1 import * as express from 'express'
2 import { logger } from '@server/helpers/logger'
3 import { createAccountAbuse, createVideoAbuse, createVideoCommentAbuse } from '@server/lib/moderation'
4 import { Notifier } from '@server/lib/notifier'
5 import { AbuseModel } from '@server/models/abuse/abuse'
6 import { AbuseMessageModel } from '@server/models/abuse/abuse-message'
7 import { getServerActor } from '@server/models/application/application'
8 import { abusePredefinedReasonsMap } from '@shared/core-utils/abuse'
9 import { HttpStatusCode } from '@shared/core-utils/miscs/http-error-codes'
10 import { AbuseCreate, AbuseState, UserRight } from '../../../shared'
11 import { getFormattedObjects } from '../../helpers/utils'
12 import { sequelizeTypescript } from '../../initializers/database'
15 abuseListForAdminsValidator,
19 addAbuseMessageValidator,
21 asyncRetryTransactionMiddleware,
23 checkAbuseValidForMessagesValidator,
24 deleteAbuseMessageValidator,
30 } from '../../middlewares'
31 import { AccountModel } from '../../models/account/account'
33 const abuseRouter = express.Router()
37 ensureUserHasRight(UserRight.MANAGE_ABUSES),
42 abuseListForAdminsValidator,
43 asyncMiddleware(listAbusesForAdmins)
45 abuseRouter.put('/:id',
47 ensureUserHasRight(UserRight.MANAGE_ABUSES),
48 asyncMiddleware(abuseUpdateValidator),
49 asyncRetryTransactionMiddleware(updateAbuse)
53 asyncMiddleware(abuseReportValidator),
54 asyncRetryTransactionMiddleware(reportAbuse)
56 abuseRouter.delete('/:id',
58 ensureUserHasRight(UserRight.MANAGE_ABUSES),
59 asyncMiddleware(abuseGetValidator),
60 asyncRetryTransactionMiddleware(deleteAbuse)
63 abuseRouter.get('/:id/messages',
65 asyncMiddleware(getAbuseValidator),
66 checkAbuseValidForMessagesValidator,
67 asyncRetryTransactionMiddleware(listAbuseMessages)
70 abuseRouter.post('/:id/messages',
72 asyncMiddleware(getAbuseValidator),
73 checkAbuseValidForMessagesValidator,
74 addAbuseMessageValidator,
75 asyncRetryTransactionMiddleware(addAbuseMessage)
78 abuseRouter.delete('/:id/messages/:messageId',
80 asyncMiddleware(getAbuseValidator),
81 checkAbuseValidForMessagesValidator,
82 asyncMiddleware(deleteAbuseMessageValidator),
83 asyncRetryTransactionMiddleware(deleteAbuseMessage)
86 // ---------------------------------------------------------------------------
92 // ---------------------------------------------------------------------------
94 async function listAbusesForAdmins (req: express.Request, res: express.Response) {
95 const user = res.locals.oauth.token.user
96 const serverActor = await getServerActor()
98 const resultList = await AbuseModel.listForAdminApi({
99 start: req.query.start,
100 count: req.query.count,
101 sort: req.query.sort,
103 filter: req.query.filter,
104 predefinedReason: req.query.predefinedReason,
105 search: req.query.search,
106 state: req.query.state,
107 videoIs: req.query.videoIs,
108 searchReporter: req.query.searchReporter,
109 searchReportee: req.query.searchReportee,
110 searchVideo: req.query.searchVideo,
111 searchVideoChannel: req.query.searchVideoChannel,
112 serverAccountId: serverActor.Account.id,
117 total: resultList.total,
118 data: resultList.data.map(d => d.toFormattedAdminJSON())
122 async function updateAbuse (req: express.Request, res: express.Response) {
123 const abuse = res.locals.abuse
124 let stateUpdated = false
126 if (req.body.moderationComment !== undefined) abuse.moderationComment = req.body.moderationComment
128 if (req.body.state !== undefined) {
129 abuse.state = req.body.state
133 await sequelizeTypescript.transaction(t => {
134 return abuse.save({ transaction: t })
137 if (stateUpdated === true) {
138 AbuseModel.loadFull(abuse.id)
139 .then(abuseFull => Notifier.Instance.notifyOnAbuseStateChange(abuseFull))
140 .catch(err => logger.error('Cannot notify on abuse state change', { err }))
143 // Do not send the delete to other instances, we updated OUR copy of this abuse
145 return res.sendStatus(HttpStatusCode.NO_CONTENT_204)
148 async function deleteAbuse (req: express.Request, res: express.Response) {
149 const abuse = res.locals.abuse
151 await sequelizeTypescript.transaction(t => {
152 return abuse.destroy({ transaction: t })
155 // Do not send the delete to other instances, we delete OUR copy of this abuse
157 return res.sendStatus(HttpStatusCode.NO_CONTENT_204)
160 async function reportAbuse (req: express.Request, res: express.Response) {
161 const videoInstance = res.locals.videoAll
162 const commentInstance = res.locals.videoCommentFull
163 const accountInstance = res.locals.account
165 const body: AbuseCreate = req.body
167 const { id } = await sequelizeTypescript.transaction(async t => {
168 const reporterAccount = await AccountModel.load(res.locals.oauth.token.User.Account.id, t)
169 const predefinedReasons = body.predefinedReasons?.map(r => abusePredefinedReasonsMap[r])
172 reporterAccountId: reporterAccount.id,
174 state: AbuseState.PENDING,
179 return createVideoAbuse({
184 startAt: body.video.startAt,
185 endAt: body.video.endAt
190 return createVideoCommentAbuse({
199 return createAccountAbuse({
207 return res.json({ abuse: { id } })
210 async function listAbuseMessages (req: express.Request, res: express.Response) {
211 const abuse = res.locals.abuse
213 const resultList = await AbuseMessageModel.listForApi(abuse.id)
215 return res.json(getFormattedObjects(resultList.data, resultList.total))
218 async function addAbuseMessage (req: express.Request, res: express.Response) {
219 const abuse = res.locals.abuse
220 const user = res.locals.oauth.token.user
222 const abuseMessage = await AbuseMessageModel.create({
223 message: req.body.message,
224 byModerator: abuse.reporterAccountId !== user.Account.id,
225 accountId: user.Account.id,
229 AbuseModel.loadFull(abuse.id)
230 .then(abuseFull => Notifier.Instance.notifyOnAbuseMessage(abuseFull, abuseMessage))
231 .catch(err => logger.error('Cannot notify on new abuse message', { err }))
240 async function deleteAbuseMessage (req: express.Request, res: express.Response) {
241 const abuseMessage = res.locals.abuseMessage
243 await sequelizeTypescript.transaction(t => {
244 return abuseMessage.destroy({ transaction: t })
247 return res.sendStatus(HttpStatusCode.NO_CONTENT_204)