AdminController.php 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488
  1. <?php
  2. namespace App\Http\Controllers;
  3. use App\{
  4. AccountInterstitial,
  5. Contact,
  6. Hashtag,
  7. Newsroom,
  8. OauthClient,
  9. Profile,
  10. Report,
  11. Status,
  12. Story,
  13. User
  14. };
  15. use DB, Cache, Storage;
  16. use Carbon\Carbon;
  17. use Illuminate\Http\Request;
  18. use Illuminate\Support\Facades\Redis;
  19. use App\Http\Controllers\Admin\{
  20. AdminDiscoverController,
  21. AdminInstanceController,
  22. AdminReportController,
  23. // AdminGroupsController,
  24. AdminMediaController,
  25. AdminSettingsController,
  26. // AdminStorageController,
  27. AdminSupportController,
  28. AdminUserController
  29. };
  30. use Illuminate\Validation\Rule;
  31. use App\Services\AdminStatsService;
  32. use App\Services\StatusService;
  33. use App\Services\StoryService;
  34. use App\Models\CustomEmoji;
  35. class AdminController extends Controller
  36. {
  37. use AdminReportController,
  38. AdminDiscoverController,
  39. // AdminGroupsController,
  40. AdminMediaController,
  41. AdminSettingsController,
  42. AdminInstanceController,
  43. // AdminStorageController,
  44. AdminUserController;
  45. public function __construct()
  46. {
  47. $this->middleware('admin');
  48. $this->middleware('dangerzone');
  49. $this->middleware('twofactor');
  50. }
  51. public function home()
  52. {
  53. $data = AdminStatsService::get();
  54. return view('admin.home', compact('data'));
  55. }
  56. public function statuses(Request $request)
  57. {
  58. $statuses = Status::orderBy('id', 'desc')->cursorPaginate(10);
  59. $data = $statuses->map(function($status) {
  60. return StatusService::get($status->id, false);
  61. })
  62. ->filter(function($s) {
  63. return $s;
  64. })
  65. ->toArray();
  66. return view('admin.statuses.home', compact('statuses', 'data'));
  67. }
  68. public function showStatus(Request $request, $id)
  69. {
  70. $status = Status::findOrFail($id);
  71. return view('admin.statuses.show', compact('status'));
  72. }
  73. public function profiles(Request $request)
  74. {
  75. $this->validate($request, [
  76. 'search' => 'nullable|string|max:250',
  77. 'filter' => [
  78. 'nullable',
  79. 'string',
  80. Rule::in(['all', 'local', 'remote'])
  81. ]
  82. ]);
  83. $search = $request->input('search');
  84. $filter = $request->input('filter');
  85. $limit = 12;
  86. $profiles = Profile::select('id','username')
  87. ->whereNull('status')
  88. ->when($search, function($q, $search) {
  89. return $q->where('username', 'like', "%$search%");
  90. })->when($filter, function($q, $filter) {
  91. if($filter == 'local') {
  92. return $q->whereNull('domain');
  93. }
  94. if($filter == 'remote') {
  95. return $q->whereNotNull('domain');
  96. }
  97. return $q;
  98. })->orderByDesc('id')
  99. ->simplePaginate($limit);
  100. return view('admin.profiles.home', compact('profiles'));
  101. }
  102. public function profileShow(Request $request, $id)
  103. {
  104. $profile = Profile::findOrFail($id);
  105. $user = $profile->user;
  106. return view('admin.profiles.edit', compact('profile', 'user'));
  107. }
  108. public function appsHome(Request $request)
  109. {
  110. $filter = $request->input('filter');
  111. if(in_array($filter, ['revoked'])) {
  112. $apps = OauthClient::with('user')
  113. ->whereNotNull('user_id')
  114. ->whereRevoked(true)
  115. ->orderByDesc('id')
  116. ->paginate(10);
  117. } else {
  118. $apps = OauthClient::with('user')
  119. ->whereNotNull('user_id')
  120. ->orderByDesc('id')
  121. ->paginate(10);
  122. }
