]> git.immae.eu Git - github/Chocobozzz/PeerTube.git/blob - server/controllers/api/users/me.ts
Check current password on server side
[github/Chocobozzz/PeerTube.git] / server / controllers / api / users / me.ts
1 import * as express from 'express'
2 import 'multer'
3 import { UserUpdateMe, UserVideoRate as FormattedUserVideoRate } from '../../../../shared'
4 import { getFormattedObjects } from '../../../helpers/utils'
5 import { CONFIG, IMAGE_MIMETYPE_EXT, sequelizeTypescript } from '../../../initializers'
6 import { sendUpdateActor } from '../../../lib/activitypub/send'
7 import {
8 asyncMiddleware,
9 asyncRetryTransactionMiddleware,
10 authenticate,
11 commonVideosFiltersValidator,
12 paginationValidator,
13 setDefaultPagination,
14 setDefaultSort,
15 userSubscriptionAddValidator,
16 userSubscriptionGetValidator,
17 usersUpdateMeValidator,
18 usersVideoRatingValidator
19 } from '../../../middlewares'
20 import {
21 areSubscriptionsExistValidator,
22 deleteMeValidator,
23 userSubscriptionsSortValidator,
24 videoImportsSortValidator,
25 videosSortValidator
26 } from '../../../middlewares/validators'
27 import { AccountVideoRateModel } from '../../../models/account/account-video-rate'
28 import { UserModel } from '../../../models/account/user'
29 import { VideoModel } from '../../../models/video/video'
30 import { VideoSortField } from '../../../../client/src/app/shared/video/sort-field.type'
31 import { buildNSFWFilter, createReqFiles } from '../../../helpers/express-utils'
32 import { UserVideoQuota } from '../../../../shared/models/users/user-video-quota.model'
33 import { updateAvatarValidator } from '../../../middlewares/validators/avatar'
34 import { updateActorAvatarFile } from '../../../lib/avatar'
35 import { auditLoggerFactory, getAuditIdFromRes, UserAuditView } from '../../../helpers/audit-logger'
36 import { VideoImportModel } from '../../../models/video/video-import'
37 import { VideoFilter } from '../../../../shared/models/videos/video-query.type'
38 import { ActorFollowModel } from '../../../models/activitypub/actor-follow'
39 import { JobQueue } from '../../../lib/job-queue'
40 import { logger } from '../../../helpers/logger'
41 import { AccountModel } from '../../../models/account/account'
42
43 const auditLogger = auditLoggerFactory('users-me')
44
45 const reqAvatarFile = createReqFiles([ 'avatarfile' ], IMAGE_MIMETYPE_EXT, { avatarfile: CONFIG.STORAGE.AVATARS_DIR })
46
47 const meRouter = express.Router()
48
49 meRouter.get('/me',
50 authenticate,
51 asyncMiddleware(getUserInformation)
52 )
53 meRouter.delete('/me',
54 authenticate,
55 asyncMiddleware(deleteMeValidator),
56 asyncMiddleware(deleteMe)
57 )
58
59 meRouter.get('/me/video-quota-used',
60 authenticate,
61 asyncMiddleware(getUserVideoQuotaUsed)
62 )
63
64 meRouter.get('/me/videos/imports',
65 authenticate,
66 paginationValidator,
67 videoImportsSortValidator,
68 setDefaultSort,
69 setDefaultPagination,
70 asyncMiddleware(getUserVideoImports)
71 )
72
73 meRouter.get('/me/videos',
74 authenticate,
75 paginationValidator,
76 videosSortValidator,
77 setDefaultSort,
78 setDefaultPagination,
79 asyncMiddleware(getUserVideos)
80 )
81
82 meRouter.get('/me/videos/:videoId/rating',
83 authenticate,
84 asyncMiddleware(usersVideoRatingValidator),
85 asyncMiddleware(getUserVideoRating)
86 )
87
88 meRouter.put('/me',
89 authenticate,
90 asyncMiddleware(usersUpdateMeValidator),
91 asyncRetryTransactionMiddleware(updateMe)
92 )
93
94 meRouter.post('/me/avatar/pick',
95 authenticate,
96 reqAvatarFile,
97 updateAvatarValidator,
98 asyncRetryTransactionMiddleware(updateMyAvatar)
99 )
100
101 // ##### Subscriptions part #####
102
103 meRouter.get('/me/subscriptions/videos',
104 authenticate,
105 paginationValidator,
106 videosSortValidator,
107 setDefaultSort,
108 setDefaultPagination,
109 commonVideosFiltersValidator,
110 asyncMiddleware(getUserSubscriptionVideos)
111 )
112
113 meRouter.get('/me/subscriptions/exist',
114 authenticate,
115 areSubscriptionsExistValidator,
116 asyncMiddleware(areSubscriptionsExist)
117 )
118
119 meRouter.get('/me/subscriptions',
120 authenticate,
121 paginationValidator,
122 userSubscriptionsSortValidator,
123 setDefaultSort,
