CustomFilterController.php 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469
  1. <?php
  2. namespace App\Http\Controllers;
  3. use App\Models\CustomFilter;
  4. use App\Models\CustomFilterKeyword;
  5. use Illuminate\Http\Request;
  6. use Illuminate\Support\Facades\Cache;
  7. use Illuminate\Support\Facades\DB;
  8. use Illuminate\Support\Facades\Gate;
  9. class CustomFilterController extends Controller
  10. {
  11. public function index(Request $request)
  12. {
  13. abort_if(! $request->user() || ! $request->user()->token(), 403);
  14. abort_unless($request->user()->tokenCan('read'), 403);
  15. $filters = CustomFilter::where('profile_id', $request->user()->profile_id)
  16. ->unexpired()
  17. ->with(['keywords', 'statuses'])
  18. ->orderByDesc('updated_at')
  19. ->get()
  20. ->map(function ($filter) {
  21. return [
  22. 'id' => $filter->id,
  23. 'title' => $filter->title,
  24. 'context' => $filter->context,
  25. 'expires_at' => $filter->expires_at,
  26. 'filter_action' => $filter->filterAction,
  27. 'keywords' => $filter->keywords->map(function ($keyword) {
  28. return [
  29. 'id' => $keyword->id,
  30. 'keyword' => $keyword->keyword,
  31. 'whole_word' => (bool) $keyword->whole_word,
  32. ];
  33. }),
  34. 'statuses' => $filter->statuses->map(function ($status) {
  35. return [
  36. 'id' => $status->id,
  37. 'status_id' => $status->status_id,
  38. ];
  39. }),
  40. ];
  41. });
  42. return response()->json($filters);
  43. }
  44. public function show(Request $request, $id)
  45. {
  46. abort_if(! $request->user() || ! $request->user()->token(), 403);
  47. abort_unless($request->user()->tokenCan('read'), 403);
  48. $filter = CustomFilter::findOrFail($id);
  49. Gate::authorize('view', $filter);
  50. $filter->load(['keywords', 'statuses']);
  51. $res = [
  52. 'id' => $filter->id,
  53. 'title' => $filter->title,
  54. 'context' => $filter->context,
  55. 'expires_at' => $filter->expires_at,
  56. 'filter_action' => $filter->filterAction,
  57. 'keywords' => $filter->keywords->map(function ($keyword) {
  58. return [
  59. 'id' => $keyword->id,
  60. 'keyword' => $keyword->keyword,
  61. 'whole_word' => (bool) $keyword->whole_word,
  62. ];
  63. }),
  64. 'statuses' => $filter->statuses->map(function ($status) {
  65. return [
  66. 'id' => $status->id,
  67. 'status_id' => $status->status_id,
  68. ];
  69. }),
  70. ];
  71. return response()->json($res);
  72. }
  73. public function store(Request $request)
  74. {
  75. abort_if(! $request->user() || ! $request->user()->token(), 403);
  76. abort_unless($request->user()->tokenCan('write'), 403);
  77. Gate::authorize('create', CustomFilter::class);
  78. $validatedData = $request->validate([
  79. 'title' => 'required|string|max:100',
  80. 'context' => 'required|array',
  81. 'context.*' => 'string|in:home,notifications,public,thread,account,tags,groups',
  82. 'filter_action' => 'string|in:warn,hide,blur',
  83. 'expires_in' => 'nullable|integer|min:0|max:63072000',
  84. 'keywords_attributes' => 'required|array|min:1|max:'.CustomFilter::MAX_KEYWORDS_PER_FILTER,
  85. 'keywords_attributes.*.keyword' => [
  86. 'required',
  87. 'string',
  88. 'min:1',
  89. 'max:'.CustomFilter::MAX_KEYWORD_LEN,
  90. 'regex:/^[\p{L}\p{N}\p{Zs}\p{P}\p{M}]+$/u',
  91. function ($attribute, $value, $fail) {
  92. if (preg_match('/(.)\1{20,}/', $value)) {
  93. $fail('The keyword contains excessive character repetition.');
  94. }
  95. },
  96. ],
  97. 'keywords_attributes.*.whole_word' => 'boolean',
  98. ]);
  99. $rateKey = 'filters_created:'.$request->user()->id;
  100. $maxFiltersPerHour = CustomFilter::MAX_PER_HOUR;
  101. $currentCount = Cache::get($rateKey, 0);
