]> git.immae.eu Git - github/Chocobozzz/PeerTube.git/blame - server/controllers/api/videos/index.ts
Fix runner api rate limit bypass
[github/Chocobozzz/PeerTube.git] / server / controllers / api / videos / index.ts
CommitLineData
41fb13c3 1import express from 'express'
d6886027 2import { pickCommonVideoQuery } from '@server/helpers/query'
304a84d5 3import { doJSONRequest } from '@server/helpers/requests'
1c627fd8 4import { openapiOperationDoc } from '@server/middlewares/doc'
8054669f 5import { getServerActor } from '@server/models/application/application'
2760b454 6import { guessAdditionalAttributesFromQuery } from '@server/models/video/formatter/video-format-utils'
304a84d5 7import { MVideoAccountLight } from '@server/types/models'
c0e8b12e 8import { HttpStatusCode } from '../../../../shared/models'
8054669f 9import { auditLoggerFactory, getAuditIdFromRes, VideoAuditView } from '../../../helpers/audit-logger'
c158a5fa
C
10import { buildNSFWFilter, getCountVideos } from '../../../helpers/express-utils'
11import { logger } from '../../../helpers/logger'
8dc8a34e 12import { getFormattedObjects } from '../../../helpers/utils'
304a84d5 13import { REMOTE_SCHEME, VIDEO_CATEGORIES, VIDEO_LANGUAGES, VIDEO_LICENCES, VIDEO_PRIVACIES } from '../../../initializers/constants'
8054669f 14import { sequelizeTypescript } from '../../../initializers/database'
94a5ff8a 15import { JobQueue } from '../../../lib/job-queue'
8054669f 16import { Hooks } from '../../../lib/plugins/hooks'
65fcc311 17import {
e915cde3 18 apiRateLimiter,
ac81d1a0 19 asyncMiddleware,
90d4bb81 20 asyncRetryTransactionMiddleware,
ac81d1a0 21 authenticate,
8d427346 22 checkVideoFollowConstraints,
d525fc39 23 commonVideosFiltersValidator,
0883b324 24 optionalAuthenticate,
ac81d1a0
C
25 paginationValidator,
26 setDefaultPagination,
8054669f 27 setDefaultVideosSort,
09209296 28 videosCustomGetValidator,
ac81d1a0 29 videosGetValidator,
2e401e85 30 videoSourceGetValidator,
ac81d1a0 31 videosRemoveValidator,
c158a5fa 32 videosSortValidator
65fcc311 33} from '../../../middlewares'
3fd3ab2d 34import { VideoModel } from '../../../models/video/video'
65fcc311 35import { blacklistRouter } from './blacklist'
40e87e9e 36import { videoCaptionsRouter } from './captions'
8054669f 37import { videoCommentRouter } from './comment'
b46cf4b9 38import { filesRouter } from './files'
fbad87b0 39import { videoImportsRouter } from './import'
c6c0fa6c 40import { liveRouter } from './live'
8054669f
C
41import { ownershipVideoRouter } from './ownership'
42import { rateVideoRouter } from './rate'
b2111066
C
43import { statsRouter } from './stats'
44import { studioRouter } from './studio'
3545e72c 45import { tokenRouter } from './token'
ad5db104 46import { transcodingRouter } from './transcoding'
c158a5fa
C
47import { updateRouter } from './update'
48import { uploadRouter } from './upload'
b2111066 49import { viewRouter } from './view'
65fcc311 50
80e36cd9 51const auditLogger = auditLoggerFactory('videos')
65fcc311 52const videosRouter = express.Router()
8c308c2b 53
e915cde3
C
54videosRouter.use(apiRateLimiter)
55
65fcc311 56videosRouter.use('/', blacklistRouter)
b2111066 57videosRouter.use('/', statsRouter)
65fcc311 58videosRouter.use('/', rateVideoRouter)
bf1f6508 59videosRouter.use('/', videoCommentRouter)
92e66e04 60videosRouter.use('/', studioRouter)
