ApiV1Dot1Controller.php 44 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255
  1. <?php
  2. namespace App\Http\Controllers\Api;
  3. use App\AccountLog;
  4. use App\EmailVerification;
  5. use App\Http\Controllers\Controller;
  6. use App\Http\Controllers\StatusController;
  7. use App\Http\Resources\StatusStateless;
  8. use App\Jobs\ImageOptimizePipeline\ImageOptimize;
  9. use App\Jobs\ReportPipeline\ReportNotifyAdminViaEmail;
  10. use App\Jobs\StatusPipeline\NewStatusPipeline;
  11. use App\Jobs\StatusPipeline\RemoteStatusDelete;
  12. use App\Jobs\StatusPipeline\StatusDelete;
  13. use App\Jobs\VideoPipeline\VideoThumbnail;
  14. use App\Mail\ConfirmAppEmail;
  15. use App\Mail\PasswordChange;
  16. use App\Media;
  17. use App\Place;
  18. use App\Profile;
  19. use App\Report;
  20. use App\Services\AccountService;
  21. use App\Services\BouncerService;
  22. use App\Services\EmailService;
  23. use App\Services\FollowerService;
  24. use App\Services\MediaBlocklistService;
  25. use App\Services\MediaPathService;
  26. use App\Services\NetworkTimelineService;
  27. use App\Services\ProfileStatusService;
  28. use App\Services\PublicTimelineService;
  29. use App\Services\StatusService;
  30. use App\Services\UserStorageService;
  31. use App\Status;
  32. use App\StatusArchived;
  33. use App\User;
  34. use App\UserSetting;
  35. use App\Util\Lexer\Autolink;
  36. use App\Util\Lexer\RestrictedNames;
  37. use Cache;
  38. use DB;
  39. use Illuminate\Http\Request;
  40. use Illuminate\Support\Facades\Hash;
  41. use Illuminate\Support\Facades\RateLimiter;
  42. use Illuminate\Support\Str;
  43. use Jenssegers\Agent\Agent;
  44. use League\Fractal;
  45. use League\Fractal\Serializer\ArraySerializer;
  46. use Mail;
  47. use NotificationChannels\Expo\ExpoPushToken;
  48. class ApiV1Dot1Controller extends Controller
  49. {
  50. protected $fractal;
  51. public function __construct()
  52. {
  53. $this->fractal = new Fractal\Manager();
  54. $this->fractal->setSerializer(new ArraySerializer());
  55. }
  56. public function json($res, $code = 200, $headers = [])
  57. {
  58. return response()->json($res, $code, $headers, JSON_UNESCAPED_SLASHES);
  59. }
  60. public function error($msg, $code = 400, $extra = [], $headers = [])
  61. {
  62. $res = [
  63. 'msg' => $msg,
  64. 'code' => $code,
  65. ];
  66. return response()->json(array_merge($res, $extra), $code, $headers, JSON_UNESCAPED_SLASHES);
  67. }
  68. public function report(Request $request)
  69. {
  70. abort_if(! $request->user() || ! $request->user()->token(), 403);
  71. abort_unless($request->user()->tokenCan('write'), 403);
  72. $user = $request->user();
  73. abort_if($user->status != null, 403);
  74. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  75. abort_if(BouncerService::checkIp($request->ip()), 404);
  76. }
  77. $report_type = $request->input('report_type');
  78. $object_id = $request->input('object_id');
  79. $object_type = $request->input('object_type');
  80. $types = [
  81. 'spam',
  82. 'sensitive',
  83. 'abusive',
  84. 'underage',
  85. 'violence',
  86. 'copyright',
  87. 'impersonation',
  88. 'scam',
  89. 'terrorism',
  90. ];
  91. if (! $report_type || ! $object_id || ! $object_type) {
  92. return $this->error('Invalid or missing parameters', 400, ['error_code' => 'ERROR_INVALID_PARAMS']);
  93. }
  94. if (! in_array($report_type, $types)) {
  95. return $this->error('Invalid report type', 400, ['error_code' => 'ERROR_TYPE_INVALID']);
  96. }
  97. if ($object_type === 'user' && $object_id == $user->profile_id) {
  98. return $this->error('Cannot self report', 400, ['error_code' => 'ERROR_NO_SELF_REPORTS']);
  99. }
  100. $rpid = null;
  101. switch ($object_type) {
  102. case 'post':
  103. $object = Status::find($object_id);
  104. if (! $object) {
  105. return $this->error('Invalid object id', 400, ['error_code' => 'ERROR_INVALID_OBJECT_ID']);
  106. }
  107. $object_type = 'App\Status';
  108. $exists = Report::whereUserId($user->id)
  109. ->whereObjectId($object->id)
  110. ->whereObjectType('App\Status')
  111. ->count();
  112. $rpid = $object->profile_id;
  113. break;
  114. case 'user':
  115. $object = Profile::find($object_id);
  116. if (! $object) {
  117. return $this->error('Invalid object id', 400, ['error_code' => 'ERROR_INVALID_OBJECT_ID']);
  118. }
  119. $object_type = 'App\Profile';
  120. $exists = Report::whereUserId($user->id)
  121. ->whereObjectId($object->id)
  122. ->whereObjectType('App\Profile')
  123. ->count();
  124. $rpid = $object->id;
  125. break;
  126. default:
  127. return $this->error('Invalid report type', 400, ['error_code' => 'ERROR_REPORT_OBJECT_TYPE_INVALID']);
  128. break;
  129. }
  130. if ($exists !== 0) {
  131. return $this->error('Duplicate report', 400, ['error_code' => 'ERROR_REPORT_DUPLICATE']);
  132. }
  133. if ($object->profile_id == $user->profile_id) {
  134. return $this->error('Cannot self report', 400, ['error_code' => 'ERROR_NO_SELF_REPORTS']);
  135. }
  136. $report = new Report;
  137. $report->profile_id = $user->profile_id;
  138. $report->user_id = $user->id;
  139. $report->object_id = $object->id;
  140. $report->object_type = $object_type;
  141. $report->reported_profile_id = $rpid;
