QuickConnectController.cs 5.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136
  1. using System;
  2. using System.ComponentModel.DataAnnotations;
  3. using System.Threading.Tasks;
  4. using Jellyfin.Api.Constants;
  5. using Jellyfin.Api.Extensions;
  6. using MediaBrowser.Common.Extensions;
  7. using MediaBrowser.Controller.Authentication;
  8. using MediaBrowser.Controller.Net;
  9. using MediaBrowser.Controller.QuickConnect;
  10. using MediaBrowser.Model.QuickConnect;
  11. using Microsoft.AspNetCore.Authorization;
  12. using Microsoft.AspNetCore.Http;
  13. using Microsoft.AspNetCore.Mvc;
  14. namespace Jellyfin.Api.Controllers;
  15. /// <summary>
  16. /// Quick connect controller.
  17. /// </summary>
  18. public class QuickConnectController : BaseJellyfinApiController
  19. {
  20. private readonly IQuickConnect _quickConnect;
  21. private readonly IAuthorizationContext _authContext;
  22. /// <summary>
  23. /// Initializes a new instance of the <see cref="QuickConnectController"/> class.
  24. /// </summary>
  25. /// <param name="quickConnect">Instance of the <see cref="IQuickConnect"/> interface.</param>
  26. /// <param name="authContext">Instance of the <see cref="IAuthorizationContext"/> interface.</param>
  27. public QuickConnectController(IQuickConnect quickConnect, IAuthorizationContext authContext)
  28. {
  29. _quickConnect = quickConnect;
  30. _authContext = authContext;
  31. }
  32. /// <summary>
  33. /// Gets the current quick connect state.
  34. /// </summary>
  35. /// <response code="200">Quick connect state returned.</response>
  36. /// <returns>Whether Quick Connect is enabled on the server or not.</returns>
  37. [HttpGet("Enabled")]
  38. [ProducesResponseType(StatusCodes.Status200OK)]
  39. public ActionResult<bool> GetQuickConnectEnabled()
  40. {
  41. return _quickConnect.IsEnabled;
  42. }
  43. /// <summary>
  44. /// Initiate a new quick connect request.
  45. /// </summary>
  46. /// <response code="200">Quick connect request successfully created.</response>
  47. /// <response code="401">Quick connect is not active on this server.</response>
  48. /// <returns>A <see cref="QuickConnectResult"/> with a secret and code for future use or an error message.</returns>
  49. [HttpPost("Initiate")]
  50. [ProducesResponseType(StatusCodes.Status200OK)]
  51. public async Task<ActionResult<QuickConnectResult>> InitiateQuickConnect()
  52. {
  53. try
  54. {
  55. var auth = await _authContext.GetAuthorizationInfo(Request).ConfigureAwait(false);
  56. return _quickConnect.TryConnect(auth);
  57. }
  58. catch (AuthenticationException)
  59. {
  60. return Unauthorized("Quick connect is disabled");
  61. }
  62. }
  63. /// <summary>
  64. /// Old version of <see cref="InitiateQuickConnect" /> using a GET method.
  65. /// Still available to avoid breaking compatibility.
  66. /// </summary>
  67. /// <returns>The result of <see cref="InitiateQuickConnect" />.</returns>
  68. [Obsolete("Use POST request instead")]
  69. [HttpGet("Initiate")]
  70. [ApiExplorerSettings(IgnoreApi = true)]
  71. public Task<ActionResult<QuickConnectResult>> InitiateQuickConnectLegacy() => InitiateQuickConnect();
  72. /// <summary>
  73. /// Attempts to retrieve authentication information.
  74. /// </summary>
  75. /// <param name="secret">Secret previously returned from the Initiate endpoint.</param>
  76. /// <response code="200">Quick connect result returned.</response>
  77. /// <response code="404">Unknown quick connect secret.</response>
  78. /// <returns>An updated <see cref="QuickConnectResult"/>.</returns>
  79. [HttpGet("Connect")]
  80. [ProducesResponseType(StatusCodes.Status200OK)]
  81. [ProducesResponseType(StatusCodes.Status404NotFound)]
  82. public ActionResult<QuickConnectResult> GetQuickConnectState([FromQuery, Required] string secret)
  83. {
  84. try
  85. {
  86. return _quickConnect.CheckRequestStatus(secret);
  87. }
  88. catch (ResourceNotFoundException)
  89. {
  90. return NotFound("Unknown secret");
  91. }
  92. catch (AuthenticationException)
  93. {
  94. return Unauthorized("Quick connect is disabled");
  95. }
  96. }
  97. /// <summary>
  98. /// Authorizes a pending quick connect request.
  99. /// </summary>
  100. /// <param name="code">Quick connect code to authorize.</param>
  101. /// <param name="userId">The user the authorize. Access to the requested user is required.</param>
  102. /// <response code="200">Quick connect result authorized successfully.</response>
  103. /// <response code="403">Unknown user id.</response>
  104. /// <returns>Boolean indicating if the authorization was successful.</returns>
  105. [HttpPost("Authorize")]
  106. [Authorize]
  107. [ProducesResponseType(StatusCodes.Status200OK)]
  108. [ProducesResponseType(StatusCodes.Status403Forbidden)]
  109. public async Task<ActionResult<bool>> AuthorizeQuickConnect([FromQuery, Required] string code, [FromQuery] Guid? userId = null)
  110. {
  111. var currentUserId = User.GetUserId();
  112. var actualUserId = userId ?? currentUserId;
  113. if (actualUserId.Equals(default) || (!userId.Equals(currentUserId) && !User.IsInRole(UserRoles.Administrator)))
  114. {
  115. return Forbid("Unknown user id");
  116. }
  117. try
  118. {
  119. return await _quickConnect.AuthorizeRequest(actualUserId, code).ConfigureAwait(false);
  120. }
  121. catch (AuthenticationException)
  122. {
  123. return Unauthorized("Quick connect is disabled");
  124. }
  125. }
  126. }