1 import express from 'express'
2 import { logger } from '@server/helpers/logger'
3 import { createAccountAbuse, createVideoAbuse, createVideoCommentAbuse } from '@server/lib/moderation'
4 import { Notifier } from '@server/lib/notifier'
5 import { AbuseModel } from '@server/models/abuse/abuse'
6 import { AbuseMessageModel } from '@server/models/abuse/abuse-message'
7 import { getServerActor } from '@server/models/application/application'
8 import { abusePredefinedReasonsMap } from '@shared/core-utils/abuse'
9 import { AbuseCreate, AbuseState, HttpStatusCode, UserRight } from '@shared/models'
10 import { getFormattedObjects } from '../../helpers/utils'
11 import { sequelizeTypescript } from '../../initializers/database'
14 abuseListForAdminsValidator,
18 addAbuseMessageValidator,
21 asyncRetryTransactionMiddleware,
23 checkAbuseValidForMessagesValidator,
24 deleteAbuseMessageValidator,
31 } from '../../middlewares'
32 import { AccountModel } from '../../models/account/account'
34 const abuseRouter = express.Router()
36 abuseRouter.use(apiRateLimiter)
39 openapiOperationDoc({ operationId: 'getAbuses' }),
41 ensureUserHasRight(UserRight.MANAGE_ABUSES),
46 abuseListForAdminsValidator,
47 asyncMiddleware(listAbusesForAdmins)
49 abuseRouter.put('/:id',
51 ensureUserHasRight(UserRight.MANAGE_ABUSES),
52 asyncMiddleware(abuseUpdateValidator),
53 asyncRetryTransactionMiddleware(updateAbuse)
57 asyncMiddleware(abuseReportValidator),
58 asyncRetryTransactionMiddleware(reportAbuse)
60 abuseRouter.delete('/:id',
62 ensureUserHasRight(UserRight.MANAGE_ABUSES),
63 asyncMiddleware(abuseGetValidator),
64 asyncRetryTransactionMiddleware(deleteAbuse)
67 abuseRouter.get('/:id/messages',
69 asyncMiddleware(getAbuseValidator),
70 checkAbuseValidForMessagesValidator,
71 asyncRetryTransactionMiddleware(listAbuseMessages)
74 abuseRouter.post('/:id/messages',
76 asyncMiddleware(getAbuseValidator),
77 checkAbuseValidForMessagesValidator,
78 addAbuseMessageValidator,
79 asyncRetryTransactionMiddleware(addAbuseMessage)
82 abuseRouter.delete('/:id/messages/:messageId',
84 asyncMiddleware(getAbuseValidator),
85 checkAbuseValidForMessagesValidator,
86 asyncMiddleware(deleteAbuseMessageValidator),
87 asyncRetryTransactionMiddleware(deleteAbuseMessage)
90 // ---------------------------------------------------------------------------
96 // ---------------------------------------------------------------------------
98 async function listAbusesForAdmins (req: express.Request, res: express.Response) {
99 const user = res.locals.oauth.token.user
100 const serverActor = await getServerActor()
102 const resultList = await AbuseModel.listForAdminApi({
103 start: req.query.start,
104 count: req.query.count,
105 sort: req.query.sort,
107 filter: req.query.filter,
108 predefinedReason: req.query.predefinedReason,
109 search: req.query.search,
110 state: req.query.state,
111 videoIs: req.query.videoIs,
112 searchReporter: req.query.searchReporter,
113 searchReportee: req.query.searchReportee,
114 searchVideo: req.query.searchVideo,
115 searchVideoChannel: req.query.searchVideoChannel,
116 serverAccountId: serverActor.Account.id,
121 total: resultList.total,
122 data: resultList.data.map(d => d.toFormattedAdminJSON())
126 async function updateAbuse (req: express.Request, res: express.Response) {
127 const abuse = res.locals.abuse
128 let stateUpdated = false
130 if (req.body.moderationComment !== undefined) abuse.moderationComment = req.body.moderationComment
132 if (req.body.state !== undefined) {
133 abuse.state = req.body.state
137 await sequelizeTypescript.transaction(t => {
138 return abuse.save({ transaction: t })
141 if (stateUpdated === true) {
142 AbuseModel.loadFull(abuse.id)
143 .then(abuseFull => Notifier.Instance.notifyOnAbuseStateChange(abuseFull))
144 .catch(err => logger.error('Cannot notify on abuse state change', { err }))
147 // Do not send the delete to other instances, we updated OUR copy of this abuse
149 return res.status(HttpStatusCode.NO_CONTENT_204).end()
152 async function deleteAbuse (req: express.Request, res: express.Response) {
153 const abuse = res.locals.abuse
155 await sequelizeTypescript.transaction(t => {
156 return abuse.destroy({ transaction: t })
159 // Do not send the delete to other instances, we delete OUR copy of this abuse
161 return res.status(HttpStatusCode.NO_CONTENT_204).end()
164 async function reportAbuse (req: express.Request, res: express.Response) {
165 const videoInstance = res.locals.videoAll
166 const commentInstance = res.locals.videoCommentFull
167 const accountInstance = res.locals.account
169 const body: AbuseCreate = req.body
171 const { id } = await sequelizeTypescript.transaction(async t => {
172 const user = res.locals.oauth.token.User
173 // Don't send abuse notification if reporter is an admin/moderator
174 const skipNotification = user.hasRight(UserRight.MANAGE_ABUSES)
176 const reporterAccount = await AccountModel.load(user.Account.id, t)
177 const predefinedReasons = body.predefinedReasons?.map(r => abusePredefinedReasonsMap[r])
180 reporterAccountId: reporterAccount.id,
182 state: AbuseState.PENDING,
187 return createVideoAbuse({
192 startAt: body.video.startAt,
193 endAt: body.video.endAt,
199 return createVideoCommentAbuse({
209 return createAccountAbuse({
218 return res.json({ abuse: { id } })
221 async function listAbuseMessages (req: express.Request, res: express.Response) {
222 const abuse = res.locals.abuse
224 const resultList = await AbuseMessageModel.listForApi(abuse.id)
226 return res.json(getFormattedObjects(resultList.data, resultList.total))
229 async function addAbuseMessage (req: express.Request, res: express.Response) {
230 const abuse = res.locals.abuse
231 const user = res.locals.oauth.token.user
233 const abuseMessage = await AbuseMessageModel.create({
234 message: req.body.message,
235 byModerator: abuse.reporterAccountId !== user.Account.id,
236 accountId: user.Account.id,
240 AbuseModel.loadFull(abuse.id)
241 .then(abuseFull => Notifier.Instance.notifyOnAbuseMessage(abuseFull, abuseMessage))
242 .catch(err => logger.error('Cannot notify on new abuse message', { err }))
251 async function deleteAbuseMessage (req: express.Request, res: express.Response) {
252 const abuseMessage = res.locals.abuseMessage
254 await sequelizeTypescript.transaction(t => {
255 return abuseMessage.destroy({ transaction: t })
258 return res.status(HttpStatusCode.NO_CONTENT_204).end()