  142. $report->type = $report_type;
  143. $report->save();
  144. if (config('instance.reports.email.enabled')) {
  145. ReportNotifyAdminViaEmail::dispatch($report)->onQueue('default');
  146. }
  147. $res = [
  148. 'msg' => 'Successfully sent report',
  149. 'code' => 200,
  150. ];
  151. return $this->json($res);
  152. }
  153. /**
  154. * DELETE /api/v1.1/accounts/avatar
  155. *
  156. * @return \App\Transformer\Api\AccountTransformer
  157. */
  158. public function deleteAvatar(Request $request)
  159. {
  160. abort_if(! $request->user() || ! $request->user()->token(), 403);
  161. abort_unless($request->user()->tokenCan('write'), 403);
  162. $user = $request->user();
  163. abort_if($user->status != null, 403);
  164. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  165. abort_if(BouncerService::checkIp($request->ip()), 404);
  166. }
  167. $avatar = $user->profile->avatar;
  168. if ($avatar->media_path == 'public/avatars/default.png' ||
  169. $avatar->media_path == 'public/avatars/default.jpg'
  170. ) {
  171. return AccountService::get($user->profile_id);
  172. }
  173. if (is_file(storage_path('app/'.$avatar->media_path))) {
  174. @unlink(storage_path('app/'.$avatar->media_path));
  175. }
  176. $avatar->media_path = 'public/avatars/default.jpg';
  177. $avatar->change_count = $avatar->change_count + 1;
  178. $avatar->save();
  179. Cache::forget('avatar:'.$user->profile_id);
  180. Cache::forget("avatar:{$user->profile_id}");
  181. Cache::forget('user:account:id:'.$user->id);
  182. AccountService::del($user->profile_id);
  183. return AccountService::get($user->profile_id);
  184. }
  185. /**
  186. * GET /api/v1.1/accounts/{id}/posts
  187. *
  188. * @return \App\Transformer\Api\StatusTransformer
  189. */
  190. public function accountPosts(Request $request, $id)
  191. {
  192. abort_if(! $request->user() || ! $request->user()->token(), 403);
  193. abort_unless($request->user()->tokenCan('read'), 403);
  194. $user = $request->user();
  195. abort_if($user->status != null, 403);
  196. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  197. abort_if(BouncerService::checkIp($request->ip()), 404);
  198. }
  199. $account = AccountService::get($id);
  200. if (! $account || $account['username'] !== $request->input('username')) {
  201. return $this->json([]);
  202. }
  203. $posts = ProfileStatusService::get($id);
  204. if (! $posts) {
  205. return $this->json([]);
  206. }
  207. $res = collect($posts)
  208. ->map(function ($id) {
  209. return StatusService::get($id);
  210. })
  211. ->filter(function ($post) {
  212. return $post && isset($post['account']);
  213. })
  214. ->toArray();
  215. return $this->json($res);
  216. }
  217. /**
  218. * POST /api/v1.1/accounts/change-password
  219. *
  220. * @return \App\Transformer\Api\AccountTransformer
  221. */
  222. public function accountChangePassword(Request $request)
  223. {
  224. abort_if(! $request->user() || ! $request->user()->token(), 403);
  225. abort_unless($request->user()->tokenCan('write'), 403);
  226. $user = $request->user();
  227. abort_if($user->status != null, 403);
  228. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  229. abort_if(BouncerService::checkIp($request->ip()), 404);
  230. }
  231. $this->validate($request, [
  232. 'current_password' => 'bail|required|current_password',
  233. 'new_password' => 'required|min:'.config('pixelfed.min_password_length', 8),
  234. 'confirm_password' => 'required|same:new_password',
  235. ], [
  236. 'current_password' => 'The password you entered is incorrect',
  237. ]);
  238. $user->password = bcrypt($request->input('new_password'));
  239. $user->save();
  240. $log = new AccountLog;
  241. $log->user_id = $user->id;
  242. $log->item_id = $user->id;
  243. $log->item_type = 'App\User';
  244. $log->action = 'account.edit.password';
  245. $log->message = 'Password changed';
  246. $log->link = null;
  247. $log->ip_address = $request->ip();
  248. $log->user_agent = $request->userAgent();
  249. $log->save();
  250. Mail::to($request->user())->send(new PasswordChange($user));
  251. return $this->json(AccountService::get($user->profile_id));
  252. }
  253. /**
  254. * GET /api/v1.1/accounts/login-activity
  255. *
  256. * @return array
  257. */
  258. public function accountLoginActivity(Request $request)
  259. {
  260. abort_if(! $request->user() || ! $request->user()->token(), 403);
  261. abort_unless($request->user()->tokenCan('read'), 403);
  262. $user = $request->user();
  263. abort_if($user->status != null, 403);
  264. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  265. abort_if(BouncerService::checkIp($request->ip()), 404);
  266. }
  267. $agent = new Agent();
  268. $currentIp = $request->ip();
  269. $activity = AccountLog::whereUserId($user->id)
  270. ->whereAction('auth.login')
  271. ->orderBy('created_at', 'desc')
  272. ->groupBy('ip_address')
  273. ->limit(10)
  274. ->get()
  275. ->map(function ($item) use ($agent, $currentIp) {
  276. $agent->setUserAgent($item->user_agent);
  277. return [
  278. 'id' => $item->id,
  279. 'action' => $item->action,
  280. 'ip' => $item->ip_address,
  281. 'ip_current' => $item->ip_address === $currentIp,
