $request->user()->token() || ! $username, 403);
  812. abort_unless($request->user()->tokenCan('read'), 403);
  813. $username = trim($username);
  814. $rateLimiting = (bool) config_cache('api.rate-limits.v1Dot1.accounts.usernameToId.enabled');
  815. $ipRateLimiting = (bool) config_cache('api.rate-limits.v1Dot1.accounts.usernameToId.ip_enabled');
  816. if ($ipRateLimiting) {
  817. $userLimit = (int) config_cache('api.rate-limits.v1Dot1.accounts.usernameToId.ip_limit');
  818. $userDecay = (int) config_cache('api.rate-limits.v1Dot1.accounts.usernameToId.ip_decay');
  819. $userKey = 'pf:apiv1.1:acctU2ID:byIp:'.$request->ip();
  820. if (RateLimiter::tooManyAttempts($userKey, $userLimit)) {
  821. $limits = [
  822. 'X-Rate-Limit-Limit' => $userLimit,
  823. 'X-Rate-Limit-Remaining' => RateLimiter::remaining($userKey, $userLimit),
  824. 'X-Rate-Limit-Reset' => RateLimiter::availableIn($userKey),
  825. ];
  826. return $this->json(['error' => 'Too many attempts!'], 429, $limits);
  827. }
  828. RateLimiter::increment($userKey, $userDecay);
  829. $limits = [
  830. 'X-Rate-Limit-Limit' => $userLimit,
  831. 'X-Rate-Limit-Remaining' => RateLimiter::remaining($userKey, $userLimit),
  832. 'X-Rate-Limit-Reset' => RateLimiter::availableIn($userKey),
  833. ];
  834. }
  835. if ($rateLimiting) {
  836. $userLimit = (int) config_cache('api.rate-limits.v1Dot1.accounts.usernameToId.limit');
  837. $userDecay = (int) config_cache('api.rate-limits.v1Dot1.accounts.usernameToId.decay');
  838. $userKey = 'pf:apiv1.1:acctU2ID:byUid:'.$request->user()->id;
  839. if (RateLimiter::tooManyAttempts($userKey, $userLimit)) {
  840. $limits = [
  841. 'X-Rate-Limit-Limit' => $userLimit,
  842. 'X-Rate-Limit-Remaining' => RateLimiter::remaining($userKey, $userLimit),
  843. 'X-Rate-Limit-Reset' => RateLimiter::availableIn($userKey),
  844. ];
  845. return $this->json(['error' => 'Too many attempts!'], 429, $limits);
  846. }
  847. RateLimiter::increment($userKey, $userDecay);
  848. $limits = [
  849. 'X-Rate-Limit-Limit' => $userLimit,
  850. 'X-Rate-Limit-Remaining' => RateLimiter::remaining($userKey, $userLimit),
  851. 'X-Rate-Limit-Reset' => RateLimiter::availableIn($userKey),
  852. ];
  853. }
  854. if (str_ends_with($username, config_cache('pixelfed.domain.app'))) {
  855. $pre = str_starts_with($username, '@') ? substr($username, 1) : $username;
  856. $parts = explode('@', $pre);
  857. $username = $parts[0];
  858. }
  859. $accountId = AccountService::usernameToId($username, true);
  860. if (! $accountId) {
  861. return [];
  862. }
  863. $account = AccountService::get($accountId);
  864. return $this->json($account, 200, $rateLimiting ? $limits : []);
  865. }
  866. public function getExpoPushNotifications(Request $request)
  867. {
  868. abort_if(! $request->user() || ! $request->user()->token(), 403);
  869. abort_unless($request->user()->tokenCan('push'), 403);
  870. abort_unless(config('services.expo.access_token') && strlen(config('services.expo.access_token')) > 10, 404, 'Push notifications are not supported on this server.');
  871. $user = $request->user();
  872. $res = [
  873. 'expo_token' => (bool) $user->expo_token,
  874. 'notify_like' => (bool) $user->notify_like,
  875. 'notify_follow' => (bool) $user->notify_follow,
  876. 'notify_mention' => (bool) $user->notify_mention,
  877. 'notify_comment' => (bool) $user->notify_comment,
  878. ];
  879. return $this->json($res);
  880. }
  881. public function disableExpoPushNotifications(Request $request)
  882. {
  883. abort_if(! $request->user() || ! $request->user()->token(), 403);
  884. abort_unless($request->user()->tokenCan('push'), 403);
  885. abort_unless(config('services.expo.access_token') && strlen(config('services.expo.access_token')) > 10, 404, 'Push notifications are not supported on this server.');
  886. $request->user()->update([
  887. 'expo_token' => null,
