]> git.immae.eu Git - github/Chocobozzz/PeerTube.git/blob - server/controllers/api/config.ts
Fix runner api rate limit bypass
[github/Chocobozzz/PeerTube.git] / server / controllers / api / config.ts
1 import express from 'express'
2 import { remove, writeJSON } from 'fs-extra'
3 import { snakeCase } from 'lodash'
4 import validator from 'validator'
5 import { ServerConfigManager } from '@server/lib/server-config-manager'
6 import { About, CustomConfig, UserRight } from '@shared/models'
7 import { auditLoggerFactory, CustomConfigAuditView, getAuditIdFromRes } from '../../helpers/audit-logger'
8 import { objectConverter } from '../../helpers/core-utils'
9 import { CONFIG, reloadConfig } from '../../initializers/config'
10 import { ClientHtml } from '../../lib/client-html'
11 import { apiRateLimiter, asyncMiddleware, authenticate, ensureUserHasRight, openapiOperationDoc } from '../../middlewares'
12 import { customConfigUpdateValidator, ensureConfigIsEditable } from '../../middlewares/validators/config'
13
14 const configRouter = express.Router()
15
16 configRouter.use(apiRateLimiter)
17
18 const auditLogger = auditLoggerFactory('config')
19
20 configRouter.get('/',
21 openapiOperationDoc({ operationId: 'getConfig' }),
22 asyncMiddleware(getConfig)
23 )
24
25 configRouter.get('/about',
26 openapiOperationDoc({ operationId: 'getAbout' }),
27 getAbout
28 )
29
30 configRouter.get('/custom',
31 openapiOperationDoc({ operationId: 'getCustomConfig' }),
32 authenticate,
33 ensureUserHasRight(UserRight.MANAGE_CONFIGURATION),
34 getCustomConfig
35 )
36
37 configRouter.put('/custom',
38 openapiOperationDoc({ operationId: 'putCustomConfig' }),
39 authenticate,
40 ensureUserHasRight(UserRight.MANAGE_CONFIGURATION),
41 ensureConfigIsEditable,
42 customConfigUpdateValidator,
43 asyncMiddleware(updateCustomConfig)
44 )
45
46 configRouter.delete('/custom',
47 openapiOperationDoc({ operationId: 'delCustomConfig' }),
48 authenticate,
49 ensureUserHasRight(UserRight.MANAGE_CONFIGURATION),
50 ensureConfigIsEditable,
51 asyncMiddleware(deleteCustomConfig)
52 )
53
54 async function getConfig (req: express.Request, res: express.Response) {
55 const json = await ServerConfigManager.Instance.getServerConfig(req.ip)
56
57 return res.json(json)
58 }
59
60 function getAbout (req: express.Request, res: express.Response) {
61 const about: About = {
62 instance: {
63 name: CONFIG.INSTANCE.NAME,
64 shortDescription: CONFIG.INSTANCE.SHORT_DESCRIPTION,
65 description: CONFIG.INSTANCE.DESCRIPTION,
66 terms: CONFIG.INSTANCE.TERMS,
67 codeOfConduct: CONFIG.INSTANCE.CODE_OF_CONDUCT,
68
69 hardwareInformation: CONFIG.INSTANCE.HARDWARE_INFORMATION,
70
71 creationReason: CONFIG.INSTANCE.CREATION_REASON,
72 moderationInformation: CONFIG.INSTANCE.MODERATION_INFORMATION,
73 administrator: CONFIG.INSTANCE.ADMINISTRATOR,
74 maintenanceLifetime: CONFIG.INSTANCE.MAINTENANCE_LIFETIME,