  282. 'is_mobile' => $agent->isMobile(),
  283. 'device' => $agent->device(),
  284. 'browser' => $agent->browser(),
  285. 'platform' => $agent->platform(),
  286. 'created_at' => $item->created_at->format('c'),
  287. ];
  288. });
  289. return $this->json($activity);
  290. }
  291. /**
  292. * GET /api/v1.1/accounts/two-factor
  293. *
  294. * @return array
  295. */
  296. public function accountTwoFactor(Request $request)
  297. {
  298. abort_if(! $request->user() || ! $request->user()->token(), 403);
  299. abort_unless($request->user()->tokenCan('read'), 403);
  300. $user = $request->user();
  301. abort_if($user->status != null, 403);
  302. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  303. abort_if(BouncerService::checkIp($request->ip()), 404);
  304. }
  305. $res = [
  306. 'active' => (bool) $user->{'2fa_enabled'},
  307. 'setup_at' => $user->{'2fa_setup_at'},
  308. ];
  309. return $this->json($res);
  310. }
  311. /**
  312. * GET /api/v1.1/accounts/emails-from-pixelfed
  313. *
  314. * @return array
  315. */
  316. public function accountEmailsFromPixelfed(Request $request)
  317. {
  318. abort_if(! $request->user() || ! $request->user()->token(), 403);
  319. abort_unless($request->user()->tokenCan('read'), 403);
  320. $user = $request->user();
  321. abort_if($user->status != null, 403);
  322. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  323. abort_if(BouncerService::checkIp($request->ip()), 404);
  324. }
  325. $from = config('mail.from.address');
  326. $emailVerifications = EmailVerification::whereUserId($user->id)
  327. ->orderByDesc('id')
  328. ->where('created_at', '>', now()->subDays(14))
  329. ->limit(10)
  330. ->get()
  331. ->map(function ($mail) use ($user, $from) {
  332. return [
  333. 'type' => 'Email Verification',
  334. 'subject' => 'Confirm Email',
  335. 'to_address' => $user->email,
  336. 'from_address' => $from,
  337. 'created_at' => str_replace('@', 'at', $mail->created_at->format('M j, Y @ g:i:s A')),
  338. ];
  339. })
  340. ->toArray();
  341. $passwordResets = DB::table('password_resets')
  342. ->whereEmail($user->email)
  343. ->where('created_at', '>', now()->subDays(14))
  344. ->orderByDesc('created_at')
  345. ->limit(10)
  346. ->get()
  347. ->map(function ($mail) use ($user, $from) {
  348. return [
  349. 'type' => 'Password Reset',
  350. 'subject' => 'Reset Password Notification',
  351. 'to_address' => $user->email,
  352. 'from_address' => $from,
  353. 'created_at' => str_replace('@', 'at', now()->parse($mail->created_at)->format('M j, Y @ g:i:s A')),
  354. ];
  355. })
  356. ->toArray();
  357. $passwordChanges = AccountLog::whereUserId($user->id)
  358. ->whereAction('account.edit.password')
  359. ->where('created_at', '>', now()->subDays(14))
  360. ->orderByDesc('created_at')
  361. ->limit(10)
  362. ->get()
  363. ->map(function ($mail) use ($user, $from) {
  364. return [
  365. 'type' => 'Password Change',
  366. 'subject' => 'Password Change',
  367. 'to_address' => $user->email,
  368. 'from_address' => $from,
  369. 'created_at' => str_replace('@', 'at', now()->parse($mail->created_at)->format('M j, Y @ g:i:s A')),
  370. ];
  371. })
  372. ->toArray();
  373. $res = collect([])
  374. ->merge($emailVerifications)
  375. ->merge($passwordResets)
  376. ->merge($passwordChanges)
  377. ->sortByDesc('created_at')
  378. ->values();
  379. return $this->json($res);
  380. }
  381. /**
  382. * GET /api/v1.1/accounts/apps-and-applications
  383. *
  384. * @return array
  385. */
  386. public function accountApps(Request $request)
  387. {
  388. abort_if(! $request->user() || ! $request->user()->token(), 403);
  389. abort_unless($request->user()->tokenCan('read'), 403);
  390. $user = $request->user();
  391. abort_if($user->status != null, 403);
  392. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  393. abort_if(BouncerService::checkIp($request->ip()), 404);
  394. }
  395. $res = $user->tokens->sortByDesc('created_at')->take(10)->map(function ($token, $key) use ($request) {
  396. return [
  397. 'id' => $token->id,
  398. 'current_session' => $request->user()->token()->id == $token->id,
  399. 'name' => $token->client->name,
  400. 'scopes' => $token->scopes,
  401. 'revoked' => $token->revoked,
  402. 'created_at' => str_replace('@', 'at', now()->parse($token->created_at)->format('M j, Y @ g:i:s A')),
  403. 'expires_at' => str_replace('@', 'at', now()->parse($token->expires_at)->format('M j, Y @ g:i:s A')),
  404. ];
  405. });
  406. return $this->json($res);
  407. }
  408. public function inAppRegistrationPreFlightCheck(Request $request)
  409. {
  410. return [
  411. 'open' => (bool) config_cache('pixelfed.open_registration'),
  412. 'iara' => (bool) config_cache('pixelfed.allow_app_registration'),
  413. ];
  414. }
  415. public function inAppRegistration(Request $request)
  416. {
  417. abort_if($request->user(), 404);
  418. abort_unless((bool) config_cache('pixelfed.open_registration'), 404);
  419. abort_unless((bool) config_cache('pixelfed.allow_app_registration'), 404);
  420. abort_unless($request->hasHeader('X-PIXELFED-APP'), 403);
  421. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  422. abort_if(BouncerService::checkIp($request->ip()), 404);