  123. return view('admin.apps.home', compact('apps'));
  124. }
  125. public function hashtagsHome(Request $request)
  126. {
  127. $hashtags = Hashtag::orderByDesc('id')->paginate(10);
  128. return view('admin.hashtags.home', compact('hashtags'));
  129. }
  130. public function messagesHome(Request $request)
  131. {
  132. $messages = Contact::orderByDesc('id')->paginate(10);
  133. return view('admin.messages.home', compact('messages'));
  134. }
  135. public function messagesShow(Request $request, $id)
  136. {
  137. $message = Contact::findOrFail($id);
  138. return view('admin.messages.show', compact('message'));
  139. }
  140. public function messagesMarkRead(Request $request)
  141. {
  142. $this->validate($request, [
  143. 'id' => 'required|integer|min:1'
  144. ]);
  145. $id = $request->input('id');
  146. $message = Contact::findOrFail($id);
  147. if($message->read_at) {
  148. return;
  149. }
  150. $message->read_at = now();
  151. $message->save();
  152. return;
  153. }
  154. public function newsroomHome(Request $request)
  155. {
  156. $newsroom = Newsroom::latest()->paginate(10);
  157. return view('admin.newsroom.home', compact('newsroom'));
  158. }
  159. public function newsroomCreate(Request $request)
  160. {
  161. return view('admin.newsroom.create');
  162. }
  163. public function newsroomEdit(Request $request, $id)
  164. {
  165. $news = Newsroom::findOrFail($id);
  166. return view('admin.newsroom.edit', compact('news'));
  167. }
  168. public function newsroomDelete(Request $request, $id)
  169. {
  170. $news = Newsroom::findOrFail($id);
  171. $news->delete();
  172. return redirect('/i/admin/newsroom');
  173. }
  174. public function newsroomUpdate(Request $request, $id)
  175. {
  176. $this->validate($request, [
  177. 'title' => 'required|string|min:1|max:100',
  178. 'summary' => 'nullable|string|max:200',
  179. 'body' => 'nullable|string'
  180. ]);
  181. $changed = false;
  182. $changedFields = [];
  183. $news = Newsroom::findOrFail($id);
  184. $fields = [
  185. 'title' => 'string',
  186. 'summary' => 'string',
  187. 'body' => 'string',
  188. 'category' => 'string',
  189. 'show_timeline' => 'boolean',
  190. 'auth_only' => 'boolean',
  191. 'show_link' => 'boolean',
  192. 'force_modal' => 'boolean',
  193. 'published' => 'published'
  194. ];
  195. foreach($fields as $field => $type) {
  196. switch ($type) {
  197. case 'string':
  198. if($request->{$field} != $news->{$field}) {
  199. if($field == 'title') {
  200. $news->slug = str_slug($request->{$field});
  201. }
  202. $news->{$field} = $request->{$field};
  203. $changed = true;
  204. array_push($changedFields, $field);
  205. }
  206. break;
  207. case 'boolean':
  208. $state = $request->{$field} == 'on' ? true : false;
  209. if($state != $news->{$field}) {
  210. $news->{$field} = $state;
  211. $changed = true;
  212. array_push($changedFields, $field);
  213. }
  214. break;
  215. case 'published':
  216. $state = $request->{$field} == 'on' ? true : false;
  217. $published = $news->published_at != null;
  218. if($state != $published) {
  219. $news->published_at = $state ? now() : null;
  220. $changed = true;
  221. array_push($changedFields, $field);
  222. }
  223. break;
  224. }
  225. }
  226. if($changed) {
  227. $news->save();
  228. }
  229. $redirect = $news->published_at ? $news->permalink() : $news->editUrl();
  230. return redirect($redirect);
  231. }
  232. public function newsroomStore(Request $request)
  233. {
  234. $this->validate($request, [
  235. 'title' => 'required|string|min:1|max:100',
  236. 'summary' => 'nullable|string|max:200',
  237. 'body' => 'nullable|string'
  238. ]);
