]> git.immae.eu Git - github/Chocobozzz/PeerTube.git/blob - server/controllers/api/video-channel.ts
Fix runner api rate limit bypass
[github/Chocobozzz/PeerTube.git] / server / controllers / api / video-channel.ts
1 import express from 'express'
2 import { pickCommonVideoQuery } from '@server/helpers/query'
3 import { getBiggestActorImage } from '@server/lib/actor-image'
4 import { Hooks } from '@server/lib/plugins/hooks'
5 import { ActorFollowModel } from '@server/models/actor/actor-follow'
6 import { getServerActor } from '@server/models/application/application'
7 import { guessAdditionalAttributesFromQuery } from '@server/models/video/formatter/video-format-utils'
8 import { MChannelBannerAccountDefault } from '@server/types/models'
9 import { ActorImageType, HttpStatusCode, VideoChannelCreate, VideoChannelUpdate, VideosImportInChannelCreate } from '@shared/models'
10 import { auditLoggerFactory, getAuditIdFromRes, VideoChannelAuditView } from '../../helpers/audit-logger'
11 import { resetSequelizeInstance } from '../../helpers/database-utils'
12 import { buildNSFWFilter, createReqFiles, getCountVideos, isUserAbleToSearchRemoteURI } from '../../helpers/express-utils'
13 import { logger } from '../../helpers/logger'
14 import { getFormattedObjects } from '../../helpers/utils'
15 import { MIMETYPES } from '../../initializers/constants'
16 import { sequelizeTypescript } from '../../initializers/database'
17 import { sendUpdateActor } from '../../lib/activitypub/send'
18 import { JobQueue } from '../../lib/job-queue'
19 import { deleteLocalActorImageFile, updateLocalActorImageFiles } from '../../lib/local-actor'
20 import { createLocalVideoChannel, federateAllVideosOfChannel } from '../../lib/video-channel'
21 import {
22 apiRateLimiter,
23 asyncMiddleware,
24 asyncRetryTransactionMiddleware,
25 authenticate,
26 commonVideosFiltersValidator,
27 ensureCanManageChannelOrAccount,
28 optionalAuthenticate,
29 paginationValidator,
30 setDefaultPagination,
31 setDefaultSort,
32 setDefaultVideosSort,
33 videoChannelsAddValidator,
34 videoChannelsRemoveValidator,
35 videoChannelsSortValidator,
36 videoChannelsUpdateValidator,
37 videoPlaylistsSortValidator
38 } from '../../middlewares'
39 import {
40 ensureChannelOwnerCanUpload,
41 ensureIsLocalChannel,
42 videoChannelImportVideosValidator,
43 videoChannelsFollowersSortValidator,
44 videoChannelsListValidator,
45 videoChannelsNameWithHostValidator,
46 videosSortValidator
47 } from '../../middlewares/validators'
48 import { updateAvatarValidator, updateBannerValidator } from '../../middlewares/validators/actor-image'
49 import { commonVideoPlaylistFiltersValidator } from '../../middlewares/validators/videos/video-playlists'
50 import { AccountModel } from '../../models/account/account'
51 import { VideoModel } from '../../models/video/video'
52 import { VideoChannelModel } from '../../models/video/video-channel'
53 import { VideoPlaylistModel } from '../../models/video/video-playlist'
54
55 const auditLogger = auditLoggerFactory('channels')
56 const reqAvatarFile = createReqFiles([ 'avatarfile' ], MIMETYPES.IMAGE.MIMETYPE_EXT)
57 const reqBannerFile = createReqFiles([ 'bannerfile' ], MIMETYPES.IMAGE.MIMETYPE_EXT)
58
59 const videoChannelRouter = express.Router()
60
61 videoChannelRouter.use(apiRateLimiter)
62
63 videoChannelRouter.get('/',
64 paginationValidator,
65 videoChannelsSortValidator,
66 setDefaultSort,
67 setDefaultPagination,
68 videoChannelsListValidator,
69 asyncMiddleware(listVideoChannels)
70 )
71
72 videoChannelRouter.post('/',
73 authenticate,
74 asyncMiddleware(videoChannelsAddValidator),
75 asyncRetryTransactionMiddleware(addVideoChannel)
76 )
77
78 videoChannelRouter.post('/:nameWithHost/avatar/pick',
79 authenticate,
80 reqAvatarFile,
81 asyncMiddleware(videoChannelsNameWithHostValidator),
82 ensureIsLocalChannel,
83 ensureCanManageChannelOrAccount,
84 updateAvatarValidator,
85 asyncMiddleware(updateVideoChannelAvatar)
86 )
87
88 videoChannelRouter.post('/:nameWithHost/banner/pick',
89 authenticate,
90 reqBannerFile,
91 asyncMiddleware(videoChannelsNameWithHostValidator),
92 ensureIsLocalChannel,
93 ensureCanManageChannelOrAccount,
