InternalApiController.php 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479
  1. <?php
  2. namespace App\Http\Controllers;
  3. use Illuminate\Http\Request;
  4. use App\{
  5. AccountInterstitial,
  6. Bookmark,
  7. DirectMessage,
  8. DiscoverCategory,
  9. Hashtag,
  10. Follower,
  11. Like,
  12. Media,
  13. MediaTag,
  14. Notification,
  15. Profile,
  16. StatusHashtag,
  17. Status,
  18. UserFilter,
  19. };
  20. use Auth,Cache;
  21. use Illuminate\Support\Facades\Redis;
  22. use Carbon\Carbon;
  23. use League\Fractal;
  24. use App\Transformer\Api\{
  25. AccountTransformer,
  26. StatusTransformer,
  27. // StatusMediaContainerTransformer,
  28. };
  29. use App\Util\Media\Filter;
  30. use App\Jobs\StatusPipeline\NewStatusPipeline;
  31. use App\Jobs\ModPipeline\HandleSpammerPipeline;
  32. use League\Fractal\Serializer\ArraySerializer;
  33. use League\Fractal\Pagination\IlluminatePaginatorAdapter;
  34. use Illuminate\Validation\Rule;
  35. use Illuminate\Support\Str;
  36. use App\Services\MediaTagService;
  37. use App\Services\ModLogService;
  38. use App\Services\PublicTimelineService;
  39. use App\Services\SnowflakeService;
  40. use App\Services\StatusService;
  41. class InternalApiController extends Controller
  42. {
  43. protected $fractal;
  44. public function __construct()
  45. {
  46. $this->middleware('auth');
  47. $this->fractal = new Fractal\Manager();
  48. $this->fractal->setSerializer(new ArraySerializer());
  49. }
  50. // deprecated v2 compose api
  51. public function compose(Request $request)
  52. {
  53. return redirect('/');
  54. }
  55. // deprecated
  56. public function discover(Request $request)
  57. {
  58. return;
  59. }
  60. public function discoverPosts(Request $request)
  61. {
  62. $profile = Auth::user()->profile;
  63. $pid = $profile->id;
  64. $following = Cache::remember('feature:discover:following:'.$pid, now()->addMinutes(15), function() use ($pid) {
  65. return Follower::whereProfileId($pid)->pluck('following_id')->toArray();
  66. });
  67. $filters = Cache::remember("user:filter:list:$pid", now()->addMinutes(15), function() use($pid) {
  68. $private = Profile::whereIsPrivate(true)
  69. ->orWhere('unlisted', true)
  70. ->orWhere('status', '!=', null)
  71. ->pluck('id')
  72. ->toArray();
  73. $filters = UserFilter::whereUserId($pid)
  74. ->whereFilterableType('App\Profile')
  75. ->whereIn('filter_type', ['mute', 'block'])
  76. ->pluck('filterable_id')
  77. ->toArray();
  78. return array_merge($private, $filters);
  79. });
  80. $following = array_merge($following, $filters);
  81. $sql = config('database.default') !== 'pgsql';
  82. $min_id = SnowflakeService::byDate(now()->subMonths(3));
  83. $posts = Status::select(
  84. 'id',
  85. 'is_nsfw',
  86. 'profile_id',
  87. 'type',
  88. 'uri',
  89. )
  90. ->whereNull('uri')
  91. ->whereIn('type', ['photo','photo:album', 'video'])
  92. ->whereIsNsfw(false)
  93. ->whereVisibility('public')
  94. ->whereNotIn('profile_id', $following)
  95. ->where('id', '>', $min_id)
  96. ->inRandomOrder()
  97. ->take(39)
  98. ->pluck('id');
  99. $res = [
  100. 'posts' => $posts->map(function($post) {
  101. return StatusService::get($post);
  102. })
  103. ];
  104. return response()->json($res);
  105. }
  106. public function directMessage(Request $request, $profileId, $threadId)
  107. {
  108. $profile = Auth::user()->profile;
  109. if($profileId != $profile->id) {
  110. abort(403);
  111. }
  112. $msg = DirectMessage::whereToId($profile->id)
  113. ->orWhere('from_id',$profile->id)
  114. ->findOrFail($threadId);
  115. $thread = DirectMessage::with('status')->whereIn('to_id', [$profile->id, $msg->from_id])
  116. ->whereIn('from_id', [$profile->id,$msg->from_id])
