import * as express from 'express'
import 'multer'
-import { extname, join } from 'path'
-import * as uuidv4 from 'uuid/v4'
import * as RateLimit from 'express-rate-limit'
import { UserCreate, UserRight, UserRole, UserUpdate, UserUpdateMe, UserVideoRate as FormattedUserVideoRate } from '../../../shared'
-import { retryTransactionWrapper } from '../../helpers/database-utils'
-import { processImage } from '../../helpers/image-utils'
import { logger } from '../../helpers/logger'
-import { createReqFiles, getFormattedObjects } from '../../helpers/utils'
-import { AVATARS_SIZE, CONFIG, IMAGE_MIMETYPE_EXT, RATES_LIMIT, sequelizeTypescript } from '../../initializers'
-import { updateActorAvatarInstance } from '../../lib/activitypub'
+import { getFormattedObjects } from '../../helpers/utils'
+import { CONFIG, IMAGE_MIMETYPE_EXT, RATES_LIMIT, sequelizeTypescript } from '../../initializers'
import { sendUpdateActor } from '../../lib/activitypub/send'
import { Emailer } from '../../lib/emailer'
import { Redis } from '../../lib/redis'
import { createUserAccountAndChannel } from '../../lib/user'
import {
asyncMiddleware,
+ asyncRetryTransactionMiddleware,
authenticate,
ensureUserHasRight,
ensureUserRegistrationAllowed,
+ ensureUserRegistrationAllowedForIP,
paginationValidator,
setDefaultPagination,
setDefaultSort,
usersUpdateValidator,
usersVideoRatingValidator
} from '../../middlewares'
-import {
- usersAskResetPasswordValidator,
- usersResetPasswordValidator,
- usersUpdateMyAvatarValidator,
- videosSortValidator
-} from '../../middlewares/validators'
+import { usersAskResetPasswordValidator, usersResetPasswordValidator, videosSortValidator } from '../../middlewares/validators'
import { AccountVideoRateModel } from '../../models/account/account-video-rate'
import { UserModel } from '../../models/account/user'
import { OAuthTokenModel } from '../../models/oauth/oauth-token'
import { VideoModel } from '../../models/video/video'
import { VideoSortField } from '../../../client/src/app/shared/video/sort-field.type'
+import { createReqFiles } from '../../helpers/express-utils'
+import { UserVideoQuota } from '../../../shared/models/users/user-video-quota.model'
+import { updateAvatarValidator } from '../../middlewares/validators/avatar'
+import { updateActorAvatarFile } from '../../lib/avatar'
+import { auditLoggerFactory, UserAuditView } from '../../helpers/audit-logger'
+
+const auditLogger = auditLoggerFactory('users')
const reqAvatarFile = createReqFiles([ 'avatarfile' ], IMAGE_MIMETYPE_EXT, { avatarfile: CONFIG.STORAGE.AVATARS_DIR })
const loginRateLimiter = new RateLimit({
authenticate,
ensureUserHasRight(UserRight.MANAGE_USERS),
asyncMiddleware(usersAddValidator),
- asyncMiddleware(createUserRetryWrapper)
+ asyncRetryTransactionMiddleware(createUser)
)
usersRouter.post('/register',
asyncMiddleware(ensureUserRegistrationAllowed),
+ ensureUserRegistrationAllowedForIP,
asyncMiddleware(usersRegisterValidator),
- asyncMiddleware(registerUserRetryWrapper)
+ asyncRetryTransactionMiddleware(registerUser)
)
usersRouter.put('/me',
usersRouter.post('/me/avatar/pick',
authenticate,
reqAvatarFile,
- usersUpdateMyAvatarValidator,
+ updateAvatarValidator,
asyncMiddleware(updateMyAvatar)
)
async function getUserVideos (req: express.Request, res: express.Response, next: express.NextFunction) {
const user = res.locals.oauth.token.User as UserModel
- const resultList = await VideoModel.listAccountVideosForApi(
+ const resultList = await VideoModel.listUserVideosForApi(
user.Account.id,
req.query.start as number,
req.query.count as number,
false // Display my NSFW videos
)
- return res.json(getFormattedObjects(resultList.data, resultList.total))
-}
-
-async function createUserRetryWrapper (req: express.Request, res: express.Response, next: express.NextFunction) {
- const options = {
- arguments: [ req ],
- errorMessage: 'Cannot insert the user with many retries.'
+ const additionalAttributes = {
+ waitTranscoding: true,
+ state: true,
+ scheduledUpdate: true
}
-
- const { user, account } = await retryTransactionWrapper(createUser, options)
-
- return res.json({
- user: {
- id: user.id,
- uuid: account.uuid
- }
- }).end()
+ return res.json(getFormattedObjects(resultList.data, resultList.total, { additionalAttributes }))
}
-async function createUser (req: express.Request) {
+async function createUser (req: express.Request, res: express.Response) {
const body: UserCreate = req.body
const userToCreate = new UserModel({
username: body.username,
const { user, account } = await createUserAccountAndChannel(userToCreate)
+ auditLogger.create(res.locals.oauth.token.User.Account.Actor.getIdentifier(), new UserAuditView(user.toFormattedJSON()))
logger.info('User %s with its channel and account created.', body.username)
- return { user, account }
-}
-
-async function registerUserRetryWrapper (req: express.Request, res: express.Response, next: express.NextFunction) {
- const options = {
- arguments: [ req ],
- errorMessage: 'Cannot insert the user with many retries.'
