AdminApiController.php 31 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853
  1. <?php
  2. namespace App\Http\Controllers\Api;
  3. use Illuminate\Http\Request;
  4. use App\Http\Controllers\Controller;
  5. use App\Jobs\StatusPipeline\StatusDelete;
  6. use Auth, Cache, DB;
  7. use Carbon\Carbon;
  8. use App\{
  9. AccountInterstitial,
  10. Instance,
  11. Like,
  12. Notification,
  13. Media,
  14. Profile,
  15. Report,
  16. Status,
  17. User
  18. };
  19. use App\Models\Conversation;
  20. use App\Models\RemoteReport;
  21. use App\Services\AccountService;
  22. use App\Services\AdminStatsService;
  23. use App\Services\ConfigCacheService;
  24. use App\Services\InstanceService;
  25. use App\Services\ModLogService;
  26. use App\Services\SnowflakeService;
  27. use App\Services\StatusService;
  28. use App\Services\PublicTimelineService;
  29. use App\Services\NetworkTimelineService;
  30. use App\Services\NotificationService;
  31. use App\Http\Resources\AdminInstance;
  32. use App\Http\Resources\AdminUser;
  33. use App\Jobs\DeletePipeline\DeleteAccountPipeline;
  34. use App\Jobs\DeletePipeline\DeleteRemoteProfilePipeline;
  35. use App\Jobs\DeletePipeline\DeleteRemoteStatusPipeline;
  36. class AdminApiController extends Controller
  37. {
  38. public function supported(Request $request)
  39. {
  40. abort_if(!$request->user() || !$request->user()->token(), 404);
  41. abort_unless($request->user()->is_admin == 1, 404);
  42. abort_unless($request->user()->tokenCan('admin:read'), 404);
  43. return response()->json(['supported' => true]);
  44. }
  45. public function getStats(Request $request)
  46. {
  47. abort_if(!$request->user() || !$request->user()->token(), 404);
  48. abort_unless($request->user()->is_admin == 1, 404);
  49. abort_unless($request->user()->tokenCan('admin:read'), 404);
  50. $res = AdminStatsService::summary();
  51. $res['autospam_count'] = AccountInterstitial::whereType('post.autospam')
  52. ->whereNull('appeal_handled_at')
  53. ->count();
  54. return $res;
  55. }
  56. public function autospam(Request $request)
  57. {
  58. abort_if(!$request->user() || !$request->user()->token(), 404);
  59. abort_unless($request->user()->is_admin == 1, 404);
  60. abort_unless($request->user()->tokenCan('admin:read'), 404);
  61. $appeals = AccountInterstitial::whereType('post.autospam')
  62. ->whereNull('appeal_handled_at')
  63. ->latest()
  64. ->simplePaginate(6)
  65. ->map(function($report) {
  66. $r = [
  67. 'id' => $report->id,
  68. 'type' => $report->type,
  69. 'item_id' => $report->item_id,
  70. 'item_type' => $report->item_type,
  71. 'created_at' => $report->created_at
  72. ];
  73. if($report->item_type === 'App\\Status') {
  74. $status = StatusService::get($report->item_id, false);
  75. if(!$status) {
  76. return;
  77. }
  78. $r['status'] = $status;
  79. if($status['in_reply_to_id']) {
  80. $r['parent'] = StatusService::get($status['in_reply_to_id'], false);
  81. }
  82. }
  83. return $r;
  84. });
  85. return $appeals;
  86. }
  87. public function autospamHandle(Request $request)
  88. {
  89. abort_if(!$request->user() || !$request->user()->token(), 404);
  90. abort_unless($request->user()->is_admin == 1, 404);
  91. abort_unless($request->user()->tokenCan('admin:write'), 404);
  92. $this->validate($request, [
  93. 'action' => 'required|in:dismiss,approve,dismiss-all,approve-all,delete-post,delete-account',
  94. 'id' => 'required'
  95. ]);
  96. $action = $request->input('action');
  97. $id = $request->input('id');
  98. $appeal = AccountInterstitial::whereType('post.autospam')
  99. ->whereNull('appeal_handled_at')
  100. ->findOrFail($id);
  101. $now = now();
  102. $res = ['status' => 'success'];
  103. $meta = json_decode($appeal->meta);
  104. $user = $appeal->user;
  105. $profile = $user->profile;
  106. if($action == 'dismiss') {
  107. $appeal->is_spam = true;