  102. if ($currentCount >= $maxFiltersPerHour) {
  103. return response()->json([
  104. 'error' => 'Rate limit exceeded',
  105. 'message' => 'You can only create '.$maxFiltersPerHour.' filters per hour.',
  106. ], 429);
  107. }
  108. DB::beginTransaction();
  109. try {
  110. $profile_id = $request->user()->profile_id;
  111. $requestedKeywords = array_map(function ($item) {
  112. return $item['keyword'];
  113. }, $validatedData['keywords_attributes']);
  114. $existingKeywords = DB::table('custom_filter_keywords')
  115. ->join('custom_filters', 'custom_filter_keywords.custom_filter_id', '=', 'custom_filters.id')
  116. ->where('custom_filters.profile_id', $profile_id)
  117. ->whereIn('custom_filter_keywords.keyword', $requestedKeywords)
  118. ->pluck('custom_filter_keywords.keyword')
  119. ->toArray();
  120. if (! empty($existingKeywords)) {
  121. return response()->json([
  122. 'error' => 'Duplicate keywords found',
  123. 'message' => 'The following keywords already exist: '.implode(', ', $existingKeywords),
  124. ], 422);
  125. }
  126. $userFilterCount = CustomFilter::where('profile_id', $profile_id)->count();
  127. $maxFiltersPerUser = CustomFilter::MAX_LIMIT;
  128. if ($userFilterCount >= $maxFiltersPerUser) {
  129. return response()->json([
  130. 'error' => 'Filter limit exceeded',
  131. 'message' => 'You can only have '.$maxFiltersPerUser.' filters at a time.',
  132. ], 422);
  133. }
  134. $expiresAt = null;
  135. if (isset($validatedData['expires_in']) && $validatedData['expires_in'] > 0) {
  136. $expiresAt = now()->addSeconds($validatedData['expires_in']);
  137. }
  138. $action = CustomFilter::ACTION_WARN;
  139. if (isset($validatedData['filter_action'])) {
  140. $action = $this->filterActionToAction($validatedData['filter_action']);
  141. }
  142. $filter = CustomFilter::create([
  143. 'title' => $validatedData['title'],
  144. 'context' => $validatedData['context'],
  145. 'action' => $action,
  146. 'expires_at' => $expiresAt,
  147. 'profile_id' => $request->user()->profile_id,
  148. ]);
  149. if (isset($validatedData['keywords_attributes'])) {
  150. foreach ($validatedData['keywords_attributes'] as $keywordData) {
  151. $keyword = trim($keywordData['keyword']);
  152. $filter->keywords()->create([
  153. 'keyword' => $keyword,
  154. 'whole_word' => (bool) $keywordData['whole_word'] ?? true,
  155. ]);
  156. }
  157. }
  158. Cache::increment($rateKey);
  159. if (! Cache::has($rateKey)) {
  160. Cache::put($rateKey, 1, 3600);
  161. }
  162. Cache::forget("filters:v3:{$profile_id}");
  163. DB::commit();
  164. $filter->load(['keywords', 'statuses']);
  165. $res = [
  166. 'id' => $filter->id,
  167. 'title' => $filter->title,
  168. 'context' => $filter->context,
  169. 'expires_at' => $filter->expires_at,
  170. 'filter_action' => $filter->filterAction,
  171. 'keywords' => $filter->keywords->map(function ($keyword) {
  172. return [
  173. 'id' => $keyword->id,
  174. 'keyword' => $keyword->keyword,
  175. 'whole_word' => (bool) $keyword->whole_word,
  176. ];
  177. }),
  178. 'statuses' => $filter->statuses->map(function ($status) {
  179. return [
  180. 'id' => $status->id,
  181. 'status_id' => $status->status_id,
  182. ];
  183. }),
  184. ];
  185. return response()->json($res, 200);
  186. } catch (\Exception $e) {
  187. DB::rollBack();
  188. return response()->json([
  189. 'error' => 'Failed to create filter',
  190. 'message' => $e->getMessage(),
  191. ], 500);
  192. }
  193. }
  194. /**
  195. * Convert Mastodon filter_action string to internal action value
  196. *
  197. * @param string $filterAction
  198. * @return int
  199. */
  200. private function filterActionToAction($filterAction)
  201. {