40e87e9e 61videosRouter.use('/', videoCaptionsRouter)
fbad87b0 62videosRouter.use('/', videoImportsRouter)
74d63469 63videosRouter.use('/', ownershipVideoRouter)
b2111066 64videosRouter.use('/', viewRouter)
c6c0fa6c 65videosRouter.use('/', liveRouter)
c158a5fa
C
66videosRouter.use('/', uploadRouter)
67videosRouter.use('/', updateRouter)
b46cf4b9 68videosRouter.use('/', filesRouter)
ad5db104 69videosRouter.use('/', transcodingRouter)
3545e72c 70videosRouter.use('/', tokenRouter)
d33242b0 71
c756bae0
RK
72videosRouter.get('/categories',
73 openapiOperationDoc({ operationId: 'getCategories' }),
74 listVideoCategories
75)
76videosRouter.get('/licences',
77 openapiOperationDoc({ operationId: 'getLicences' }),
78 listVideoLicences
79)
80videosRouter.get('/languages',
81 openapiOperationDoc({ operationId: 'getLanguages' }),
82 listVideoLanguages
83)
84videosRouter.get('/privacies',
85 openapiOperationDoc({ operationId: 'getPrivacies' }),
86 listVideoPrivacies
87)
6e07c3de 88
65fcc311 89videosRouter.get('/',
c756bae0 90 openapiOperationDoc({ operationId: 'getVideos' }),
65fcc311
C
91 paginationValidator,
92 videosSortValidator,
8054669f 93 setDefaultVideosSort,
f05a1c30 94 setDefaultPagination,
0883b324 95 optionalAuthenticate,
d525fc39 96 commonVideosFiltersValidator,
eb080476 97 asyncMiddleware(listVideos)
fbf1134e 98)
f6d6e7f8 99
a5858c3e 100// TODO: remove, deprecated in 5.0 now we send the complete description in VideoDetails
9567011b 101videosRouter.get('/:id/description',
c756bae0 102 openapiOperationDoc({ operationId: 'getVideoDesc' }),
a2431b7d 103 asyncMiddleware(videosGetValidator),
9567011b
C
104 asyncMiddleware(getVideoDescription)
105)
2e401e85 106
107videosRouter.get('/:id/source',
108 openapiOperationDoc({ operationId: 'getVideoSource' }),
109 authenticate,
110 asyncMiddleware(videoSourceGetValidator),
111 getVideoSource
112)
113
65fcc311 114videosRouter.get('/:id',
1c627fd8 115 openapiOperationDoc({ operationId: 'getVideo' }),
6e46de09 116 optionalAuthenticate,
ca4b4b2e 117 asyncMiddleware(videosCustomGetValidator('for-api')),
8d427346 118 asyncMiddleware(checkVideoFollowConstraints),
0260dc8a 119 asyncMiddleware(getVideo)
fbf1134e 120)
198b205c 121
65fcc311 122videosRouter.delete('/:id',
1c627fd8 123 openapiOperationDoc({ operationId: 'delVideo' }),
65fcc311 124 authenticate,
a2431b7d 125 asyncMiddleware(videosRemoveValidator),
90d4bb81 126 asyncRetryTransactionMiddleware(removeVideo)
fbf1134e 127)
198b205c 128
9f10b292 129// ---------------------------------------------------------------------------
c45f7f84 130
65fcc311
C
131export {
132 videosRouter
133}
c45f7f84 134
9f10b292 135// ---------------------------------------------------------------------------
c45f7f84 136
f6d6e7f8 137function listVideoCategories (_req: express.Request, res: express.Response) {
65fcc311 138 res.json(VIDEO_CATEGORIES)
6e07c3de
C
139}
140
f6d6e7f8 141function listVideoLicences (_req: express.Request, res: express.Response) {
65fcc311 142 res.json(VIDEO_LICENCES)
6f0c39e2
C
143}
144
f6d6e7f8 145function listVideoLanguages (_req: express.Request, res: express.Response) {
65fcc311 146 res.json(VIDEO_LANGUAGES)
3092476e
C
147}
148
f6d6e7f8 149function listVideoPrivacies (_req: express.Request, res: express.Response) {
fd45e8f4
C
150 res.json(VIDEO_PRIVACIES)
151}
152
0260dc8a
C