  108. $appeal->appeal_handled_at = $now;
  109. $appeal->save();
  110. Cache::forget('pf:bouncer_v0:exemption_by_pid:' . $profile->id);
  111. Cache::forget('pf:bouncer_v0:recent_by_pid:' . $profile->id);
  112. Cache::forget('admin-dash:reports:spam-count');
  113. return $res;
  114. }
  115. if($action == 'delete-post') {
  116. $appeal->appeal_handled_at = now();
  117. $appeal->is_spam = true;
  118. $appeal->save();
  119. ModLogService::boot()
  120. ->objectUid($profile->id)
  121. ->objectId($appeal->status->id)
  122. ->objectType('App\Status::class')
  123. ->user($request->user())
  124. ->action('admin.status.delete')
  125. ->accessLevel('admin')
  126. ->save();
  127. PublicTimelineService::deleteByProfileId($profile->id);
  128. StatusDelete::dispatch($appeal->status)->onQueue('high');
  129. Cache::forget('admin-dash:reports:spam-count');
  130. return $res;
  131. }
  132. if($action == 'delete-account') {
  133. abort_if($user->is_admin, 400, 'Cannot delete an admin account.');
  134. $appeal->appeal_handled_at = now();
  135. $appeal->is_spam = true;
  136. $appeal->save();
  137. ModLogService::boot()
  138. ->objectUid($profile->id)
  139. ->objectId($profile->id)
  140. ->objectType('App\User::class')
  141. ->user($request->user())
  142. ->action('admin.user.delete')
  143. ->accessLevel('admin')
  144. ->save();
  145. PublicTimelineService::deleteByProfileId($profile->id);
  146. DeleteAccountPipeline::dispatch($appeal->user)->onQueue('high');
  147. Cache::forget('admin-dash:reports:spam-count');
  148. return $res;
  149. }
  150. if($action == 'dismiss-all') {
  151. AccountInterstitial::whereType('post.autospam')
  152. ->whereItemType('App\Status')
  153. ->whereNull('appeal_handled_at')
  154. ->whereUserId($appeal->user_id)
  155. ->update(['appeal_handled_at' => $now, 'is_spam' => true]);
  156. Cache::forget('pf:bouncer_v0:exemption_by_pid:' . $appeal->user->profile_id);
  157. Cache::forget('pf:bouncer_v0:recent_by_pid:' . $appeal->user->profile_id);
  158. Cache::forget('admin-dash:reports:spam-count');
  159. return $res;
  160. }
  161. if($action == 'approve') {
  162. $status = $appeal->status;
  163. $status->is_nsfw = $meta->is_nsfw;
  164. $status->scope = 'public';
  165. $status->visibility = 'public';
  166. $status->save();
  167. $appeal->is_spam = false;
  168. $appeal->appeal_handled_at = now();
  169. $appeal->save();
  170. StatusService::del($status->id);
  171. Notification::whereAction('autospam.warning')
  172. ->whereProfileId($appeal->user->profile_id)
  173. ->get()
  174. ->each(function($n) use($appeal) {
  175. NotificationService::del($appeal->user->profile_id, $n->id);
  176. $n->forceDelete();
  177. });
  178. Cache::forget('pf:bouncer_v0:exemption_by_pid:' . $appeal->user->profile_id);
  179. Cache::forget('pf:bouncer_v0:recent_by_pid:' . $appeal->user->profile_id);
  180. Cache::forget('admin-dash:reports:spam-count');
  181. return $res;
  182. }
  183. if($action == 'approve-all') {
  184. AccountInterstitial::whereType('post.autospam')
  185. ->whereItemType('App\Status')
  186. ->whereNull('appeal_handled_at')
  187. ->whereUserId($appeal->user_id)
  188. ->get()
  189. ->each(function($report) use($meta) {
  190. $report->is_spam = false;
  191. $report->appeal_handled_at = now();
  192. $report->save();
  193. $status = Status::find($report->item_id);
  194. if($status) {
  195. $status->is_nsfw = $meta->is_nsfw;
  196. $status->scope = 'public';
  197. $status->visibility = 'public';
  198. $status->save();
  199. StatusService::del($status->id, true);
  200. }
  201. Notification::whereAction('autospam.warning')
  202. ->whereProfileId($report->user->profile_id)
  203. ->get()
  204. ->each(function($n) use($report) {
  205. NotificationService::del($report->user->profile_id, $n->id);
  206. $n->forceDelete();
  207. });
  208. });