  202. switch ($filterAction) {
  203. case 'warn':
  204. return CustomFilter::ACTION_WARN;
  205. case 'hide':
  206. return CustomFilter::ACTION_HIDE;
  207. case 'blur':
  208. return CustomFilter::ACTION_BLUR;
  209. default:
  210. return CustomFilter::ACTION_WARN;
  211. }
  212. }
  213. public function update(Request $request, $id)
  214. {
  215. abort_if(! $request->user() || ! $request->user()->token(), 403);
  216. abort_unless($request->user()->tokenCan('write'), 403);
  217. $filter = CustomFilter::findOrFail($id);
  218. Gate::authorize('update', $filter);
  219. $validatedData = $request->validate([
  220. 'title' => 'string|max:100',
  221. 'context' => 'array|max:10',
  222. 'context.*' => 'string|in:home,notifications,public,thread,account,tags,groups',
  223. 'filter_action' => 'string|in:warn,hide,blur',
  224. 'expires_in' => 'nullable|integer|min:0|max:63072000',
  225. 'keywords_attributes' => 'required|array|min:1|max:'.CustomFilter::MAX_KEYWORDS_PER_FILTER,
  226. 'keywords_attributes.*.id' => 'nullable|integer|exists:custom_filter_keywords,id',
  227. 'keywords_attributes.*.keyword' => [
  228. 'required_without:keywords_attributes.*.id',
  229. 'string',
  230. 'min:1',
  231. 'max:'.CustomFilter::MAX_KEYWORD_LEN,
  232. 'regex:/^[\p{L}\p{N}\p{Zs}\p{P}\p{M}]+$/u',
  233. function ($attribute, $value, $fail) {
  234. if (preg_match('/(.)\1{20,}/', $value)) {
  235. $fail('The keyword contains excessive character repetition.');
  236. }
  237. },
  238. ],
  239. 'keywords_attributes.*.whole_word' => 'boolean',
  240. 'keywords_attributes.*._destroy' => 'boolean',
  241. ]);
  242. $rateKey = 'filters_updated:'.$request->user()->id;
  243. $maxUpdatesPerHour = CustomFilter::MAX_UPDATES_PER_HOUR;
  244. $currentCount = Cache::get($rateKey, 0);
  245. if ($currentCount >= $maxUpdatesPerHour) {
  246. return response()->json([
  247. 'error' => 'Rate limit exceeded',
  248. 'message' => 'You can only update filters '.$maxUpdatesPerHour.' times per hour.',
  249. ], 429);
  250. }
  251. DB::beginTransaction();
  252. try {
  253. $pid = $request->user()->profile_id;
  254. $requestedKeywords = [];
  255. foreach ($validatedData['keywords_attributes'] as $item) {
  256. if (isset($item['keyword']) && (! isset($item['_destroy']) || ! $item['_destroy'])) {
  257. $requestedKeywords[] = $item['keyword'];
  258. }
  259. }
  260. if (! empty($requestedKeywords)) {
  261. $existingKeywords = DB::table('custom_filter_keywords')
  262. ->join('custom_filters', 'custom_filter_keywords.custom_filter_id', '=', 'custom_filters.id')
  263. ->where('custom_filters.profile_id', $pid)
  264. ->where('custom_filter_keywords.custom_filter_id', '!=', $id)
  265. ->whereIn('custom_filter_keywords.keyword', $requestedKeywords)
  266. ->pluck('custom_filter_keywords.keyword')
  267. ->toArray();
  268. if (! empty($existingKeywords)) {
  269. return response()->json([
  270. 'error' => 'Duplicate keywords found',
  271. 'message' => 'The following keywords already exist: '.implode(', ', $existingKeywords),
  272. ], 422);
  273. }
  274. }
  275. if (isset($validatedData['expires_in'])) {
  276. if ($validatedData['expires_in'] > 0) {
  277. $filter->expires_at = now()->addSeconds($validatedData['expires_in']);
  278. } else {
  279. $filter->expires_at = null;
  280. }
  281. }
  282. if (isset($validatedData['title'])) {
  283. $filter->title = $validatedData['title'];
  284. }
  285. if (isset($validatedData['context'])) {
  286. $filter->context = $validatedData['context'];
  287. }
  288. if (isset($validatedData['filter_action'])) {
  289. $filter->action = $this->filterActionToAction($validatedData['filter_action']);
  290. }
  291. $filter->save();
