]> git.immae.eu Git - github/Chocobozzz/PeerTube.git/blob - server/models/video/video-share.ts
Don't inject untrusted input
[github/Chocobozzz/PeerTube.git] / server / models / video / video-share.ts
1 import { literal, Op, QueryTypes, Transaction } from 'sequelize'
2 import { AllowNull, BelongsTo, Column, CreatedAt, DataType, ForeignKey, Is, Model, Scopes, Table, UpdatedAt } from 'sequelize-typescript'
3 import { forceNumber } from '@shared/core-utils'
4 import { AttributesOnly } from '@shared/typescript-utils'
5 import { isActivityPubUrlValid } from '../../helpers/custom-validators/activitypub/misc'
6 import { CONSTRAINTS_FIELDS } from '../../initializers/constants'
7 import { MActorDefault, MActorFollowersUrl, MActorId } from '../../types/models'
8 import { MVideoShareActor, MVideoShareFull } from '../../types/models/video'
9 import { ActorModel } from '../actor/actor'
10 import { buildLocalActorIdsIn, throwIfNotValid } from '../utils'
11 import { VideoModel } from './video'
12
13 enum ScopeNames {
14 FULL = 'FULL',
15 WITH_ACTOR = 'WITH_ACTOR'
16 }
17
18 @Scopes(() => ({
19 [ScopeNames.FULL]: {
20 include: [
21 {
22 model: ActorModel,
23 required: true
24 },
25 {
26 model: VideoModel,
27 required: true
28 }
29 ]
30 },
31 [ScopeNames.WITH_ACTOR]: {
32 include: [
33 {
34 model: ActorModel,
35 required: true
36 }
37 ]
38 }
39 }))
40 @Table({
41 tableName: 'videoShare',
42 indexes: [
43 {
44 fields: [ 'actorId' ]
45 },
46 {
47 fields: [ 'videoId' ]
48 },
49 {
50 fields: [ 'url' ],
51 unique: true
52 }
53 ]
54 })
55 export class VideoShareModel extends Model<Partial<AttributesOnly<VideoShareModel>>> {
56
57 @AllowNull(false)
58 @Is('VideoShareUrl', value => throwIfNotValid(value, isActivityPubUrlValid, 'url'))
59 @Column(DataType.STRING(CONSTRAINTS_FIELDS.VIDEO_SHARE.URL.max))
60 url: string
61
62 @CreatedAt
63 createdAt: Date
64
65 @UpdatedAt
66 updatedAt: Date
67
68 @ForeignKey(() => ActorModel)
69 @Column
70 actorId: number
71
72 @BelongsTo(() => ActorModel, {
73 foreignKey: {
74 allowNull: false
75 },
76 onDelete: 'cascade'
77 })
78 Actor: ActorModel
79
80 @ForeignKey(() => VideoModel)
81 @Column
82 videoId: number
83
84 @BelongsTo(() => VideoModel, {
85 foreignKey: {
86 allowNull: false
87 },
88 onDelete: 'cascade'
89 })
90 Video: VideoModel
91
92 static load (actorId: number | string, videoId: number | string, t?: Transaction): Promise<MVideoShareActor> {
93 return VideoShareModel.scope(ScopeNames.WITH_ACTOR).findOne({
94 where: {
95 actorId,
96 videoId
97 },
98 transaction: t
99 })
100 }
101
102 static loadByUrl (url: string, t: Transaction): Promise<MVideoShareFull> {
103 return VideoShareModel.scope(ScopeNames.FULL).findOne({
104 where: {
105 url
106 },
107 transaction: t
108 })
109 }
110
111 static listActorIdsAndFollowerUrlsByShare (videoId: number, t: Transaction) {
112 const query = `SELECT "actor"."id" AS "id", "actor"."followersUrl" AS "followersUrl" ` +
113 `FROM "videoShare" ` +
114 `INNER JOIN "actor" ON "actor"."id" = "videoShare"."actorId" ` +
115 `WHERE "videoShare"."videoId" = :videoId`
116
117 const options = {
118 type: QueryTypes.SELECT as QueryTypes.SELECT,
119 replacements: { videoId },
120 transaction: t
121 }
122
123 return VideoShareModel.sequelize.query<MActorId & MActorFollowersUrl>(query, options)
124 }
125
126 static loadActorsWhoSharedVideosOf (actorOwnerId: number, t: Transaction): Promise<MActorDefault[]> {
127 const safeOwnerId = forceNumber(actorOwnerId)
128
129 // /!\ On actor model
130 const query = {
131 where: {
132 [Op.and]: [
133 literal(
134 `EXISTS (` +
135 ` SELECT 1 FROM "videoShare" ` +
136 ` INNER JOIN "video" ON "videoShare"."videoId" = "video"."id" ` +
137 ` INNER JOIN "videoChannel" ON "videoChannel"."id" = "video"."channelId" ` +
138 ` INNER JOIN "account" ON "account"."id" = "videoChannel"."accountId" ` +
139 ` WHERE "videoShare"."actorId" = "ActorModel"."id" AND "account"."actorId" = ${safeOwnerId} ` +
140 ` LIMIT 1` +
141 `)`
142 )
143 ]
144 },
145 transaction: t
146 }
147
148 return ActorModel.findAll(query)
149 }
150
151 static loadActorsByVideoChannel (videoChannelId: number, t: Transaction): Promise<MActorDefault[]> {
152 const safeChannelId = forceNumber(videoChannelId)
153
154 // /!\ On actor model
155 const query = {
156 where: {
157 [Op.and]: [
158 literal(
159 `EXISTS (` +
160 ` SELECT 1 FROM "videoShare" ` +
161 ` INNER JOIN "video" ON "videoShare"."videoId" = "video"."id" ` +
162 ` WHERE "videoShare"."actorId" = "ActorModel"."id" AND "video"."channelId" = ${safeChannelId} ` +
163 ` LIMIT 1` +
164 `)`
165 )
166 ]
167 },
168 transaction: t
169 }
170
171 return ActorModel.findAll(query)
172 }
173
174 static listAndCountByVideoId (videoId: number, start: number, count: number, t?: Transaction) {
175 const query = {
176 offset: start,
177 limit: count,
178 where: {
179 videoId
180 },
181 transaction: t
182 }
183
184 return Promise.all([
185 VideoShareModel.count(query),
186 VideoShareModel.findAll(query)
187 ]).then(([ total, data ]) => ({ total, data }))
188 }
189
190 static listRemoteShareUrlsOfLocalVideos () {
191 const query = `SELECT "videoShare".url FROM "videoShare" ` +
192 `INNER JOIN actor ON actor.id = "videoShare"."actorId" AND actor."serverId" IS NOT NULL ` +
193 `INNER JOIN video ON video.id = "videoShare"."videoId" AND video.remote IS FALSE`
194
195 return VideoShareModel.sequelize.query<{ url: string }>(query, {
196 type: QueryTypes.SELECT,
197 raw: true
198 }).then(rows => rows.map(r => r.url))
199 }
200
201 static cleanOldSharesOf (videoId: number, beforeUpdatedAt: Date) {
202 const query = {
203 where: {
204 updatedAt: {
205 [Op.lt]: beforeUpdatedAt
206 },
207 videoId,
208 actorId: {
209 [Op.notIn]: buildLocalActorIdsIn()
210 }
211 }
212 }
213
214 return VideoShareModel.destroy(query)
215 }
216 }