  209. Cache::forget('pf:bouncer_v0:exemption_by_pid:' . $appeal->user->profile_id);
  210. Cache::forget('pf:bouncer_v0:recent_by_pid:' . $appeal->user->profile_id);
  211. Cache::forget('admin-dash:reports:spam-count');
  212. return $res;
  213. }
  214. return $res;
  215. }
  216. public function modReports(Request $request)
  217. {
  218. abort_if(!$request->user() || !$request->user()->token(), 404);
  219. abort_unless($request->user()->is_admin == 1, 404);
  220. abort_unless($request->user()->tokenCan('admin:read'), 404);
  221. $reports = Report::whereNull('admin_seen')
  222. ->orderBy('created_at','desc')
  223. ->paginate(6)
  224. ->map(function($report) {
  225. $r = [
  226. 'id' => $report->id,
  227. 'type' => $report->type,
  228. 'message' => $report->message,
  229. 'object_id' => $report->object_id,
  230. 'object_type' => $report->object_type,
  231. 'created_at' => $report->created_at
  232. ];
  233. if($report->profile_id) {
  234. $r['reported_by_account'] = AccountService::get($report->profile_id, true);
  235. }
  236. if($report->object_type === 'App\\Status') {
  237. $status = StatusService::get($report->object_id, false);
  238. if(!$status) {
  239. return;
  240. }
  241. $r['status'] = $status;
  242. if($status['in_reply_to_id']) {
  243. $r['parent'] = StatusService::get($status['in_reply_to_id'], false);
  244. }
  245. }
  246. if($report->object_type === 'App\\Profile') {
  247. $r['account'] = AccountService::get($report->object_id, false);
  248. }
  249. return $r;
  250. })
  251. ->filter()
  252. ->values();
  253. return $reports;
  254. }
  255. public function modReportHandle(Request $request)
  256. {
  257. abort_if(!$request->user() || !$request->user()->token(), 404);
  258. abort_unless($request->user()->is_admin == 1, 404);
  259. abort_unless($request->user()->tokenCan('admin:write'), 404);
  260. $this->validate($request, [
  261. 'action' => 'required|string',
  262. 'id' => 'required'
  263. ]);
  264. $action = $request->input('action');
  265. $id = $request->input('id');
  266. $actions = [
  267. 'ignore',
  268. 'cw',
  269. 'unlist'
  270. ];
  271. if (!in_array($action, $actions)) {
  272. return abort(403);
  273. }
  274. $report = Report::findOrFail($id);
  275. $item = $report->reported();
  276. $report->admin_seen = now();
  277. switch ($action) {
  278. case 'ignore':
  279. $report->not_interested = true;
  280. break;
  281. case 'cw':
  282. Cache::forget('status:thumb:'.$item->id);
  283. $item->is_nsfw = true;
  284. $item->save();
  285. $report->nsfw = true;
  286. StatusService::del($item->id, true);
  287. break;
  288. case 'unlist':
  289. $item->visibility = 'unlisted';
  290. $item->save();
  291. StatusService::del($item->id, true);
  292. break;
  293. default:
  294. $report->admin_seen = null;
  295. break;
  296. }
  297. $report->save();
  298. Cache::forget('admin-dash:reports:list-cache');
  299. Cache::forget('admin:dashboard:home:data:v0:15min');
  300. return ['success' => true];
  301. }
  302. public function getConfiguration(Request $request)
  303. {
  304. abort_if(!$request->user() || !$request->user()->token(), 404);
  305. abort_unless($request->user()->is_admin == 1, 404);
  306. abort_unless($request->user()->tokenCan('admin:read'), 404);
  307. abort_unless(config('instance.enable_cc'), 400);
  308. return collect([
  309. [
  310. 'name' => 'ActivityPub Federation',
  311. 'description' => 'Enable activitypub federation support, compatible with Pixelfed, Mastodon and other platforms.',
  312. 'key' => 'federation.activitypub.enabled'
  313. ],
  314. [
  315. 'name' => 'Open Registration',
  316. 'description' => 'Allow new account registrations.',
  317. 'key' => 'pixelfed.open_registration'
  318. ],
  319. [
  320. 'name' => 'Stories',
  321. 'description' => 'Enable the ephemeral Stories feature.',
  322. 'key' => 'instance.stories.enabled'
  323. ],
  324. [
