ApiV1Dot1Controller.php 26 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940
  1. <?php
  2. namespace App\Http\Controllers\Api;
  3. use Cache;
  4. use DB;
  5. use App\Http\Controllers\Controller;
  6. use Illuminate\Http\Request;
  7. use League\Fractal;
  8. use League\Fractal\Serializer\ArraySerializer;
  9. use League\Fractal\Pagination\IlluminatePaginatorAdapter;
  10. use App\AccountLog;
  11. use App\EmailVerification;
  12. use App\Follower;
  13. use App\Place;
  14. use App\Status;
  15. use App\Report;
  16. use App\Profile;
  17. use App\StatusArchived;
  18. use App\User;
  19. use App\UserSetting;
  20. use App\Services\AccountService;
  21. use App\Services\FollowerService;
  22. use App\Services\StatusService;
  23. use App\Services\ProfileStatusService;
  24. use App\Services\LikeService;
  25. use App\Services\ReblogService;
  26. use App\Services\PublicTimelineService;
  27. use App\Services\NetworkTimelineService;
  28. use App\Util\Lexer\RestrictedNames;
  29. use App\Services\BouncerService;
  30. use App\Services\EmailService;
  31. use Illuminate\Support\Str;
  32. use Illuminate\Support\Facades\Hash;
  33. use Jenssegers\Agent\Agent;
  34. use Mail;
  35. use App\Mail\PasswordChange;
  36. use App\Mail\ConfirmAppEmail;
  37. use App\Http\Resources\StatusStateless;
  38. use App\Jobs\StatusPipeline\StatusDelete;
  39. use App\Jobs\StatusPipeline\RemoteStatusDelete;
  40. use App\Jobs\ReportPipeline\ReportNotifyAdminViaEmail;
  41. use Illuminate\Support\Facades\RateLimiter;
  42. class ApiV1Dot1Controller extends Controller
  43. {
  44. protected $fractal;
  45. public function __construct()
  46. {
  47. $this->fractal = new Fractal\Manager();
  48. $this->fractal->setSerializer(new ArraySerializer());
  49. }
  50. public function json($res, $code = 200, $headers = [])
  51. {
  52. return response()->json($res, $code, $headers, JSON_UNESCAPED_SLASHES);
  53. }
  54. public function error($msg, $code = 400, $extra = [], $headers = [])
  55. {
  56. $res = [
  57. "msg" => $msg,
  58. "code" => $code
  59. ];
  60. return response()->json(array_merge($res, $extra), $code, $headers, JSON_UNESCAPED_SLASHES);
  61. }
  62. public function report(Request $request)
  63. {
  64. abort_if(!$request->user() || !$request->user()->token(), 403);
  65. abort_unless($request->user()->tokenCan('write'), 403);
  66. $user = $request->user();
  67. abort_if($user->status != null, 403);
  68. if(config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  69. abort_if(BouncerService::checkIp($request->ip()), 404);
  70. }
  71. $report_type = $request->input('report_type');
  72. $object_id = $request->input('object_id');
  73. $object_type = $request->input('object_type');
  74. $types = [
  75. 'spam',
  76. 'sensitive',
  77. 'abusive',
  78. 'underage',
  79. 'violence',
  80. 'copyright',
  81. 'impersonation',
  82. 'scam',
  83. 'terrorism'
  84. ];
  85. if (!$report_type || !$object_id || !$object_type) {
  86. return $this->error("Invalid or missing parameters", 400, ["error_code" => "ERROR_INVALID_PARAMS"]);
  87. }
  88. if (!in_array($report_type, $types)) {
  89. return $this->error("Invalid report type", 400, ["error_code" => "ERROR_TYPE_INVALID"]);
  90. }
  91. if ($object_type === "user" && $object_id == $user->profile_id) {
  92. return $this->error("Cannot self report", 400, ["error_code" => "ERROR_NO_SELF_REPORTS"]);
  93. }
  94. $rpid = null;
  95. switch ($object_type) {
  96. case 'post':
  97. $object = Status::find($object_id);
  98. if (!$object) {
  99. return $this->error("Invalid object id", 400, ["error_code" => "ERROR_INVALID_OBJECT_ID"]);
  100. }
  101. $object_type = 'App\Status';
  102. $exists = Report::whereUserId($user->id)
  103. ->whereObjectId($object->id)
