InternalApiController.php 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552
  1. <?php
  2. namespace App\Http\Controllers;
  3. use Illuminate\Http\Request;
  4. use App\{
  5. AccountInterstitial,
  6. DirectMessage,
  7. DiscoverCategory,
  8. Hashtag,
  9. Follower,
  10. Like,
  11. Media,
  12. MediaTag,
  13. Notification,
  14. Profile,
  15. StatusHashtag,
  16. Status,
  17. UserFilter,
  18. };
  19. use Auth,Cache;
  20. use Carbon\Carbon;
  21. use League\Fractal;
  22. use App\Transformer\Api\{
  23. AccountTransformer,
  24. StatusTransformer,
  25. // StatusMediaContainerTransformer,
  26. };
  27. use App\Util\Media\Filter;
  28. use App\Jobs\StatusPipeline\NewStatusPipeline;
  29. use League\Fractal\Serializer\ArraySerializer;
  30. use League\Fractal\Pagination\IlluminatePaginatorAdapter;
  31. use Illuminate\Validation\Rule;
  32. use Illuminate\Support\Str;
  33. use App\Services\MediaTagService;
  34. use App\Services\ModLogService;
  35. use App\Services\PublicTimelineService;
  36. class InternalApiController extends Controller
  37. {
  38. protected $fractal;
  39. public function __construct()
  40. {
  41. $this->middleware('auth');
  42. $this->fractal = new Fractal\Manager();
  43. $this->fractal->setSerializer(new ArraySerializer());
  44. }
  45. // deprecated v2 compose api
  46. public function compose(Request $request)
  47. {
  48. return redirect('/');
  49. }
  50. // deprecated
  51. public function discover(Request $request)
  52. {
  53. return;
  54. }
  55. public function discoverPosts(Request $request)
  56. {
  57. $profile = Auth::user()->profile;
  58. $pid = $profile->id;
  59. $following = Cache::remember('feature:discover:following:'.$pid, now()->addMinutes(15), function() use ($pid) {
  60. return Follower::whereProfileId($pid)->pluck('following_id')->toArray();
  61. });
  62. $filters = Cache::remember("user:filter:list:$pid", now()->addMinutes(15), function() use($pid) {
  63. $private = Profile::whereIsPrivate(true)
  64. ->orWhere('unlisted', true)
  65. ->orWhere('status', '!=', null)
  66. ->pluck('id')
  67. ->toArray();
  68. $filters = UserFilter::whereUserId($pid)
  69. ->whereFilterableType('App\Profile')
  70. ->whereIn('filter_type', ['mute', 'block'])
  71. ->pluck('filterable_id')
  72. ->toArray();
  73. return array_merge($private, $filters);
  74. });
  75. $following = array_merge($following, $filters);
  76. $sql = config('database.default') !== 'pgsql';
  77. $posts = Status::select(
  78. 'id',
  79. 'caption',
  80. 'is_nsfw',
  81. 'profile_id',
  82. 'type',
  83. 'uri',
  84. 'created_at'
  85. )
  86. ->whereNull('uri')
  87. ->whereIn('type', ['photo','photo:album', 'video'])
  88. ->whereIsNsfw(false)
  89. ->whereVisibility('public')
  90. ->whereNotIn('profile_id', $following)
  91. ->when($sql, function($q, $s) {
  92. return $q->where('created_at', '>', now()->subMonths(3));
  93. })
  94. ->with('media')
  95. ->inRandomOrder()
  96. ->latest()
  97. ->take(39)
  98. ->get();
  99. $res = [
  100. 'posts' => $posts->map(function($post) {
  101. return [
  102. 'type' => $post->type,
  103. 'url' => $post->url(),
  104. 'thumb' => $post->thumb(),
  105. ];
  106. })
  107. ];
  108. return response()->json($res);
  109. }
  110. public function directMessage(Request $request, $profileId, $threadId)
  111. {
  112. $profile = Auth::user()->profile;
  113. if($profileId != $profile->id) {
  114. abort(403);
  115. }
  116. $msg = DirectMessage::whereToId($profile->id)
  117. ->orWhere('from_id',$profile->id)
  118. ->findOrFail($threadId);
  119. $thread = DirectMessage::with('status')->whereIn('to_id', [$profile->id, $msg->from_id])