94 updateBannerValidator,
95 asyncMiddleware(updateVideoChannelBanner)
96 )
97
98 videoChannelRouter.delete('/:nameWithHost/avatar',
99 authenticate,
100 asyncMiddleware(videoChannelsNameWithHostValidator),
101 ensureIsLocalChannel,
102 ensureCanManageChannelOrAccount,
103 asyncMiddleware(deleteVideoChannelAvatar)
104 )
105
106 videoChannelRouter.delete('/:nameWithHost/banner',
107 authenticate,
108 asyncMiddleware(videoChannelsNameWithHostValidator),
109 ensureIsLocalChannel,
110 ensureCanManageChannelOrAccount,
111 asyncMiddleware(deleteVideoChannelBanner)
112 )
113
114 videoChannelRouter.put('/:nameWithHost',
115 authenticate,
116 asyncMiddleware(videoChannelsNameWithHostValidator),
117 ensureIsLocalChannel,
118 ensureCanManageChannelOrAccount,
119 videoChannelsUpdateValidator,
120 asyncRetryTransactionMiddleware(updateVideoChannel)
121 )
122
123 videoChannelRouter.delete('/:nameWithHost',
124 authenticate,
125 asyncMiddleware(videoChannelsNameWithHostValidator),
126 ensureIsLocalChannel,
127 ensureCanManageChannelOrAccount,
128 asyncMiddleware(videoChannelsRemoveValidator),
129 asyncRetryTransactionMiddleware(removeVideoChannel)
130 )
131
132 videoChannelRouter.get('/:nameWithHost',
133 asyncMiddleware(videoChannelsNameWithHostValidator),
134 asyncMiddleware(getVideoChannel)
135 )
136
137 videoChannelRouter.get('/:nameWithHost/video-playlists',
138 asyncMiddleware(videoChannelsNameWithHostValidator),
139 paginationValidator,
140 videoPlaylistsSortValidator,
141 setDefaultSort,
142 setDefaultPagination,
143 commonVideoPlaylistFiltersValidator,
144 asyncMiddleware(listVideoChannelPlaylists)
145 )
146
147 videoChannelRouter.get('/:nameWithHost/videos',
148 asyncMiddleware(videoChannelsNameWithHostValidator),
149 paginationValidator,
150 videosSortValidator,
151 setDefaultVideosSort,
152 setDefaultPagination,
153 optionalAuthenticate,
154 commonVideosFiltersValidator,
155 asyncMiddleware(listVideoChannelVideos)
156 )
157
158 videoChannelRouter.get('/:nameWithHost/followers',
159 authenticate,
160 asyncMiddleware(videoChannelsNameWithHostValidator),
161 ensureCanManageChannelOrAccount,
162 paginationValidator,
163 videoChannelsFollowersSortValidator,
164 setDefaultSort,
165 setDefaultPagination,
166 asyncMiddleware(listVideoChannelFollowers)
167 )
168
169 videoChannelRouter.post('/:nameWithHost/import-videos',
170 authenticate,
171 asyncMiddleware(videoChannelsNameWithHostValidator),
172 asyncMiddleware(videoChannelImportVideosValidator),
173 ensureIsLocalChannel,
174 ensureCanManageChannelOrAccount,
175 asyncMiddleware(ensureChannelOwnerCanUpload),
176 asyncMiddleware(importVideosInChannel)
177 )
178
179 // ---------------------------------------------------------------------------
180
181 export {
182 videoChannelRouter
183 }
184
185 // ---------------------------------------------------------------------------
186
187 async function listVideoChannels (req: express.Request, res: express.Response) {
188 const serverActor = await getServerActor()
189
190 const apiOptions = await Hooks.wrapObject({
191 actorId: serverActor.id,
192 start: req.query.start,
193 count: req.query.count,
194 sort: req.query.sort
195 }, 'filter:api.video-channels.list.params')
196
197 const resultList = await Hooks.wrapPromiseFun(
198 VideoChannelModel.listForApi,
199 apiOptions,
200 'filter:api.video-channels.list.result'
201 )
202
203 return res.json(getFormattedObjects(resultList.data, resultList.total))
204 }
205
206 async function updateVideoChannelBanner (req: express.Request, res: express.Response) {
207 const bannerPhysicalFile = req.files['bannerfile'][0]
208 const videoChannel = res.locals.videoChannel
209 const oldVideoChannelAuditKeys = new VideoChannelAuditView(videoChannel.toFormattedJSON())
210
211 const banners = await updateLocalActorImageFiles(videoChannel, bannerPhysicalFile, ActorImageType.BANNER)
212
213 auditLogger.update(getAuditIdFromRes(res), new VideoChannelAuditView(videoChannel.toFormattedJSON()), oldVideoChannelAuditKeys)
214
215 return res.json({
216 // TODO: remove, deprecated in 4.2
217 banner: getBiggestActorImage(banners).toFormattedJSON(),
218 banners: banners.map(b => b.toFormattedJSON())
219 })
220 }