  423. }
  424. $rl = RateLimiter::attempt('pf:apiv1.1:iar:'.$request->ip(), config('pixelfed.app_registration_rate_limit_attempts', 3), function () {}, config('pixelfed.app_registration_rate_limit_decay', 1800));
  425. abort_if(! $rl, 400, 'Too many requests');
  426. $this->validate($request, [
  427. 'email' => [
  428. 'required',
  429. 'string',
  430. 'email',
  431. 'max:255',
  432. 'unique:users',
  433. function ($attribute, $value, $fail) {
  434. $banned = EmailService::isBanned($value);
  435. if ($banned) {
  436. return $fail('Email is invalid.');
  437. }
  438. },
  439. ],
  440. 'username' => [
  441. 'required',
  442. 'min:2',
  443. 'max:15',
  444. 'unique:users',
  445. function ($attribute, $value, $fail) {
  446. $dash = substr_count($value, '-');
  447. $underscore = substr_count($value, '_');
  448. $period = substr_count($value, '.');
  449. if (ends_with($value, ['.php', '.js', '.css'])) {
  450. return $fail('Username is invalid.');
  451. }
  452. if (($dash + $underscore + $period) > 1) {
  453. return $fail('Username is invalid. Can only contain one dash (-), period (.) or underscore (_).');
  454. }
  455. if (! ctype_alnum($value[0])) {
  456. return $fail('Username is invalid. Must start with a letter or number.');
  457. }
  458. if (! ctype_alnum($value[strlen($value) - 1])) {
  459. return $fail('Username is invalid. Must end with a letter or number.');
  460. }
  461. $val = str_replace(['_', '.', '-'], '', $value);
  462. if (! ctype_alnum($val)) {
  463. return $fail('Username is invalid. Username must be alpha-numeric and may contain dashes (-), periods (.) and underscores (_).');
  464. }
  465. $restricted = RestrictedNames::get();
  466. if (in_array(strtolower($value), array_map('strtolower', $restricted))) {
  467. return $fail('Username cannot be used.');
  468. }
  469. },
  470. ],
  471. 'password' => 'required|string|min:8',
  472. ]);
  473. $email = $request->input('email');
  474. $username = $request->input('username');
  475. $password = $request->input('password');
  476. if (config('database.default') == 'pgsql') {
  477. $username = strtolower($username);
  478. $email = strtolower($email);
  479. }
  480. $user = new User;
  481. $user->name = $username;
  482. $user->username = $username;
  483. $user->email = $email;
  484. $user->password = Hash::make($password);
  485. $user->register_source = 'app';
  486. $user->app_register_ip = $request->ip();
  487. $user->app_register_token = Str::random(40);
  488. $user->save();
  489. $rtoken = Str::random(64);
  490. $verify = new EmailVerification();
  491. $verify->user_id = $user->id;
  492. $verify->email = $user->email;
  493. $verify->user_token = $user->app_register_token;
  494. $verify->random_token = $rtoken;
  495. $verify->save();
  496. $params = http_build_query([
  497. 'ut' => $user->app_register_token,
  498. 'rt' => $rtoken,
  499. 'ea' => base64_encode($user->email),
  500. ]);
  501. $appUrl = url('/api/v1.1/auth/iarer?'.$params);
  502. Mail::to($user->email)->send(new ConfirmAppEmail($verify, $appUrl));
  503. return response()->json([
  504. 'success' => true,
  505. ]);
  506. }
  507. public function inAppRegistrationEmailRedirect(Request $request)
  508. {
  509. $this->validate($request, [
  510. 'ut' => 'required',
  511. 'rt' => 'required',
  512. 'ea' => 'required',
  513. ]);
  514. $ut = $request->input('ut');
  515. $rt = $request->input('rt');
  516. $ea = $request->input('ea');
  517. $params = http_build_query([
  518. 'ut' => $ut,
  519. 'rt' => $rt,
  520. 'domain' => config('pixelfed.domain.app'),
  521. 'ea' => $ea,
  522. ]);
  523. $url = 'pixelfed://confirm-account/'.$ut.'?'.$params;
  524. return redirect()->away($url);
  525. }
  526. public function inAppRegistrationConfirm(Request $request)
  527. {
  528. abort_if($request->user(), 404);
  529. abort_unless((bool) config_cache('pixelfed.open_registration'), 404);
  530. abort_unless((bool) config_cache('pixelfed.allow_app_registration'), 404);
  531. abort_unless($request->hasHeader('X-PIXELFED-APP'), 403);
  532. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  533. abort_if(BouncerService::checkIp($request->ip()), 404);
  534. }
  535. $rl = RateLimiter::attempt('pf:apiv1.1:iarc:'.$request->ip(), config('pixelfed.app_registration_confirm_rate_limit_attempts', 20), function () {}, config('pixelfed.app_registration_confirm_rate_limit_decay', 1800));
  536. abort_if(! $rl, 429, 'Too many requests');
  537. $request->validate([
  538. 'user_token' => 'required',
  539. 'random_token' => 'required',
  540. 'email' => 'required',
  541. ]);
  542. $verify = EmailVerification::whereEmail($request->input('email'))
  543. ->whereUserToken($request->input('user_token'))
  544. ->whereRandomToken($request->input('random_token'))
  545. ->first();
  546. if (! $verify) {
  547. return response()->json(['error' => 'Invalid tokens'], 403);
  548. }
  549. if ($verify->created_at->lt(now()->subHours(24))) {
  550. $verify->delete();
  551. return response()->json(['error' => 'Invalid tokens'], 403);
  552. }
  553. $user = User::findOrFail($verify->user_id);
  554. $user->email_verified_at = now();
  555. $user->last_active_at = now();
  556. $user->save();