  104. ->whereObjectType('App\Status')
  105. ->count();
  106. $rpid = $object->profile_id;
  107. break;
  108. case 'user':
  109. $object = Profile::find($object_id);
  110. if (!$object) {
  111. return $this->error("Invalid object id", 400, ["error_code" => "ERROR_INVALID_OBJECT_ID"]);
  112. }
  113. $object_type = 'App\Profile';
  114. $exists = Report::whereUserId($user->id)
  115. ->whereObjectId($object->id)
  116. ->whereObjectType('App\Profile')
  117. ->count();
  118. $rpid = $object->id;
  119. break;
  120. default:
  121. return $this->error("Invalid report type", 400, ["error_code" => "ERROR_REPORT_OBJECT_TYPE_INVALID"]);
  122. break;
  123. }
  124. if ($exists !== 0) {
  125. return $this->error("Duplicate report", 400, ["error_code" => "ERROR_REPORT_DUPLICATE"]);
  126. }
  127. if ($object->profile_id == $user->profile_id) {
  128. return $this->error("Cannot self report", 400, ["error_code" => "ERROR_NO_SELF_REPORTS"]);
  129. }
  130. $report = new Report;
  131. $report->profile_id = $user->profile_id;
  132. $report->user_id = $user->id;
  133. $report->object_id = $object->id;
  134. $report->object_type = $object_type;
  135. $report->reported_profile_id = $rpid;
  136. $report->type = $report_type;
  137. $report->save();
  138. if(config('instance.reports.email.enabled')) {
  139. ReportNotifyAdminViaEmail::dispatch($report)->onQueue('default');
  140. }
  141. $res = [
  142. "msg" => "Successfully sent report",
  143. "code" => 200
  144. ];
  145. return $this->json($res);
  146. }
  147. /**
  148. * DELETE /api/v1.1/accounts/avatar
  149. *
  150. * @return \App\Transformer\Api\AccountTransformer
  151. */
  152. public function deleteAvatar(Request $request)
  153. {
  154. abort_if(!$request->user() || !$request->user()->token(), 403);
  155. abort_unless($request->user()->tokenCan('write'), 403);
  156. $user = $request->user();
  157. abort_if($user->status != null, 403);
  158. if(config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  159. abort_if(BouncerService::checkIp($request->ip()), 404);
  160. }
  161. $avatar = $user->profile->avatar;
  162. if( $avatar->media_path == 'public/avatars/default.png' ||
  163. $avatar->media_path == 'public/avatars/default.jpg'
  164. ) {
  165. return AccountService::get($user->profile_id);
  166. }
  167. if(is_file(storage_path('app/' . $avatar->media_path))) {
  168. @unlink(storage_path('app/' . $avatar->media_path));
  169. }
  170. $avatar->media_path = 'public/avatars/default.jpg';
  171. $avatar->change_count = $avatar->change_count + 1;
  172. $avatar->save();
  173. Cache::forget('avatar:' . $user->profile_id);
  174. Cache::forget("avatar:{$user->profile_id}");
  175. Cache::forget('user:account:id:'.$user->id);
  176. AccountService::del($user->profile_id);
  177. return AccountService::get($user->profile_id);
  178. }
  179. /**
  180. * GET /api/v1.1/accounts/{id}/posts
  181. *
  182. * @return \App\Transformer\Api\StatusTransformer
  183. */
  184. public function accountPosts(Request $request, $id)
  185. {
  186. abort_if(!$request->user() || !$request->user()->token(), 403);
  187. abort_unless($request->user()->tokenCan('read'), 403);
  188. $user = $request->user();
  189. abort_if($user->status != null, 403);
  190. if(config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  191. abort_if(BouncerService::checkIp($request->ip()), 404);
  192. }
  193. $account = AccountService::get($id);
  194. if(!$account || $account['username'] !== $request->input('username')) {
  195. return $this->json([]);
  196. }
  197. $posts = ProfileStatusService::get($id);
  198. if(!$posts) {
  199. return $this->json([]);
  200. }
  201. $res = collect($posts)
  202. ->map(function($id) {