75 businessModel: CONFIG.INSTANCE.BUSINESS_MODEL,
76
77 languages: CONFIG.INSTANCE.LANGUAGES,
78 categories: CONFIG.INSTANCE.CATEGORIES
79 }
80 }
81
82 return res.json(about)
83 }
84
85 function getCustomConfig (req: express.Request, res: express.Response) {
86 const data = customConfig()
87
88 return res.json(data)
89 }
90
91 async function deleteCustomConfig (req: express.Request, res: express.Response) {
92 await remove(CONFIG.CUSTOM_FILE)
93
94 auditLogger.delete(getAuditIdFromRes(res), new CustomConfigAuditView(customConfig()))
95
96 reloadConfig()
97 ClientHtml.invalidCache()
98
99 const data = customConfig()
100
101 return res.json(data)
102 }
103
104 async function updateCustomConfig (req: express.Request, res: express.Response) {
105 const oldCustomConfigAuditKeys = new CustomConfigAuditView(customConfig())
106
107 // camelCase to snake_case key + Force number conversion
108 const toUpdateJSON = convertCustomConfigBody(req.body)
109
110 await writeJSON(CONFIG.CUSTOM_FILE, toUpdateJSON, { spaces: 2 })
111
112 reloadConfig()
113 ClientHtml.invalidCache()
114
115 const data = customConfig()
116
117 auditLogger.update(
118 getAuditIdFromRes(res),
119 new CustomConfigAuditView(data),
120 oldCustomConfigAuditKeys
121 )
122
123 return res.json(data)
124 }
125
126 // ---------------------------------------------------------------------------
127
128 export {
129 configRouter
130 }
131
132 // ---------------------------------------------------------------------------
133
134 function customConfig (): CustomConfig {
135 return {
136 instance: {
137 name: CONFIG.INSTANCE.NAME,
138 shortDescription: CONFIG.INSTANCE.SHORT_DESCRIPTION,
139 description: CONFIG.INSTANCE.DESCRIPTION,
140 terms: CONFIG.INSTANCE.TERMS,
141 codeOfConduct: CONFIG.INSTANCE.CODE_OF_CONDUCT,
142
143 creationReason: CONFIG.INSTANCE.CREATION_REASON,
144 moderationInformation: CONFIG.INSTANCE.MODERATION_INFORMATION,
145 administrator: CONFIG.INSTANCE.ADMINISTRATOR,
146 maintenanceLifetime: CONFIG.INSTANCE.MAINTENANCE_LIFETIME,
147 businessModel: CONFIG.INSTANCE.BUSINESS_MODEL,
148 hardwareInformation: CONFIG.INSTANCE.HARDWARE_INFORMATION,
149
150 languages: CONFIG.INSTANCE.LANGUAGES,
151 categories: CONFIG.INSTANCE.CATEGORIES,
152
153 isNSFW: CONFIG.INSTANCE.IS_NSFW,
154 defaultNSFWPolicy: CONFIG.INSTANCE.DEFAULT_NSFW_POLICY,
155
156 defaultClientRoute: CONFIG.INSTANCE.DEFAULT_CLIENT_ROUTE,
157
158 customizations: {
159 css: CONFIG.INSTANCE.CUSTOMIZATIONS.CSS,
160 javascript: CONFIG.INSTANCE.CUSTOMIZATIONS.JAVASCRIPT
161 }
162 },
163 theme: {
164 default: CONFIG.THEME.DEFAULT
165 },
166 services: {
167 twitter: {
168 username: CONFIG.SERVICES.TWITTER.USERNAME,
169 whitelisted: CONFIG.SERVICES.TWITTER.WHITELISTED
170 }
171 },
172 client: {
173 videos: {
174 miniature: {
175 preferAuthorDisplayName: CONFIG.CLIENT.VIDEOS.MINIATURE.PREFER_AUTHOR_DISPLAY_NAME
