-import * as express from 'express'
+import express from 'express'
import { param, query } from 'express-validator'
+import { HttpStatusCode } from '../../../shared/models/http/http-error-codes'
import { isValidRSSFeed } from '../../helpers/custom-validators/feeds'
-import { exists, isIdOrUUIDValid, isIdValid } from '../../helpers/custom-validators/misc'
-import { logger } from '../../helpers/logger'
+import { exists, isIdOrUUIDValid, isIdValid, toCompleteUUID } from '../../helpers/custom-validators/misc'
import {
+ areValidationErrors,
+ checkCanSeeVideo,
doesAccountIdExist,
doesAccountNameWithHostExist,
doesUserFeedTokenCorrespond,
doesVideoChannelIdExist,
- doesVideoChannelNameWithHostExist
-} from '../../helpers/middlewares'
-import { doesVideoExist } from '../../helpers/middlewares/videos'
-import { areValidationErrors } from './utils'
-import { HttpStatusCode } from '../../../shared/core-utils/miscs/http-error-codes'
+ doesVideoChannelNameWithHostExist,
+ doesVideoExist
+} from './shared'
const feedsFormatValidator = [
- param('format').optional().custom(isValidRSSFeed).withMessage('Should have a valid format (rss, atom, json)'),
- query('format').optional().custom(isValidRSSFeed).withMessage('Should have a valid format (rss, atom, json)')
+ param('format')
+ .optional()
+ .custom(isValidRSSFeed).withMessage('Should have a valid format (rss, atom, json)'),
+ query('format')
+ .optional()
+ .custom(isValidRSSFeed).withMessage('Should have a valid format (rss, atom, json)'),
+
+ (req: express.Request, res: express.Response, next: express.NextFunction) => {
+ if (areValidationErrors(req, res)) return
+
+ return next()
+ }
]
function setFeedFormatContentType (req: express.Request, res: express.Response, next: express.NextFunction) {
const videoFeedsValidator = [
query('accountId')
.optional()
- .custom(isIdValid)
- .withMessage('Should have a valid account id'),
+ .custom(isIdValid),
query('accountName')
.optional(),
query('videoChannelId')
.optional()
- .custom(isIdValid)
- .withMessage('Should have a valid channel id'),
+ .custom(isIdValid),
query('videoChannelName')
.optional(),
async (req: express.Request, res: express.Response, next: express.NextFunction) => {
- logger.debug('Checking feeds parameters', { parameters: req.query })
-
if (areValidationErrors(req, res)) return
if (req.query.accountId && !await doesAccountIdExist(req.query.accountId, res)) return
const videoSubscriptionFeedsValidator = [
query('accountId')
- .custom(isIdValid)
- .withMessage('Should have a valid account id'),
+ .custom(isIdValid),
query('token')
- .custom(exists)
- .withMessage('Should have a token'),
+ .custom(exists),
async (req: express.Request, res: express.Response, next: express.NextFunction) => {
- logger.debug('Checking subscription feeds parameters', { parameters: req.query })
-
if (areValidationErrors(req, res)) return
if (!await doesAccountIdExist(req.query.accountId, res)) return
]
const videoCommentsFeedsValidator = [
- query('videoId').optional().custom(isIdOrUUIDValid),
+ query('videoId')
+ .optional()
+ .customSanitizer(toCompleteUUID)
+ .custom(isIdOrUUIDValid),
async (req: express.Request, res: express.Response, next: express.NextFunction) => {
- logger.debug('Checking feeds parameters', { parameters: req.query })
-
if (areValidationErrors(req, res)) return
if (req.query.videoId && (req.query.videoChannelId || req.query.videoChannelName)) {
return res.fail({ message: 'videoId cannot be mixed with a channel filter' })
}
- if (req.query.videoId && !await doesVideoExist(req.query.videoId, res)) return
+ if (req.query.videoId) {
+ if (!await doesVideoExist(req.query.videoId, res)) return
+ if (!await checkCanSeeVideo({ req, res, paramId: req.query.videoId, video: res.locals.videoAll })) return
+ }
return next()
}