  203. return StatusService::get($id);
  204. })
  205. ->filter(function($post) {
  206. return $post && isset($post['account']);
  207. })
  208. ->toArray();
  209. return $this->json($res);
  210. }
  211. /**
  212. * POST /api/v1.1/accounts/change-password
  213. *
  214. * @return \App\Transformer\Api\AccountTransformer
  215. */
  216. public function accountChangePassword(Request $request)
  217. {
  218. abort_if(!$request->user() || !$request->user()->token(), 403);
  219. abort_unless($request->user()->tokenCan('write'), 403);
  220. $user = $request->user();
  221. abort_if($user->status != null, 403);
  222. if(config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  223. abort_if(BouncerService::checkIp($request->ip()), 404);
  224. }
  225. $this->validate($request, [
  226. 'current_password' => 'bail|required|current_password',
  227. 'new_password' => 'required|min:' . config('pixelfed.min_password_length', 8),
  228. 'confirm_password' => 'required|same:new_password'
  229. ],[
  230. 'current_password' => 'The password you entered is incorrect'
  231. ]);
  232. $user->password = bcrypt($request->input('new_password'));
  233. $user->save();
  234. $log = new AccountLog;
  235. $log->user_id = $user->id;
  236. $log->item_id = $user->id;
  237. $log->item_type = 'App\User';
  238. $log->action = 'account.edit.password';
  239. $log->message = 'Password changed';
  240. $log->link = null;
  241. $log->ip_address = $request->ip();
  242. $log->user_agent = $request->userAgent();
  243. $log->save();
  244. Mail::to($request->user())->send(new PasswordChange($user));
  245. return $this->json(AccountService::get($user->profile_id));
  246. }
  247. /**
  248. * GET /api/v1.1/accounts/login-activity
  249. *
  250. * @return array
  251. */
  252. public function accountLoginActivity(Request $request)
  253. {
  254. abort_if(!$request->user() || !$request->user()->token(), 403);
  255. abort_unless($request->user()->tokenCan('read'), 403);
  256. $user = $request->user();
  257. abort_if($user->status != null, 403);
  258. if(config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  259. abort_if(BouncerService::checkIp($request->ip()), 404);
  260. }
  261. $agent = new Agent();
  262. $currentIp = $request->ip();
  263. $activity = AccountLog::whereUserId($user->id)
  264. ->whereAction('auth.login')
  265. ->orderBy('created_at', 'desc')
  266. ->groupBy('ip_address')
  267. ->limit(10)
  268. ->get()
  269. ->map(function($item) use($agent, $currentIp) {
  270. $agent->setUserAgent($item->user_agent);
  271. return [
  272. 'id' => $item->id,
  273. 'action' => $item->action,
  274. 'ip' => $item->ip_address,
  275. 'ip_current' => $item->ip_address === $currentIp,
  276. 'is_mobile' => $agent->isMobile(),
  277. 'device' => $agent->device(),
  278. 'browser' => $agent->browser(),
  279. 'platform' => $agent->platform(),
  280. 'created_at' => $item->created_at->format('c')
  281. ];
  282. });
  283. return $this->json($activity);
  284. }
  285. /**
  286. * GET /api/v1.1/accounts/two-factor
  287. *
  288. * @return array
  289. */
  290. public function accountTwoFactor(Request $request)
  291. {
  292. abort_if(!$request->user() || !$request->user()->token(), 403);
  293. abort_unless($request->user()->tokenCan('read'), 403);
  294. $user = $request->user();
  295. abort_if($user->status != null, 403);
  296. if(config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  297. abort_if(BouncerService::checkIp($request->ip()), 404);
  298. }
  299. $res = [
  300. 'active' => (bool) $user->{'2fa_enabled'},
  301. 'setup_at' => $user->{'2fa_setup_at'}
  302. ];
  303. return $this->json($res);
  304. }
  305. /**
  306. * GET /api/v1.1/accounts/emails-from-pixelfed
  307. *
  308. * @return array