  325. 'name' => 'Require Email Verification',
  326. 'description' => 'Require new accounts to verify their email address.',
  327. 'key' => 'pixelfed.enforce_email_verification'
  328. ],
  329. [
  330. 'name' => 'AutoSpam Detection',
  331. 'description' => 'Detect and remove spam from public timelines.',
  332. 'key' => 'pixelfed.bouncer.enabled'
  333. ],
  334. ])
  335. ->map(function($s) {
  336. $s['state'] = (bool) config_cache($s['key']);
  337. return $s;
  338. });
  339. }
  340. public function updateConfiguration(Request $request)
  341. {
  342. abort_if(!$request->user() || !$request->user()->token(), 404);
  343. abort_unless($request->user()->is_admin == 1, 404);
  344. abort_unless($request->user()->tokenCan('admin:write'), 404);
  345. abort_unless(config('instance.enable_cc'), 400);
  346. $this->validate($request, [
  347. 'key' => 'required',
  348. 'value' => 'required'
  349. ]);
  350. $allowedKeys = [
  351. 'federation.activitypub.enabled',
  352. 'pixelfed.open_registration',
  353. 'instance.stories.enabled',
  354. 'pixelfed.enforce_email_verification',
  355. 'pixelfed.bouncer.enabled',
  356. ];
  357. $key = $request->input('key');
  358. $value = (bool) filter_var($request->input('value'), FILTER_VALIDATE_BOOLEAN);
  359. abort_if(!in_array($key, $allowedKeys), 400, 'Invalid cache key.');
  360. ConfigCacheService::put($key, $value);
  361. return collect([
  362. [
  363. 'name' => 'ActivityPub Federation',
  364. 'description' => 'Enable activitypub federation support, compatible with Pixelfed, Mastodon and other platforms.',
  365. 'key' => 'federation.activitypub.enabled'
  366. ],
  367. [
  368. 'name' => 'Open Registration',
  369. 'description' => 'Allow new account registrations.',
  370. 'key' => 'pixelfed.open_registration'
  371. ],
  372. [
  373. 'name' => 'Stories',
  374. 'description' => 'Enable the ephemeral Stories feature.',
  375. 'key' => 'instance.stories.enabled'
  376. ],
  377. [
  378. 'name' => 'Require Email Verification',
  379. 'description' => 'Require new accounts to verify their email address.',
  380. 'key' => 'pixelfed.enforce_email_verification'
  381. ],
  382. [
  383. 'name' => 'AutoSpam Detection',
  384. 'description' => 'Detect and remove spam from public timelines.',
  385. 'key' => 'pixelfed.bouncer.enabled'
  386. ],
  387. ])
  388. ->map(function($s) {
  389. $s['state'] = (bool) config_cache($s['key']);
  390. return $s;
  391. });
  392. }
  393. public function getUsers(Request $request)
  394. {
  395. abort_if(!$request->user() || !$request->user()->token(), 404);
  396. abort_unless($request->user()->is_admin == 1, 404);
  397. abort_unless($request->user()->tokenCan('admin:read'), 404);
  398. $this->validate($request, [
  399. 'sort' => 'sometimes|in:asc,desc',
  400. ]);
  401. $q = $request->input('q');
  402. $sort = $request->input('sort', 'desc') === 'asc' ? 'asc' : 'desc';
  403. $res = User::whereNull('status')
  404. ->when($q, function($query, $q) {
  405. return $query->where('username', 'like', '%' . $q . '%');
  406. })
  407. ->orderBy('id', $sort)
  408. ->cursorPaginate(10);
  409. return AdminUser::collection($res);
  410. }
  411. public function getUser(Request $request)
  412. {
  413. abort_if(!$request->user() || !$request->user()->token(), 404);
  414. abort_unless($request->user()->is_admin == 1, 404);
  415. abort_unless($request->user()->tokenCan('admin:read'), 404);
  416. $id = $request->input('user_id');
  417. $key = 'pf-admin-api:getUser:byId:' . $id;
  418. if($request->has('refresh')) {
  419. Cache::forget($key);
  420. }
  421. return Cache::remember($key, 86400, function() use($id) {
  422. $user = User::findOrFail($id);
  423. $profile = $user->profile;
  424. $account = AccountService::get($user->profile_id, true);
  425. $res = (new AdminUser($user))->additional(['meta' => [