- }
-
- await retryTransactionWrapper(registerUser, options)
-
- return res.type('json').status(204).end()
+ return res.json({
+ user: {
+ id: user.id,
+ account: {
+ id: account.id,
+ uuid: account.Actor.uuid
+ }
+ }
+ }).end()
}
-async function registerUser (req: express.Request) {
+async function registerUser (req: express.Request, res: express.Response) {
const body: UserCreate = req.body
- const user = new UserModel({
+ const userToCreate = new UserModel({
username: body.username,
password: body.password,
email: body.email,
videoQuota: CONFIG.USER.VIDEO_QUOTA
})
- await createUserAccountAndChannel(user)
+ const { user } = await createUserAccountAndChannel(userToCreate)
+ auditLogger.create(body.username, new UserAuditView(user.toFormattedJSON()))
logger.info('User %s with its channel and account registered.', body.username)
+
+ return res.type('json').status(204).end()
}
async function getUserInformation (req: express.Request, res: express.Response, next: express.NextFunction) {
const user = await UserModel.loadByUsernameAndPopulateChannels(res.locals.oauth.token.user.username)
const videoQuotaUsed = await UserModel.getOriginalVideoFileTotalFromUser(user)
- return res.json({
+ const data: UserVideoQuota = {
videoQuotaUsed
- })
+ }
+ return res.json(data)
}
function getUser (req: express.Request, res: express.Response, next: express.NextFunction) {
await user.destroy()
+ auditLogger.delete(res.locals.oauth.token.User.Account.Actor.getIdentifier(), new UserAuditView(user.toFormattedJSON()))
+
return res.sendStatus(204)
}
const body: UserUpdateMe = req.body
const user: UserModel = res.locals.oauth.token.user
+ const oldUserAuditView = new UserAuditView(user.toFormattedJSON())
if (body.password !== undefined) user.password = body.password
if (body.email !== undefined) user.email = body.email
await sequelizeTypescript.transaction(async t => {
await user.save({ transaction: t })
+ if (body.displayName !== undefined) user.Account.name = body.displayName
if (body.description !== undefined) user.Account.description = body.description
await user.Account.save({ transaction: t })
await sendUpdateActor(user.Account, t)
+
+ auditLogger.update(
+ res.locals.oauth.token.User.Account.Actor.getIdentifier(),
+ new UserAuditView(user.toFormattedJSON()),
+ oldUserAuditView
+ )
})
return res.sendStatus(204)
}
async function updateMyAvatar (req: express.Request, res: express.Response, next: express.NextFunction) {
- const avatarPhysicalFile = req.files['avatarfile'][0]
- const user = res.locals.oauth.token.user
- const actor = user.Account.Actor
-
- const extension = extname(avatarPhysicalFile.filename)
- const avatarName = uuidv4() + extension
- const destination = join(CONFIG.STORAGE.AVATARS_DIR, avatarName)
- await processImage(avatarPhysicalFile, destination, AVATARS_SIZE)
-
- const avatar = await sequelizeTypescript.transaction(async t => {
- const updatedActor = await updateActorAvatarInstance(actor, avatarName, t)
- await updatedActor.save({ transaction: t })
+ const avatarPhysicalFile = req.files[ 'avatarfile' ][ 0 ]
+ const user: UserModel = res.locals.oauth.token.user
+ const oldUserAuditView = new UserAuditView(user.toFormattedJSON())
+ const account = user.Account
- await sendUpdateActor(user.Account, t)
+ const avatar = await updateActorAvatarFile(avatarPhysicalFile, account.Actor, account)
- return updatedActor.Avatar
- })
+ auditLogger.update(
+ res.locals.oauth.token.User.Account.Actor.getIdentifier(),
+ new UserAuditView(user.toFormattedJSON()),
+ oldUserAuditView
+ )
return res
.json({
async function updateUser (req: express.Request, res: express.Response, next: express.NextFunction) {
const body: UserUpdate = req.body
- const user = res.locals.user as UserModel
- const roleChanged = body.role !== undefined && body.role !== user.role
+ const userToUpdate = res.locals.user as UserModel
+ const oldUserAuditView = new UserAuditView(userToUpdate.toFormattedJSON())
+ const roleChanged = body.role !== undefined && body.role !== userToUpdate.role
- if (body.email !== undefined) user.email = body.email
- if (body.videoQuota !== undefined) user.videoQuota = body.videoQuota
- if (body.role !== undefined) user.role = body.role
+ if (body.email !== undefined) userToUpdate.email = body.email
+ if (body.videoQuota !== undefined) userToUpdate.videoQuota = body.videoQuota
+ if (body.role !== undefined) userToUpdate.role = body.role
- await user.save()
+ const user = await userToUpdate.save()
// Destroy user token to refresh rights
if (roleChanged) {
- await OAuthTokenModel.deleteUserToken(user.id)
+ await OAuthTokenModel.deleteUserToken(userToUpdate.id)
}
+ auditLogger.update(
+ res.locals.oauth.token.User.Account.Actor.getIdentifier(),
+ new UserAuditView(user.toFormattedJSON()),
+ oldUserAuditView
+ )
+
// Don't need to send this update to followers, these attributes are not propagated
return res.sendStatus(204)