settings.js 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507
  1. //var nodemailer = require('nodemailer');
  2. // Sandstorm context is detected using the METEOR_SETTINGS environment variable
  3. // in the package definition.
  4. const isSandstorm =
  5. Meteor.settings && Meteor.settings.public && Meteor.settings.public.sandstorm;
  6. Settings = new Mongo.Collection('settings');
  7. Settings.attachSchema(
  8. new SimpleSchema({
  9. disableRegistration: {
  10. type: Boolean,
  11. },
  12. disableForgotPassword: {
  13. type: Boolean,
  14. },
  15. 'mailServer.username': {
  16. type: String,
  17. optional: true,
  18. },
  19. 'mailServer.password': {
  20. type: String,
  21. optional: true,
  22. },
  23. 'mailServer.host': {
  24. type: String,
  25. optional: true,
  26. },
  27. 'mailServer.port': {
  28. type: String,
  29. optional: true,
  30. },
  31. 'mailServer.enableTLS': {
  32. type: Boolean,
  33. optional: true,
  34. },
  35. 'mailServer.from': {
  36. type: String,
  37. optional: true,
  38. },
  39. productName: {
  40. type: String,
  41. optional: true,
  42. },
  43. displayAuthenticationMethod: {
  44. type: Boolean,
  45. optional: true,
  46. },
  47. defaultAuthenticationMethod: {
  48. type: String,
  49. optional: false,
  50. },
  51. spinnerName: {
  52. type: String,
  53. optional: true,
  54. },
  55. hideLogo: {
  56. type: Boolean,
  57. optional: true,
  58. },
  59. customLoginLogoImageUrl: {
  60. type: String,
  61. optional: true,
  62. },
  63. customLoginLogoLinkUrl: {
  64. type: String,
  65. optional: true,
  66. },
  67. textBelowCustomLoginLogo: {
  68. type: String,
  69. optional: true,
  70. },
  71. automaticLinkedUrlSchemes: {
  72. type: String,
  73. optional: true,
  74. },
  75. customTopLeftCornerLogoImageUrl: {
  76. type: String,
  77. optional: true,
  78. },
  79. customTopLeftCornerLogoLinkUrl: {
  80. type: String,
  81. optional: true,
  82. },
  83. customTopLeftCornerLogoHeight: {
  84. type: String,
  85. optional: true,
  86. },
  87. oidcBtnText: {
  88. type: String,
  89. optional: true,
  90. },
  91. mailDomainName: {
  92. type: String,
  93. optional: true,
  94. },
  95. legalNotice: {
  96. type: String,
  97. optional: true,
  98. },
  99. createdAt: {
  100. type: Date,
  101. denyUpdate: true,
  102. // eslint-disable-next-line consistent-return
  103. autoValue() {
  104. if (this.isInsert) {
  105. return new Date();
  106. } else if (this.isUpsert) {
  107. return { $setOnInsert: new Date() };
  108. } else {
  109. this.unset();
  110. }
  111. },
  112. },
  113. modifiedAt: {
  114. type: Date,
  115. // eslint-disable-next-line consistent-return
  116. autoValue() {
  117. if (this.isInsert || this.isUpsert || this.isUpdate) {
  118. return new Date();
  119. } else {
  120. this.unset();
  121. }
  122. },
  123. },
  124. }),
  125. );
  126. Settings.helpers({
  127. mailUrl() {
  128. if (!this.mailServer.host) {
  129. return null;
  130. }
  131. const protocol = this.mailServer.enableTLS ? 'smtps://' : 'smtp://';
  132. if (!this.mailServer.username && !this.mailServer.password) {
  133. return `${protocol}${this.mailServer.host}:${this.mailServer.port}/`;
  134. }
  135. return `${protocol}${this.mailServer.username}:${encodeURIComponent(
  136. this.mailServer.password,