176 }
177 },
178 menu: {
179 login: {
180 redirectOnSingleExternalAuth: CONFIG.CLIENT.MENU.LOGIN.REDIRECT_ON_SINGLE_EXTERNAL_AUTH
181 }
182 }
183 },
184 cache: {
185 previews: {
186 size: CONFIG.CACHE.PREVIEWS.SIZE
187 },
188 captions: {
189 size: CONFIG.CACHE.VIDEO_CAPTIONS.SIZE
190 },
191 torrents: {
192 size: CONFIG.CACHE.TORRENTS.SIZE
193 }
194 },
195 signup: {
196 enabled: CONFIG.SIGNUP.ENABLED,
197 limit: CONFIG.SIGNUP.LIMIT,
198 requiresApproval: CONFIG.SIGNUP.REQUIRES_APPROVAL,
199 requiresEmailVerification: CONFIG.SIGNUP.REQUIRES_EMAIL_VERIFICATION,
200 minimumAge: CONFIG.SIGNUP.MINIMUM_AGE
201 },
202 admin: {
203 email: CONFIG.ADMIN.EMAIL
204 },
205 contactForm: {
206 enabled: CONFIG.CONTACT_FORM.ENABLED
207 },
208 user: {
209 history: {
210 videos: {
211 enabled: CONFIG.USER.HISTORY.VIDEOS.ENABLED
212 }
213 },
214 videoQuota: CONFIG.USER.VIDEO_QUOTA,
215 videoQuotaDaily: CONFIG.USER.VIDEO_QUOTA_DAILY
216 },
217 videoChannels: {
218 maxPerUser: CONFIG.VIDEO_CHANNELS.MAX_PER_USER
219 },
220 transcoding: {
221 enabled: CONFIG.TRANSCODING.ENABLED,
222 remoteRunners: {
223 enabled: CONFIG.TRANSCODING.REMOTE_RUNNERS.ENABLED
224 },
225 allowAdditionalExtensions: CONFIG.TRANSCODING.ALLOW_ADDITIONAL_EXTENSIONS,
226 allowAudioFiles: CONFIG.TRANSCODING.ALLOW_AUDIO_FILES,
227 threads: CONFIG.TRANSCODING.THREADS,
228 concurrency: CONFIG.TRANSCODING.CONCURRENCY,
229 profile: CONFIG.TRANSCODING.PROFILE,
230 resolutions: {
231 '0p': CONFIG.TRANSCODING.RESOLUTIONS['0p'],
232 '144p': CONFIG.TRANSCODING.RESOLUTIONS['144p'],
233 '240p': CONFIG.TRANSCODING.RESOLUTIONS['240p'],
234 '360p': CONFIG.TRANSCODING.RESOLUTIONS['360p'],
235 '480p': CONFIG.TRANSCODING.RESOLUTIONS['480p'],
236 '720p': CONFIG.TRANSCODING.RESOLUTIONS['720p'],
237 '1080p': CONFIG.TRANSCODING.RESOLUTIONS['1080p'],
238 '1440p': CONFIG.TRANSCODING.RESOLUTIONS['1440p'],
239 '2160p': CONFIG.TRANSCODING.RESOLUTIONS['2160p']
240 },
241 alwaysTranscodeOriginalResolution: CONFIG.TRANSCODING.ALWAYS_TRANSCODE_ORIGINAL_RESOLUTION,
242 webtorrent: {
243 enabled: CONFIG.TRANSCODING.WEBTORRENT.ENABLED
244 },
245 hls: {
246 enabled: CONFIG.TRANSCODING.HLS.ENABLED
247 }
248 },
249 live: {
250 enabled: CONFIG.LIVE.ENABLED,
251 allowReplay: CONFIG.LIVE.ALLOW_REPLAY,
252 latencySetting: {
253 enabled: CONFIG.LIVE.LATENCY_SETTING.ENABLED
254 },
255 maxDuration: CONFIG.LIVE.MAX_DURATION,
256 maxInstanceLives: CONFIG.LIVE.MAX_INSTANCE_LIVES,
257 maxUserLives: CONFIG.LIVE.MAX_USER_LIVES,
258 transcoding: {
259 enabled: CONFIG.LIVE.TRANSCODING.ENABLED,
260 remoteRunners: {
261 enabled: CONFIG.LIVE.TRANSCODING.REMOTE_RUNNERS.ENABLED
262 },
263 threads: CONFIG.LIVE.TRANSCODING.THREADS,
264 profile: CONFIG.LIVE.TRANSCODING.PROFILE,
265 resolutions: {
266 '144p': CONFIG.LIVE.TRANSCODING.RESOLUTIONS['144p'],
267 '240p': CONFIG.LIVE.TRANSCODING.RESOLUTIONS['240p'],