  557. $token = $user->createToken('Pixelfed', ['read', 'write', 'follow', 'admin:read', 'admin:write', 'push']);
  558. return response()->json([
  559. 'access_token' => $token->accessToken,
  560. ]);
  561. }
  562. public function archive(Request $request, $id)
  563. {
  564. abort_if(! $request->user() || ! $request->user()->token(), 403);
  565. abort_unless($request->user()->tokenCan('write'), 403);
  566. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  567. abort_if(BouncerService::checkIp($request->ip()), 404);
  568. }
  569. $status = Status::whereNull('in_reply_to_id')
  570. ->whereNull('reblog_of_id')
  571. ->whereProfileId($request->user()->profile_id)
  572. ->findOrFail($id);
  573. if ($status->scope === 'archived') {
  574. return [200];
  575. }
  576. $archive = new StatusArchived;
  577. $archive->status_id = $status->id;
  578. $archive->profile_id = $status->profile_id;
  579. $archive->original_scope = $status->scope;
  580. $archive->save();
  581. $status->scope = 'archived';
  582. $status->visibility = 'draft';
  583. $status->save();
  584. StatusService::del($status->id, true);
  585. AccountService::syncPostCount($status->profile_id);
  586. return [200];
  587. }
  588. public function unarchive(Request $request, $id)
  589. {
  590. abort_if(! $request->user() || ! $request->user()->token(), 403);
  591. abort_unless($request->user()->tokenCan('write'), 403);
  592. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  593. abort_if(BouncerService::checkIp($request->ip()), 404);
  594. }
  595. $status = Status::whereNull('in_reply_to_id')
  596. ->whereNull('reblog_of_id')
  597. ->whereProfileId($request->user()->profile_id)
  598. ->findOrFail($id);
  599. if ($status->scope !== 'archived') {
  600. return [200];
  601. }
  602. $archive = StatusArchived::whereStatusId($status->id)
  603. ->whereProfileId($status->profile_id)
  604. ->firstOrFail();
  605. $status->scope = $archive->original_scope;
  606. $status->visibility = $archive->original_scope;
  607. $status->save();
  608. $archive->delete();
  609. StatusService::del($status->id, true);
  610. AccountService::syncPostCount($status->profile_id);
  611. return [200];
  612. }
  613. public function archivedPosts(Request $request)
  614. {
  615. abort_if(! $request->user() || ! $request->user()->token(), 403);
  616. abort_unless($request->user()->tokenCan('read'), 403);
  617. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  618. abort_if(BouncerService::checkIp($request->ip()), 404);
  619. }
  620. $statuses = Status::whereProfileId($request->user()->profile_id)
  621. ->whereScope('archived')
  622. ->orderByDesc('id')
  623. ->cursorPaginate(10);
  624. return StatusStateless::collection($statuses);
  625. }
  626. public function placesById(Request $request, $id, $slug)
  627. {
  628. abort_if(! $request->user() || ! $request->user()->token(), 403);
  629. abort_unless($request->user()->tokenCan('read'), 403);
  630. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  631. abort_if(BouncerService::checkIp($request->ip()), 404);
  632. }
  633. $place = Place::whereSlug($slug)->findOrFail($id);
  634. $posts = Cache::remember('pf-api:v1.1:places-by-id:'.$place->id, 3600, function () use ($place) {
  635. return Status::wherePlaceId($place->id)
  636. ->whereNull('uri')
  637. ->whereScope('public')
  638. ->orderByDesc('created_at')
  639. ->limit(60)
  640. ->pluck('id');
  641. });
  642. $posts = $posts->map(function ($id) {
  643. return StatusService::get($id);
  644. })
  645. ->filter()
  646. ->values();
  647. return [
  648. 'place' => [
  649. 'id' => $place->id,
  650. 'name' => $place->name,
  651. 'slug' => $place->slug,
  652. 'country' => $place->country,
  653. 'lat' => $place->lat,
  654. 'long' => $place->long,
  655. ],
  656. 'posts' => $posts];
  657. }
  658. public function moderatePost(Request $request, $id)
  659. {
  660. abort_if(! $request->user() || ! $request->user()->token(), 403);
  661. abort_if($request->user()->is_admin != true, 403);
  662. abort_unless($request->user()->tokenCan('admin:write'), 403);
  663. if (config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  664. abort_if(BouncerService::checkIp($request->ip()), 404);
  665. }
  666. $this->validate($request, [
  667. 'action' => 'required|in:cw,mark-public,mark-unlisted,mark-private,mark-spammer,delete',
  668. ]);
  669. $action = $request->input('action');
  670. $status = Status::find($id);
  671. if (! $status) {
  672. return response()->json(['error' => 'Cannot find status'], 400);
  673. }
  674. if ($status->uri == null) {
  675. if ($status->profile->user && $status->profile->user->is_admin) {
  676. return response()->json(['error' => 'Cannot moderate admin accounts'], 400);
  677. }
  678. }
  679. if ($action == 'mark-spammer') {
  680. $status->profile->update([
  681. 'unlisted' => true,
  682. 'cw' => true,
  683. 'no_autolink' => true,
  684. ]);
  685. Status::whereProfileId($status->profile_id)
  686. ->get()
  687. ->each(function ($s) {
  688. if (in_array($s->scope, ['public', 'unlisted'])) {
  689. $s->scope = 'private';
  690. $s->visibility = 'private';
  691. }
  692. $s->is_nsfw = true;
  693. $s->save();
  694. StatusService::del($s->id, true);
  695. });