  292. if (isset($validatedData['keywords_attributes'])) {
  293. $existingKeywords = $filter->keywords()->pluck('id')->toArray();
  294. $processedIds = [];
  295. foreach ($validatedData['keywords_attributes'] as $keywordData) {
  296. // Case 1: Explicit deletion with _destroy flag
  297. if (isset($keywordData['id']) && isset($keywordData['_destroy']) && $keywordData['_destroy']) {
  298. // Verify this ID belongs to this filter before deletion
  299. $kwf = CustomFilterKeyword::where('custom_filter_id', $filter->id)
  300. ->where('id', $keywordData['id'])
  301. ->first();
  302. if ($kwf) {
  303. $kwf->delete();
  304. $processedIds[] = $keywordData['id'];
  305. }
  306. }
  307. // Case 2: Update existing keyword
  308. elseif (isset($keywordData['id'])) {
  309. // Skip if we've already processed this ID
  310. if (in_array($keywordData['id'], $processedIds)) {
  311. continue;
  312. }
  313. // Verify this ID belongs to this filter before updating
  314. $keyword = CustomFilterKeyword::where('custom_filter_id', $filter->id)
  315. ->where('id', $keywordData['id'])
  316. ->first();
  317. if ($keyword) {
  318. $updateData = [];
  319. if (isset($keywordData['keyword'])) {
  320. $updateData['keyword'] = trim($keywordData['keyword']);
  321. }
  322. if (isset($keywordData['whole_word'])) {
  323. $updateData['whole_word'] = (bool) $keywordData['whole_word'];
  324. }
  325. if (! empty($updateData)) {
  326. $keyword->update($updateData);
  327. }
  328. $processedIds[] = $keywordData['id'];
  329. }
  330. }
  331. // Case 3: Create new keyword
  332. elseif (isset($keywordData['keyword'])) {
  333. // Check if we're about to exceed the keyword limit
  334. $existingKeywordCount = $filter->keywords()->count();
  335. $maxKeywordsPerFilter = CustomFilter::MAX_KEYWORDS_PER_FILTER;
  336. if ($existingKeywordCount >= $maxKeywordsPerFilter) {
  337. return response()->json([
  338. 'error' => 'Keyword limit exceeded',
  339. 'message' => 'A filter can have a maximum of '.$maxKeywordsPerFilter.' keywords.',
  340. ], 422);
  341. }
  342. $filter->keywords()->create([
  343. 'keyword' => trim($keywordData['keyword']),
  344. 'whole_word' => (bool) ($keywordData['whole_word'] ?? true),
  345. ]);
  346. }
  347. }
  348. }
  349. Cache::increment($rateKey);
  350. if (! Cache::has($rateKey)) {
  351. Cache::put($rateKey, 1, 3600);
  352. }
  353. Cache::forget("filters:v3:{$request->user()->profile_id}");
  354. DB::commit();
  355. $filter->load(['keywords', 'statuses']);
  356. $res = [
  357. 'id' => $filter->id,
  358. 'title' => $filter->title,
  359. 'context' => $filter->context,
  360. 'expires_at' => $filter->expires_at,
  361. 'filter_action' => $filter->filterAction,
  362. 'keywords' => $filter->keywords->map(function ($keyword) {
  363. return [
  364. 'id' => $keyword->id,
  365. 'keyword' => $keyword->keyword,
  366. 'whole_word' => (bool) $keyword->whole_word,
  367. ];
  368. }),
  369. 'statuses' => $filter->statuses->map(function ($status) {
  370. return [
  371. 'id' => $status->id,
  372. 'status_id' => $status->status_id,
  373. ];
  374. }),
  375. ];
  376. return response()->json($res);
  377. } catch (\Exception $e) {
  378. DB::rollBack();
  379. return response()->json([
  380. 'error' => 'Failed to update filter',
  381. 'message' => $e->getMessage(),
  382. ], 500);
  383. }
  384. }
  385. public function delete(Request $request, $id)
  386. {
  387. abort_if(! $request->user() || ! $request->user()->token(), 403);
  388. abort_unless($request->user()->tokenCan('write'), 403);
  389. $filter = CustomFilter::findOrFail($id);
  390. Gate::authorize('delete', $filter);
  391. $filter->delete();
  392. return response()->json([], 200);
  393. }
  394. }