3.0.0.js 25 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713
  1. const { v4: uuid } = require('uuid')
  2. const bcrypt = require('bcryptjs-then')
  3. const crypto = require('crypto')
  4. const { DateTime } = require('luxon')
  5. const pem2jwk = require('pem-jwk').pem2jwk
  6. exports.up = async knex => {
  7. WIKI.logger.info('Running 3.0.0 database migration...')
  8. // =====================================
  9. // PG EXTENSIONS
  10. // =====================================
  11. await knex.raw('CREATE EXTENSION IF NOT EXISTS pgcrypto;')
  12. await knex.schema
  13. // =====================================
  14. // MODEL TABLES
  15. // =====================================
  16. // ACTIVITY LOGS -----------------------
  17. .createTable('activityLogs', table => {
  18. table.uuid('id').notNullable().primary().defaultTo(knex.raw('gen_random_uuid()'))
  19. table.timestamp('ts').notNullable().defaultTo(knex.fn.now())
  20. table.string('action').notNullable()
  21. table.jsonb('meta').notNullable()
  22. })
  23. // ANALYTICS ---------------------------
  24. .createTable('analytics', table => {
  25. table.uuid('id').notNullable().primary().defaultTo(knex.raw('gen_random_uuid()'))
  26. table.string('module').notNullable()
  27. table.boolean('isEnabled').notNullable().defaultTo(false)
  28. table.jsonb('config').notNullable()
  29. })
  30. // API KEYS ----------------------------
  31. .createTable('apiKeys', table => {
  32. table.uuid('id').notNullable().primary().defaultTo(knex.raw('gen_random_uuid()'))
  33. table.string('name').notNullable()
  34. table.text('key').notNullable()
  35. table.timestamp('expiration').notNullable().defaultTo(knex.fn.now())
  36. table.boolean('isRevoked').notNullable().defaultTo(false)
  37. table.timestamp('createdAt').notNullable().defaultTo(knex.fn.now())
  38. table.timestamp('updatedAt').notNullable().defaultTo(knex.fn.now())
  39. })
  40. // ASSETS ------------------------------
  41. .createTable('assets', table => {
  42. table.uuid('id').notNullable().primary().defaultTo(knex.raw('gen_random_uuid()'))
  43. table.string('filename').notNullable()
  44. table.string('hash').notNullable().index()
  45. table.string('ext').notNullable()
  46. table.enum('kind', ['binary', 'image']).notNullable().defaultTo('binary')
  47. table.string('mime').notNullable().defaultTo('application/octet-stream')
  48. table.integer('fileSize').unsigned().comment('In kilobytes')
  49. table.jsonb('metadata')
  50. table.timestamp('createdAt').notNullable().defaultTo(knex.fn.now())
  51. table.timestamp('updatedAt').notNullable().defaultTo(knex.fn.now())
  52. })
  53. // ASSET DATA --------------------------
  54. .createTable('assetData', table => {
  55. table.uuid('id').notNullable().primary()
  56. table.binary('data').notNullable()
  57. })
  58. // ASSET FOLDERS -----------------------
  59. .createTable('assetFolders', table => {
  60. table.uuid('id').notNullable().primary().defaultTo(knex.raw('gen_random_uuid()'))
  61. table.string('name').notNullable()
  62. table.string('slug').notNullable()
  63. })
  64. // AUTHENTICATION ----------------------
  65. .createTable('authentication', table => {
  66. table.uuid('id').notNullable().primary().defaultTo(knex.raw('gen_random_uuid()'))
  67. table.string('module').notNullable()
  68. table.boolean('isEnabled').notNullable().defaultTo(false)
  69. table.string('displayName').notNullable().defaultTo('')
  70. table.jsonb('config').notNullable().defaultTo('{}')
  71. table.boolean('selfRegistration').notNullable().defaultTo(false)
  72. table.jsonb('domainWhitelist').notNullable().defaultTo('[]')
  73. table.jsonb('autoEnrollGroups').notNullable().defaultTo('[]')
  74. })
  75. .createTable('commentProviders', table => {
  76. table.uuid('id').notNullable().primary().defaultTo(knex.raw('gen_random_uuid()'))
  77. table.string('module').notNullable()
  78. table.boolean('isEnabled').notNullable().defaultTo(false)
  79. table.json('config').notNullable()
  80. })
  81. // COMMENTS ----------------------------
  82. .createTable('comments', table => {
  83. table.uuid('id').notNullable().primary().defaultTo(knex.raw('gen_random_uuid()'))
