2
0

common.js 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508
  1. const express = require('express')
  2. const router = express.Router()
  3. const pageHelper = require('../helpers/page')
  4. const _ = require('lodash')
  5. const CleanCSS = require('clean-css')
  6. const moment = require('moment')
  7. const path = require('path')
  8. const tmplCreateRegex = /^[0-9]+(,[0-9]+)?$/
  9. const siteAssetsPath = path.resolve(WIKI.ROOTPATH, WIKI.config.dataPath, 'assets')
  10. /**
  11. * Robots.txt
  12. */
  13. router.get('/robots.txt', (req, res, next) => {
  14. res.type('text/plain')
  15. if (_.includes(WIKI.config.seo.robots, 'noindex')) {
  16. res.send('User-agent: *\nDisallow: /')
  17. } else {
  18. res.status(200).end()
  19. }
  20. })
  21. /**
  22. * Health Endpoint
  23. */
  24. router.get('/healthz', (req, res, next) => {
  25. if (WIKI.db.knex.client.pool.numFree() < 1 && WIKI.db.knex.client.pool.numUsed() < 1) {
  26. res.status(503).json({ ok: false }).end()
  27. } else {
  28. res.status(200).json({ ok: true }).end()
  29. }
  30. })
  31. /**
  32. * Site Asset
  33. */
  34. router.get('/_site/:siteId?/:resource', async (req, res, next) => {
  35. const site = req.params.siteId ? WIKI.sites[req.params.siteId] : await WIKI.db.sites.getSiteByHostname({ hostname: req.hostname })
  36. if (!site) {
  37. return res.status(404).send('Site Not Found')
  38. }
  39. switch (req.params.resource) {
  40. case 'logo': {
  41. if (site.config.assets.logo) {
  42. res.sendFile(path.join(siteAssetsPath, `logo-${site.id}.${site.config.assets.logoExt}`))
  43. } else {
  44. res.sendFile(path.join(WIKI.ROOTPATH, 'assets/_assets/logo-wikijs.svg'))
  45. }
  46. break
  47. }
  48. case 'favicon': {
  49. if (site.config.assets.favicon) {
  50. res.sendFile(path.join(siteAssetsPath, `favicon-${site.id}.${site.config.assets.faviconExt}`))
  51. } else {
  52. res.sendFile(path.join(WIKI.ROOTPATH, 'assets/_assets/logo-wikijs.svg'))
  53. }
  54. break
  55. }
  56. case 'loginbg': {
  57. if (site.config.assets.loginBg) {
  58. res.sendFile(path.join(siteAssetsPath, `loginbg-${site.id}.jpg`))
  59. } else {
  60. res.sendFile(path.join(WIKI.ROOTPATH, 'assets/_assets/bg/login.jpg'))
  61. }
  62. break
  63. }
  64. default: {
  65. return res.status(404).send('Invalid Site Resource')
  66. }
  67. }
  68. })
  69. /**
  70. * New v3 vue app
  71. */
  72. router.get([
  73. '/_admin',
  74. '/_admin/*',
  75. '/_profile',
  76. '/_profile/*',
  77. '/_error',
  78. '/_error/*',
  79. '/_welcome'
  80. ], (req, res, next) => {
  81. res.sendFile(path.join(WIKI.ROOTPATH, 'assets/index.html'))
  82. })
  83. // router.get(['/_admin', '/_admin/*'], (req, res, next) => {
  84. // if (!WIKI.auth.checkAccess(req.user, [
  85. // 'manage:system',
  86. // 'write:users',
  87. // 'manage:users',
  88. // 'write:groups',
  89. // 'manage:groups',
  90. // 'manage:navigation',
  91. // 'manage:theme',
  92. // 'manage:api'
  93. // ])) {
  94. // _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  95. // return res.status(403).render('unauthorized', { action: 'view' })
  96. // }
  97. // _.set(res.locals, 'pageMeta.title', 'Admin')
  98. // res.render('admin')
  99. // })
  100. /**
  101. * Download Page / Version
  102. */
  103. router.get(['/d', '/d/*'], async (req, res, next) => {
  104. const pageArgs = pageHelper.parsePath(req.path, { stripExt: true })
  105. const versionId = (req.query.v) ? _.toSafeInteger(req.query.v) : 0
  106. const page = await WIKI.db.pages.getPageFromDb({
  107. path: pageArgs.path,
  108. locale: pageArgs.locale,
  109. userId: req.user.id,
  110. isPrivate: false
  111. })
  112. pageArgs.tags = _.get(page, 'tags', [])
  113. if (versionId > 0) {
  114. if (!WIKI.auth.checkAccess(req.user, ['read:history'], pageArgs)) {
  115. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  116. return res.render('unauthorized', { action: 'downloadVersion' })
  117. }
  118. } else {
  119. if (!WIKI.auth.checkAccess(req.user, ['read:source'], pageArgs)) {