  309. */
  310. public function accountEmailsFromPixelfed(Request $request)
  311. {
  312. abort_if(!$request->user() || !$request->user()->token(), 403);
  313. abort_unless($request->user()->tokenCan('read'), 403);
  314. $user = $request->user();
  315. abort_if($user->status != null, 403);
  316. if(config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  317. abort_if(BouncerService::checkIp($request->ip()), 404);
  318. }
  319. $from = config('mail.from.address');
  320. $emailVerifications = EmailVerification::whereUserId($user->id)
  321. ->orderByDesc('id')
  322. ->where('created_at', '>', now()->subDays(14))
  323. ->limit(10)
  324. ->get()
  325. ->map(function($mail) use($user, $from) {
  326. return [
  327. 'type' => 'Email Verification',
  328. 'subject' => 'Confirm Email',
  329. 'to_address' => $user->email,
  330. 'from_address' => $from,
  331. 'created_at' => str_replace('@', 'at', $mail->created_at->format('M j, Y @ g:i:s A'))
  332. ];
  333. })
  334. ->toArray();
  335. $passwordResets = DB::table('password_resets')
  336. ->whereEmail($user->email)
  337. ->where('created_at', '>', now()->subDays(14))
  338. ->orderByDesc('created_at')
  339. ->limit(10)
  340. ->get()
  341. ->map(function($mail) use($user, $from) {
  342. return [
  343. 'type' => 'Password Reset',
  344. 'subject' => 'Reset Password Notification',
  345. 'to_address' => $user->email,
  346. 'from_address' => $from,
  347. 'created_at' => str_replace('@', 'at', now()->parse($mail->created_at)->format('M j, Y @ g:i:s A'))
  348. ];
  349. })
  350. ->toArray();
  351. $passwordChanges = AccountLog::whereUserId($user->id)
  352. ->whereAction('account.edit.password')
  353. ->where('created_at', '>', now()->subDays(14))
  354. ->orderByDesc('created_at')
  355. ->limit(10)
  356. ->get()
  357. ->map(function($mail) use($user, $from) {
  358. return [
  359. 'type' => 'Password Change',
  360. 'subject' => 'Password Change',
  361. 'to_address' => $user->email,
  362. 'from_address' => $from,
  363. 'created_at' => str_replace('@', 'at', now()->parse($mail->created_at)->format('M j, Y @ g:i:s A'))
  364. ];
  365. })
  366. ->toArray();
  367. $res = collect([])
  368. ->merge($emailVerifications)
  369. ->merge($passwordResets)
  370. ->merge($passwordChanges)
  371. ->sortByDesc('created_at')
  372. ->values();
  373. return $this->json($res);
  374. }
  375. /**
  376. * GET /api/v1.1/accounts/apps-and-applications
  377. *
  378. * @return array
  379. */
  380. public function accountApps(Request $request)
  381. {
  382. abort_if(!$request->user() || !$request->user()->token(), 403);
  383. abort_unless($request->user()->tokenCan('read'), 403);
  384. $user = $request->user();
  385. abort_if($user->status != null, 403);
  386. if(config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  387. abort_if(BouncerService::checkIp($request->ip()), 404);
  388. }
  389. $res = $user->tokens->sortByDesc('created_at')->take(10)->map(function($token, $key) use($request) {
  390. return [
  391. 'id' => $token->id,
  392. 'current_session' => $request->user()->token()->id == $token->id,
  393. 'name' => $token->client->name,
  394. 'scopes' => $token->scopes,
  395. 'revoked' => $token->revoked,
  396. 'created_at' => str_replace('@', 'at', now()->parse($token->created_at)->format('M j, Y @ g:i:s A')),
  397. 'expires_at' => str_replace('@', 'at', now()->parse($token->expires_at)->format('M j, Y @ g:i:s A'))
  398. ];
  399. });
  400. return $this->json($res);
  401. }
  402. public function inAppRegistrationPreFlightCheck(Request $request)
  403. {
  404. return [
  405. 'open' => (bool) config_cache('pixelfed.open_registration'),
  406. 'iara' => config('pixelfed.allow_app_registration')
  407. ];
  408. }