  137. )}@${this.mailServer.host}:${this.mailServer.port}/`;
  138. },
  139. });
  140. Settings.allow({
  141. update(userId) {
  142. const user = Users.findOne(userId);
  143. return user && user.isAdmin;
  144. },
  145. });
  146. if (Meteor.isServer) {
  147. Meteor.startup(() => {
  148. Settings._collection._ensureIndex({ modifiedAt: -1 });
  149. const setting = Settings.findOne({});
  150. if (!setting) {
  151. const now = new Date();
  152. const domain = process.env.ROOT_URL.match(
  153. /\/\/(?:www\.)?(.*)?(?:\/)?/,
  154. )[1];
  155. const from = `Boards Support <support@${domain}>`;
  156. const defaultSetting = {
  157. disableRegistration: false,
  158. mailServer: {
  159. username: '',
  160. password: '',
  161. host: '',
  162. port: '',
  163. enableTLS: false,
  164. from,
  165. },
  166. createdAt: now,
  167. modifiedAt: now,
  168. displayAuthenticationMethod: true,
  169. defaultAuthenticationMethod: 'password',
  170. };
  171. Settings.insert(defaultSetting);
  172. }
  173. if (isSandstorm) {
  174. // At Sandstorm, Admin Panel has SMTP settings
  175. const newSetting = Settings.findOne();
  176. if (!process.env.MAIL_URL && newSetting.mailUrl())
  177. process.env.MAIL_URL = newSetting.mailUrl();
  178. Accounts.emailTemplates.from = process.env.MAIL_FROM
  179. ? process.env.MAIL_FROM
  180. : newSetting.mailServer.from;
  181. } else {
  182. // Not running on Sandstorm, so using environment variables
  183. Accounts.emailTemplates.from = process.env.MAIL_FROM;
  184. }
  185. });
  186. if (isSandstorm) {
  187. // At Sandstorm Wekan Admin Panel, save SMTP settings.
  188. Settings.after.update((userId, doc, fieldNames) => {
  189. // assign new values to mail-from & MAIL_URL in environment
  190. if (_.contains(fieldNames, 'mailServer') && doc.mailServer.host) {
  191. const protocol = doc.mailServer.enableTLS ? 'smtps://' : 'smtp://';
  192. if (!doc.mailServer.username && !doc.mailServer.password) {
  193. process.env.MAIL_URL = `${protocol}${doc.mailServer.host}:${doc.mailServer.port}/`;
  194. } else {
  195. process.env.MAIL_URL = `${protocol}${
  196. doc.mailServer.username
  197. }:${encodeURIComponent(doc.mailServer.password)}@${
  198. doc.mailServer.host
  199. }:${doc.mailServer.port}/`;
  200. }
  201. Accounts.emailTemplates.from = doc.mailServer.from;
  202. }
  203. });
  204. }
  205. function getRandomNum(min, max) {
  206. const range = max - min;
  207. const rand = Math.random();
  208. return min + Math.round(rand * range);
  209. }
  210. function getEnvVar(name) {
  211. const value = process.env[name];
  212. if (value) {
  213. return value;
  214. }
  215. throw new Meteor.Error([
  216. 'var-not-exist',
  217. `The environment variable ${name} does not exist`,
  218. ]);
  219. }
  220. function sendInvitationEmail(_id) {
  221. const icode = InvitationCodes.findOne(_id);
  222. const author = Users.findOne(Meteor.userId());
  223. try {
  224. const fullName = Users.findOne(icode.authorId)
  225. && Users.findOne(icode.authorId).profile
  226. && Users.findOne(icode.authorId).profile !== undefined
  227. && Users.findOne(icode.authorId).profile.fullname ? Users.findOne(icode.authorId).profile.fullname : "";
  228. const params = {
  229. email: icode.email,