268 '360p': CONFIG.LIVE.TRANSCODING.RESOLUTIONS['360p'],
269 '480p': CONFIG.LIVE.TRANSCODING.RESOLUTIONS['480p'],
270 '720p': CONFIG.LIVE.TRANSCODING.RESOLUTIONS['720p'],
271 '1080p': CONFIG.LIVE.TRANSCODING.RESOLUTIONS['1080p'],
272 '1440p': CONFIG.LIVE.TRANSCODING.RESOLUTIONS['1440p'],
273 '2160p': CONFIG.LIVE.TRANSCODING.RESOLUTIONS['2160p']
274 },
275 alwaysTranscodeOriginalResolution: CONFIG.LIVE.TRANSCODING.ALWAYS_TRANSCODE_ORIGINAL_RESOLUTION
276 }
277 },
278 videoStudio: {
279 enabled: CONFIG.VIDEO_STUDIO.ENABLED,
280 remoteRunners: {
281 enabled: CONFIG.VIDEO_STUDIO.REMOTE_RUNNERS.ENABLED
282 }
283 },
284 import: {
285 videos: {
286 concurrency: CONFIG.IMPORT.VIDEOS.CONCURRENCY,
287 http: {
288 enabled: CONFIG.IMPORT.VIDEOS.HTTP.ENABLED
289 },
290 torrent: {
291 enabled: CONFIG.IMPORT.VIDEOS.TORRENT.ENABLED
292 }
293 },
294 videoChannelSynchronization: {
295 enabled: CONFIG.IMPORT.VIDEO_CHANNEL_SYNCHRONIZATION.ENABLED,
296 maxPerUser: CONFIG.IMPORT.VIDEO_CHANNEL_SYNCHRONIZATION.MAX_PER_USER
297 }
298 },
299 trending: {
300 videos: {
301 algorithms: {
302 enabled: CONFIG.TRENDING.VIDEOS.ALGORITHMS.ENABLED,
303 default: CONFIG.TRENDING.VIDEOS.ALGORITHMS.DEFAULT
304 }
305 }
306 },
307 autoBlacklist: {
308 videos: {
309 ofUsers: {
310 enabled: CONFIG.AUTO_BLACKLIST.VIDEOS.OF_USERS.ENABLED
311 }
312 }
313 },
314 followers: {
315 instance: {
316 enabled: CONFIG.FOLLOWERS.INSTANCE.ENABLED,
317 manualApproval: CONFIG.FOLLOWERS.INSTANCE.MANUAL_APPROVAL
318 }
319 },
320 followings: {
321 instance: {
322 autoFollowBack: {
323 enabled: CONFIG.FOLLOWINGS.INSTANCE.AUTO_FOLLOW_BACK.ENABLED
324 },
325
326 autoFollowIndex: {
327 enabled: CONFIG.FOLLOWINGS.INSTANCE.AUTO_FOLLOW_INDEX.ENABLED,
328 indexUrl: CONFIG.FOLLOWINGS.INSTANCE.AUTO_FOLLOW_INDEX.INDEX_URL
329 }
330 }
331 },
332 broadcastMessage: {
333 enabled: CONFIG.BROADCAST_MESSAGE.ENABLED,
334 message: CONFIG.BROADCAST_MESSAGE.MESSAGE,
335 level: CONFIG.BROADCAST_MESSAGE.LEVEL,
336 dismissable: CONFIG.BROADCAST_MESSAGE.DISMISSABLE
337 },
338 search: {
339 remoteUri: {
340 users: CONFIG.SEARCH.REMOTE_URI.USERS,
341 anonymous: CONFIG.SEARCH.REMOTE_URI.ANONYMOUS
342 },
343 searchIndex: {
344 enabled: CONFIG.SEARCH.SEARCH_INDEX.ENABLED,
345 url: CONFIG.SEARCH.SEARCH_INDEX.URL,
346 disableLocalSearch: CONFIG.SEARCH.SEARCH_INDEX.DISABLE_LOCAL_SEARCH,
347 isDefaultSearch: CONFIG.SEARCH.SEARCH_INDEX.IS_DEFAULT_SEARCH
348 }
349 }
350 }
351 }
352
353 function convertCustomConfigBody (body: CustomConfig) {
354 function keyConverter (k: string) {
355 // Transcoding resolutions exception
356 if (/^\d{3,4}p$/.exec(k)) return k
357 if (k === '0p') return k
358
359 return snakeCase(k)
360 }
361
362 function valueConverter (v: any) {
363 if (validator.isNumeric(v + '')) return parseInt('' + v, 10)
364
365 return v
366 }
367
368 return objectConverter(body, keyConverter, valueConverter)
369 }