221
222 async function updateVideoChannelAvatar (req: express.Request, res: express.Response) {
223 const avatarPhysicalFile = req.files['avatarfile'][0]
224 const videoChannel = res.locals.videoChannel
225 const oldVideoChannelAuditKeys = new VideoChannelAuditView(videoChannel.toFormattedJSON())
226
227 const avatars = await updateLocalActorImageFiles(videoChannel, avatarPhysicalFile, ActorImageType.AVATAR)
228 auditLogger.update(getAuditIdFromRes(res), new VideoChannelAuditView(videoChannel.toFormattedJSON()), oldVideoChannelAuditKeys)
229
230 return res.json({
231 // TODO: remove, deprecated in 4.2
232 avatar: getBiggestActorImage(avatars).toFormattedJSON(),
233 avatars: avatars.map(a => a.toFormattedJSON())
234 })
235 }
236
237 async function deleteVideoChannelAvatar (req: express.Request, res: express.Response) {
238 const videoChannel = res.locals.videoChannel
239
240 await deleteLocalActorImageFile(videoChannel, ActorImageType.AVATAR)
241
242 return res.status(HttpStatusCode.NO_CONTENT_204).end()
243 }
244
245 async function deleteVideoChannelBanner (req: express.Request, res: express.Response) {
246 const videoChannel = res.locals.videoChannel
247
248 await deleteLocalActorImageFile(videoChannel, ActorImageType.BANNER)
249
250 return res.status(HttpStatusCode.NO_CONTENT_204).end()
251 }
252
253 async function addVideoChannel (req: express.Request, res: express.Response) {
254 const videoChannelInfo: VideoChannelCreate = req.body
255
256 const videoChannelCreated = await sequelizeTypescript.transaction(async t => {
257 const account = await AccountModel.load(res.locals.oauth.token.User.Account.id, t)
258
259 return createLocalVideoChannel(videoChannelInfo, account, t)
260 })
261
262 const payload = { actorId: videoChannelCreated.actorId }
263 await JobQueue.Instance.createJob({ type: 'actor-keys', payload })
264
265 auditLogger.create(getAuditIdFromRes(res), new VideoChannelAuditView(videoChannelCreated.toFormattedJSON()))
266 logger.info('Video channel %s created.', videoChannelCreated.Actor.url)
267
268 Hooks.runAction('action:api.video-channel.created', { videoChannel: videoChannelCreated, req, res })
269
270 return res.json({
271 videoChannel: {
272 id: videoChannelCreated.id
273 }
274 })
275 }
276
277 async function updateVideoChannel (req: express.Request, res: express.Response) {
278 const videoChannelInstance = res.locals.videoChannel
279 const oldVideoChannelAuditKeys = new VideoChannelAuditView(videoChannelInstance.toFormattedJSON())
280 const videoChannelInfoToUpdate = req.body as VideoChannelUpdate
281 let doBulkVideoUpdate = false
282
283 try {
284 await sequelizeTypescript.transaction(async t => {
285 if (videoChannelInfoToUpdate.displayName !== undefined) videoChannelInstance.name = videoChannelInfoToUpdate.displayName
286 if (videoChannelInfoToUpdate.description !== undefined) videoChannelInstance.description = videoChannelInfoToUpdate.description
287
288 if (videoChannelInfoToUpdate.support !== undefined) {
289 const oldSupportField = videoChannelInstance.support
290 videoChannelInstance.support = videoChannelInfoToUpdate.support
291
292 if (videoChannelInfoToUpdate.bulkVideosSupportUpdate === true && oldSupportField !== videoChannelInfoToUpdate.support) {
293 doBulkVideoUpdate = true
294 await VideoModel.bulkUpdateSupportField(videoChannelInstance, t)
295 }
296 }
297
298 const videoChannelInstanceUpdated = await videoChannelInstance.save({ transaction: t }) as MChannelBannerAccountDefault
299 await sendUpdateActor(videoChannelInstanceUpdated, t)
300
301 auditLogger.update(
302 getAuditIdFromRes(res),
303 new VideoChannelAuditView(videoChannelInstanceUpdated.toFormattedJSON()),
304 oldVideoChannelAuditKeys
305 )
306
307 Hooks.runAction('action:api.video-channel.updated', { videoChannel: videoChannelInstanceUpdated, req, res })
308
309 logger.info('Video channel %s updated.', videoChannelInstance.Actor.url)
310 })
311 } catch (err) {
312 logger.debug('Cannot update the video channel.', { err })
313
314 // If the transaction is retried, sequelize will think the object has not changed
315 // So we need to restore the previous fields
316 await resetSequelizeInstance(videoChannelInstance)