  120. ->whereIn('from_id', [$profile->id,$msg->from_id])
  121. ->orderBy('created_at', 'asc')
  122. ->paginate(30);
  123. return response()->json(compact('msg', 'profile', 'thread'), 200, [], JSON_PRETTY_PRINT);
  124. }
  125. public function statusReplies(Request $request, int $id)
  126. {
  127. $parent = Status::whereScope('public')->findOrFail($id);
  128. $children = Status::whereInReplyToId($parent->id)
  129. ->orderBy('created_at', 'desc')
  130. ->take(3)
  131. ->get();
  132. $resource = new Fractal\Resource\Collection($children, new StatusTransformer());
  133. $res = $this->fractal->createData($resource)->toArray();
  134. return response()->json($res);
  135. }
  136. public function stories(Request $request)
  137. {
  138. }
  139. public function discoverCategories(Request $request)
  140. {
  141. $categories = DiscoverCategory::whereActive(true)->orderBy('order')->take(10)->get();
  142. $res = $categories->map(function($item) {
  143. return [
  144. 'name' => $item->name,
  145. 'url' => $item->url(),
  146. 'thumb' => $item->thumb()
  147. ];
  148. });
  149. return response()->json($res);
  150. }
  151. public function modAction(Request $request)
  152. {
  153. abort_unless(Auth::user()->is_admin, 400);
  154. $this->validate($request, [
  155. 'action' => [
  156. 'required',
  157. 'string',
  158. Rule::in([
  159. 'addcw',
  160. 'remcw',
  161. 'unlist'
  162. ])
  163. ],
  164. 'item_id' => 'required|integer|min:1',
  165. 'item_type' => [
  166. 'required',
  167. 'string',
  168. Rule::in(['profile', 'status'])
  169. ]
  170. ]);
  171. $action = $request->input('action');
  172. $item_id = $request->input('item_id');
  173. $item_type = $request->input('item_type');
  174. switch($action) {
  175. case 'addcw':
  176. $status = Status::findOrFail($item_id);
  177. $status->is_nsfw = true;
  178. $status->save();
  179. ModLogService::boot()
  180. ->user(Auth::user())
  181. ->objectUid($status->profile->user_id)
  182. ->objectId($status->id)
  183. ->objectType('App\Status::class')
  184. ->action('admin.status.moderate')
  185. ->metadata([
  186. 'action' => 'cw',
  187. 'message' => 'Success!'
  188. ])
  189. ->accessLevel('admin')
  190. ->save();
  191. if($status->uri == null) {
  192. $media = $status->media;
  193. $ai = new AccountInterstitial;
  194. $ai->user_id = $status->profile->user_id;
  195. $ai->type = 'post.cw';
  196. $ai->view = 'account.moderation.post.cw';
  197. $ai->item_type = 'App\Status';
  198. $ai->item_id = $status->id;
  199. $ai->has_media = (bool) $media->count();
  200. $ai->blurhash = $media->count() ? $media->first()->blurhash : null;
  201. $ai->meta = json_encode([
  202. 'caption' => $status->caption,
  203. 'created_at' => $status->created_at,
  204. 'type' => $status->type,
  205. 'url' => $status->url(),
  206. 'is_nsfw' => $status->is_nsfw,
  207. 'scope' => $status->scope,
  208. 'reblog' => $status->reblog_of_id,
  209. 'likes_count' => $status->likes_count,
  210. 'reblogs_count' => $status->reblogs_count,
  211. ]);
  212. $ai->save();
  213. $u = $status->profile->user;
  214. $u->has_interstitial = true;
  215. $u->save();
  216. }
  217. break;
  218. case 'remcw':
  219. $status = Status::findOrFail($item_id);
  220. $status->is_nsfw = false;
  221. $status->save();
  222. ModLogService::boot()
  223. ->user(Auth::user())
  224. ->objectUid($status->profile->user_id)
  225. ->objectId($status->id)
  226. ->objectType('App\Status::class')
  227. ->action('admin.status.moderate')
  228. ->metadata([
  229. 'action' => 'remove_cw',
  230. 'message' => 'Success!'