  696. Cache::forget('pf:bouncer_v0:exemption_by_pid:'.$status->profile_id);
  697. Cache::forget('pf:bouncer_v0:recent_by_pid:'.$status->profile_id);
  698. Cache::forget('admin-dash:reports:spam-count');
  699. } elseif ($action == 'cw') {
  700. $state = $status->is_nsfw;
  701. $status->is_nsfw = ! $state;
  702. $status->save();
  703. StatusService::del($status->id);
  704. } elseif ($action == 'mark-public') {
  705. $state = $status->scope;
  706. $status->scope = 'public';
  707. $status->visibility = 'public';
  708. $status->save();
  709. StatusService::del($status->id, true);
  710. if ($state !== 'public') {
  711. if ($status->uri) {
  712. if ($status->in_reply_to_id == null && $status->reblog_of_id == null) {
  713. NetworkTimelineService::add($status->id);
  714. }
  715. } else {
  716. if ($status->in_reply_to_id == null && $status->reblog_of_id == null) {
  717. PublicTimelineService::add($status->id);
  718. }
  719. }
  720. }
  721. } elseif ($action == 'mark-unlisted') {
  722. $state = $status->scope;
  723. $status->scope = 'unlisted';
  724. $status->visibility = 'unlisted';
  725. $status->save();
  726. StatusService::del($status->id);
  727. if ($state == 'public') {
  728. PublicTimelineService::del($status->id);
  729. NetworkTimelineService::del($status->id);
  730. }
  731. } elseif ($action == 'mark-private') {
  732. $state = $status->scope;
  733. $status->scope = 'private';
  734. $status->visibility = 'private';
  735. $status->save();
  736. StatusService::del($status->id);
  737. if ($state == 'public') {
  738. PublicTimelineService::del($status->id);
  739. NetworkTimelineService::del($status->id);
  740. }
  741. } elseif ($action == 'delete') {
  742. PublicTimelineService::del($status->id);
  743. NetworkTimelineService::del($status->id);
  744. Cache::forget('_api:statuses:recent_9:'.$status->profile_id);
  745. Cache::forget('profile:status_count:'.$status->profile_id);
  746. Cache::forget('profile:embed:'.$status->profile_id);
  747. StatusService::del($status->id, true);
  748. Cache::forget('profile:status_count:'.$status->profile_id);
  749. $status->uri ? RemoteStatusDelete::dispatch($status) : StatusDelete::dispatch($status);
  750. return [];
  751. }
  752. Cache::forget('_api:statuses:recent_9:'.$status->profile_id);
  753. return StatusService::get($status->id, false);
  754. }
  755. public function getWebSettings(Request $request)
  756. {
  757. abort_if(! $request->user() || ! $request->user()->token(), 403);
  758. abort_unless($request->user()->tokenCan('read'), 403);
  759. $uid = $request->user()->id;
  760. $settings = UserSetting::firstOrCreate([
  761. 'user_id' => $uid,
  762. ]);
  763. if (! $settings->other) {
  764. return [];
  765. }
  766. return $settings->other;
  767. }
  768. public function setWebSettings(Request $request)
  769. {
  770. abort_if(! $request->user() || ! $request->user()->token(), 403);
  771. abort_unless($request->user()->tokenCan('write'), 403);
  772. $this->validate($request, [
  773. 'field' => 'required|in:enable_reblogs,hide_reblog_banner',
  774. 'value' => 'required',
  775. ]);
  776. $field = $request->input('field');
  777. $value = $request->input('value');
  778. $settings = UserSetting::firstOrCreate([
  779. 'user_id' => $request->user()->id,
  780. ]);
  781. if (! $settings->other) {
  782. $other = [];
  783. } else {
  784. $other = $settings->other;
  785. }
  786. $other[$field] = $value;
  787. $settings->other = $other;
  788. $settings->save();
  789. return [200];
  790. }
  791. public function getMutualAccounts(Request $request, $id)
  792. {
  793. abort_if(! $request->user() || ! $request->user()->token(), 403);
  794. abort_unless($request->user()->tokenCan('follow'), 403);
  795. $account = AccountService::get($id, true);
  796. if (! $account || ! isset($account['id'])) {
  797. return [];
  798. }
  799. $res = collect(FollowerService::mutualAccounts($request->user()->profile_id, $id))
  800. ->map(function ($accountId) {
  801. return AccountService::get($accountId, true);
  802. })
  803. ->filter()
  804. ->take(24)
  805. ->values();
  806. return $this->json($res);
  807. }
  808. public function accountUsernameToId(Request $request, $username)
  809. {
  810. abort_if(! $request->user() || ! $request->user()->token() || ! $username, 403);
  811. abort_unless($request->user()->tokenCan('read'), 403);
  812. $username = trim($username);
  813. $rateLimiting = (bool) config_cache('api.rate-limits.v1Dot1.accounts.usernameToId.enabled');
  814. $ipRateLimiting = (bool) config_cache('api.rate-limits.v1Dot1.accounts.usernameToId.ip_enabled');
  815. if ($ipRateLimiting) {
  816. $userLimit = (int) config_cache('api.rate-limits.v1Dot1.accounts.usernameToId.ip_limit');
  817. $userDecay = (int) config_cache('api.rate-limits.v1Dot1.accounts.usernameToId.ip_decay');
  818. $userKey = 'pf:apiv1.1:acctU2ID:byIp:'.$request->ip();
  819. if (RateLimiter::tooManyAttempts($userKey, $userLimit)) {
  820. $limits = [
  821. 'X-Rate-Limit-Limit' => $userLimit,
  822. 'X-Rate-Limit-Remaining' => RateLimiter::remaining($userKey, $userLimit),
  823. 'X-Rate-Limit-Reset' => RateLimiter::availableIn($userKey),
  824. ];
  825. return $this->json(['error' => 'Too many attempts!'], 429, $limits);