  117. ->orderBy('created_at', 'asc')
  118. ->paginate(30);
  119. return response()->json(compact('msg', 'profile', 'thread'), 200, [], JSON_PRETTY_PRINT);
  120. }
  121. public function statusReplies(Request $request, int $id)
  122. {
  123. $this->validate($request, [
  124. 'limit' => 'nullable|int|min:1|max:6'
  125. ]);
  126. $parent = Status::whereScope('public')->findOrFail($id);
  127. $limit = $request->input('limit') ?? 3;
  128. $children = Status::whereInReplyToId($parent->id)
  129. ->orderBy('created_at', 'desc')
  130. ->take($limit)
  131. ->get();
  132. $resource = new Fractal\Resource\Collection($children, new StatusTransformer());
  133. $res = $this->fractal->createData($resource)->toArray();
  134. return response()->json($res);
  135. }
  136. public function stories(Request $request)
  137. {
  138. }
  139. public function discoverCategories(Request $request)
  140. {
  141. $categories = DiscoverCategory::whereActive(true)->orderBy('order')->take(10)->get();
  142. $res = $categories->map(function($item) {
  143. return [
  144. 'name' => $item->name,
  145. 'url' => $item->url(),
  146. 'thumb' => $item->thumb()
  147. ];
  148. });
  149. return response()->json($res);
  150. }
  151. public function modAction(Request $request)
  152. {
  153. abort_unless(Auth::user()->is_admin, 400);
  154. $this->validate($request, [
  155. 'action' => [
  156. 'required',
  157. 'string',
  158. Rule::in([
  159. 'addcw',
  160. 'remcw',
  161. 'unlist',
  162. 'spammer'
  163. ])
  164. ],
  165. 'item_id' => 'required|integer|min:1',
  166. 'item_type' => [
  167. 'required',
  168. 'string',
  169. Rule::in(['profile', 'status'])
  170. ]
  171. ]);
  172. $action = $request->input('action');
  173. $item_id = $request->input('item_id');
  174. $item_type = $request->input('item_type');
  175. switch($action) {
  176. case 'addcw':
  177. $status = Status::findOrFail($item_id);
  178. $status->is_nsfw = true;
  179. $status->save();
  180. ModLogService::boot()
  181. ->user(Auth::user())
  182. ->objectUid($status->profile->user_id)
  183. ->objectId($status->id)
  184. ->objectType('App\Status::class')
  185. ->action('admin.status.moderate')
  186. ->metadata([
  187. 'action' => 'cw',
  188. 'message' => 'Success!'
  189. ])
  190. ->accessLevel('admin')
  191. ->save();
  192. if($status->uri == null) {
  193. $media = $status->media;
  194. $ai = new AccountInterstitial;
  195. $ai->user_id = $status->profile->user_id;
  196. $ai->type = 'post.cw';
  197. $ai->view = 'account.moderation.post.cw';
  198. $ai->item_type = 'App\Status';
  199. $ai->item_id = $status->id;
  200. $ai->has_media = (bool) $media->count();
  201. $ai->blurhash = $media->count() ? $media->first()->blurhash : null;
  202. $ai->meta = json_encode([
  203. 'caption' => $status->caption,
  204. 'created_at' => $status->created_at,
  205. 'type' => $status->type,
  206. 'url' => $status->url(),
  207. 'is_nsfw' => $status->is_nsfw,
  208. 'scope' => $status->scope,
  209. 'reblog' => $status->reblog_of_id,
  210. 'likes_count' => $status->likes_count,
  211. 'reblogs_count' => $status->reblogs_count,
  212. ]);
  213. $ai->save();
  214. $u = $status->profile->user;
  215. $u->has_interstitial = true;
  216. $u->save();
  217. }
  218. break;
  219. case 'remcw':
  220. $status = Status::findOrFail($item_id);
  221. $status->is_nsfw = false;
  222. $status->save();
  223. ModLogService::boot()
  224. ->user(Auth::user())
  225. ->objectUid($status->profile->user_id)
  226. ->objectId($status->id)
  227. ->objectType('App\Status::class')
  228. ->action('admin.status.moderate')
  229. ->metadata([
  230. 'action' => 'remove_cw',
  231. 'message' => 'Success!'