  231. ])
  232. ->accessLevel('admin')
  233. ->save();
  234. if($status->uri == null) {
  235. $ai = AccountInterstitial::whereUserId($status->profile->user_id)
  236. ->whereType('post.cw')
  237. ->whereItemId($status->id)
  238. ->whereItemType('App\Status')
  239. ->first();
  240. $ai->delete();
  241. }
  242. break;
  243. case 'unlist':
  244. $status = Status::whereScope('public')->findOrFail($item_id);
  245. $status->scope = $status->visibility = 'unlisted';
  246. $status->save();
  247. PublicTimelineService::del($status->id);
  248. ModLogService::boot()
  249. ->user(Auth::user())
  250. ->objectUid($status->profile->user_id)
  251. ->objectId($status->id)
  252. ->objectType('App\Status::class')
  253. ->action('admin.status.moderate')
  254. ->metadata([
  255. 'action' => 'unlist',
  256. 'message' => 'Success!'
  257. ])
  258. ->accessLevel('admin')
  259. ->save();
  260. if($status->uri == null) {
  261. $media = $status->media;
  262. $ai = new AccountInterstitial;
  263. $ai->user_id = $status->profile->user_id;
  264. $ai->type = 'post.unlist';
  265. $ai->view = 'account.moderation.post.unlist';
  266. $ai->item_type = 'App\Status';
  267. $ai->item_id = $status->id;
  268. $ai->has_media = (bool) $media->count();
  269. $ai->blurhash = $media->count() ? $media->first()->blurhash : null;
  270. $ai->meta = json_encode([
  271. 'caption' => $status->caption,
  272. 'created_at' => $status->created_at,
  273. 'type' => $status->type,
  274. 'url' => $status->url(),
  275. 'is_nsfw' => $status->is_nsfw,
  276. 'scope' => $status->scope,
  277. 'reblog' => $status->reblog_of_id,
  278. 'likes_count' => $status->likes_count,
  279. 'reblogs_count' => $status->reblogs_count,
  280. ]);
  281. $ai->save();
  282. $u = $status->profile->user;
  283. $u->has_interstitial = true;
  284. $u->save();
  285. }
  286. break;
  287. }
  288. return ['msg' => 200];
  289. }
  290. public function composePost(Request $request)
  291. {
  292. $this->validate($request, [
  293. 'caption' => 'nullable|string|max:'.config('pixelfed.max_caption_length', 500),
  294. 'media.*' => 'required',
  295. 'media.*.id' => 'required|integer|min:1',
  296. 'media.*.filter_class' => 'nullable|alpha_dash|max:30',
  297. 'media.*.license' => 'nullable|string|max:140',
  298. 'media.*.alt' => 'nullable|string|max:140',
  299. 'cw' => 'nullable|boolean',
  300. 'visibility' => 'required|string|in:public,private,unlisted|min:2|max:10',
  301. 'place' => 'nullable',
  302. 'comments_disabled' => 'nullable',
  303. 'tagged' => 'nullable'
  304. ]);
  305. if(config('costar.enabled') == true) {
  306. $blockedKeywords = config('costar.keyword.block');
  307. if($blockedKeywords !== null && $request->caption) {
  308. $keywords = config('costar.keyword.block');
  309. foreach($keywords as $kw) {
  310. if(Str::contains($request->caption, $kw) == true) {
  311. abort(400, 'Invalid object');
  312. }
  313. }
  314. }
  315. }
  316. $user = Auth::user();
  317. $profile = $user->profile;
  318. $visibility = $request->input('visibility');
  319. $medias = $request->input('media');
  320. $attachments = [];
  321. $status = new Status;
  322. $mimes = [];
  323. $place = $request->input('place');
  324. $cw = $request->input('cw');
  325. $tagged = $request->input('tagged');
  326. foreach($medias as $k => $media) {
  327. if($k + 1 > config('pixelfed.max_album_length')) {
  328. continue;
  329. }
  330. $m = Media::findOrFail($media['id']);
  331. if($m->profile_id !== $profile->id || $m->status_id) {
