1 import express from 'express'
2 import { body, param, query } from 'express-validator'
3 import { areValidActorHandles } from '@server/helpers/custom-validators/activitypub/actor'
4 import { getServerActor } from '@server/models/application/application'
5 import { arrayify } from '@shared/core-utils'
6 import { HttpStatusCode } from '../../../shared/models/http/http-error-codes'
7 import { isEachUniqueHostValid, isHostValid } from '../../helpers/custom-validators/servers'
8 import { WEBSERVER } from '../../initializers/constants'
9 import { AccountBlocklistModel } from '../../models/account/account-blocklist'
10 import { ServerModel } from '../../models/server/server'
11 import { ServerBlocklistModel } from '../../models/server/server-blocklist'
12 import { areValidationErrors, doesAccountNameWithHostExist } from './shared'
14 const blockAccountValidator = [
18 async (req: express.Request, res: express.Response, next: express.NextFunction) => {
19 if (areValidationErrors(req, res)) return
20 if (!await doesAccountNameWithHostExist(req.body.accountName, res)) return
22 const user = res.locals.oauth.token.User
23 const accountToBlock = res.locals.account
25 if (user.Account.id === accountToBlock.id) {
27 status: HttpStatusCode.CONFLICT_409,
28 message: 'You cannot block yourself.'
37 const unblockAccountByAccountValidator = [
41 async (req: express.Request, res: express.Response, next: express.NextFunction) => {
42 if (areValidationErrors(req, res)) return
43 if (!await doesAccountNameWithHostExist(req.params.accountName, res)) return
45 const user = res.locals.oauth.token.User
46 const targetAccount = res.locals.account
47 if (!await doesUnblockAccountExist(user.Account.id, targetAccount.id, res)) return
53 const unblockAccountByServerValidator = [
57 async (req: express.Request, res: express.Response, next: express.NextFunction) => {
58 if (areValidationErrors(req, res)) return
59 if (!await doesAccountNameWithHostExist(req.params.accountName, res)) return
61 const serverActor = await getServerActor()
62 const targetAccount = res.locals.account
63 if (!await doesUnblockAccountExist(serverActor.Account.id, targetAccount.id, res)) return
69 const blockServerValidator = [
73 async (req: express.Request, res: express.Response, next: express.NextFunction) => {
74 if (areValidationErrors(req, res)) return
76 const host: string = req.body.host
78 if (host === WEBSERVER.HOST) {
80 status: HttpStatusCode.CONFLICT_409,
81 message: 'You cannot block your own server.'
85 const server = await ServerModel.loadOrCreateByHost(host)
87 res.locals.server = server
93 const unblockServerByAccountValidator = [
97 async (req: express.Request, res: express.Response, next: express.NextFunction) => {
98 if (areValidationErrors(req, res)) return
100 const user = res.locals.oauth.token.User
101 if (!await doesUnblockServerExist(user.Account.id, req.params.host, res)) return
107 const unblockServerByServerValidator = [
109 .custom(isHostValid),
111 async (req: express.Request, res: express.Response, next: express.NextFunction) => {
112 if (areValidationErrors(req, res)) return
114 const serverActor = await getServerActor()
115 if (!await doesUnblockServerExist(serverActor.Account.id, req.params.host, res)) return
121 const blocklistStatusValidator = [
124 .customSanitizer(arrayify)
125 .custom(isEachUniqueHostValid).withMessage('Should have a valid hosts array'),
129 .customSanitizer(arrayify)
130 .custom(areValidActorHandles).withMessage('Should have a valid accounts array'),
132 (req: express.Request, res: express.Response, next: express.NextFunction) => {
133 if (areValidationErrors(req, res)) return
139 // ---------------------------------------------------------------------------
142 blockServerValidator,
143 blockAccountValidator,
144 unblockAccountByAccountValidator,
145 unblockServerByAccountValidator,
146 unblockAccountByServerValidator,
147 unblockServerByServerValidator,
148 blocklistStatusValidator
151 // ---------------------------------------------------------------------------
153 async function doesUnblockAccountExist (accountId: number, targetAccountId: number, res: express.Response) {
154 const accountBlock = await AccountBlocklistModel.loadByAccountAndTarget(accountId, targetAccountId)
157 status: HttpStatusCode.NOT_FOUND_404,
158 message: 'Account block entry not found.'
163 res.locals.accountBlock = accountBlock
167 async function doesUnblockServerExist (accountId: number, host: string, res: express.Response) {
168 const serverBlock = await ServerBlocklistModel.loadByAccountAndHost(accountId, host)
171 status: HttpStatusCode.NOT_FOUND_404,
172 message: 'Server block entry not found.'
177 res.locals.serverBlock = serverBlock