124 setDefaultPagination,
125 asyncMiddleware(getUserSubscriptions)
126 )
127
128 meRouter.post('/me/subscriptions',
129 authenticate,
130 userSubscriptionAddValidator,
131 asyncMiddleware(addUserSubscription)
132 )
133
134 meRouter.get('/me/subscriptions/:uri',
135 authenticate,
136 userSubscriptionGetValidator,
137 getUserSubscription
138 )
139
140 meRouter.delete('/me/subscriptions/:uri',
141 authenticate,
142 userSubscriptionGetValidator,
143 asyncRetryTransactionMiddleware(deleteUserSubscription)
144 )
145
146 // ---------------------------------------------------------------------------
147
148 export {
149 meRouter
150 }
151
152 // ---------------------------------------------------------------------------
153
154 async function areSubscriptionsExist (req: express.Request, res: express.Response) {
155 const uris = req.query.uris as string[]
156 const user = res.locals.oauth.token.User as UserModel
157
158 const handles = uris.map(u => {
159 let [ name, host ] = u.split('@')
160 if (host === CONFIG.WEBSERVER.HOST) host = null
161
162 return { name, host, uri: u }
163 })
164
165 const results = await ActorFollowModel.listSubscribedIn(user.Account.Actor.id, handles)
166
167 const existObject: { [id: string ]: boolean } = {}
168 for (const handle of handles) {
169 const obj = results.find(r => {
170 const server = r.ActorFollowing.Server
171
172 return r.ActorFollowing.preferredUsername === handle.name &&
173 (
174 (!server && !handle.host) ||
175 (server.host === handle.host)
176 )
177 })
178
179 existObject[handle.uri] = obj !== undefined
180 }
181
182 return res.json(existObject)
183 }
184
185 async function addUserSubscription (req: express.Request, res: express.Response) {
186 const user = res.locals.oauth.token.User as UserModel
187 const [ name, host ] = req.body.uri.split('@')
188
189 const payload = {
190 name,
191 host,
192 followerActorId: user.Account.Actor.id
193 }
194
195 JobQueue.Instance.createJob({ type: 'activitypub-follow', payload })
196 .catch(err => logger.error('Cannot create follow job for subscription %s.', req.body.uri, err))
197
198 return res.status(204).end()
199 }
200
201 function getUserSubscription (req: express.Request, res: express.Response) {
202 const subscription: ActorFollowModel = res.locals.subscription
203
204 return res.json(subscription.ActorFollowing.VideoChannel.toFormattedJSON())
205 }
206
207 async function deleteUserSubscription (req: express.Request, res: express.Response) {
208 const subscription: ActorFollowModel = res.locals.subscription
209
210 await sequelizeTypescript.transaction(async t => {
211 return subscription.destroy({ transaction: t })
212 })
213
214 return res.type('json').status(204).end()
215 }
216
217 async function getUserSubscriptions (req: express.Request, res: express.Response) {
218 const user = res.locals.oauth.token.User as UserModel
219 const actorId = user.Account.Actor.id
220
221 const resultList = await ActorFollowModel.listSubscriptionsForApi(actorId, req.query.start, req.query.count, req.query.sort)
222
223 return res.json(getFormattedObjects(resultList.data, resultList.total))
224 }
225
226 async function getUserSubscriptionVideos (req: express.Request, res: express.Response, next: express.NextFunction) {
227 const user = res.locals.oauth.token.User as UserModel
228 const resultList = await VideoModel.listForApi({
229 start: req.query.start,
230 count: req.query.count,
231 sort: req.query.sort,
232 includeLocalVideos: false,
233 categoryOneOf: req.query.categoryOneOf,
234 licenceOneOf: req.query.licenceOneOf,
235 languageOneOf: req.query.languageOneOf,
236 tagsOneOf: req.query.tagsOneOf,
237 tagsAllOf: req.query.tagsAllOf,
238 nsfw: buildNSFWFilter(res, req.query.nsfw),
239 filter: req.query.filter as VideoFilter,
240 withFiles: false,
241 actorId: user.Account.Actor.id
242 })
243
244 return res.json(getFormattedObjects(resultList.data, resultList.total))
245 }
246
247 async function getUserVideos (req: express.Request, res: express.Response, next: express.NextFunction) {
248 const user = res.locals.oauth.token.User as UserModel
249 const resultList = await VideoModel.listUserVideosForApi(
250 user.Account.id,
251 req.query.start as number,
