QuickConnectController.cs 5.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138
  1. using System;
  2. using System.ComponentModel.DataAnnotations;
  3. using System.Threading.Tasks;
  4. using Jellyfin.Api.Constants;
  5. using Jellyfin.Api.Extensions;
  6. using Jellyfin.Api.Helpers;
  7. using MediaBrowser.Common.Extensions;
  8. using MediaBrowser.Controller.Authentication;
  9. using MediaBrowser.Controller.Net;
  10. using MediaBrowser.Controller.QuickConnect;
  11. using MediaBrowser.Model.QuickConnect;
  12. using Microsoft.AspNetCore.Authorization;
  13. using Microsoft.AspNetCore.Http;
  14. using Microsoft.AspNetCore.Mvc;
  15. namespace Jellyfin.Api.Controllers
  16. {
  17. /// <summary>
  18. /// Quick connect controller.
  19. /// </summary>
  20. public class QuickConnectController : BaseJellyfinApiController
  21. {
  22. private readonly IQuickConnect _quickConnect;
  23. private readonly IAuthorizationContext _authContext;
  24. /// <summary>
  25. /// Initializes a new instance of the <see cref="QuickConnectController"/> class.
  26. /// </summary>
  27. /// <param name="quickConnect">Instance of the <see cref="IQuickConnect"/> interface.</param>
  28. /// <param name="authContext">Instance of the <see cref="IAuthorizationContext"/> interface.</param>
  29. public QuickConnectController(IQuickConnect quickConnect, IAuthorizationContext authContext)
  30. {
  31. _quickConnect = quickConnect;
  32. _authContext = authContext;
  33. }
  34. /// <summary>
  35. /// Gets the current quick connect state.
  36. /// </summary>
  37. /// <response code="200">Quick connect state returned.</response>
  38. /// <returns>Whether Quick Connect is enabled on the server or not.</returns>
  39. [HttpGet("Enabled")]
  40. [ProducesResponseType(StatusCodes.Status200OK)]
  41. public ActionResult<bool> GetQuickConnectEnabled()
  42. {
  43. return _quickConnect.IsEnabled;
  44. }
  45. /// <summary>
  46. /// Initiate a new quick connect request.
  47. /// </summary>
  48. /// <response code="200">Quick connect request successfully created.</response>
  49. /// <response code="401">Quick connect is not active on this server.</response>
  50. /// <returns>A <see cref="QuickConnectResult"/> with a secret and code for future use or an error message.</returns>
  51. [HttpPost("Initiate")]
  52. [ProducesResponseType(StatusCodes.Status200OK)]
  53. public async Task<ActionResult<QuickConnectResult>> InitiateQuickConnect()
  54. {
  55. try
  56. {
  57. var auth = await _authContext.GetAuthorizationInfo(Request).ConfigureAwait(false);
  58. return _quickConnect.TryConnect(auth);
  59. }
  60. catch (AuthenticationException)
  61. {
  62. return Unauthorized("Quick connect is disabled");
  63. }
  64. }
  65. /// <summary>
  66. /// Old version of <see cref="InitiateQuickConnect" /> using a GET method.
  67. /// Still available to avoid breaking compatibility.
  68. /// </summary>
  69. /// <returns>The result of <see cref="InitiateQuickConnect" />.</returns>
  70. [Obsolete("Use POST request instead")]
  71. [HttpGet("Initiate")]
  72. [ApiExplorerSettings(IgnoreApi = true)]
  73. public Task<ActionResult<QuickConnectResult>> InitiateQuickConnectLegacy() => InitiateQuickConnect();
  74. /// <summary>
  75. /// Attempts to retrieve authentication information.
  76. /// </summary>
  77. /// <param name="secret">Secret previously returned from the Initiate endpoint.</param>
  78. /// <response code="200">Quick connect result returned.</response>
  79. /// <response code="404">Unknown quick connect secret.</response>
  80. /// <returns>An updated <see cref="QuickConnectResult"/>.</returns>
  81. [HttpGet("Connect")]
  82. [ProducesResponseType(StatusCodes.Status200OK)]
  83. [ProducesResponseType(StatusCodes.Status404NotFound)]
  84. public ActionResult<QuickConnectResult> GetQuickConnectState([FromQuery, Required] string secret)
  85. {
  86. try
  87. {
  88. return _quickConnect.CheckRequestStatus(secret);
  89. }
  90. catch (ResourceNotFoundException)
  91. {
  92. return NotFound("Unknown secret");
  93. }
  94. catch (AuthenticationException)
  95. {
  96. return Unauthorized("Quick connect is disabled");
  97. }
  98. }
  99. /// <summary>
  100. /// Authorizes a pending quick connect request.
  101. /// </summary>
  102. /// <param name="code">Quick connect code to authorize.</param>
  103. /// <param name="userId">The user the authorize. Access to the requested user is required.</param>
  104. /// <response code="200">Quick connect result authorized successfully.</response>
  105. /// <response code="403">Unknown user id.</response>
  106. /// <returns>Boolean indicating if the authorization was successful.</returns>
  107. [HttpPost("Authorize")]
  108. [Authorize(Policy = Policies.DefaultAuthorization)]
  109. [ProducesResponseType(StatusCodes.Status200OK)]
  110. [ProducesResponseType(StatusCodes.Status403Forbidden)]
  111. public async Task<ActionResult<bool>> AuthorizeQuickConnect([FromQuery, Required] string code, [FromQuery] Guid? userId = null)
  112. {
  113. var currentUserId = User.GetUserId();
  114. var actualUserId = userId ?? currentUserId;
  115. if (actualUserId.Equals(default) || (!userId.Equals(currentUserId) && !User.IsInRole(UserRoles.Administrator)))
  116. {
  117. return Forbid("Unknown user id");
  118. }
  119. try
  120. {
  121. return await _quickConnect.AuthorizeRequest(actualUserId, code).ConfigureAwait(false);
  122. }
  123. catch (AuthenticationException)
  124. {
  125. return Unauthorized("Quick connect is disabled");
  126. }
  127. }
  128. }
  129. }