  426. 'cached_at' => str_replace('+00:00', 'Z', now()->format(DATE_RFC3339_EXTENDED)),
  427. 'account' => $account,
  428. 'dms_sent' => Conversation::whereFromId($profile->id)->count(),
  429. 'report_count' => Report::where('object_id', $profile->id)->orWhere('reported_profile_id', $profile->id)->count(),
  430. 'remote_report_count' => RemoteReport::whereAccountId($profile->id)->count(),
  431. 'moderation' => [
  432. 'unlisted' => (bool) $profile->unlisted,
  433. 'cw' => (bool) $profile->cw,
  434. 'no_autolink' => (bool) $profile->no_autolink
  435. ]
  436. ]]);
  437. return $res;
  438. });
  439. }
  440. public function userAdminAction(Request $request)
  441. {
  442. abort_if(!$request->user() || !$request->user()->token(), 404);
  443. abort_unless($request->user()->is_admin == 1, 404);
  444. abort_unless($request->user()->tokenCan('admin:write'), 404);
  445. $this->validate($request, [
  446. 'id' => 'required',
  447. 'action' => 'required|in:unlisted,cw,no_autolink,refresh_stats,verify_email,delete',
  448. 'value' => 'sometimes'
  449. ]);
  450. $id = $request->input('id');
  451. $user = User::findOrFail($id);
  452. $profile = Profile::findOrFail($user->profile_id);
  453. $action = $request->input('action');
  454. abort_if($user->is_admin == true && $action !== 'refresh_stats', 400, 'Cannot moderate admin accounts');
  455. if($action === 'delete') {
  456. if(config('pixelfed.account_deletion') == false) {
  457. abort(404);
  458. }
  459. abort_if($user->is_admin, 400, 'Cannot delete an admin account.');
  460. $ts = now()->addMonth();
  461. $user->status = 'delete';
  462. $user->delete_after = $ts;
  463. $user->save();
  464. $profile->status = 'delete';
  465. $profile->delete_after = $ts;
  466. $profile->save();
  467. ModLogService::boot()
  468. ->objectUid($profile->id)
  469. ->objectId($profile->id)
  470. ->objectType('App\Profile::class')
  471. ->user($request->user())
  472. ->action('admin.user.delete')
  473. ->accessLevel('admin')
  474. ->save();
  475. PublicTimelineService::deleteByProfileId($profile->id);
  476. NetworkTimelineService::deleteByProfileId($profile->id);
  477. if($profile->user_id) {
  478. DB::table('oauth_access_tokens')->whereUserId($user->id)->delete();
  479. DB::table('oauth_auth_codes')->whereUserId($user->id)->delete();
  480. $user->email = $user->id;
  481. $user->password = '';
  482. $user->status = 'delete';
  483. $user->save();
  484. $profile->status = 'delete';
  485. $profile->delete_after = now()->addMonth();
  486. $profile->save();
  487. AccountService::del($profile->id);
  488. DeleteAccountPipeline::dispatch($user)->onQueue('high');
  489. } else {
  490. $profile->status = 'delete';
  491. $profile->delete_after = now()->addMonth();
  492. $profile->save();
  493. AccountService::del($profile->id);
  494. DeleteRemoteProfilePipeline::dispatch($profile)->onQueue('high');
  495. }
  496. return [
  497. 'status' => 200,
  498. 'msg' => 'deleted',
  499. ];
  500. } else if($action === 'refresh_stats') {
  501. $profile->following_count = DB::table('followers')->whereProfileId($user->profile_id)->count();
  502. $profile->followers_count = DB::table('followers')->whereFollowingId($user->profile_id)->count();
  503. $statusCount = Status::whereProfileId($user->profile_id)
  504. ->whereNull('in_reply_to_id')
  505. ->whereNull('reblog_of_id')
  506. ->whereIn('scope', ['public', 'unlisted', 'private'])
  507. ->count();
  508. $profile->status_count = $statusCount;
  509. $profile->save();
  510. } else if($action === 'verify_email') {
  511. $user->email_verified_at = now();
  512. $user->save();
  513. ModLogService::boot()
  514. ->objectUid($user->id)
  515. ->objectId($user->id)
  516. ->objectType('App\User::class')
  517. ->user($request->user())
  518. ->action('admin.user.moderate')
  519. ->metadata([
  520. 'action' => 'Manually verified email address',
  521. 'message' => 'Success!'
