1 import express from 'express'
2 import { body, param, query } from 'express-validator'
3 import { MUserAccountUrl } from '@server/types/models'
4 import { HttpStatusCode, UserRight } from '@shared/models'
5 import { exists, isBooleanValid, isIdValid, toBooleanOrNull } from '../../../helpers/custom-validators/misc'
6 import { isValidVideoCommentText } from '../../../helpers/custom-validators/video-comments'
7 import { logger } from '../../../helpers/logger'
8 import { AcceptResult, isLocalVideoCommentReplyAccepted, isLocalVideoThreadAccepted } from '../../../lib/moderation'
9 import { Hooks } from '../../../lib/plugins/hooks'
10 import { MCommentOwnerVideoReply, MVideo, MVideoFullLight } from '../../../types/models/video'
14 doesVideoCommentExist,
15 doesVideoCommentThreadExist,
20 const listVideoCommentsValidator = [
23 .customSanitizer(toBooleanOrNull)
24 .custom(isBooleanValid)
25 .withMessage('Should have a valid is local boolean'),
29 .customSanitizer(toBooleanOrNull)
30 .custom(isBooleanValid)
31 .withMessage('Should have a valid is on local video boolean'),
35 .custom(exists).withMessage('Should have a valid search'),
37 query('searchAccount')
39 .custom(exists).withMessage('Should have a valid account search'),
43 .custom(exists).withMessage('Should have a valid video search'),
45 (req: express.Request, res: express.Response, next: express.NextFunction) => {
46 logger.debug('Checking listVideoCommentsValidator parameters.', { parameters: req.query })
48 if (areValidationErrors(req, res)) return
54 const listVideoCommentThreadsValidator = [
55 isValidVideoIdParam('videoId'),
57 async (req: express.Request, res: express.Response, next: express.NextFunction) => {
58 logger.debug('Checking listVideoCommentThreads parameters.', { parameters: req.params })
60 if (areValidationErrors(req, res)) return
61 if (!await doesVideoExist(req.params.videoId, res, 'only-video')) return
63 if (!await checkCanSeeVideo({ req, res, paramId: req.params.videoId, video: res.locals.onlyVideo })) return
69 const listVideoThreadCommentsValidator = [
70 isValidVideoIdParam('videoId'),
73 .custom(isIdValid).not().isEmpty().withMessage('Should have a valid threadId'),
75 async (req: express.Request, res: express.Response, next: express.NextFunction) => {
76 logger.debug('Checking listVideoThreadComments parameters.', { parameters: req.params })
78 if (areValidationErrors(req, res)) return
79 if (!await doesVideoExist(req.params.videoId, res, 'only-video')) return
80 if (!await doesVideoCommentThreadExist(req.params.threadId, res.locals.onlyVideo, res)) return
82 if (!await checkCanSeeVideo({ req, res, paramId: req.params.videoId, video: res.locals.onlyVideo })) return
88 const addVideoCommentThreadValidator = [
89 isValidVideoIdParam('videoId'),
92 .custom(isValidVideoCommentText).not().isEmpty().withMessage('Should have a valid comment text'),
94 async (req: express.Request, res: express.Response, next: express.NextFunction) => {
95 logger.debug('Checking addVideoCommentThread parameters.', { parameters: req.params, body: req.body })
97 if (areValidationErrors(req, res)) return
98 if (!await doesVideoExist(req.params.videoId, res)) return
100 if (!await checkCanSeeVideo({ req, res, paramId: req.params.videoId, video: res.locals.videoAll })) return
102 if (!isVideoCommentsEnabled(res.locals.videoAll, res)) return
103 if (!await isVideoCommentAccepted(req, res, res.locals.videoAll, false)) return
109 const addVideoCommentReplyValidator = [
110 isValidVideoIdParam('videoId'),
112 param('commentId').custom(isIdValid).not().isEmpty().withMessage('Should have a valid commentId'),
114 body('text').custom(isValidVideoCommentText).not().isEmpty().withMessage('Should have a valid comment text'),
116 async (req: express.Request, res: express.Response, next: express.NextFunction) => {
117 logger.debug('Checking addVideoCommentReply parameters.', { parameters: req.params, body: req.body })