  232. ])
  233. ->accessLevel('admin')
  234. ->save();
  235. if($status->uri == null) {
  236. $ai = AccountInterstitial::whereUserId($status->profile->user_id)
  237. ->whereType('post.cw')
  238. ->whereItemId($status->id)
  239. ->whereItemType('App\Status')
  240. ->first();
  241. $ai->delete();
  242. }
  243. break;
  244. case 'unlist':
  245. $status = Status::whereScope('public')->findOrFail($item_id);
  246. $status->scope = $status->visibility = 'unlisted';
  247. $status->save();
  248. PublicTimelineService::del($status->id);
  249. ModLogService::boot()
  250. ->user(Auth::user())
  251. ->objectUid($status->profile->user_id)
  252. ->objectId($status->id)
  253. ->objectType('App\Status::class')
  254. ->action('admin.status.moderate')
  255. ->metadata([
  256. 'action' => 'unlist',
  257. 'message' => 'Success!'
  258. ])
  259. ->accessLevel('admin')
  260. ->save();
  261. if($status->uri == null) {
  262. $media = $status->media;
  263. $ai = new AccountInterstitial;
  264. $ai->user_id = $status->profile->user_id;
  265. $ai->type = 'post.unlist';
  266. $ai->view = 'account.moderation.post.unlist';
  267. $ai->item_type = 'App\Status';
  268. $ai->item_id = $status->id;
  269. $ai->has_media = (bool) $media->count();
  270. $ai->blurhash = $media->count() ? $media->first()->blurhash : null;
  271. $ai->meta = json_encode([
  272. 'caption' => $status->caption,
  273. 'created_at' => $status->created_at,
  274. 'type' => $status->type,
  275. 'url' => $status->url(),
  276. 'is_nsfw' => $status->is_nsfw,
  277. 'scope' => $status->scope,
  278. 'reblog' => $status->reblog_of_id,
  279. 'likes_count' => $status->likes_count,
  280. 'reblogs_count' => $status->reblogs_count,
  281. ]);
  282. $ai->save();
  283. $u = $status->profile->user;
  284. $u->has_interstitial = true;
  285. $u->save();
  286. }
  287. break;
  288. case 'spammer':
  289. $status = Status::findOrFail($item_id);
  290. HandleSpammerPipeline::dispatch($status->profile);
  291. ModLogService::boot()
  292. ->user(Auth::user())
  293. ->objectUid($status->profile->user_id)
  294. ->objectId($status->id)
  295. ->objectType('App\User::class')
  296. ->action('admin.status.moderate')
  297. ->metadata([
  298. 'action' => 'spammer',
  299. 'message' => 'Success!'
  300. ])
  301. ->accessLevel('admin')
  302. ->save();
  303. break;
  304. }
  305. Cache::forget('_api:statuses:recent_9:' . $status->profile_id);
  306. Cache::forget('profile:embed:' . $status->profile_id);
  307. StatusService::del($status->id);
  308. return ['msg' => 200];
  309. }
  310. public function composePost(Request $request)
  311. {
  312. abort(400, 'Endpoint deprecated');
  313. }
  314. public function bookmarks(Request $request)
  315. {
  316. $res = Bookmark::whereProfileId($request->user()->profile_id)
  317. ->orderByDesc('created_at')
  318. ->simplePaginate(10)
  319. ->map(function($bookmark) {
  320. $status = StatusService::get($bookmark->status_id);
  321. $status['bookmarked_at'] = $bookmark->created_at->format('c');
  322. return $status;
  323. })
  324. ->filter(function($bookmark) {
  325. return isset($bookmark['id']);
  326. })
  327. ->values();
  328. return response()->json($res);
  329. }
  330. public function accountStatuses(Request $request, $id)
  331. {
  332. $this->validate($request, [
  333. 'only_media' => 'nullable',
  334. 'pinned' => 'nullable',
  335. 'exclude_replies' => 'nullable',
  336. 'max_id' => 'nullable|integer|min:0|max:' . PHP_INT_MAX,
  337. 'since_id' => 'nullable|integer|min:0|max:' . PHP_INT_MAX,
  338. 'min_id' => 'nullable|integer|min:0|max:' . PHP_INT_MAX,
  339. 'limit' => 'nullable|integer|min:1|max:24'
  340. ]);
  341. $profile = Profile::whereNull('status')->findOrFail($id);
  342. $limit = $request->limit ?? 9;
  343. $max_id = $request->max_id;
  344. $min_id = $request->min_id;
  345. $scope = $request->only_media == true ?