317
318 throw err
319 }
320
321 res.type('json').status(HttpStatusCode.NO_CONTENT_204).end()
322
323 // Don't process in a transaction, and after the response because it could be long
324 if (doBulkVideoUpdate) {
325 await federateAllVideosOfChannel(videoChannelInstance)
326 }
327 }
328
329 async function removeVideoChannel (req: express.Request, res: express.Response) {
330 const videoChannelInstance = res.locals.videoChannel
331
332 await sequelizeTypescript.transaction(async t => {
333 await VideoPlaylistModel.resetPlaylistsOfChannel(videoChannelInstance.id, t)
334
335 await videoChannelInstance.destroy({ transaction: t })
336
337 Hooks.runAction('action:api.video-channel.deleted', { videoChannel: videoChannelInstance, req, res })
338
339 auditLogger.delete(getAuditIdFromRes(res), new VideoChannelAuditView(videoChannelInstance.toFormattedJSON()))
340 logger.info('Video channel %s deleted.', videoChannelInstance.Actor.url)
341 })
342
343 return res.type('json').status(HttpStatusCode.NO_CONTENT_204).end()
344 }
345
346 async function getVideoChannel (req: express.Request, res: express.Response) {
347 const id = res.locals.videoChannel.id
348 const videoChannel = await Hooks.wrapObject(res.locals.videoChannel, 'filter:api.video-channel.get.result', { id })
349
350 if (videoChannel.isOutdated()) {
351 JobQueue.Instance.createJobAsync({ type: 'activitypub-refresher', payload: { type: 'actor', url: videoChannel.Actor.url } })
352 }
353
354 return res.json(videoChannel.toFormattedJSON())
355 }
356
357 async function listVideoChannelPlaylists (req: express.Request, res: express.Response) {
358 const serverActor = await getServerActor()
359
360 const resultList = await VideoPlaylistModel.listForApi({
361 followerActorId: serverActor.id,
362 start: req.query.start,
363 count: req.query.count,
364 sort: req.query.sort,
365 videoChannelId: res.locals.videoChannel.id,
366 type: req.query.playlistType
367 })
368
369 return res.json(getFormattedObjects(resultList.data, resultList.total))
370 }
371
372 async function listVideoChannelVideos (req: express.Request, res: express.Response) {
373 const serverActor = await getServerActor()
374
375 const videoChannelInstance = res.locals.videoChannel
376
377 const displayOnlyForFollower = isUserAbleToSearchRemoteURI(res)
378 ? null
379 : {
380 actorId: serverActor.id,
381 orLocalVideos: true
382 }
383
384 const countVideos = getCountVideos(req)
385 const query = pickCommonVideoQuery(req.query)
386
387 const apiOptions = await Hooks.wrapObject({
388 ...query,
389
390 displayOnlyForFollower,
391 nsfw: buildNSFWFilter(res, query.nsfw),
392 videoChannelId: videoChannelInstance.id,
393 user: res.locals.oauth ? res.locals.oauth.token.User : undefined,
394 countVideos
395 }, 'filter:api.video-channels.videos.list.params')
396
397 const resultList = await Hooks.wrapPromiseFun(
398 VideoModel.listForApi,
399 apiOptions,
400 'filter:api.video-channels.videos.list.result'
401 )
402
403 return res.json(getFormattedObjects(resultList.data, resultList.total, guessAdditionalAttributesFromQuery(query)))
404 }
405
406 async function listVideoChannelFollowers (req: express.Request, res: express.Response) {
407 const channel = res.locals.videoChannel
408
409 const resultList = await ActorFollowModel.listFollowersForApi({
410 actorIds: [ channel.actorId ],
411 start: req.query.start,
412 count: req.query.count,
413 sort: req.query.sort,
414 search: req.query.search,
415 state: 'accepted'
416 })
417
418 return res.json(getFormattedObjects(resultList.data, resultList.total))
419 }
420
421 async function importVideosInChannel (req: express.Request, res: express.Response) {
422 const { externalChannelUrl } = req.body as VideosImportInChannelCreate
423
424 await JobQueue.Instance.createJob({
425 type: 'video-channel-import',
426 payload: {
427 externalChannelUrl,
428 videoChannelId: res.locals.videoChannel.id,
429 partOfChannelSyncId: res.locals.videoChannelSync?.id
430 }
431 })
432
433 logger.info('Video import job for channel "%s" with url "%s" created.', res.locals.videoChannel.name, externalChannelUrl)
434
435 return res.type('json').status(HttpStatusCode.NO_CONTENT_204).end()
436 }