-import { parallel } from 'async'
-import express = require('express')
-import fs = require('fs')
+import * as express from 'express'
+import { constants, promises as fs } from 'fs'
+import { readFile } from 'fs-extra'
import { join } from 'path'
-import expressValidator = require('express-validator')
-// TODO: use .validator when express-validator typing will have validator field
-const validator = expressValidator['validator']
-
-import { database as db } from '../initializers/database'
-import {
- CONFIG,
- REMOTE_SCHEME,
- STATIC_PATHS,
- STATIC_MAX_AGE
-} from '../initializers'
-import { root } from '../helpers'
+import { logger } from '@server/helpers/logger'
+import { CONFIG } from '@server/initializers/config'
+import { Hooks } from '@server/lib/plugins/hooks'
+import { HttpStatusCode } from '@shared/core-utils'
+import { buildFileLocale, getCompleteLocale, is18nLocale, LOCALE_FILES } from '@shared/core-utils/i18n'
+import { root } from '../helpers/core-utils'
+import { STATIC_MAX_AGE } from '../initializers/constants'
+import { ClientHtml, sendHTML, serveIndexHTML } from '../lib/client-html'
+import { asyncMiddleware, embedCSP } from '../middlewares'
const clientsRouter = express.Router()
-// TODO: move to constants
-const opengraphComment = '<!-- opengraph tags -->'
const distPath = join(root(), 'client', 'dist')
-const embedPath = join(distPath, 'standalone', 'videos', 'embed.html')
-const indexPath = join(distPath, 'index.html')
+const testEmbedPath = join(distPath, 'standalone', 'videos', 'test-embed.html')
-// Special route that add OpenGraph tags
+// Special route that add OpenGraph and oEmbed tags
// Do not use a template engine for a so little thing
-clientsRouter.use('/videos/watch/:id', generateWatchHtmlPage)
-
-clientsRouter.use('/videos/embed', function (req, res, next) {
- res.sendFile(embedPath)
-})
+clientsRouter.use('/videos/watch/playlist/:id', asyncMiddleware(generateWatchPlaylistHtmlPage))
+clientsRouter.use('/videos/watch/:id', asyncMiddleware(generateWatchHtmlPage))
+clientsRouter.use('/accounts/:nameWithHost', asyncMiddleware(generateAccountHtmlPage))
+clientsRouter.use('/video-channels/:nameWithHost', asyncMiddleware(generateVideoChannelHtmlPage))
+
+const embedMiddlewares = [
+ CONFIG.CSP.ENABLED
+ ? embedCSP
+ : (req: express.Request, res: express.Response, next: express.NextFunction) => next(),
+
+ // Set headers
+ (req: express.Request, res: express.Response, next: express.NextFunction) => {
+ res.removeHeader('X-Frame-Options')
+
+ // Don't cache HTML file since it's an index to the immutable JS/CSS files
+ res.setHeader('Cache-Control', 'public, max-age=0')
+
+ next()
+ },
+
+ asyncMiddleware(generateEmbedHtmlPage)
+]
+
+clientsRouter.use('/videos/embed', ...embedMiddlewares)
+clientsRouter.use('/video-playlists/embed', ...embedMiddlewares)
+
+const testEmbedController = (req: express.Request, res: express.Response) => res.sendFile(testEmbedPath)
+
+clientsRouter.use('/videos/test-embed', testEmbedController)
+clientsRouter.use('/video-playlists/test-embed', testEmbedController)
+
+// Dynamic PWA manifest
+clientsRouter.get('/manifest.webmanifest', asyncMiddleware(generateManifest))
+
+// Static client overrides
+// Must be consistent with static client overrides redirections in /support/nginx/peertube
+const staticClientOverrides = [
+ 'assets/images/logo.svg',
+ 'assets/images/favicon.png',
+ 'assets/images/icons/icon-36x36.png',
+ 'assets/images/icons/icon-48x48.png',
+ 'assets/images/icons/icon-72x72.png',
+ 'assets/images/icons/icon-96x96.png',
+ 'assets/images/icons/icon-144x144.png',
+ 'assets/images/icons/icon-192x192.png',
+ 'assets/images/icons/icon-512x512.png'
+]
+
+for (const staticClientOverride of staticClientOverrides) {
+ const overridePhysicalPath = join(CONFIG.STORAGE.CLIENT_OVERRIDES_DIR, staticClientOverride)
+ clientsRouter.use(`/client/${staticClientOverride}`, asyncMiddleware(serveClientOverride(overridePhysicalPath)))
+}
-// Static HTML/CSS/JS client files
-clientsRouter.use('/client', express.static(distPath, { maxAge: STATIC_MAX_AGE }))
+clientsRouter.use('/client/locales/:locale/:file.json', serveServerTranslations)
+clientsRouter.use('/client', express.static(distPath, { maxAge: STATIC_MAX_AGE.CLIENT }))
// 404 for static files not found
-clientsRouter.use('/client/*', function (req, res, next) {
- res.sendStatus(404)
+clientsRouter.use('/client/*', (req: express.Request, res: express.Response) => {
+ res.sendStatus(HttpStatusCode.NOT_FOUND_404)
})
+// Always serve index client page (the client is a single page application, let it handle routing)
+// Try to provide the right language index.html
+clientsRouter.use('/(:language)?', asyncMiddleware(serveIndexHTML))
+
// ---------------------------------------------------------------------------
export {
// ---------------------------------------------------------------------------
-function addOpenGraphTags (htmlStringPage, video) {
- let basePreviewUrlHttp