  239. $changed = false;
  240. $changedFields = [];
  241. $news = new Newsroom();
  242. $fields = [
  243. 'title' => 'string',
  244. 'summary' => 'string',
  245. 'body' => 'string',
  246. 'category' => 'string',
  247. 'show_timeline' => 'boolean',
  248. 'auth_only' => 'boolean',
  249. 'show_link' => 'boolean',
  250. 'force_modal' => 'boolean',
  251. 'published' => 'published'
  252. ];
  253. foreach($fields as $field => $type) {
  254. switch ($type) {
  255. case 'string':
  256. if($request->{$field} != $news->{$field}) {
  257. if($field == 'title') {
  258. $news->slug = str_slug($request->{$field});
  259. }
  260. $news->{$field} = $request->{$field};
  261. $changed = true;
  262. array_push($changedFields, $field);
  263. }
  264. break;
  265. case 'boolean':
  266. $state = $request->{$field} == 'on' ? true : false;
  267. if($state != $news->{$field}) {
  268. $news->{$field} = $state;
  269. $changed = true;
  270. array_push($changedFields, $field);
  271. }
  272. break;
  273. case 'published':
  274. $state = $request->{$field} == 'on' ? true : false;
  275. $published = $news->published_at != null;
  276. if($state != $published) {
  277. $news->published_at = $state ? now() : null;
  278. $changed = true;
  279. array_push($changedFields, $field);
  280. }
  281. break;
  282. }
  283. }
  284. if($changed) {
  285. $news->save();
  286. }
  287. $redirect = $news->published_at ? $news->permalink() : $news->editUrl();
  288. return redirect($redirect);
  289. }
  290. public function diagnosticsHome(Request $request)
  291. {
  292. return view('admin.diagnostics.home');
  293. }
  294. public function diagnosticsDecrypt(Request $request)
  295. {
  296. $this->validate($request, [
  297. 'payload' => 'required'
  298. ]);
  299. $key = 'exception_report:';
  300. $decrypted = decrypt($request->input('payload'));
  301. if(!starts_with($decrypted, $key)) {
  302. abort(403, 'Can only decrypt error diagnostics');
  303. }
  304. $res = [
  305. 'decrypted' => substr($decrypted, strlen($key))
  306. ];
  307. return response()->json($res);
  308. }
  309. public function stories(Request $request)
  310. {
  311. $stories = Story::with('profile')->latest()->paginate(10);
  312. $stats = StoryService::adminStats();
  313. return view('admin.stories.home', compact('stories', 'stats'));
  314. }
  315. public function customEmojiHome(Request $request)
  316. {
  317. if(!config('federation.custom_emoji.enabled')) {
  318. return view('admin.custom-emoji.not-enabled');
  319. }
  320. $this->validate($request, [
  321. 'sort' => 'sometimes|in:all,local,remote,duplicates,disabled,search'
  322. ]);
  323. if($request->has('cc')) {
  324. Cache::forget('pf:admin:custom_emoji:stats');
  325. Cache::forget('pf:custom_emoji');
  326. return redirect(route('admin.custom-emoji'));
  327. }
  328. $sort = $request->input('sort') ?? 'all';
  329. if($sort == 'search' && empty($request->input('q'))) {
  330. return redirect(route('admin.custom-emoji'));
  331. }
  332. $pg = config('database.default') == 'pgsql';
  333. $emojis = CustomEmoji::when($sort, function($query, $sort) use($request, $pg) {
  334. if($sort == 'all') {
  335. if($pg) {
  336. return $query->latest();
  337. } else {
  338. return $query->groupBy('shortcode')->latest();
  339. }
  340. } else if($sort == 'local') {
  341. return $query->latest()->where('domain', '=', config('pixelfed.domain.app'));
  342. } else if($sort == 'remote') {
  343. return $query->latest()->where('domain', '!=', config('pixelfed.domain.app'));
  344. } else if($sort == 'duplicates') {
  345. return $query->latest()->groupBy('shortcode')->havingRaw('count(*) > 1');
