QuickConnectController.cs 5.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137
  1. using System;
  2. using System.ComponentModel.DataAnnotations;
  3. using System.Threading.Tasks;
  4. using Jellyfin.Api.Constants;
  5. using Jellyfin.Api.Extensions;
  6. using Jellyfin.Api.Helpers;
  7. using MediaBrowser.Common.Extensions;
  8. using MediaBrowser.Controller.Authentication;
  9. using MediaBrowser.Controller.Net;
  10. using MediaBrowser.Controller.QuickConnect;
  11. using MediaBrowser.Model.QuickConnect;
  12. using Microsoft.AspNetCore.Authorization;
  13. using Microsoft.AspNetCore.Http;
  14. using Microsoft.AspNetCore.Mvc;
  15. namespace Jellyfin.Api.Controllers;
  16. /// <summary>
  17. /// Quick connect controller.
  18. /// </summary>
  19. public class QuickConnectController : BaseJellyfinApiController
  20. {
  21. private readonly IQuickConnect _quickConnect;
  22. private readonly IAuthorizationContext _authContext;
  23. /// <summary>
  24. /// Initializes a new instance of the <see cref="QuickConnectController"/> class.
  25. /// </summary>
  26. /// <param name="quickConnect">Instance of the <see cref="IQuickConnect"/> interface.</param>
  27. /// <param name="authContext">Instance of the <see cref="IAuthorizationContext"/> interface.</param>
  28. public QuickConnectController(IQuickConnect quickConnect, IAuthorizationContext authContext)
  29. {
  30. _quickConnect = quickConnect;
  31. _authContext = authContext;
  32. }
  33. /// <summary>
  34. /// Gets the current quick connect state.
  35. /// </summary>
  36. /// <response code="200">Quick connect state returned.</response>
  37. /// <returns>Whether Quick Connect is enabled on the server or not.</returns>
  38. [HttpGet("Enabled")]
  39. [ProducesResponseType(StatusCodes.Status200OK)]
  40. public ActionResult<bool> GetQuickConnectEnabled()
  41. {
  42. return _quickConnect.IsEnabled;
  43. }
  44. /// <summary>
  45. /// Initiate a new quick connect request.
  46. /// </summary>
  47. /// <response code="200">Quick connect request successfully created.</response>
  48. /// <response code="401">Quick connect is not active on this server.</response>
  49. /// <returns>A <see cref="QuickConnectResult"/> with a secret and code for future use or an error message.</returns>
  50. [HttpPost("Initiate")]
  51. [ProducesResponseType(StatusCodes.Status200OK)]
  52. public async Task<ActionResult<QuickConnectResult>> InitiateQuickConnect()
  53. {
  54. try
  55. {
  56. var auth = await _authContext.GetAuthorizationInfo(Request).ConfigureAwait(false);
  57. return _quickConnect.TryConnect(auth);
  58. }
  59. catch (AuthenticationException)
  60. {
  61. return Unauthorized("Quick connect is disabled");
  62. }
  63. }
  64. /// <summary>
  65. /// Old version of <see cref="InitiateQuickConnect" /> using a GET method.
  66. /// Still available to avoid breaking compatibility.
  67. /// </summary>
  68. /// <returns>The result of <see cref="InitiateQuickConnect" />.</returns>
  69. [Obsolete("Use POST request instead")]
  70. [HttpGet("Initiate")]
  71. [ApiExplorerSettings(IgnoreApi = true)]
  72. public Task<ActionResult<QuickConnectResult>> InitiateQuickConnectLegacy() => InitiateQuickConnect();
  73. /// <summary>
  74. /// Attempts to retrieve authentication information.
  75. /// </summary>
  76. /// <param name="secret">Secret previously returned from the Initiate endpoint.</param>
  77. /// <response code="200">Quick connect result returned.</response>
  78. /// <response code="404">Unknown quick connect secret.</response>
  79. /// <returns>An updated <see cref="QuickConnectResult"/>.</returns>
  80. [HttpGet("Connect")]
  81. [ProducesResponseType(StatusCodes.Status200OK)]
  82. [ProducesResponseType(StatusCodes.Status404NotFound)]
  83. public ActionResult<QuickConnectResult> GetQuickConnectState([FromQuery, Required] string secret)
  84. {
  85. try
  86. {
  87. return _quickConnect.CheckRequestStatus(secret);
  88. }
  89. catch (ResourceNotFoundException)
  90. {
  91. return NotFound("Unknown secret");
  92. }
  93. catch (AuthenticationException)
  94. {
  95. return Unauthorized("Quick connect is disabled");
  96. }
  97. }
  98. /// <summary>
  99. /// Authorizes a pending quick connect request.
  100. /// </summary>
  101. /// <param name="code">Quick connect code to authorize.</param>
  102. /// <param name="userId">The user the authorize. Access to the requested user is required.</param>
  103. /// <response code="200">Quick connect result authorized successfully.</response>
  104. /// <response code="403">Unknown user id.</response>
  105. /// <returns>Boolean indicating if the authorization was successful.</returns>
  106. [HttpPost("Authorize")]
  107. [Authorize(Policy = Policies.DefaultAuthorization)]
  108. [ProducesResponseType(StatusCodes.Status200OK)]
  109. [ProducesResponseType(StatusCodes.Status403Forbidden)]
  110. public async Task<ActionResult<bool>> AuthorizeQuickConnect([FromQuery, Required] string code, [FromQuery] Guid? userId = null)
  111. {
  112. var currentUserId = User.GetUserId();
  113. var actualUserId = userId ?? currentUserId;
  114. if (actualUserId.Equals(default) || (!userId.Equals(currentUserId) && !User.IsInRole(UserRoles.Administrator)))
  115. {
  116. return Forbid("Unknown user id");
  117. }
  118. try
  119. {
  120. return await _quickConnect.AuthorizeRequest(actualUserId, code).ConfigureAwait(false);
  121. }
  122. catch (AuthenticationException)
  123. {
  124. return Unauthorized("Quick connect is disabled");
  125. }
  126. }
  127. }