]> git.immae.eu Git - github/Chocobozzz/PeerTube.git/blame - server/controllers/api/abuse.ts
Remove traefik docker support
[github/Chocobozzz/PeerTube.git] / server / controllers / api / abuse.ts
CommitLineData
d95d1559 1import * as express from 'express'
bd45d503 2import { logger } from '@server/helpers/logger'
d95d1559 3import { createAccountAbuse, createVideoAbuse, createVideoCommentAbuse } from '@server/lib/moderation'
bd45d503 4import { Notifier } from '@server/lib/notifier'
d95d1559 5import { AbuseModel } from '@server/models/abuse/abuse'
edbc9325 6import { AbuseMessageModel } from '@server/models/abuse/abuse-message'
d95d1559 7import { getServerActor } from '@server/models/application/application'
bd45d503 8import { abusePredefinedReasonsMap } from '@shared/core-utils/abuse'
2d53be02 9import { HttpStatusCode } from '@shared/core-utils/miscs/http-error-codes'
bd45d503 10import { AbuseCreate, AbuseState, UserRight } from '../../../shared'
d95d1559
C
11import { getFormattedObjects } from '../../helpers/utils'
12import { sequelizeTypescript } from '../../initializers/database'
13import {
14 abuseGetValidator,
edbc9325 15 abuseListForAdminsValidator,
d95d1559
C
16 abuseReportValidator,
17 abusesSortValidator,
18 abuseUpdateValidator,
edbc9325 19 addAbuseMessageValidator,
d95d1559
C
20 asyncMiddleware,
21 asyncRetryTransactionMiddleware,
22 authenticate,
94148c90 23 checkAbuseValidForMessagesValidator,
edbc9325 24 deleteAbuseMessageValidator,
d95d1559 25 ensureUserHasRight,
edbc9325 26 getAbuseValidator,
d95d1559
C
27 paginationValidator,
28 setDefaultPagination,
29 setDefaultSort
30} from '../../middlewares'
31import { AccountModel } from '../../models/account/account'
32
33const abuseRouter = express.Router()
34
57f6896f 35abuseRouter.get('/',
d95d1559
C
36 authenticate,
37 ensureUserHasRight(UserRight.MANAGE_ABUSES),
38 paginationValidator,
39 abusesSortValidator,
40 setDefaultSort,
41 setDefaultPagination,
edbc9325
C
42 abuseListForAdminsValidator,
43 asyncMiddleware(listAbusesForAdmins)
d95d1559 44)
57f6896f 45abuseRouter.put('/:id',
d95d1559
C
46 authenticate,
47 ensureUserHasRight(UserRight.MANAGE_ABUSES),
48 asyncMiddleware(abuseUpdateValidator),
49 asyncRetryTransactionMiddleware(updateAbuse)
50)
57f6896f 51abuseRouter.post('/',
d95d1559
C
52 authenticate,
53 asyncMiddleware(abuseReportValidator),
54 asyncRetryTransactionMiddleware(reportAbuse)
55)
57f6896f 56abuseRouter.delete('/:id',
d95d1559
C
57 authenticate,
58 ensureUserHasRight(UserRight.MANAGE_ABUSES),
59 asyncMiddleware(abuseGetValidator),
60 asyncRetryTransactionMiddleware(deleteAbuse)
61)
62
edbc9325
C
63abuseRouter.get('/:id/messages',
64 authenticate,
65 asyncMiddleware(getAbuseValidator),
94148c90 66 checkAbuseValidForMessagesValidator,
edbc9325
C
67 asyncRetryTransactionMiddleware(listAbuseMessages)
68)
69
70abuseRouter.post('/:id/messages',
71 authenticate,
72 asyncMiddleware(getAbuseValidator),
94148c90 73 checkAbuseValidForMessagesValidator,
edbc9325
C
74 addAbuseMessageValidator,
75 asyncRetryTransactionMiddleware(addAbuseMessage)
76)
77
78abuseRouter.delete('/:id/messages/:messageId',
79 authenticate,
80 asyncMiddleware(getAbuseValidator),
94148c90 81 checkAbuseValidForMessagesValidator,
edbc9325
C
82 asyncMiddleware(deleteAbuseMessageValidator),
83 asyncRetryTransactionMiddleware(deleteAbuseMessage)
84)
85
d95d1559
C
86// ---------------------------------------------------------------------------
87
88export {
7a4ea932 89 abuseRouter
d95d1559
C
90}
91
92// ---------------------------------------------------------------------------
93
edbc9325 94async function listAbusesForAdmins (req: express.Request, res: express.Response) {
d95d1559
C
95 const user = res.locals.oauth.token.user
96 const serverActor = await getServerActor()
97
edbc9325 98 const resultList = await AbuseModel.listForAdminApi({
d95d1559
C
99 start: req.query.start,
100 count: req.query.count,
101 sort: req.query.sort,
102 id: req.query.id,
57f6896f 103 filter: req.query.filter,
d95d1559
C
104 predefinedReason: req.query.predefinedReason,
105 search: req.query.search,
106 state: req.query.state,
107 videoIs: req.query.videoIs,
108 searchReporter: req.query.searchReporter,
109 searchReportee: req.query.searchReportee,