  230. inviter: fullName != "" ? fullName + " (" + Users.findOne(icode.authorId).username + " )" : Users.findOne(icode.authorId).username,
  231. user: icode.email.split('@')[0],
  232. icode: icode.code,
  233. url: FlowRouter.url('sign-up'),
  234. };
  235. const lang = author.getLanguage();
  236. /*
  237. if (process.env.MAIL_SERVICE !== '') {
  238. let transporter = nodemailer.createTransport({
  239. service: process.env.MAIL_SERVICE,
  240. auth: {
  241. user: process.env.MAIL_SERVICE_USER,
  242. pass: process.env.MAIL_SERVICE_PASSWORD
  243. },
  244. })
  245. let info = transporter.sendMail({
  246. to: icode.email,
  247. from: Accounts.emailTemplates.from,
  248. subject: TAPi18n.__('email-invite-register-subject', params, lang),
  249. text: TAPi18n.__('email-invite-register-text', params, lang),
  250. })
  251. } else {
  252. Email.send({
  253. to: icode.email,
  254. from: Accounts.emailTemplates.from,
  255. subject: TAPi18n.__('email-invite-register-subject', params, lang),
  256. text: TAPi18n.__('email-invite-register-text', params, lang),
  257. });
  258. }
  259. */
  260. Email.send({
  261. to: icode.email,
  262. from: Accounts.emailTemplates.from,
  263. subject: TAPi18n.__('email-invite-register-subject', params, lang),
  264. text: TAPi18n.__('email-invite-register-text', params, lang),
  265. });
  266. } catch (e) {
  267. InvitationCodes.remove(_id);
  268. throw new Meteor.Error('email-fail', e.message);
  269. }
  270. }
  271. function isNonAdminAllowedToSendMail(currentUser){
  272. const currSett = Settings.findOne({});
  273. let isAllowed = false;
  274. if(currSett && currSett != undefined && currSett.disableRegistration && currSett.mailDomainName !== undefined && currSett.mailDomainName != ""){
  275. for(let i = 0; i < currentUser.emails.length; i++) {
  276. if(currentUser.emails[i].address.endsWith(currSett.mailDomainName)){
  277. isAllowed = true;
  278. break;
  279. }
  280. }
  281. }
  282. return isAllowed;
  283. }
  284. function isLdapEnabled() {
  285. return (
  286. process.env.LDAP_ENABLE === 'true' || process.env.LDAP_ENABLE === true
  287. );
  288. }
  289. function isOauth2Enabled() {
  290. return (
  291. process.env.OAUTH2_ENABLED === 'true' ||
  292. process.env.OAUTH2_ENABLED === true
  293. );
  294. }
  295. function isCasEnabled() {
  296. return (
  297. process.env.CAS_ENABLED === 'true' || process.env.CAS_ENABLED === true
  298. );
  299. }
  300. function isApiEnabled() {
  301. return process.env.WITH_API === 'true' || process.env.WITH_API === true;
  302. }
  303. Meteor.methods({
  304. sendInvitation(emails, boards) {
  305. let rc = 0;
  306. check(emails, [String]);
  307. check(boards, [String]);
  308. const user = Users.findOne(Meteor.userId());
  309. if (!user.isAdmin && !isNonAdminAllowedToSendMail(user)) {
  310. rc = -1;
  311. throw new Meteor.Error('not-allowed');
  312. }
  313. emails.forEach(email => {
  314. if (email && SimpleSchema.RegEx.Email.test(email)) {
  315. // Checks if the email is already link to an account.
  316. const userExist = Users.findOne({ email });
  317. if (userExist) {
  318. rc = -1;
  319. throw new Meteor.Error(
  320. 'user-exist',
  321. `The user with the email ${email} has already an account.`,
  322. );
  323. }
  324. // Checks if the email is already link to an invitation.