  826. }
  827. RateLimiter::increment($userKey, $userDecay);
  828. $limits = [
  829. 'X-Rate-Limit-Limit' => $userLimit,
  830. 'X-Rate-Limit-Remaining' => RateLimiter::remaining($userKey, $userLimit),
  831. 'X-Rate-Limit-Reset' => RateLimiter::availableIn($userKey),
  832. ];
  833. }
  834. if ($rateLimiting) {
  835. $userLimit = (int) config_cache('api.rate-limits.v1Dot1.accounts.usernameToId.limit');
  836. $userDecay = (int) config_cache('api.rate-limits.v1Dot1.accounts.usernameToId.decay');
  837. $userKey = 'pf:apiv1.1:acctU2ID:byUid:'.$request->user()->id;
  838. if (RateLimiter::tooManyAttempts($userKey, $userLimit)) {
  839. $limits = [
  840. 'X-Rate-Limit-Limit' => $userLimit,
  841. 'X-Rate-Limit-Remaining' => RateLimiter::remaining($userKey, $userLimit),
  842. 'X-Rate-Limit-Reset' => RateLimiter::availableIn($userKey),
  843. ];
  844. return $this->json(['error' => 'Too many attempts!'], 429, $limits);
  845. }
  846. RateLimiter::increment($userKey, $userDecay);
  847. $limits = [
  848. 'X-Rate-Limit-Limit' => $userLimit,
  849. 'X-Rate-Limit-Remaining' => RateLimiter::remaining($userKey, $userLimit),
  850. 'X-Rate-Limit-Reset' => RateLimiter::availableIn($userKey),
  851. ];
  852. }
  853. if (str_ends_with($username, config_cache('pixelfed.domain.app'))) {
  854. $pre = str_starts_with($username, '@') ? substr($username, 1) : $username;
  855. $parts = explode('@', $pre);
  856. $username = $parts[0];
  857. }
  858. $accountId = AccountService::usernameToId($username, true);
  859. if (! $accountId) {
  860. return [];
  861. }
  862. $account = AccountService::get($accountId);
  863. return $this->json($account, 200, $rateLimiting ? $limits : []);
  864. }
  865. public function getExpoPushNotifications(Request $request)
  866. {
  867. abort_if(! $request->user() || ! $request->user()->token(), 403);
  868. abort_unless($request->user()->tokenCan('push'), 403);
  869. abort_unless(config('services.expo.access_token') && strlen(config('services.expo.access_token')) > 10, 404, 'Push notifications are not supported on this server.');
  870. $user = $request->user();
  871. $res = [
  872. 'expo_token' => (bool) $user->expo_token,
  873. 'notify_like' => (bool) $user->notify_like,
  874. 'notify_follow' => (bool) $user->notify_follow,
  875. 'notify_mention' => (bool) $user->notify_mention,
  876. 'notify_comment' => (bool) $user->notify_comment,
  877. ];
  878. return $this->json($res);
  879. }
  880. public function disableExpoPushNotifications(Request $request)
  881. {
  882. abort_if(! $request->user() || ! $request->user()->token(), 403);
  883. abort_unless($request->user()->tokenCan('push'), 403);
  884. abort_unless(config('services.expo.access_token') && strlen(config('services.expo.access_token')) > 10, 404, 'Push notifications are not supported on this server.');
  885. $request->user()->update([
  886. 'expo_token' => null,
  887. ]);
  888. return $this->json(['expo_token' => null]);
  889. }
  890. public function updateExpoPushNotifications(Request $request)
  891. {
  892. abort_if(! $request->user() || ! $request->user()->token(), 403);
  893. abort_unless($request->user()->tokenCan('push'), 403);
  894. abort_unless(config('services.expo.access_token') && strlen(config('services.expo.access_token')) > 10, 404, 'Push notifications are not supported on this server.');
  895. $this->validate($request, [
  896. 'expo_token' => ['required', ExpoPushToken::rule()],
  897. 'notify_like' => 'sometimes',
  898. 'notify_follow' => 'sometimes',
  899. 'notify_mention' => 'sometimes',
  900. 'notify_comment' => 'sometimes',
  901. ]);
  902. $user = $request->user()->update([
  903. 'expo_token' => $request->input('expo_token'),
  904. 'notify_like' => $request->has('notify_like') && $request->boolean('notify_like'),
  905. 'notify_follow' => $request->has('notify_follow') && $request->boolean('notify_follow'),
  906. 'notify_mention' => $request->has('notify_mention') && $request->boolean('notify_mention'),
  907. 'notify_comment' => $request->has('notify_comment') && $request->boolean('notify_comment'),
  908. ]);
  909. $res = [
  910. 'expo_token' => (bool) $request->user()->expo_token,
  911. 'notify_like' => (bool) $request->user()->notify_like,
  912. 'notify_follow' => (bool) $request->user()->notify_follow,
  913. 'notify_mention' => (bool) $request->user()->notify_mention,
  914. 'notify_comment' => (bool) $request->user()->notify_comment,
  915. ];
  916. return $this->json($res);
  917. }
  918. /**
  919. * POST /api/v1.1/status/create
  920. *
  921. *
  922. * @return StatusTransformer
  923. */
  924. public function statusCreate(Request $request)
  925. {
  926. abort_if(! $request->user() || ! $request->user()->token(), 403);
  927. abort_unless($request->user()->tokenCan('write'), 403);
  928. $this->validate($request, [
  929. 'status' => 'nullable|string|max:'.(int) config_cache('pixelfed.max_caption_length'),
  930. 'file' => [
  931. 'required',
  932. 'file',
  933. 'mimetypes:'.config_cache('pixelfed.media_types'),
  934. 'max:'.config_cache('pixelfed.max_photo_size'),
  935. function ($attribute, $value, $fail) {
  936. if (is_array($value) && count($value) > 1) {