153async function getVideo (_req: express.Request, res: express.Response) {
154 const videoId = res.locals.videoAPI.id
155 const userId = res.locals.oauth?.token.User.id
156
157 const video = await Hooks.wrapObject(res.locals.videoAPI, 'filter:api.video.get.result', { id: videoId, userId })
1f3e9fec 158
09209296 159 if (video.isOutdated()) {
bd911b54 160 JobQueue.Instance.createJobAsync({ type: 'activitypub-refresher', payload: { type: 'video', url: video.url } })
04b8c3fb
C
161 }
162
09209296 163 return res.json(video.toFormattedDetailsJSON())
1f3e9fec
C
164}
165
9567011b 166async function getVideoDescription (req: express.Request, res: express.Response) {
453e83ea 167 const videoInstance = res.locals.videoAll
9567011b 168
c158a5fa
C
169 const description = videoInstance.isOwned()
170 ? videoInstance.description
171 : await fetchRemoteVideoDescription(videoInstance)
9567011b
C
172
173 return res.json({ description })
174}
175
2e401e85 176function getVideoSource (req: express.Request, res: express.Response) {
177 return res.json(res.locals.videoSource.toFormattedJSON())
178}
179
04b8c3fb 180async function listVideos (req: express.Request, res: express.Response) {
2760b454
C
181 const serverActor = await getServerActor()
182
d6886027 183 const query = pickCommonVideoQuery(req.query)
fe987656
C
184 const countVideos = getCountVideos(req)
185
b4055e1c 186 const apiOptions = await Hooks.wrapObject({
d6886027
C
187 ...query,
188
2760b454
C
189 displayOnlyForFollower: {
190 actorId: serverActor.id,
191 orLocalVideos: true
192 },
1fd61899 193 nsfw: buildNSFWFilter(res, query.nsfw),
fe987656
C
194 user: res.locals.oauth ? res.locals.oauth.token.User : undefined,
195 countVideos
b4055e1c
C
196 }, 'filter:api.videos.list.params')
197
89cd1275
C
198 const resultList = await Hooks.wrapPromiseFun(
199 VideoModel.listForApi,
200 apiOptions,
b4055e1c
C
201 'filter:api.videos.list.result'
202 )
eb080476 203
2760b454 204 return res.json(getFormattedObjects(resultList.data, resultList.total, guessAdditionalAttributesFromQuery(query)))
9f10b292 205}
c45f7f84 206
7226e90f 207async function removeVideo (req: express.Request, res: express.Response) {
453e83ea 208 const videoInstance = res.locals.videoAll
91f6f169 209
3fd3ab2d 210 await sequelizeTypescript.transaction(async t => {
eb080476 211 await videoInstance.destroy({ transaction: t })
91f6f169 212 })
eb080476 213
993cef4b 214 auditLogger.delete(getAuditIdFromRes(res), new VideoAuditView(videoInstance.toFormattedDetailsJSON()))
eb080476 215 logger.info('Video with name %s and uuid %s deleted.', videoInstance.name, videoInstance.uuid)
90d4bb81 216
7226e90f 217 Hooks.runAction('action:api.video.deleted', { video: videoInstance, req, res })
b4055e1c 218
2d53be02
RK
219 return res.type('json')
220 .status(HttpStatusCode.NO_CONTENT_204)
221 .end()
9f10b292 222}
304a84d5
C
223
224// ---------------------------------------------------------------------------
225
226// FIXME: Should not exist, we rely on specific API
227async function fetchRemoteVideoDescription (video: MVideoAccountLight) {
228 const host = video.VideoChannel.Account.Actor.Server.host
229 const path = video.getDescriptionAPIPath()
230 const url = REMOTE_SCHEME.HTTP + '://' + host + path
231
232 const { body } = await doJSONRequest<any>(url)
233 return body.description || ''
234}