119 if (areValidationErrors(req, res)) return
120 if (!await doesVideoExist(req.params.videoId, res)) return
122 if (!await checkCanSeeVideo({ req, res, paramId: req.params.videoId, video: res.locals.videoAll })) return
124 if (!isVideoCommentsEnabled(res.locals.videoAll, res)) return
125 if (!await doesVideoCommentExist(req.params.commentId, res.locals.videoAll, res)) return
126 if (!await isVideoCommentAccepted(req, res, res.locals.videoAll, true)) return
132 const videoCommentGetValidator = [
133 isValidVideoIdParam('videoId'),
136 .custom(isIdValid).not().isEmpty().withMessage('Should have a valid commentId'),
138 async (req: express.Request, res: express.Response, next: express.NextFunction) => {
139 logger.debug('Checking videoCommentGetValidator parameters.', { parameters: req.params })
141 if (areValidationErrors(req, res)) return
142 if (!await doesVideoExist(req.params.videoId, res, 'id')) return
143 if (!await doesVideoCommentExist(req.params.commentId, res.locals.videoId, res)) return
149 const removeVideoCommentValidator = [
150 isValidVideoIdParam('videoId'),
152 param('commentId').custom(isIdValid).not().isEmpty().withMessage('Should have a valid commentId'),
154 async (req: express.Request, res: express.Response, next: express.NextFunction) => {
155 logger.debug('Checking removeVideoCommentValidator parameters.', { parameters: req.params })
157 if (areValidationErrors(req, res)) return
158 if (!await doesVideoExist(req.params.videoId, res)) return
159 if (!await doesVideoCommentExist(req.params.commentId, res.locals.videoAll, res)) return
161 // Check if the user who did the request is able to delete the video
162 if (!checkUserCanDeleteVideoComment(res.locals.oauth.token.User, res.locals.videoCommentFull, res)) return
168 // ---------------------------------------------------------------------------
171 listVideoCommentThreadsValidator,
172 listVideoThreadCommentsValidator,
173 addVideoCommentThreadValidator,
174 listVideoCommentsValidator,
175 addVideoCommentReplyValidator,
176 videoCommentGetValidator,
177 removeVideoCommentValidator
180 // ---------------------------------------------------------------------------
182 function isVideoCommentsEnabled (video: MVideo, res: express.Response) {
183 if (video.commentsEnabled !== true) {
185 status: HttpStatusCode.CONFLICT_409,
186 message: 'Video comments are disabled for this video.'
194 function checkUserCanDeleteVideoComment (user: MUserAccountUrl, videoComment: MCommentOwnerVideoReply, res: express.Response) {
195 if (videoComment.isDeleted()) {
197 status: HttpStatusCode.CONFLICT_409,
198 message: 'This comment is already deleted'
203 const userAccount = user.Account
206 user.hasRight(UserRight.REMOVE_ANY_VIDEO_COMMENT) === false && // Not a moderator
207 videoComment.accountId !== userAccount.id && // Not the comment owner
208 videoComment.Video.VideoChannel.accountId !== userAccount.id // Not the video owner
211 status: HttpStatusCode.FORBIDDEN_403,
212 message: 'Cannot remove video comment of another user'
220 async function isVideoCommentAccepted (req: express.Request, res: express.Response, video: MVideoFullLight, isReply: boolean) {
221 const acceptParameters = {
223 commentBody: req.body,
224 user: res.locals.oauth.token.User
227 let acceptedResult: AcceptResult
230 const acceptReplyParameters = Object.assign(acceptParameters, { parentComment: res.locals.videoCommentFull })
232 acceptedResult = await Hooks.wrapFun(
233 isLocalVideoCommentReplyAccepted,
234 acceptReplyParameters,
235 'filter:api.video-comment-reply.create.accept.result'
238 acceptedResult = await Hooks.wrapFun(
239 isLocalVideoThreadAccepted,
241 'filter:api.video-thread.create.accept.result'
245 if (!acceptedResult || acceptedResult.accepted !== true) {
246 logger.info('Refused local comment.', { acceptedResult, acceptParameters })
249 status: HttpStatusCode.FORBIDDEN_403,
250 message: acceptedResult?.errorMessage || 'Refused local comment'