  937. $fail('Only one file can be uploaded at a time.');
  938. }
  939. },
  940. ],
  941. 'sensitive' => 'nullable',
  942. 'visibility' => 'string|in:private,unlisted,public',
  943. 'spoiler_text' => 'sometimes|max:140',
  944. ]);
  945. if ($request->hasHeader('idempotency-key')) {
  946. $key = 'pf:api:v1:status:idempotency-key:'.$request->user()->id.':'.hash('sha1', $request->header('idempotency-key'));
  947. $exists = Cache::has($key);
  948. abort_if($exists, 400, 'Duplicate idempotency key.');
  949. Cache::put($key, 1, 3600);
  950. }
  951. if (config('costar.enabled') == true) {
  952. $blockedKeywords = config('costar.keyword.block');
  953. if ($blockedKeywords !== null && $request->status) {
  954. $keywords = config('costar.keyword.block');
  955. foreach ($keywords as $kw) {
  956. if (Str::contains($request->status, $kw) == true) {
  957. abort(400, 'Invalid object. Contains banned keyword.');
  958. }
  959. }
  960. }
  961. }
  962. $user = $request->user();
  963. if ($user->has_roles) {
  964. abort_if(! UserRoleService::can('can-post', $user->id), 403, 'Invalid permissions for this action');
  965. }
  966. $profile = $user->profile;
  967. $limitKey = 'compose:rate-limit:media-upload:'.$user->id;
  968. $photo = $request->file('file');
  969. $fileSize = $photo->getSize();
  970. $sizeInKbs = (int) ceil($fileSize / 1000);
  971. $accountSize = UserStorageService::get($user->id);
  972. abort_if($accountSize === -1, 403, 'Invalid request.');
  973. $updatedAccountSize = (int) $accountSize + (int) $sizeInKbs;
  974. if ((bool) config_cache('pixelfed.enforce_account_limit') == true) {
  975. $limit = (int) config_cache('pixelfed.max_account_size');
  976. if ($updatedAccountSize >= $limit) {
  977. abort(403, 'Account size limit reached.');
  978. }
  979. }
  980. $mimes = explode(',', config_cache('pixelfed.media_types'));
  981. if (in_array($photo->getMimeType(), $mimes) == false) {
  982. abort(403, 'Invalid or unsupported mime type.');
  983. }
  984. $storagePath = MediaPathService::get($user, 2);
  985. $path = $photo->storePublicly($storagePath);
  986. $hash = \hash_file('sha256', $photo);
  987. $license = null;
  988. $mime = $photo->getMimeType();
  989. $settings = UserSetting::whereUserId($user->id)->first();
  990. if ($settings && ! empty($settings->compose_settings)) {
  991. $compose = $settings->compose_settings;
  992. if (isset($compose['default_license']) && $compose['default_license'] != 1) {
  993. $license = $compose['default_license'];
  994. }
  995. }
  996. abort_if(MediaBlocklistService::exists($hash) == true, 451);
  997. $visibility = $profile->is_private ? 'private' : (
  998. $profile->unlisted == true &&
  999. $request->input('visibility', 'public') == 'public' ?
  1000. 'unlisted' :
  1001. $request->input('visibility', 'public'));
  1002. if ($user->last_active_at == null) {
  1003. return [];
  1004. }
  1005. $content = strip_tags($request->input('status'));
  1006. $rendered = Autolink::create()->autolink($content);
  1007. $cw = $user->profile->cw == true ? true : $request->boolean('sensitive', false);
  1008. $spoilerText = $cw && $request->filled('spoiler_text') ? $request->input('spoiler_text') : null;
  1009. $status = new Status;
  1010. $status->caption = $content;
  1011. $status->rendered = $rendered;
  1012. $status->profile_id = $user->profile_id;
  1013. $status->is_nsfw = $cw;
  1014. $status->cw_summary = $spoilerText;
  1015. $status->scope = $visibility;
  1016. $status->visibility = $visibility;
  1017. $status->type = StatusController::mimeTypeCheck([$mime]);
  1018. $status->save();
  1019. if (! $status) {
  1020. abort(500, 'An error occured.');
  1021. }
  1022. $media = new Media();
  1023. $media->status_id = $status->id;
  1024. $media->profile_id = $profile->id;
  1025. $media->user_id = $user->id;
  1026. $media->media_path = $path;
  1027. $media->original_sha256 = $hash;
  1028. $media->size = $photo->getSize();
  1029. $media->mime = $mime;
  1030. $media->order = 1;
  1031. $media->caption = $request->input('description');
  1032. if ($license) {
  1033. $media->license = $license;
  1034. }
  1035. $media->save();
  1036. switch ($media->mime) {
  1037. case 'image/jpeg':
  1038. case 'image/png':
  1039. ImageOptimize::dispatch($media)->onQueue('mmo');
  1040. break;
  1041. case 'video/mp4':
  1042. VideoThumbnail::dispatch($media)->onQueue('mmo');
  1043. $preview_url = '/storage/no-preview.png';
  1044. $url = '/storage/no-preview.png';
  1045. break;
  1046. }
  1047. $user->storage_used = (int) $updatedAccountSize;
  1048. $user->storage_used_updated_at = now();
  1049. $user->save();
  1050. NewStatusPipeline::dispatch($status);
  1051. Cache::forget('user:account:id:'.$user->id);
  1052. Cache::forget('_api:statuses:recent_9:'.$user->profile_id);
  1053. Cache::forget('profile:status_count:'.$user->profile_id);
  1054. Cache::forget($user->storageUsedKey());
  1055. Cache::forget('profile:embed:'.$status->profile_id);
  1056. Cache::forget($limitKey);
  1057. $res = StatusService::getMastodon($status->id, false);
  1058. $res['favourited'] = false;
  1059. $res['language'] = 'en';
  1060. $res['bookmarked'] = false;
  1061. $res['card'] = null;
  1062. return $this->json($res);
  1063. }
  1064. }