  522. ])
  523. ->accessLevel('admin')
  524. ->save();
  525. } else if($action === 'unlisted') {
  526. ModLogService::boot()
  527. ->objectUid($profile->id)
  528. ->objectId($profile->id)
  529. ->objectType('App\Profile::class')
  530. ->user($request->user())
  531. ->action('admin.user.moderate')
  532. ->metadata([
  533. 'action' => $action,
  534. 'message' => 'Success!'
  535. ])
  536. ->accessLevel('admin')
  537. ->save();
  538. $profile->unlisted = !$profile->unlisted;
  539. $profile->save();
  540. } else if($action === 'cw') {
  541. ModLogService::boot()
  542. ->objectUid($profile->id)
  543. ->objectId($profile->id)
  544. ->objectType('App\Profile::class')
  545. ->user($request->user())
  546. ->action('admin.user.moderate')
  547. ->metadata([
  548. 'action' => $action,
  549. 'message' => 'Success!'
  550. ])
  551. ->accessLevel('admin')
  552. ->save();
  553. $profile->cw = !$profile->cw;
  554. $profile->save();
  555. } else if($action === 'no_autolink') {
  556. ModLogService::boot()
  557. ->objectUid($profile->id)
  558. ->objectId($profile->id)
  559. ->objectType('App\Profile::class')
  560. ->user($request->user())
  561. ->action('admin.user.moderate')
  562. ->metadata([
  563. 'action' => $action,
  564. 'message' => 'Success!'
  565. ])
  566. ->accessLevel('admin')
  567. ->save();
  568. $profile->no_autolink = !$profile->no_autolink;
  569. $profile->save();
  570. } else {
  571. $profile->{$action} = filter_var($request->input('value'), FILTER_VALIDATE_BOOLEAN);
  572. $profile->save();
  573. ModLogService::boot()
  574. ->objectUid($user->id)
  575. ->objectId($user->id)
  576. ->objectType('App\User::class')
  577. ->user($request->user())
  578. ->action('admin.user.moderate')
  579. ->metadata([
  580. 'action' => $action,
  581. 'message' => 'Success!'
  582. ])
  583. ->accessLevel('admin')
  584. ->save();
  585. }
  586. AccountService::del($user->profile_id);
  587. $account = AccountService::get($user->profile_id, true);
  588. return (new AdminUser($user))->additional(['meta' => [
  589. 'account' => $account,
  590. 'moderation' => [
  591. 'unlisted' => (bool) $profile->unlisted,
  592. 'cw' => (bool) $profile->cw,
  593. 'no_autolink' => (bool) $profile->no_autolink
  594. ]
  595. ]]);
  596. }
  597. public function instances(Request $request)
  598. {
  599. abort_if(!$request->user() || !$request->user()->token(), 404);
  600. abort_unless($request->user()->is_admin == 1, 404);
  601. abort_unless($request->user()->tokenCan('admin:write'), 404);
  602. $this->validate($request, [
  603. 'q' => 'sometimes',
  604. 'sort' => 'sometimes|in:asc,desc',
  605. 'sort_by' => 'sometimes|in:id,status_count,user_count,domain',
  606. 'filter' => 'sometimes|in:all,unlisted,auto_cw,banned',
  607. ]);
  608. $q = $request->input('q');
  609. $sort = $request->input('sort', 'desc') === 'asc' ? 'asc' : 'desc';
  610. $sortBy = $request->input('sort_by', 'id');
  611. $filter = $request->input('filter');
  612. $res = Instance::when($q, function($query, $q) {
  613. return $query->where('domain', 'like', '%' . $q . '%');
  614. })
  615. ->when($filter, function($query, $filter) {
  616. if($filter === 'all') {
  617. return $query;
  618. } else {
  619. return $query->where($filter, true);
  620. }
  621. })
  622. ->when($sortBy, function($query, $sortBy) use($sort) {
  623. return $query->orderBy($sortBy, $sort);
  624. }, function($query) {
  625. return $query->orderBy('id', 'desc');
  626. })
  627. ->cursorPaginate(10)
  628. ->withQueryString();
  629. return AdminInstance::collection($res);
  630. }
  631. public function getInstance(Request $request)
  632. {
  633. abort_if(!$request->user() || !$request->user()->token(), 404);
  634. abort_unless($request->user()->is_admin == 1, 404);
  635. abort_unless($request->user()->tokenCan('admin:read'), 404);
  636. $id = $request->input('id');
  637. $res = Instance::findOrFail($id);
  638. return new AdminInstance($res);
  639. }