  409. public function inAppRegistration(Request $request)
  410. {
  411. abort_if($request->user(), 404);
  412. abort_unless(config_cache('pixelfed.open_registration'), 404);
  413. abort_unless(config('pixelfed.allow_app_registration'), 404);
  414. abort_unless($request->hasHeader('X-PIXELFED-APP'), 403);
  415. if(config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  416. abort_if(BouncerService::checkIp($request->ip()), 404);
  417. }
  418. $rl = RateLimiter::attempt('pf:apiv1.1:iar:'.$request->ip(), config('pixelfed.app_registration_rate_limit_attempts', 3), function(){}, config('pixelfed.app_registration_rate_limit_decay', 1800));
  419. abort_if(!$rl, 400, 'Too many requests');
  420. $this->validate($request, [
  421. 'email' => [
  422. 'required',
  423. 'string',
  424. 'email',
  425. 'max:255',
  426. 'unique:users',
  427. function ($attribute, $value, $fail) {
  428. $banned = EmailService::isBanned($value);
  429. if($banned) {
  430. return $fail('Email is invalid.');
  431. }
  432. },
  433. ],
  434. 'username' => [
  435. 'required',
  436. 'min:2',
  437. 'max:15',
  438. 'unique:users',
  439. function ($attribute, $value, $fail) {
  440. $dash = substr_count($value, '-');
  441. $underscore = substr_count($value, '_');
  442. $period = substr_count($value, '.');
  443. if(ends_with($value, ['.php', '.js', '.css'])) {
  444. return $fail('Username is invalid.');
  445. }
  446. if(($dash + $underscore + $period) > 1) {
  447. return $fail('Username is invalid. Can only contain one dash (-), period (.) or underscore (_).');
  448. }
  449. if (!ctype_alnum($value[0])) {
  450. return $fail('Username is invalid. Must start with a letter or number.');
  451. }
  452. if (!ctype_alnum($value[strlen($value) - 1])) {
  453. return $fail('Username is invalid. Must end with a letter or number.');
  454. }
  455. $val = str_replace(['_', '.', '-'], '', $value);
  456. if(!ctype_alnum($val)) {
  457. return $fail('Username is invalid. Username must be alpha-numeric and may contain dashes (-), periods (.) and underscores (_).');
  458. }
  459. $restricted = RestrictedNames::get();
  460. if (in_array(strtolower($value), array_map('strtolower', $restricted))) {
  461. return $fail('Username cannot be used.');
  462. }
  463. },
  464. ],
  465. 'password' => 'required|string|min:8',
  466. ]);
  467. $email = $request->input('email');
  468. $username = $request->input('username');
  469. $password = $request->input('password');
  470. if(config('database.default') == 'pgsql') {
  471. $username = strtolower($username);
  472. $email = strtolower($email);
  473. }
  474. $user = new User;
  475. $user->name = $username;
  476. $user->username = $username;
  477. $user->email = $email;
  478. $user->password = Hash::make($password);
  479. $user->register_source = 'app';
  480. $user->app_register_ip = $request->ip();
  481. $user->app_register_token = Str::random(40);
  482. $user->save();
  483. $rtoken = Str::random(64);
  484. $verify = new EmailVerification();
  485. $verify->user_id = $user->id;
  486. $verify->email = $user->email;
  487. $verify->user_token = $user->app_register_token;
  488. $verify->random_token = $rtoken;
  489. $verify->save();
  490. $params = http_build_query([
  491. 'ut' => $user->app_register_token,
  492. 'rt' => $rtoken,
  493. 'ea' => base64_encode($user->email)
  494. ]);
  495. $appUrl = url('/api/v1.1/auth/iarer?'. $params);
  496. Mail::to($user->email)->send(new ConfirmAppEmail($verify, $appUrl));
  497. return response()->json([
  498. 'success' => true,
  499. ]);
  500. }
  501. public function inAppRegistrationEmailRedirect(Request $request)
  502. {
  503. $this->validate($request, [
  504. 'ut' => 'required',
  505. 'rt' => 'required',