  120. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  121. return res.render('unauthorized', { action: 'download' })
  122. }
  123. }
  124. if (page) {
  125. const fileName = _.last(page.path.split('/')) + '.' + pageHelper.getFileExtension(page.contentType)
  126. res.attachment(fileName)
  127. if (versionId > 0) {
  128. const pageVersion = await WIKI.db.pageHistory.getVersion({ pageId: page.id, versionId })
  129. res.send(pageHelper.injectPageMetadata(pageVersion))
  130. } else {
  131. res.send(pageHelper.injectPageMetadata(page))
  132. }
  133. } else {
  134. res.status(404).end()
  135. }
  136. })
  137. /**
  138. * Create/Edit document
  139. */
  140. router.get(['/_edit', '/_edit/*'], async (req, res, next) => {
  141. const pageArgs = pageHelper.parsePath(req.path, { stripExt: true })
  142. const site = await WIKI.db.sites.getSiteByHostname({ hostname: req.hostname })
  143. if (!site) {
  144. throw new Error('INVALID_SITE')
  145. }
  146. if (pageArgs.path === '') {
  147. return res.redirect(`/_edit/home`)
  148. }
  149. // if (WIKI.config.lang.namespacing && !pageArgs.explicitLocale) {
  150. // return res.redirect(`/_edit/${pageArgs.locale}/${pageArgs.path}`)
  151. // }
  152. // req.i18n.changeLanguage(pageArgs.locale)
  153. // -> Set Editor Lang
  154. _.set(res, 'locals.siteConfig.lang', pageArgs.locale)
  155. // _.set(res, 'locals.siteConfig.rtl', req.i18n.dir() === 'rtl')
  156. // -> Check for reserved path
  157. if (pageHelper.isReservedPath(pageArgs.path)) {
  158. return next(new Error('Cannot create this page because it starts with a system reserved path.'))
  159. }
  160. // -> Get page data from DB
  161. let page = await WIKI.db.pages.getPageFromDb({
  162. siteId: site.id,
  163. path: pageArgs.path,
  164. locale: pageArgs.locale,
  165. userId: req.user.id
  166. })
  167. pageArgs.tags = _.get(page, 'tags', [])
  168. // -> Effective Permissions
  169. const effectivePermissions = WIKI.auth.getEffectivePermissions(req, pageArgs)
  170. const injectCode = {
  171. css: '', // WIKI.config.theming.injectCSS,
  172. head: '', // WIKI.config.theming.injectHead,
  173. body: '' // WIKI.config.theming.injectBody
  174. }
  175. if (page) {
  176. // -> EDIT MODE
  177. if (!(effectivePermissions.pages.write || effectivePermissions.pages.manage)) {
  178. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  179. return res.render('unauthorized', { action: 'edit' })
  180. }
  181. // -> Get page tags
  182. await page.$relatedQuery('tags')
  183. page.tags = _.map(page.tags, 'tag')
  184. // Handle missing extra field
  185. page.extra = page.extra || { css: '', js: '' }
  186. // -> Beautify Script CSS
  187. if (!_.isEmpty(page.extra.css)) {
  188. page.extra.css = new CleanCSS({ format: 'beautify' }).minify(page.extra.css).styles
  189. }
  190. _.set(res.locals, 'pageMeta.title', `Edit ${page.title}`)
  191. _.set(res.locals, 'pageMeta.description', page.description)
  192. page.mode = 'update'
  193. page.isPublished = (page.isPublished === true || page.isPublished === 1) ? 'true' : 'false'
  194. page.content = Buffer.from(page.content).toString('base64')
  195. } else {
  196. // -> CREATE MODE
  197. if (!effectivePermissions.pages.write) {
  198. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  199. return res.render('unauthorized', { action: 'create' })
  200. }
  201. _.set(res.locals, 'pageMeta.title', `New Page`)
  202. page = {
  203. path: pageArgs.path,
  204. localeCode: pageArgs.locale,
  205. editorKey: null,
  206. mode: 'create',
  207. content: null,
  208. title: null,
  209. description: null,
  210. updatedAt: new Date().toISOString(),
  211. extra: {
  212. css: '',
  213. js: ''
  214. }
  215. }
  216. }
  217. res.render('editor', { page, injectCode, effectivePermissions })
  218. })
  219. /**
  220. * History
  221. */
  222. router.get(['/h', '/h/*'], async (req, res, next) => {
  223. const pageArgs = pageHelper.parsePath(req.path, { stripExt: true })