  332. abort(403, 'Invalid media id');
  333. }
  334. $m->filter_class = in_array($media['filter_class'], Filter::classes()) ? $media['filter_class'] : null;
  335. $m->license = $media['license'];
  336. $m->caption = isset($media['alt']) ? strip_tags($media['alt']) : null;
  337. $m->order = isset($media['cursor']) && is_int($media['cursor']) ? (int) $media['cursor'] : $k;
  338. if($cw == true || $profile->cw == true) {
  339. $m->is_nsfw = $cw;
  340. $status->is_nsfw = $cw;
  341. }
  342. $m->save();
  343. $attachments[] = $m;
  344. array_push($mimes, $m->mime);
  345. }
  346. $mediaType = StatusController::mimeTypeCheck($mimes);
  347. if(in_array($mediaType, ['photo', 'video', 'photo:album']) == false) {
  348. abort(400, __('exception.compose.invalid.album'));
  349. }
  350. if($place && is_array($place)) {
  351. $status->place_id = $place['id'];
  352. }
  353. if($request->filled('comments_disabled')) {
  354. $status->comments_disabled = (bool) $request->input('comments_disabled');
  355. }
  356. $status->caption = strip_tags($request->caption);
  357. $status->scope = 'draft';
  358. $status->profile_id = $profile->id;
  359. $status->save();
  360. foreach($attachments as $media) {
  361. $media->status_id = $status->id;
  362. $media->save();
  363. }
  364. $visibility = $profile->unlisted == true && $visibility == 'public' ? 'unlisted' : $visibility;
  365. $cw = $profile->cw == true ? true : $cw;
  366. $status->is_nsfw = $cw;
  367. $status->visibility = $visibility;
  368. $status->scope = $visibility;
  369. $status->type = $mediaType;
  370. $status->save();
  371. foreach($tagged as $tg) {
  372. $mt = new MediaTag;
  373. $mt->status_id = $status->id;
  374. $mt->media_id = $status->media->first()->id;
  375. $mt->profile_id = $tg['id'];
  376. $mt->tagged_username = $tg['name'];
  377. $mt->is_public = true; // (bool) $tg['privacy'] ?? 1;
  378. $mt->metadata = json_encode([
  379. '_v' => 1,
  380. ]);
  381. $mt->save();
  382. MediaTagService::set($mt->status_id, $mt->profile_id);
  383. MediaTagService::sendNotification($mt);
  384. }
  385. NewStatusPipeline::dispatch($status);
  386. Cache::forget('user:account:id:'.$profile->user_id);
  387. Cache::forget('_api:statuses:recent_9:'.$profile->id);
  388. Cache::forget('profile:status_count:'.$profile->id);
  389. Cache::forget($user->storageUsedKey());
  390. return $status->url();
  391. }
  392. public function bookmarks(Request $request)
  393. {
  394. $statuses = Auth::user()->profile
  395. ->bookmarks()
  396. ->withCount(['likes','comments'])
  397. ->orderBy('created_at', 'desc')
  398. ->simplePaginate(10);
  399. $resource = new Fractal\Resource\Collection($statuses, new StatusTransformer());
  400. $res = $this->fractal->createData($resource)->toArray();
  401. return response()->json($res);
  402. }
  403. public function accountStatuses(Request $request, $id)
  404. {
  405. $this->validate($request, [
  406. 'only_media' => 'nullable',
  407. 'pinned' => 'nullable',
  408. 'exclude_replies' => 'nullable',
  409. 'max_id' => 'nullable|integer|min:0|max:' . PHP_INT_MAX,
  410. 'since_id' => 'nullable|integer|min:0|max:' . PHP_INT_MAX,
  411. 'min_id' => 'nullable|integer|min:0|max:' . PHP_INT_MAX,
  412. 'limit' => 'nullable|integer|min:1|max:24'
  413. ]);
  414. $profile = Profile::whereNull('status')->findOrFail($id);
  415. $limit = $request->limit ?? 9;
  416. $max_id = $request->max_id;
  417. $min_id = $request->min_id;
  418. $scope = $request->only_media == true ?