  506. 'ea' => 'required'
  507. ]);
  508. $ut = $request->input('ut');
  509. $rt = $request->input('rt');
  510. $ea = $request->input('ea');
  511. $params = http_build_query([
  512. 'ut' => $ut,
  513. 'rt' => $rt,
  514. 'domain' => config('pixelfed.domain.app'),
  515. 'ea' => $ea
  516. ]);
  517. $url = 'pixelfed://confirm-account/'. $ut . '?' . $params;
  518. return redirect()->away($url);
  519. }
  520. public function inAppRegistrationConfirm(Request $request)
  521. {
  522. abort_if($request->user(), 404);
  523. abort_unless(config_cache('pixelfed.open_registration'), 404);
  524. abort_unless(config('pixelfed.allow_app_registration'), 404);
  525. abort_unless($request->hasHeader('X-PIXELFED-APP'), 403);
  526. if(config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  527. abort_if(BouncerService::checkIp($request->ip()), 404);
  528. }
  529. $rl = RateLimiter::attempt('pf:apiv1.1:iarc:'.$request->ip(), config('pixelfed.app_registration_confirm_rate_limit_attempts', 20), function(){}, config('pixelfed.app_registration_confirm_rate_limit_decay', 1800));
  530. abort_if(!$rl, 429, 'Too many requests');
  531. $this->validate($request, [
  532. 'user_token' => 'required',
  533. 'random_token' => 'required',
  534. 'email' => 'required'
  535. ]);
  536. $verify = EmailVerification::whereEmail($request->input('email'))
  537. ->whereUserToken($request->input('user_token'))
  538. ->whereRandomToken($request->input('random_token'))
  539. ->first();
  540. if(!$verify) {
  541. return response()->json(['error' => 'Invalid tokens'], 403);
  542. }
  543. if($verify->created_at->lt(now()->subHours(24))) {
  544. $verify->delete();
  545. return response()->json(['error' => 'Invalid tokens'], 403);
  546. }
  547. $user = User::findOrFail($verify->user_id);
  548. $user->email_verified_at = now();
  549. $user->last_active_at = now();
  550. $user->save();
  551. $token = $user->createToken('Pixelfed');
  552. return response()->json([
  553. 'access_token' => $token->accessToken
  554. ]);
  555. }
  556. public function archive(Request $request, $id)
  557. {
  558. abort_if(!$request->user() || !$request->user()->token(), 403);
  559. abort_unless($request->user()->tokenCan('write'), 403);
  560. if(config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  561. abort_if(BouncerService::checkIp($request->ip()), 404);
  562. }
  563. $status = Status::whereNull('in_reply_to_id')
  564. ->whereNull('reblog_of_id')
  565. ->whereProfileId($request->user()->profile_id)
  566. ->findOrFail($id);
  567. if($status->scope === 'archived') {
  568. return [200];
  569. }
  570. $archive = new StatusArchived;
  571. $archive->status_id = $status->id;
  572. $archive->profile_id = $status->profile_id;
  573. $archive->original_scope = $status->scope;
  574. $archive->save();
  575. $status->scope = 'archived';
  576. $status->visibility = 'draft';
  577. $status->save();
  578. StatusService::del($status->id, true);
  579. AccountService::syncPostCount($status->profile_id);
  580. return [200];
  581. }
  582. public function unarchive(Request $request, $id)
  583. {
  584. abort_if(!$request->user() || !$request->user()->token(), 403);
  585. abort_unless($request->user()->tokenCan('write'), 403);
  586. if(config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  587. abort_if(BouncerService::checkIp($request->ip()), 404);
  588. }
  589. $status = Status::whereNull('in_reply_to_id')
  590. ->whereNull('reblog_of_id')
  591. ->whereProfileId($request->user()->profile_id)
  592. ->findOrFail($id);
  593. if($status->scope !== 'archived') {
  594. return [200];
  595. }
  596. $archive = StatusArchived::whereStatusId($status->id)
  597. ->whereProfileId($status->profile_id)
  598. ->firstOrFail();