  84. table.uuid('replyTo')
  85. table.text('content').notNullable()
  86. table.text('render').notNullable().defaultTo('')
  87. table.string('name').notNullable().defaultTo('')
  88. table.string('email').notNullable().defaultTo('')
  89. table.string('ip').notNullable().defaultTo('')
  90. table.timestamp('createdAt').notNullable().defaultTo(knex.fn.now())
  91. table.timestamp('updatedAt').notNullable().defaultTo(knex.fn.now())
  92. })
  93. // GROUPS ------------------------------
  94. .createTable('groups', table => {
  95. table.uuid('id').notNullable().primary().defaultTo(knex.raw('gen_random_uuid()'))
  96. table.string('name').notNullable()
  97. table.jsonb('permissions').notNullable()
  98. table.jsonb('rules').notNullable()
  99. table.string('redirectOnLogin').notNullable().defaultTo('')
  100. table.string('redirectOnFirstLogin').notNullable().defaultTo('')
  101. table.string('redirectOnLogout').notNullable().defaultTo('')
  102. table.boolean('isSystem').notNullable().defaultTo(false)
  103. table.timestamp('createdAt').notNullable().defaultTo(knex.fn.now())
  104. table.timestamp('updatedAt').notNullable().defaultTo(knex.fn.now())
  105. })
  106. // HOOKS -------------------------------
  107. .createTable('hooks', table => {
  108. table.uuid('id').notNullable().primary().defaultTo(knex.raw('gen_random_uuid()'))
  109. table.string('name').notNullable()
  110. table.jsonb('events').notNullable().defaultTo('[]')
  111. table.string('url').notNullable()
  112. table.boolean('includeMetadata').notNullable().defaultTo(false)
  113. table.boolean('includeContent').notNullable().defaultTo(false)
  114. table.boolean('acceptUntrusted').notNullable().defaultTo(false)
  115. table.string('authHeader')
  116. table.enum('state', ['pending', 'error', 'success']).notNullable().defaultTo('pending')
  117. table.string('lastErrorMessage')
  118. table.timestamp('createdAt').notNullable().defaultTo(knex.fn.now())
  119. table.timestamp('updatedAt').notNullable().defaultTo(knex.fn.now())
  120. })
  121. // JOB HISTORY -------------------------
  122. .createTable('jobHistory', table => {
  123. table.uuid('id').notNullable().primary()
  124. table.string('task').notNullable()
  125. table.enum('state', ['active', 'completed', 'failed', 'interrupted']).notNullable()
  126. table.boolean('useWorker').notNullable().defaultTo(false)
  127. table.boolean('wasScheduled').notNullable().defaultTo(false)
  128. table.jsonb('payload')
  129. table.integer('attempt').notNullable().defaultTo(1)
  130. table.integer('maxRetries').notNullable().defaultTo(0)
  131. table.text('lastErrorMessage')
  132. table.string('executedBy')
  133. table.timestamp('createdAt').notNullable()
  134. table.timestamp('startedAt').notNullable().defaultTo(knex.fn.now())
  135. table.timestamp('completedAt')
  136. })
  137. // JOB SCHEDULE ------------------------
  138. .createTable('jobSchedule', table => {
  139. table.uuid('id').notNullable().primary().defaultTo(knex.raw('gen_random_uuid()'))
  140. table.string('task').notNullable()
  141. table.string('cron').notNullable()
  142. table.string('type').notNullable().defaultTo('system')
  143. table.jsonb('payload')
  144. table.timestamp('createdAt').notNullable().defaultTo(knex.fn.now())
  145. table.timestamp('updatedAt').notNullable().defaultTo(knex.fn.now())
  146. })
  147. // JOB SCHEDULE ------------------------
  148. .createTable('jobLock', table => {
  149. table.string('key').notNullable().primary()
  150. table.string('lastCheckedBy')
  151. table.timestamp('lastCheckedAt').notNullable().defaultTo(knex.fn.now())
  152. })
  153. // JOBS --------------------------------
  154. .createTable('jobs', table => {
  155. table.uuid('id').notNullable().primary().defaultTo(knex.raw('gen_random_uuid()'))
  156. table.string('task').notNullable()
  157. table.boolean('useWorker').notNullable().defaultTo(false)
  158. table.jsonb('payload')
  159. table.integer('retries').notNullable().defaultTo(0)
  160. table.integer('maxRetries').notNullable().defaultTo(0)
  161. table.timestamp('waitUntil')
  162. table.boolean('isScheduled').notNullable().defaultTo(false)
  163. table.string('createdBy')
