QuickConnectController.cs 5.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128
  1. using System;
  2. using System.ComponentModel.DataAnnotations;
  3. using System.Threading.Tasks;
  4. using Jellyfin.Api.Constants;
  5. using Jellyfin.Api.Extensions;
  6. using Jellyfin.Api.Helpers;
  7. using MediaBrowser.Common.Extensions;
  8. using MediaBrowser.Controller.Authentication;
  9. using MediaBrowser.Controller.Net;
  10. using MediaBrowser.Controller.QuickConnect;
  11. using MediaBrowser.Model.QuickConnect;
  12. using Microsoft.AspNetCore.Authorization;
  13. using Microsoft.AspNetCore.Http;
  14. using Microsoft.AspNetCore.Mvc;
  15. namespace Jellyfin.Api.Controllers
  16. {
  17. /// <summary>
  18. /// Quick connect controller.
  19. /// </summary>
  20. public class QuickConnectController : BaseJellyfinApiController
  21. {
  22. private readonly IQuickConnect _quickConnect;
  23. private readonly IAuthorizationContext _authContext;
  24. /// <summary>
  25. /// Initializes a new instance of the <see cref="QuickConnectController"/> class.
  26. /// </summary>
  27. /// <param name="quickConnect">Instance of the <see cref="IQuickConnect"/> interface.</param>
  28. /// <param name="authContext">Instance of the <see cref="IAuthorizationContext"/> interface.</param>
  29. public QuickConnectController(IQuickConnect quickConnect, IAuthorizationContext authContext)
  30. {
  31. _quickConnect = quickConnect;
  32. _authContext = authContext;
  33. }
  34. /// <summary>
  35. /// Gets the current quick connect state.
  36. /// </summary>
  37. /// <response code="200">Quick connect state returned.</response>
  38. /// <returns>Whether Quick Connect is enabled on the server or not.</returns>
  39. [HttpGet("Enabled")]
  40. [ProducesResponseType(StatusCodes.Status200OK)]
  41. public ActionResult<bool> GetQuickConnectEnabled()
  42. {
  43. return _quickConnect.IsEnabled;
  44. }
  45. /// <summary>
  46. /// Initiate a new quick connect request.
  47. /// </summary>
  48. /// <response code="200">Quick connect request successfully created.</response>
  49. /// <response code="401">Quick connect is not active on this server.</response>
  50. /// <returns>A <see cref="QuickConnectResult"/> with a secret and code for future use or an error message.</returns>
  51. [HttpGet("Initiate")]
  52. [ProducesResponseType(StatusCodes.Status200OK)]
  53. public async Task<ActionResult<QuickConnectResult>> InitiateQuickConnect()
  54. {
  55. try
  56. {
  57. var auth = await _authContext.GetAuthorizationInfo(Request).ConfigureAwait(false);
  58. return _quickConnect.TryConnect(auth);
  59. }
  60. catch (AuthenticationException)
  61. {
  62. return Unauthorized("Quick connect is disabled");
  63. }
  64. }
  65. /// <summary>
  66. /// Attempts to retrieve authentication information.
  67. /// </summary>
  68. /// <param name="secret">Secret previously returned from the Initiate endpoint.</param>
  69. /// <response code="200">Quick connect result returned.</response>
  70. /// <response code="404">Unknown quick connect secret.</response>
  71. /// <returns>An updated <see cref="QuickConnectResult"/>.</returns>
  72. [HttpGet("Connect")]
  73. [ProducesResponseType(StatusCodes.Status200OK)]
  74. [ProducesResponseType(StatusCodes.Status404NotFound)]
  75. public ActionResult<QuickConnectResult> GetQuickConnectState([FromQuery, Required] string secret)
  76. {
  77. try
  78. {
  79. return _quickConnect.CheckRequestStatus(secret);
  80. }
  81. catch (ResourceNotFoundException)
  82. {
  83. return NotFound("Unknown secret");
  84. }
  85. catch (AuthenticationException)
  86. {
  87. return Unauthorized("Quick connect is disabled");
  88. }
  89. }
  90. /// <summary>
  91. /// Authorizes a pending quick connect request.
  92. /// </summary>
  93. /// <param name="code">Quick connect code to authorize.</param>
  94. /// <param name="userId">The user the authorize. Access to the requested user is required.</param>
  95. /// <response code="200">Quick connect result authorized successfully.</response>
  96. /// <response code="403">Unknown user id.</response>
  97. /// <returns>Boolean indicating if the authorization was successful.</returns>
  98. [HttpPost("Authorize")]
  99. [Authorize(Policy = Policies.DefaultAuthorization)]
  100. [ProducesResponseType(StatusCodes.Status200OK)]
  101. [ProducesResponseType(StatusCodes.Status403Forbidden)]
  102. public async Task<ActionResult<bool>> AuthorizeQuickConnect([FromQuery, Required] string code, [FromQuery] Guid? userId = null)
  103. {
  104. var currentUserId = User.GetUserId();
  105. var actualUserId = userId ?? currentUserId;
  106. if (actualUserId.Equals(default) || (!userId.Equals(currentUserId) && !User.IsInRole(UserRoles.Administrator)))
  107. {
  108. return Forbid("Unknown user id");
  109. }
  110. try
  111. {
  112. return await _quickConnect.AuthorizeRequest(actualUserId, code).ConfigureAwait(false);
  113. }
  114. catch (AuthenticationException)
  115. {
  116. return Unauthorized("Quick connect is disabled");
  117. }
  118. }
  119. }
  120. }