  888. ]);
  889. return $this->json(['expo_token' => null]);
  890. }
  891. public function updateExpoPushNotifications(Request $request)
  892. {
  893. abort_if(! $request->user() || ! $request->user()->token(), 403);
  894. abort_unless($request->user()->tokenCan('push'), 403);
  895. abort_unless(config('services.expo.access_token') && strlen(config('services.expo.access_token')) > 10, 404, 'Push notifications are not supported on this server.');
  896. $this->validate($request, [
  897. 'expo_token' => ['required', ExpoPushToken::rule()],
  898. 'notify_like' => 'sometimes',
  899. 'notify_follow' => 'sometimes',
  900. 'notify_mention' => 'sometimes',
  901. 'notify_comment' => 'sometimes',
  902. ]);
  903. $user = $request->user()->update([
  904. 'expo_token' => $request->input('expo_token'),
  905. 'notify_like' => $request->has('notify_like') && $request->boolean('notify_like'),
  906. 'notify_follow' => $request->has('notify_follow') && $request->boolean('notify_follow'),
  907. 'notify_mention' => $request->has('notify_mention') && $request->boolean('notify_mention'),
  908. 'notify_comment' => $request->has('notify_comment') && $request->boolean('notify_comment'),
  909. ]);
  910. $res = [
  911. 'expo_token' => (bool) $request->user()->expo_token,
  912. 'notify_like' => (bool) $request->user()->notify_like,
  913. 'notify_follow' => (bool) $request->user()->notify_follow,
  914. 'notify_mention' => (bool) $request->user()->notify_mention,
  915. 'notify_comment' => (bool) $request->user()->notify_comment,
  916. ];
  917. return $this->json($res);
  918. }
  919. /**
  920. * POST /api/v1.1/status/create
  921. *
  922. *
  923. * @return StatusTransformer
  924. */
  925. public function statusCreate(Request $request)
  926. {
  927. abort_if(! $request->user() || ! $request->user()->token(), 403);
  928. abort_unless($request->user()->tokenCan('write'), 403);
  929. $this->validate($request, [
  930. 'status' => 'nullable|string|max:'.(int) config_cache('pixelfed.max_caption_length'),
  931. 'file' => [
  932. 'required',
  933. 'file',
  934. 'mimetypes:'.config_cache('pixelfed.media_types'),
  935. 'max:'.config_cache('pixelfed.max_photo_size'),
  936. function ($attribute, $value, $fail) {
  937. if (is_array($value) && count($value) > 1) {
  938. $fail('Only one file can be uploaded at a time.');
  939. }
  940. },
  941. ],
  942. 'sensitive' => 'nullable',
  943. 'visibility' => 'string|in:private,unlisted,public',
  944. 'spoiler_text' => 'sometimes|max:140',
  945. ]);
  946. if ($request->hasHeader('idempotency-key')) {
  947. $key = 'pf:api:v1:status:idempotency-key:'.$request->user()->id.':'.hash('sha1', $request->header('idempotency-key'));
  948. $exists = Cache::has($key);
  949. abort_if($exists, 400, 'Duplicate idempotency key.');
  950. Cache::put($key, 1, 3600);
  951. }
  952. if (config('costar.enabled') == true) {
  953. $blockedKeywords = config('costar.keyword.block');
  954. if ($blockedKeywords !== null && $request->status) {
  955. $keywords = config('costar.keyword.block');
  956. foreach ($keywords as $kw) {
  957. if (Str::contains($request->status, $kw) == true) {
  958. abort(400, 'Invalid object. Contains banned keyword.');
  959. }
  960. }
  961. }
  962. }
  963. $user = $request->user();
  964. if ($user->has_roles) {
  965. abort_if(! UserRoleService::can('can-post', $user->id), 403, 'Invalid permissions for this action');
  966. }
  967. $profile = $user->profile;
  968. $limitKey = 'compose:rate-limit:media-upload:'.$user->id;
  969. $photo = $request->file('file');
  970. $fileSize = $photo->getSize();
  971. $sizeInKbs = (int) ceil($fileSize / 1000);
  972. $accountSize = UserStorageService::get($user->id);
  973. abort_if($accountSize === -1, 403, 'Invalid request.');
  974. $updatedAccountSize = (int) $accountSize + (int) $sizeInKbs;