252 req.query.count as number,
253 req.query.sort as VideoSortField
254 )
255
256 const additionalAttributes = {
257 waitTranscoding: true,
258 state: true,
259 scheduledUpdate: true,
260 blacklistInfo: true
261 }
262 return res.json(getFormattedObjects(resultList.data, resultList.total, { additionalAttributes }))
263 }
264
265 async function getUserVideoImports (req: express.Request, res: express.Response, next: express.NextFunction) {
266 const user = res.locals.oauth.token.User as UserModel
267 const resultList = await VideoImportModel.listUserVideoImportsForApi(
268 user.id,
269 req.query.start as number,
270 req.query.count as number,
271 req.query.sort
272 )
273
274 return res.json(getFormattedObjects(resultList.data, resultList.total))
275 }
276
277 async function getUserInformation (req: express.Request, res: express.Response, next: express.NextFunction) {
278 // We did not load channels in res.locals.user
279 const user = await UserModel.loadByUsernameAndPopulateChannels(res.locals.oauth.token.user.username)
280
281 return res.json(user.toFormattedJSON())
282 }
283
284 async function getUserVideoQuotaUsed (req: express.Request, res: express.Response, next: express.NextFunction) {
285 // We did not load channels in res.locals.user
286 const user = await UserModel.loadByUsernameAndPopulateChannels(res.locals.oauth.token.user.username)
287 const videoQuotaUsed = await UserModel.getOriginalVideoFileTotalFromUser(user)
288 const videoQuotaUsedDaily = await UserModel.getOriginalVideoFileTotalDailyFromUser(user)
289
290 const data: UserVideoQuota = {
291 videoQuotaUsed,
292 videoQuotaUsedDaily
293 }
294 return res.json(data)
295 }
296
297 async function getUserVideoRating (req: express.Request, res: express.Response, next: express.NextFunction) {
298 const videoId = res.locals.video.id
299 const accountId = +res.locals.oauth.token.User.Account.id
300
301 const ratingObj = await AccountVideoRateModel.load(accountId, videoId, null)
302 const rating = ratingObj ? ratingObj.type : 'none'
303
304 const json: FormattedUserVideoRate = {
305 videoId,
306 rating
307 }
308 return res.json(json)
309 }
310
311 async function deleteMe (req: express.Request, res: express.Response) {
312 const user: UserModel = res.locals.oauth.token.User
313
314 await user.destroy()
315
316 auditLogger.delete(getAuditIdFromRes(res), new UserAuditView(user.toFormattedJSON()))
317
318 return res.sendStatus(204)
319 }
320
321 async function updateMe (req: express.Request, res: express.Response, next: express.NextFunction) {
322 const body: UserUpdateMe = req.body
323
324 const user: UserModel = res.locals.oauth.token.user
325 const oldUserAuditView = new UserAuditView(user.toFormattedJSON())
326
327 if (body.password !== undefined) user.password = body.password
328 if (body.email !== undefined) user.email = body.email
329 if (body.nsfwPolicy !== undefined) user.nsfwPolicy = body.nsfwPolicy
330 if (body.autoPlayVideo !== undefined) user.autoPlayVideo = body.autoPlayVideo
331
332 await sequelizeTypescript.transaction(async t => {
333 const userAccount = await AccountModel.load(user.Account.id)
334
335 await user.save({ transaction: t })
336
337 if (body.displayName !== undefined) userAccount.name = body.displayName
338 if (body.description !== undefined) userAccount.description = body.description
339 await userAccount.save({ transaction: t })
340
341 await sendUpdateActor(userAccount, t)
342
343 auditLogger.update(getAuditIdFromRes(res), new UserAuditView(user.toFormattedJSON()), oldUserAuditView)
344 })
345
346 return res.sendStatus(204)
347 }
348
349 async function updateMyAvatar (req: express.Request, res: express.Response, next: express.NextFunction) {
350 const avatarPhysicalFile = req.files[ 'avatarfile' ][ 0 ]
351 const user: UserModel = res.locals.oauth.token.user
352 const oldUserAuditView = new UserAuditView(user.toFormattedJSON())
353
354 const userAccount = await AccountModel.load(user.Account.id)
355
356 const avatar = await updateActorAvatarFile(avatarPhysicalFile, userAccount)
357
358 auditLogger.update(getAuditIdFromRes(res), new UserAuditView(user.toFormattedJSON()), oldUserAuditView)
359
360 return res.json({ avatar: avatar.toFormattedJSON() })
361 }