  224. if (WIKI.config.lang.namespacing && !pageArgs.explicitLocale) {
  225. return res.redirect(`/h/${pageArgs.locale}/${pageArgs.path}`)
  226. }
  227. req.i18n.changeLanguage(pageArgs.locale)
  228. _.set(res, 'locals.siteConfig.lang', pageArgs.locale)
  229. _.set(res, 'locals.siteConfig.rtl', req.i18n.dir() === 'rtl')
  230. const page = await WIKI.db.pages.getPageFromDb({
  231. path: pageArgs.path,
  232. locale: pageArgs.locale,
  233. userId: req.user.id,
  234. isPrivate: false
  235. })
  236. if (!page) {
  237. _.set(res.locals, 'pageMeta.title', 'Page Not Found')
  238. return res.status(404).render('notfound', { action: 'history' })
  239. }
  240. pageArgs.tags = _.get(page, 'tags', [])
  241. const effectivePermissions = WIKI.auth.getEffectivePermissions(req, pageArgs)
  242. if (!effectivePermissions.history.read) {
  243. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  244. return res.render('unauthorized', { action: 'history' })
  245. }
  246. if (page) {
  247. _.set(res.locals, 'pageMeta.title', page.title)
  248. _.set(res.locals, 'pageMeta.description', page.description)
  249. res.render('history', { page, effectivePermissions })
  250. } else {
  251. res.redirect(`/${pageArgs.path}`)
  252. }
  253. })
  254. /**
  255. * Page ID redirection
  256. */
  257. router.get(['/i', '/i/:id'], async (req, res, next) => {
  258. const pageId = _.toSafeInteger(req.params.id)
  259. if (pageId <= 0) {
  260. return res.redirect('/')
  261. }
  262. const page = await WIKI.db.pages.query().column(['path', 'localeCode', 'isPrivate', 'privateNS']).findById(pageId)
  263. if (!page) {
  264. _.set(res.locals, 'pageMeta.title', 'Page Not Found')
  265. return res.status(404).render('notfound', { action: 'view' })
  266. }
  267. if (!WIKI.auth.checkAccess(req.user, ['read:pages'], {
  268. locale: page.localeCode,
  269. path: page.path,
  270. private: page.isPrivate,
  271. privateNS: page.privateNS,
  272. explicitLocale: false,
  273. tags: page.tags
  274. })) {
  275. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  276. return res.render('unauthorized', { action: 'view' })
  277. }
  278. if (WIKI.config.lang.namespacing) {
  279. return res.redirect(`/${page.localeCode}/${page.path}`)
  280. } else {
  281. return res.redirect(`/${page.path}`)
  282. }
  283. })
  284. /**
  285. * Source
  286. */
  287. router.get(['/s', '/s/*'], async (req, res, next) => {
  288. const pageArgs = pageHelper.parsePath(req.path, { stripExt: true })
  289. const versionId = (req.query.v) ? _.toSafeInteger(req.query.v) : 0
  290. const page = await WIKI.db.pages.getPageFromDb({
  291. path: pageArgs.path,
  292. locale: pageArgs.locale,
  293. userId: req.user.id,
  294. isPrivate: false
  295. })
  296. pageArgs.tags = _.get(page, 'tags', [])
  297. if (WIKI.config.lang.namespacing && !pageArgs.explicitLocale) {
  298. return res.redirect(`/s/${pageArgs.locale}/${pageArgs.path}`)
  299. }
  300. // -> Effective Permissions
  301. const effectivePermissions = WIKI.auth.getEffectivePermissions(req, pageArgs)
  302. _.set(res, 'locals.siteConfig.lang', pageArgs.locale)
  303. _.set(res, 'locals.siteConfig.rtl', req.i18n.dir() === 'rtl')
  304. if (versionId > 0) {
  305. if (!effectivePermissions.history.read) {
  306. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  307. return res.render('unauthorized', { action: 'sourceVersion' })
  308. }
  309. } else {
  310. if (!effectivePermissions.source.read) {
  311. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  312. return res.render('unauthorized', { action: 'source' })
  313. }
  314. }
  315. if (page) {
  316. if (versionId > 0) {
  317. const pageVersion = await WIKI.db.pageHistory.getVersion({ pageId: page.id, versionId })
  318. _.set(res.locals, 'pageMeta.title', pageVersion.title)
  319. _.set(res.locals, 'pageMeta.description', pageVersion.description)
  320. res.render('source', {
  321. page: {
  322. ...page,
  323. ...pageVersion
  324. },
  325. effectivePermissions
  326. })
  327. } else {