  419. ['photo', 'photo:album', 'video', 'video:album'] :
  420. ['photo', 'photo:album', 'video', 'video:album', 'share', 'reply'];
  421. if($profile->is_private) {
  422. if(!Auth::check()) {
  423. return response()->json([]);
  424. }
  425. $pid = Auth::user()->profile->id;
  426. $following = Cache::remember('profile:following:'.$pid, now()->addMinutes(1440), function() use($pid) {
  427. $following = Follower::whereProfileId($pid)->pluck('following_id');
  428. return $following->push($pid)->toArray();
  429. });
  430. $visibility = true == in_array($profile->id, $following) ? ['public', 'unlisted', 'private'] : [];
  431. } else {
  432. if(Auth::check()) {
  433. $pid = Auth::user()->profile->id;
  434. $following = Cache::remember('profile:following:'.$pid, now()->addMinutes(1440), function() use($pid) {
  435. $following = Follower::whereProfileId($pid)->pluck('following_id');
  436. return $following->push($pid)->toArray();
  437. });
  438. $visibility = true == in_array($profile->id, $following) ? ['public', 'unlisted', 'private'] : ['public', 'unlisted'];
  439. } else {
  440. $visibility = ['public', 'unlisted'];
  441. }
  442. }
  443. $dir = $min_id ? '>' : '<';
  444. $id = $min_id ?? $max_id;
  445. $timeline = Status::select(
  446. 'id',
  447. 'uri',
  448. 'caption',
  449. 'rendered',
  450. 'profile_id',
  451. 'type',
  452. 'in_reply_to_id',
  453. 'reblog_of_id',
  454. 'is_nsfw',
  455. 'likes_count',
  456. 'reblogs_count',
  457. 'scope',
  458. 'local',
  459. 'created_at',
  460. 'updated_at'
  461. )->whereProfileId($profile->id)
  462. ->whereIn('type', $scope)
  463. ->where('id', $dir, $id)
  464. ->whereIn('visibility', $visibility)
  465. ->latest()
  466. ->limit($limit)
  467. ->get();
  468. $resource = new Fractal\Resource\Collection($timeline, new StatusTransformer());
  469. $res = $this->fractal->createData($resource)->toArray();
  470. return response()->json($res);
  471. }
  472. public function remoteProfile(Request $request, $id)
  473. {
  474. $profile = Profile::whereNull('status')
  475. ->whereNotNull('domain')
  476. ->findOrFail($id);
  477. $user = Auth::user();
  478. return view('profile.remote', compact('profile', 'user'));
  479. }
  480. public function remoteStatus(Request $request, $profileId, $statusId)
  481. {
  482. $user = Profile::whereNull('status')
  483. ->whereNotNull('domain')
  484. ->findOrFail($profileId);
  485. $status = Status::whereProfileId($user->id)
  486. ->whereNull('reblog_of_id')
  487. ->whereIn('visibility', ['public', 'unlisted'])
  488. ->findOrFail($statusId);
  489. $template = $status->in_reply_to_id ? 'status.reply' : 'status.remote';
  490. return view($template, compact('user', 'status'));
  491. }
  492. }