  975. if ((bool) config_cache('pixelfed.enforce_account_limit') == true) {
  976. $limit = (int) config_cache('pixelfed.max_account_size');
  977. if ($updatedAccountSize >= $limit) {
  978. abort(403, 'Account size limit reached.');
  979. }
  980. }
  981. $mimes = explode(',', config_cache('pixelfed.media_types'));
  982. if (in_array($photo->getMimeType(), $mimes) == false) {
  983. abort(403, 'Invalid or unsupported mime type.');
  984. }
  985. $storagePath = MediaPathService::get($user, 2);
  986. $path = $photo->storePublicly($storagePath);
  987. $hash = \hash_file('sha256', $photo);
  988. $license = null;
  989. $mime = $photo->getMimeType();
  990. $settings = UserSetting::whereUserId($user->id)->first();
  991. if ($settings && ! empty($settings->compose_settings)) {
  992. $compose = $settings->compose_settings;
  993. if (isset($compose['default_license']) && $compose['default_license'] != 1) {
  994. $license = $compose['default_license'];
  995. }
  996. }
  997. abort_if(MediaBlocklistService::exists($hash) == true, 451);
  998. $visibility = $profile->is_private ? 'private' : (
  999. $profile->unlisted == true &&
  1000. $request->input('visibility', 'public') == 'public' ?
  1001. 'unlisted' :
  1002. $request->input('visibility', 'public'));
  1003. if ($user->last_active_at == null) {
  1004. return [];
  1005. }
  1006. $content = strip_tags($request->input('status'));
  1007. $rendered = Autolink::create()->autolink($content);
  1008. $cw = $user->profile->cw == true ? true : $request->boolean('sensitive', false);
  1009. $spoilerText = $cw && $request->filled('spoiler_text') ? $request->input('spoiler_text') : null;
  1010. $status = new Status;
  1011. $status->caption = $content;
  1012. $status->rendered = $rendered;
  1013. $status->profile_id = $user->profile_id;
  1014. $status->is_nsfw = $cw;
  1015. $status->cw_summary = $spoilerText;
  1016. $status->scope = $visibility;
  1017. $status->visibility = $visibility;
  1018. $status->type = StatusController::mimeTypeCheck([$mime]);
  1019. $status->save();
  1020. if (! $status) {
  1021. abort(500, 'An error occured.');
  1022. }
  1023. $media = new Media;
  1024. $media->status_id = $status->id;
  1025. $media->profile_id = $profile->id;
  1026. $media->user_id = $user->id;
  1027. $media->media_path = $path;
  1028. $media->original_sha256 = $hash;
  1029. $media->size = $photo->getSize();
  1030. $media->mime = $mime;
  1031. $media->order = 1;
  1032. $media->caption = $request->input('description');
  1033. if ($license) {
  1034. $media->license = $license;
  1035. }
  1036. $media->save();
  1037. switch ($media->mime) {
  1038. case 'image/jpeg':
  1039. case 'image/png':
  1040. ImageOptimize::dispatch($media)->onQueue('mmo');
  1041. break;
  1042. case 'video/mp4':
  1043. VideoThumbnail::dispatch($media)->onQueue('mmo');
  1044. $preview_url = '/storage/no-preview.png';
  1045. $url = '/storage/no-preview.png';
  1046. break;
  1047. }
  1048. $user->storage_used = (int) $updatedAccountSize;
  1049. $user->storage_used_updated_at = now();
  1050. $user->save();
  1051. NewStatusPipeline::dispatch($status);
  1052. Cache::forget('user:account:id:'.$user->id);
  1053. Cache::forget('_api:statuses:recent_9:'.$user->profile_id);
  1054. Cache::forget('profile:status_count:'.$user->profile_id);
  1055. Cache::forget($user->storageUsedKey());
  1056. Cache::forget('profile:embed:'.$status->profile_id);
  1057. Cache::forget($limitKey);
  1058. $res = StatusService::getMastodon($status->id, false);
  1059. $res['favourited'] = false;
  1060. $res['language'] = 'en';
  1061. $res['bookmarked'] = false;
  1062. $res['card'] = null;
  1063. return $this->json($res);
  1064. }
  1065. public function nagState(Request $request)
  1066. {
  1067. abort_unless((bool) config_cache('pixelfed.oauth_enabled'), 404);
  1068. return NotificationAppGatewayService::config();
  1069. }
  1070. }