  640. public function moderateInstance(Request $request)
  641. {
  642. abort_if(!$request->user() || !$request->user()->token(), 404);
  643. abort_unless($request->user()->is_admin == 1, 404);
  644. abort_unless($request->user()->tokenCan('admin:write'), 404);
  645. $this->validate($request, [
  646. 'id' => 'required',
  647. 'key' => 'required|in:unlisted,auto_cw,banned',
  648. 'value' => 'required'
  649. ]);
  650. $id = $request->input('id');
  651. $key = $request->input('key');
  652. $value = (bool) filter_var($request->input('value'), FILTER_VALIDATE_BOOLEAN);
  653. $res = Instance::findOrFail($id);
  654. $res->{$key} = $value;
  655. $res->save();
  656. InstanceService::refresh();
  657. NetworkTimelineService::warmCache(true);
  658. return new AdminInstance($res);
  659. }
  660. public function refreshInstanceStats(Request $request)
  661. {
  662. abort_if(!$request->user() || !$request->user()->token(), 404);
  663. abort_unless($request->user()->is_admin == 1, 404);
  664. abort_unless($request->user()->tokenCan('admin:write'), 404);
  665. $this->validate($request, [
  666. 'id' => 'required',
  667. ]);
  668. $id = $request->input('id');
  669. $instance = Instance::findOrFail($id);
  670. $instance->user_count = Profile::whereDomain($instance->domain)->count();
  671. $instance->status_count = Profile::whereDomain($instance->domain)->leftJoin('statuses', 'profiles.id', '=', 'statuses.profile_id')->count();
  672. $instance->save();
  673. return new AdminInstance($instance);
  674. }
  675. public function getAllStats(Request $request)
  676. {
  677. abort_if(!$request->user() || !$request->user()->token(), 404);
  678. abort_unless($request->user()->is_admin === 1, 404);
  679. abort_unless($request->user()->tokenCan('admin:read'), 404);
  680. if($request->has('refresh')) {
  681. Cache::forget('admin-api:instance-all-stats-v1');
  682. }
  683. return Cache::remember('admin-api:instance-all-stats-v1', 1209600, function() {
  684. $days = range(1, 7);
  685. $res = [
  686. 'cached_at' => now()->format('c'),
  687. ];
  688. $minStatusId = SnowflakeService::byDate(now()->subDays(7));
  689. foreach($days as $day) {
  690. $label = now()->subDays($day)->format('D');
  691. $labelShort = substr($label, 0, 1);
  692. $res['users']['days'][] = [
  693. 'date' => now()->subDays($day)->format('M j Y'),
  694. 'label_full' => $label,
  695. 'label' => $labelShort,
  696. 'count' => User::whereDate('created_at', now()->subDays($day))->count()
  697. ];
  698. $res['posts']['days'][] = [
  699. 'date' => now()->subDays($day)->format('M j Y'),
  700. 'label_full' => $label,
  701. 'label' => $labelShort,
  702. 'count' => Status::whereNull('uri')->where('id', '>', $minStatusId)->whereDate('created_at', now()->subDays($day))->count()
  703. ];
  704. $res['instances']['days'][] = [
  705. 'date' => now()->subDays($day)->format('M j Y'),
  706. 'label_full' => $label,
  707. 'label' => $labelShort,
  708. 'count' => Instance::whereDate('created_at', now()->subDays($day))->count()
  709. ];
  710. }
  711. $res['users']['total'] = DB::table('users')->count();
  712. $res['users']['min'] = collect($res['users']['days'])->min('count');
  713. $res['users']['max'] = collect($res['users']['days'])->max('count');
  714. $res['users']['change'] = collect($res['users']['days'])->sum('count');;
  715. $res['posts']['total'] = DB::table('statuses')->whereNull('uri')->count();
  716. $res['posts']['min'] = collect($res['posts']['days'])->min('count');
  717. $res['posts']['max'] = collect($res['posts']['days'])->max('count');
  718. $res['posts']['change'] = collect($res['posts']['days'])->sum('count');
  719. $res['instances']['total'] = DB::table('instances')->count();
  720. $res['instances']['min'] = collect($res['instances']['days'])->min('count');
  721. $res['instances']['max'] = collect($res['instances']['days'])->max('count');
  722. $res['instances']['change'] = collect($res['instances']['days'])->sum('count');
  723. return $res;
  724. });
  725. }
  726. }