  328. _.set(res.locals, 'pageMeta.title', page.title)
  329. _.set(res.locals, 'pageMeta.description', page.description)
  330. res.render('source', { page, effectivePermissions })
  331. }
  332. } else {
  333. res.redirect(`/${pageArgs.path}`)
  334. }
  335. })
  336. /**
  337. * Tags
  338. */
  339. router.get(['/t', '/t/*'], (req, res, next) => {
  340. _.set(res.locals, 'pageMeta.title', 'Tags')
  341. res.render('tags')
  342. })
  343. /**
  344. * User Avatar
  345. */
  346. router.get('/_user/:uid/avatar', async (req, res, next) => {
  347. if (!WIKI.auth.checkAccess(req.user, ['read:pages'])) {
  348. return res.sendStatus(403)
  349. }
  350. const av = await WIKI.db.users.getUserAvatarData(req.params.uid)
  351. if (av) {
  352. res.set('Content-Type', 'image/jpeg')
  353. return res.send(av)
  354. }
  355. return res.sendStatus(404)
  356. })
  357. /**
  358. * View document / asset
  359. */
  360. router.get('/*', async (req, res, next) => {
  361. const stripExt = _.some(WIKI.data.pageExtensions, ext => _.endsWith(req.path, `.${ext}`))
  362. const pageArgs = pageHelper.parsePath(req.path, { stripExt })
  363. const isPage = (stripExt || pageArgs.path.indexOf('.') === -1)
  364. const site = await WIKI.db.sites.getSiteByHostname({ hostname: req.hostname })
  365. if (!site) {
  366. throw new Error('INVALID_SITE')
  367. }
  368. if (isPage) {
  369. // if (WIKI.config.lang.namespacing && !pageArgs.explicitLocale) {
  370. // return res.redirect(`/${pageArgs.locale}/${pageArgs.path}`)
  371. // }
  372. // req.i18n.changeLanguage(pageArgs.locale)
  373. try {
  374. // -> Get Page from cache
  375. const page = await WIKI.db.pages.getPage({
  376. siteId: site.id,
  377. path: pageArgs.path,
  378. locale: pageArgs.locale,
  379. userId: req.user.id
  380. })
  381. pageArgs.tags = _.get(page, 'tags', [])
  382. // -> Effective Permissions
  383. const effectivePermissions = WIKI.auth.getEffectivePermissions(req, pageArgs)
  384. // -> Check User Access
  385. if (!effectivePermissions.pages.read) {
  386. if (req.user.id === WIKI.auth.guest.id) {
  387. res.cookie('loginRedirect', req.path, {
  388. maxAge: 15 * 60 * 1000
  389. })
  390. }
  391. if (pageArgs.path === 'home' && req.user.id === WIKI.auth.guest.id) {
  392. return res.redirect('/login')
  393. }
  394. return res.redirect(`/_error/unauthorized?from=${req.path}`)
  395. }
  396. _.set(res, 'locals.siteConfig.lang', pageArgs.locale)
  397. // _.set(res, 'locals.siteConfig.rtl', req.i18n.dir() === 'rtl')
  398. if (page) {
  399. _.set(res.locals, 'pageMeta.title', page.title)
  400. _.set(res.locals, 'pageMeta.description', page.description)
  401. // -> Check Publishing State
  402. let pageIsPublished = page.isPublished
  403. if (pageIsPublished && !_.isEmpty(page.publishStartDate)) {
  404. pageIsPublished = moment(page.publishStartDate).isSameOrBefore()
  405. }
  406. if (pageIsPublished && !_.isEmpty(page.publishEndDate)) {
  407. pageIsPublished = moment(page.publishEndDate).isSameOrAfter()
  408. }
  409. if (!pageIsPublished && !effectivePermissions.pages.write) {
  410. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  411. return res.status(403).render('unauthorized', {
  412. action: 'view'
  413. })
  414. }
  415. // -> Render view
  416. res.sendFile(path.join(WIKI.ROOTPATH, 'assets/index.html'))
  417. } else if (pageArgs.path === 'home') {
  418. res.redirect('/_welcome')
  419. } else {
  420. _.set(res.locals, 'pageMeta.title', 'Page Not Found')
  421. if (effectivePermissions.pages.write) {
  422. res.status(404).render('new', { path: pageArgs.path, locale: pageArgs.locale })
  423. } else {
  424. res.status(404).render('notfound', { action: 'view' })
  425. }
  426. }
  427. } catch (err) {
  428. next(err)
  429. }
  430. } else {
  431. if (!WIKI.auth.checkAccess(req.user, ['read:assets'], pageArgs)) {
  432. return res.sendStatus(403)
  433. }
  434. await WIKI.db.assets.getAsset(pageArgs.path, res)
  435. }
  436. })
  437. module.exports = router