  346. ['photo', 'photo:album', 'video', 'video:album'] :
  347. ['photo', 'photo:album', 'video', 'video:album', 'share', 'reply'];
  348. if($profile->is_private) {
  349. if(!Auth::check()) {
  350. return response()->json([]);
  351. }
  352. $pid = Auth::user()->profile->id;
  353. $following = Cache::remember('profile:following:'.$pid, now()->addMinutes(1440), function() use($pid) {
  354. $following = Follower::whereProfileId($pid)->pluck('following_id');
  355. return $following->push($pid)->toArray();
  356. });
  357. $visibility = true == in_array($profile->id, $following) ? ['public', 'unlisted', 'private'] : [];
  358. } else {
  359. if(Auth::check()) {
  360. $pid = Auth::user()->profile->id;
  361. $following = Cache::remember('profile:following:'.$pid, now()->addMinutes(1440), function() use($pid) {
  362. $following = Follower::whereProfileId($pid)->pluck('following_id');
  363. return $following->push($pid)->toArray();
  364. });
  365. $visibility = true == in_array($profile->id, $following) ? ['public', 'unlisted', 'private'] : ['public', 'unlisted'];
  366. } else {
  367. $visibility = ['public', 'unlisted'];
  368. }
  369. }
  370. $dir = $min_id ? '>' : '<';
  371. $id = $min_id ?? $max_id;
  372. $timeline = Status::select(
  373. 'id',
  374. 'uri',
  375. 'caption',
  376. 'rendered',
  377. 'profile_id',
  378. 'type',
  379. 'in_reply_to_id',
  380. 'reblog_of_id',
  381. 'is_nsfw',
  382. 'likes_count',
  383. 'reblogs_count',
  384. 'scope',
  385. 'local',
  386. 'created_at',
  387. 'updated_at'
  388. )->whereProfileId($profile->id)
  389. ->whereIn('type', $scope)
  390. ->where('id', $dir, $id)
  391. ->whereIn('visibility', $visibility)
  392. ->latest()
  393. ->limit($limit)
  394. ->get();
  395. $resource = new Fractal\Resource\Collection($timeline, new StatusTransformer());
  396. $res = $this->fractal->createData($resource)->toArray();
  397. return response()->json($res);
  398. }
  399. public function remoteProfile(Request $request, $id)
  400. {
  401. $profile = Profile::whereNull('status')
  402. ->whereNotNull('domain')
  403. ->findOrFail($id);
  404. $user = Auth::user();
  405. return view('profile.remote', compact('profile', 'user'));
  406. }
  407. public function remoteStatus(Request $request, $profileId, $statusId)
  408. {
  409. $user = Profile::whereNull('status')
  410. ->whereNotNull('domain')
  411. ->findOrFail($profileId);
  412. $status = Status::whereProfileId($user->id)
  413. ->whereNull('reblog_of_id')
  414. ->whereIn('visibility', ['public', 'unlisted'])
  415. ->findOrFail($statusId);
  416. $template = $status->in_reply_to_id ? 'status.reply' : 'status.remote';
  417. return view($template, compact('user', 'status'));
  418. }
  419. public function requestEmailVerification(Request $request)
  420. {
  421. $pid = $request->user()->profile_id;
  422. $exists = Redis::sismember('email:manual', $pid);
  423. return view('account.email.request_verification', compact('exists'));
  424. }
  425. public function requestEmailVerificationStore(Request $request)
  426. {
  427. $pid = $request->user()->profile_id;
  428. Redis::sadd('email:manual', $pid);
  429. return redirect('/i/verify-email')->with(['status' => 'Successfully sent manual verification request!']);
  430. }
  431. }