  325. const invitation = InvitationCodes.findOne({ email });
  326. if (invitation) {
  327. InvitationCodes.update(invitation, {
  328. $set: { boardsToBeInvited: boards },
  329. });
  330. sendInvitationEmail(invitation._id);
  331. } else {
  332. const code = getRandomNum(100000, 999999);
  333. InvitationCodes.insert(
  334. {
  335. code,
  336. email,
  337. boardsToBeInvited: boards,
  338. createdAt: new Date(),
  339. authorId: Meteor.userId(),
  340. },
  341. function(err, _id) {
  342. if (!err && _id) {
  343. sendInvitationEmail(_id);
  344. } else {
  345. rc = -1;
  346. throw new Meteor.Error(
  347. 'invitation-generated-fail',
  348. err.message,
  349. );
  350. }
  351. },
  352. );
  353. }
  354. }
  355. });
  356. return rc;
  357. },
  358. sendSMTPTestEmail() {
  359. if (!Meteor.userId()) {
  360. throw new Meteor.Error('invalid-user');
  361. }
  362. const user = Meteor.user();
  363. if (!user.emails || !user.emails[0] || !user.emails[0].address) {
  364. throw new Meteor.Error('email-invalid');
  365. }
  366. this.unblock();
  367. const lang = user.getLanguage();
  368. try {
  369. /*
  370. if (process.env.MAIL_SERVICE !== '') {
  371. let transporter = nodemailer.createTransport({
  372. service: process.env.MAIL_SERVICE,
  373. auth: {
  374. user: process.env.MAIL_SERVICE_USER,
  375. pass: process.env.MAIL_SERVICE_PASSWORD
  376. },
  377. })
  378. let info = transporter.sendMail({
  379. to: user.emails[0].address,
  380. from: Accounts.emailTemplates.from,
  381. subject: TAPi18n.__('email-smtp-test-subject', { lng: lang }),
  382. text: TAPi18n.__('email-smtp-test-text', { lng: lang }),
  383. })
  384. } else {
  385. Email.send({
  386. to: user.emails[0].address,
  387. from: Accounts.emailTemplates.from,
  388. subject: TAPi18n.__('email-smtp-test-subject', { lng: lang }),
  389. text: TAPi18n.__('email-smtp-test-text', { lng: lang }),
  390. });
  391. }
  392. */
  393. Email.send({
  394. to: user.emails[0].address,
  395. from: Accounts.emailTemplates.from,
  396. subject: TAPi18n.__('email-smtp-test-subject', { lng: lang }),
  397. text: TAPi18n.__('email-smtp-test-text', { lng: lang }),
  398. });
  399. } catch ({ message }) {
  400. throw new Meteor.Error(
  401. 'email-fail',
  402. `${TAPi18n.__('email-fail-text', { lng: lang })}: ${message}`,
  403. message,
  404. );
  405. }
  406. return {
  407. message: 'email-sent',
  408. email: user.emails[0].address,
  409. };
  410. },
  411. getCustomUI() {
  412. const setting = Settings.findOne({});
  413. if (!setting.productName) {
  414. return {
  415. productName: '',
  416. };
  417. } else {
  418. return {
  419. productName: `${setting.productName}`,
  420. };
  421. }
  422. },
  423. getDisableRegistration() {
  424. const setting = Settings.findOne({});
  425. if (!setting.disableRegistration) {
  426. return false;
  427. } else {
  428. return {
  429. disableRegistration: `${setting.disableRegistration}`,
  430. };
  431. }
  432. },
  433. getDisableForgotPassword() {
  434. const setting = Settings.findOne({});
  435. if (!setting.disableForgotPassword) {
  436. return false;
  437. } else {
  438. return {
  439. disableForgotPassword: `${setting.disableForgotPassword}`,
  440. };
  441. }
  442. },
  443. getMatomoConf() {
  444. return {
  445. address: getEnvVar('MATOMO_ADDRESS'),
  446. siteId: getEnvVar('MATOMO_SITE_ID'),
  447. doNotTrack: process.env.MATOMO_DO_NOT_TRACK || false,
  448. withUserName: process.env.MATOMO_WITH_USERNAME || false,
  449. };
  450. },
  451. _isLdapEnabled() {
  452. return isLdapEnabled();
  453. },
  454. _isOauth2Enabled() {
  455. return isOauth2Enabled();
  456. },
  457. _isCasEnabled() {
  458. return isCasEnabled();
  459. },
  460. _isApiEnabled() {
  461. return isApiEnabled();
  462. },
  463. // Gets all connection methods to use it in the Template
  464. getAuthenticationsEnabled() {
  465. return {
  466. ldap: isLdapEnabled(),
  467. oauth2: isOauth2Enabled(),
  468. cas: isCasEnabled(),
  469. };
  470. },
  471. getDefaultAuthenticationMethod() {
  472. return process.env.DEFAULT_AUTHENTICATION_METHOD;
  473. },
  474. isPasswordLoginDisabled() {
  475. return process.env.PASSWORD_LOGIN_ENABLED === 'false';
  476. },
  477. });
  478. }
  479. export default Settings;