  346. } else if($sort == 'disabled') {
  347. return $query->latest()->whereDisabled(true);
  348. } else if($sort == 'search') {
  349. $q = $query
  350. ->latest()
  351. ->where('shortcode', 'like', '%' . $request->input('q') . '%')
  352. ->orWhere('domain', 'like', '%' . $request->input('q') . '%');
  353. if(!$request->has('dups')) {
  354. $q = $q->groupBy('shortcode');
  355. }
  356. return $q;
  357. }
  358. })
  359. ->simplePaginate(10)
  360. ->withQueryString();
  361. $stats = Cache::remember('pf:admin:custom_emoji:stats', 43200, function() use($pg) {
  362. $res = [
  363. 'total' => CustomEmoji::count(),
  364. 'active' => CustomEmoji::whereDisabled(false)->count(),
  365. 'remote' => CustomEmoji::where('domain', '!=', config('pixelfed.domain.app'))->count(),
  366. ];
  367. if($pg) {
  368. $res['duplicate'] = CustomEmoji::select('shortcode')->groupBy('shortcode')->havingRaw('count(*) > 1')->count();
  369. } else {
  370. $res['duplicate'] = CustomEmoji::groupBy('shortcode')->havingRaw('count(*) > 1')->count();
  371. }
  372. return $res;
  373. });
  374. return view('admin.custom-emoji.home', compact('emojis', 'sort', 'stats'));
  375. }
  376. public function customEmojiToggleActive(Request $request, $id)
  377. {
  378. abort_unless(config('federation.custom_emoji.enabled'), 404);
  379. $emoji = CustomEmoji::findOrFail($id);
  380. $emoji->disabled = !$emoji->disabled;
  381. $emoji->save();
  382. $key = CustomEmoji::CACHE_KEY . str_replace(':', '', $emoji->shortcode);
  383. Cache::forget($key);
  384. return redirect()->back();
  385. }
  386. public function customEmojiAdd(Request $request)
  387. {
  388. abort_unless(config('federation.custom_emoji.enabled'), 404);
  389. return view('admin.custom-emoji.add');
  390. }
  391. public function customEmojiStore(Request $request)
  392. {
  393. abort_unless(config('federation.custom_emoji.enabled'), 404);
  394. $this->validate($request, [
  395. 'shortcode' => [
  396. 'required',
  397. 'min:3',
  398. 'max:80',
  399. 'starts_with::',
  400. 'ends_with::',
  401. Rule::unique('custom_emoji')->where(function ($query) use($request) {
  402. return $query->whereDomain(config('pixelfed.domain.app'))
  403. ->whereShortcode($request->input('shortcode'));
  404. })
  405. ],
  406. 'emoji' => 'required|file|mimetypes:jpg,png|max:' . (config('federation.custom_emoji.max_size') / 1000)
  407. ]);
  408. $emoji = new CustomEmoji;
  409. $emoji->shortcode = $request->input('shortcode');
  410. $emoji->domain = config('pixelfed.domain.app');
  411. $emoji->save();
  412. $fileName = $emoji->id . '.' . $request->emoji->extension();
  413. $request->emoji->storeAs('public/emoji', $fileName);
  414. $emoji->media_path = 'emoji/' . $fileName;
  415. $emoji->save();
  416. Cache::forget('pf:custom_emoji');
  417. return redirect(route('admin.custom-emoji'));
  418. }
  419. public function customEmojiDelete(Request $request, $id)
  420. {
  421. abort_unless(config('federation.custom_emoji.enabled'), 404);
  422. $emoji = CustomEmoji::findOrFail($id);
  423. Storage::delete("public/{$emoji->media_path}");
  424. Cache::forget('pf:custom_emoji');
  425. $emoji->delete();
  426. return redirect(route('admin.custom-emoji'));
  427. }
  428. public function customEmojiShowDuplicates(Request $request, $id)
  429. {
  430. abort_unless(config('federation.custom_emoji.enabled'), 404);
  431. $emoji = CustomEmoji::orderBy('id')->whereDisabled(false)->whereShortcode($id)->firstOrFail();
  432. $emojis = CustomEmoji::whereShortcode($id)->where('id', '!=', $emoji->id)->cursorPaginate(10);
  433. return view('admin.custom-emoji.duplicates', compact('emoji', 'emojis'));
  434. }
  435. }