+function serveServerTranslations (req: express.Request, res: express.Response) {
+ const locale = req.params.locale
+ const file = req.params.file
- if (video.isOwned()) {
- basePreviewUrlHttp = CONFIG.WEBSERVER.URL
- } else {
- basePreviewUrlHttp = REMOTE_SCHEME.HTTP + '://' + video.Author.Pod.host
+ if (is18nLocale(locale) && LOCALE_FILES.includes(file)) {
+ const completeLocale = getCompleteLocale(locale)
+ const completeFileLocale = buildFileLocale(completeLocale)
+
+ const path = join(__dirname, `../../../client/dist/locale/${file}.${completeFileLocale}.json`)
+ return res.sendFile(path, { maxAge: STATIC_MAX_AGE.SERVER })
}
- // We fetch the remote preview (bigger than the thumbnail)
- // This should not overhead the remote server since social websites put in a cache the OpenGraph tags
- // We can't use the thumbnail because these social websites want bigger images (> 200x200 for Facebook for example)
- const previewUrl = basePreviewUrlHttp + STATIC_PATHS.PREVIEWS + video.getPreviewName()
- const videoUrl = CONFIG.WEBSERVER.URL + '/videos/watch/' + video.id
-
- const metaTags = {
- 'og:type': 'video',
- 'og:title': video.name,
- 'og:image': previewUrl,
- 'og:url': videoUrl,
- 'og:description': video.description,
-
- 'name': video.name,
- 'description': video.description,
- 'image': previewUrl,
-
- 'twitter:card': 'summary_large_image',
- 'twitter:site': '@Chocobozzz',
- 'twitter:title': video.name,
- 'twitter:description': video.description,
- 'twitter:image': previewUrl
+ return res.sendStatus(HttpStatusCode.NOT_FOUND_404)
+}
+
+async function generateEmbedHtmlPage (req: express.Request, res: express.Response) {
+ const hookName = req.originalUrl.startsWith('/video-playlists/')
+ ? 'filter:html.embed.video-playlist.allowed.result'
+ : 'filter:html.embed.video.allowed.result'
+
+ const allowParameters = { req }
+
+ const allowedResult = await Hooks.wrapFun(
+ isEmbedAllowed,
+ allowParameters,
+ hookName
+ )
+
+ if (!allowedResult || allowedResult.allowed !== true) {
+ logger.info('Embed is not allowed.', { allowedResult })
+
+ return sendHTML(allowedResult?.html || '', res)
}
- let tagsString = ''
- Object.keys(metaTags).forEach(function (tagName) {
- const tagValue = metaTags[tagName]
+ const html = await ClientHtml.getEmbedHTML()
+
+ return sendHTML(html, res)
+}
- tagsString += '<meta property="' + tagName + '" content="' + tagValue + '" />'
- })
+async function generateWatchHtmlPage (req: express.Request, res: express.Response) {
+ const html = await ClientHtml.getWatchHTMLPage(req.params.id + '', req, res)
- return htmlStringPage.replace(opengraphComment, tagsString)
+ return sendHTML(html, res)
}
-function generateWatchHtmlPage (req, res, next) {
- const videoId = req.params.id
+async function generateWatchPlaylistHtmlPage (req: express.Request, res: express.Response) {
+ const html = await ClientHtml.getWatchPlaylistHTMLPage(req.params.id + '', req, res)
- // Let Angular application handle errors
- if (!validator.isUUID(videoId, 4)) return res.sendFile(indexPath)
+ return sendHTML(html, res)
+}
- parallel({
- file: function (callback) {
- fs.readFile(indexPath, callback)
- },
+async function generateAccountHtmlPage (req: express.Request, res: express.Response) {
+ const html = await ClientHtml.getAccountHTMLPage(req.params.nameWithHost, req, res)
- video: function (callback) {
- db.Video.loadAndPopulateAuthorAndPodAndTags(videoId, callback)
- }
- }, function (err, result: any) {
- if (err) return next(err)
+ return sendHTML(html, res)
+}
+
+async function generateVideoChannelHtmlPage (req: express.Request, res: express.Response) {
+ const html = await ClientHtml.getVideoChannelHTMLPage(req.params.nameWithHost, req, res)
+
+ return sendHTML(html, res)
+}
- const html = result.file.toString()
- const video = result.video
+async function generateManifest (req: express.Request, res: express.Response) {
+ const manifestPhysicalPath = join(root(), 'client', 'dist', 'manifest.webmanifest')
+ const manifestJson = await readFile(manifestPhysicalPath, 'utf8')
+ const manifest = JSON.parse(manifestJson)
- // Let Angular application handle errors
- if (!video) return res.sendFile(indexPath)
+ manifest.name = CONFIG.INSTANCE.NAME
+ manifest.short_name = CONFIG.INSTANCE.NAME
+ manifest.description = CONFIG.INSTANCE.SHORT_DESCRIPTION
+
+ res.json(manifest)
+}
+
+function serveClientOverride (path: string) {
+ return async (req: express.Request, res: express.Response, next: express.NextFunction) => {
+ try {
+ await fs.access(path, constants.F_OK)
+ // Serve override client
+ res.sendFile(path, { maxAge: STATIC_MAX_AGE.SERVER })
+ } catch {
+ // Serve dist client
+ next()
+ }
+ }
+}
- const htmlStringPageWithTags = addOpenGraphTags(html, video)
- res.set('Content-Type', 'text/html; charset=UTF-8').send(htmlStringPageWithTags)
- })
+type AllowedResult = { allowed: boolean, html?: string }
+function isEmbedAllowed (_object: {
+ req: express.Request
+}): AllowedResult {
+ return { allowed: true }
}