110 searchVideo: req.query.searchVideo,
111 searchVideoChannel: req.query.searchVideoChannel,
112 serverAccountId: serverActor.Account.id,
113 user
114 })
115
edbc9325
C
116 return res.json({
117 total: resultList.total,
118 data: resultList.data.map(d => d.toFormattedAdminJSON())
119 })
d95d1559
C
120}
121
122async function updateAbuse (req: express.Request, res: express.Response) {
123 const abuse = res.locals.abuse
594d3e48 124 let stateUpdated = false
d95d1559
C
125
126 if (req.body.moderationComment !== undefined) abuse.moderationComment = req.body.moderationComment
594d3e48
C
127
128 if (req.body.state !== undefined) {
129 abuse.state = req.body.state
130 stateUpdated = true
131 }
d95d1559
C
132
133 await sequelizeTypescript.transaction(t => {
134 return abuse.save({ transaction: t })
135 })
136
594d3e48
C
137 if (stateUpdated === true) {
138 AbuseModel.loadFull(abuse.id)
139 .then(abuseFull => Notifier.Instance.notifyOnAbuseStateChange(abuseFull))
140 .catch(err => logger.error('Cannot notify on abuse state change', { err }))
141 }
edbc9325 142
310b5219 143 // Do not send the delete to other instances, we updated OUR copy of this abuse
d95d1559 144
2d53be02 145 return res.sendStatus(HttpStatusCode.NO_CONTENT_204)
d95d1559
C
146}
147
148async function deleteAbuse (req: express.Request, res: express.Response) {
149 const abuse = res.locals.abuse
150
151 await sequelizeTypescript.transaction(t => {
152 return abuse.destroy({ transaction: t })
153 })
154
310b5219 155 // Do not send the delete to other instances, we delete OUR copy of this abuse
d95d1559 156
2d53be02 157 return res.sendStatus(HttpStatusCode.NO_CONTENT_204)
d95d1559
C
158}
159
160async function reportAbuse (req: express.Request, res: express.Response) {
161 const videoInstance = res.locals.videoAll
162 const commentInstance = res.locals.videoCommentFull
163 const accountInstance = res.locals.account
164
165 const body: AbuseCreate = req.body
166
167 const { id } = await sequelizeTypescript.transaction(async t => {
168 const reporterAccount = await AccountModel.load(res.locals.oauth.token.User.Account.id, t)
169 const predefinedReasons = body.predefinedReasons?.map(r => abusePredefinedReasonsMap[r])
170
171 const baseAbuse = {
172 reporterAccountId: reporterAccount.id,
173 reason: body.reason,
174 state: AbuseState.PENDING,
175 predefinedReasons
176 }
177
178 if (body.video) {
179 return createVideoAbuse({
180 baseAbuse,
181 videoInstance,
182 reporterAccount,
183 transaction: t,
184 startAt: body.video.startAt,
185 endAt: body.video.endAt
186 })
187 }
188
189 if (body.comment) {
190 return createVideoCommentAbuse({
191 baseAbuse,
192 commentInstance,
193 reporterAccount,
194 transaction: t
195 })
196 }
197
198 // Account report
199 return createAccountAbuse({
200 baseAbuse,
201 accountInstance,
202 reporterAccount,
203 transaction: t
204 })
205 })
206
207 return res.json({ abuse: { id } })
208}
edbc9325
C
209
210async function listAbuseMessages (req: express.Request, res: express.Response) {
211 const abuse = res.locals.abuse
212
213 const resultList = await AbuseMessageModel.listForApi(abuse.id)
214
215 return res.json(getFormattedObjects(resultList.data, resultList.total))
216}
217
218async function addAbuseMessage (req: express.Request, res: express.Response) {
219 const abuse = res.locals.abuse
220 const user = res.locals.oauth.token.user
221
222 const abuseMessage = await AbuseMessageModel.create({
223 message: req.body.message,
224 byModerator: abuse.reporterAccountId !== user.Account.id,
225 accountId: user.Account.id,
226 abuseId: abuse.id
227 })
228
594d3e48
C
229 AbuseModel.loadFull(abuse.id)
230 .then(abuseFull => Notifier.Instance.notifyOnAbuseMessage(abuseFull, abuseMessage))
231 .catch(err => logger.error('Cannot notify on new abuse message', { err }))
edbc9325
C
232
233 return res.json({
234 abuseMessage: {
235 id: abuseMessage.id
236 }
237 })
238}
239
240async function deleteAbuseMessage (req: express.Request, res: express.Response) {
241 const abuseMessage = res.locals.abuseMessage
242
243 await sequelizeTypescript.transaction(t => {
244 return abuseMessage.destroy({ transaction: t })
245 })
246
2d53be02 247 return res.sendStatus(HttpStatusCode.NO_CONTENT_204)
edbc9325 248}