  599. $status->scope = $archive->original_scope;
  600. $status->visibility = $archive->original_scope;
  601. $status->save();
  602. $archive->delete();
  603. StatusService::del($status->id, true);
  604. AccountService::syncPostCount($status->profile_id);
  605. return [200];
  606. }
  607. public function archivedPosts(Request $request)
  608. {
  609. abort_if(!$request->user() || !$request->user()->token(), 403);
  610. abort_unless($request->user()->tokenCan('read'), 403);
  611. if(config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  612. abort_if(BouncerService::checkIp($request->ip()), 404);
  613. }
  614. $statuses = Status::whereProfileId($request->user()->profile_id)
  615. ->whereScope('archived')
  616. ->orderByDesc('id')
  617. ->cursorPaginate(10);
  618. return StatusStateless::collection($statuses);
  619. }
  620. public function placesById(Request $request, $id, $slug)
  621. {
  622. abort_if(!$request->user() || !$request->user()->token(), 403);
  623. abort_unless($request->user()->tokenCan('read'), 403);
  624. if(config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  625. abort_if(BouncerService::checkIp($request->ip()), 404);
  626. }
  627. $place = Place::whereSlug($slug)->findOrFail($id);
  628. $posts = Cache::remember('pf-api:v1.1:places-by-id:' . $place->id, 3600, function() use($place) {
  629. return Status::wherePlaceId($place->id)
  630. ->whereNull('uri')
  631. ->whereScope('public')
  632. ->orderByDesc('created_at')
  633. ->limit(60)
  634. ->pluck('id');
  635. });
  636. $posts = $posts->map(function($id) {
  637. return StatusService::get($id);
  638. })
  639. ->filter()
  640. ->values();
  641. return [
  642. 'place' =>
  643. [
  644. 'id' => $place->id,
  645. 'name' => $place->name,
  646. 'slug' => $place->slug,
  647. 'country' => $place->country,
  648. 'lat' => $place->lat,
  649. 'long' => $place->long
  650. ],
  651. 'posts' => $posts];
  652. }
  653. public function moderatePost(Request $request, $id)
  654. {
  655. abort_if(!$request->user() || !$request->user()->token(), 403);
  656. abort_if($request->user()->is_admin != true, 403);
  657. abort_unless($request->user()->tokenCan('admin:write'), 403);
  658. if(config('pixelfed.bouncer.cloud_ips.ban_signups')) {
  659. abort_if(BouncerService::checkIp($request->ip()), 404);
  660. }
  661. $this->validate($request, [
  662. 'action' => 'required|in:cw,mark-public,mark-unlisted,mark-private,mark-spammer,delete'
  663. ]);
  664. $action = $request->input('action');
  665. $status = Status::find($id);
  666. if(!$status) {
  667. return response()->json(['error' => 'Cannot find status'], 400);
  668. }
  669. if($status->uri == null) {
  670. if($status->profile->user && $status->profile->user->is_admin) {
  671. return response()->json(['error' => 'Cannot moderate admin accounts'], 400);
  672. }
  673. }
  674. if($action == 'mark-spammer') {
  675. $status->profile->update([
  676. 'unlisted' => true,
  677. 'cw' => true,
  678. 'no_autolink' => true
  679. ]);
  680. Status::whereProfileId($status->profile_id)
  681. ->get()
  682. ->each(function($s) {
  683. if(in_array($s->scope, ['public', 'unlisted'])) {
  684. $s->scope = 'private';
  685. $s->visibility = 'private';
  686. }
  687. $s->is_nsfw = true;
  688. $s->save();
  689. StatusService::del($s->id, true);
  690. });
  691. Cache::forget('pf:bouncer_v0:exemption_by_pid:' . $status->profile_id);
  692. Cache::forget('pf:bouncer_v0:recent_by_pid:' . $status->profile_id);
  693. Cache::forget('admin-dash:reports:spam-count');
  694. } else if ($action == 'cw') {
  695. $state = $status->is_nsfw;
  696. $status->is_nsfw = !$state;
  697. $status->save();
  698. StatusService::del($status->id);
  699. } else if ($action == 'mark-public') {
  700. $state = $status->scope;
  701. $status->scope = 'public';
  702. $status->visibility = 'public';
  703. $status->save();
  704. StatusService::del($status->id, true);
  705. if($state !== 'public') {
  706. if($status->uri) {
  707. if($status->in_reply_to_id == null && $status->reblog_of_id == null) {
  708. NetworkTimelineService::add($status->id);
  709. }
  710. } else {
  711. if($status->in_reply_to_id == null && $status->reblog_of_id == null) {
  712. PublicTimelineService::add($status->id);
  713. }
  714. }
  715. }
  716. } else if ($action == 'mark-unlisted') {
  717. $state = $status->scope;
  718. $status->scope = 'unlisted';
  719. $status->visibility = 'unlisted';
  720. $status->save();
  721. StatusService::del($status->id);
  722. if($state == 'public') {
  723. PublicTimelineService::del($status->id);
  724. NetworkTimelineService::del($status->id);
  725. }
  726. } else if ($action == 'mark-private') {
  727. $state = $status->scope;
  728. $status->scope = 'private';
  729. $status->visibility = 'private';
  730. $status->save();
  731. StatusService::del($status->id);
  732. if($state == 'public') {
  733. PublicTimelineService::del($status->id);
  734. NetworkTimelineService::del($status->id);
  735. }
  736. } else if ($action == 'delete') {
  737. PublicTimelineService::del($status->id);
  738. NetworkTimelineService::del($status->id);
  739. Cache::forget('_api:statuses:recent_9:' . $status->profile_id);
  740. Cache::forget('profile:status_count:' . $status->profile_id);
  741. Cache::forget('profile:embed:' . $status->profile_id);
  742. StatusService::del($status->id, true);
  743. Cache::forget('profile:status_count:'.$status->profile_id);
  744. $status->uri ? RemoteStatusDelete::dispatch($status) : StatusDelete::dispatch($status);
  745. return [];
  746. }
  747. Cache::forget('_api:statuses:recent_9:'.$status->profile_id);
  748. return StatusService::get($status->id, false);
  749. }
  750. public function getWebSettings(Request $request)
  751. {
  752. abort_if(!$request->user() || !$request->user()->token(), 403);
  753. abort_unless($request->user()->tokenCan('read'), 403);
  754. $uid = $request->user()->id;
  755. $settings = UserSetting::firstOrCreate([
  756. 'user_id' => $uid
  757. ]);
  758. if(!$settings->other) {
  759. return [];
  760. }
  761. return $settings->other;
  762. }
  763. public function setWebSettings(Request $request)
  764. {
  765. abort_if(!$request->user() || !$request->user()->token(), 403);
  766. abort_unless($request->user()->tokenCan('write'), 403);
  767. $this->validate($request, [
  768. 'field' => 'required|in:enable_reblogs,hide_reblog_banner',
  769. 'value' => 'required'
  770. ]);
  771. $field = $request->input('field');
  772. $value = $request->input('value');
  773. $settings = UserSetting::firstOrCreate([
  774. 'user_id' => $request->user()->id
  775. ]);
  776. if(!$settings->other) {
  777. $other = [];
  778. } else {
  779. $other = $settings->other;
  780. }
  781. $other[$field] = $value;
  782. $settings->other = $other;
  783. $settings->save();
  784. return [200];
  785. }
  786. public function getMutualAccounts(Request $request, $id)
  787. {
  788. abort_if(!$request->user() || !$request->user()->token(), 403);
  789. abort_unless($request->user()->tokenCan('follows'), 403);
  790. $account = AccountService::get($id, true);
  791. if(!$account || !isset($account['id'])) { return []; }
  792. $res = collect(FollowerService::mutualAccounts($request->user()->profile_id, $id))
  793. ->map(function($accountId) {
  794. return AccountService::get($accountId, true);
  795. })
  796. ->filter()
  797. ->take(24)
  798. ->values();
  799. return $this->json($res);
  800. }
  801. }