  164. table.timestamp('createdAt').notNullable().defaultTo(knex.fn.now())
  165. table.timestamp('updatedAt').notNullable().defaultTo(knex.fn.now())
  166. })
  167. // LOCALES -----------------------------
  168. .createTable('locales', table => {
  169. table.string('code', 5).notNullable().primary()
  170. table.jsonb('strings')
  171. table.boolean('isRTL').notNullable().defaultTo(false)
  172. table.string('name').notNullable()
  173. table.string('nativeName').notNullable()
  174. table.integer('availability').notNullable().defaultTo(0)
  175. table.timestamp('createdAt').notNullable().defaultTo(knex.fn.now())
  176. table.timestamp('updatedAt').notNullable().defaultTo(knex.fn.now())
  177. })
  178. // NAVIGATION ----------------------------
  179. .createTable('navigation', table => {
  180. table.string('key').notNullable().primary()
  181. table.jsonb('config')
  182. })
  183. // PAGE HISTORY ------------------------
  184. .createTable('pageHistory', table => {
  185. table.uuid('id').notNullable().primary().defaultTo(knex.raw('gen_random_uuid()'))
  186. table.uuid('pageId').notNullable().index()
  187. table.string('path').notNullable()
  188. table.string('hash').notNullable()
  189. table.string('title').notNullable()
  190. table.string('description')
  191. table.enu('publishState', ['draft', 'published', 'scheduled']).notNullable().defaultTo('draft')
  192. table.timestamp('publishStartDate')
  193. table.timestamp('publishEndDate')
  194. table.string('action').defaultTo('updated')
  195. table.text('content')
  196. table.string('editor').notNullable()
  197. table.string('contentType').notNullable()
  198. table.jsonb('extra').notNullable().defaultTo('{}')
  199. table.jsonb('tags').defaultTo('[]')
  200. table.timestamp('versionDate').notNullable().defaultTo(knex.fn.now())
  201. table.timestamp('createdAt').notNullable().defaultTo(knex.fn.now())
  202. })
  203. // PAGE LINKS --------------------------
  204. .createTable('pageLinks', table => {
  205. table.increments('id').primary()
  206. table.string('path').notNullable()
  207. table.string('localeCode', 5).notNullable()
  208. })
  209. // PAGES -------------------------------
  210. .createTable('pages', table => {
  211. table.uuid('id').notNullable().primary().defaultTo(knex.raw('gen_random_uuid()'))
  212. table.string('slug')
  213. table.string('path').notNullable()
  214. table.string('hash').notNullable()
  215. table.string('title').notNullable()
  216. table.string('description')
  217. table.enu('publishState', ['draft', 'published', 'scheduled']).notNullable().defaultTo('draft')
  218. table.timestamp('publishStartDate')
  219. table.timestamp('publishEndDate')
  220. table.text('content')
  221. table.text('render')
  222. table.jsonb('toc')
  223. table.string('editor').notNullable()
  224. table.string('contentType').notNullable()
  225. table.jsonb('extra').notNullable().defaultTo('{}')
  226. table.timestamp('createdAt').notNullable().defaultTo(knex.fn.now())
  227. table.timestamp('updatedAt').notNullable().defaultTo(knex.fn.now())
  228. })
  229. // PAGE TREE ---------------------------
  230. .createTable('pageTree', table => {
  231. table.integer('id').unsigned().primary()
  232. table.string('path').notNullable()
  233. table.integer('depth').unsigned().notNullable()
  234. table.string('title').notNullable()
  235. table.boolean('isFolder').notNullable().defaultTo(false)
  236. table.jsonb('ancestors')
  237. })
  238. // RENDERERS ---------------------------
  239. .createTable('renderers', table => {
  240. table.uuid('id').notNullable().primary().defaultTo(knex.raw('gen_random_uuid()'))
  241. table.string('module').notNullable()
  242. table.boolean('isEnabled').notNullable().defaultTo(false)
  243. table.jsonb('config')
  244. })
  245. // SETTINGS ----------------------------
  246. .createTable('settings', table => {
  247. table.string('key').notNullable().primary()
  248. table.jsonb('value')
  249. })
  250. // SITES -------------------------------
  251. .createTable('sites', table => {
  252. table.uuid('id').notNullable().primary().defaultTo(knex.raw('gen_random_uuid()'))
  253. table.string('hostname').notNullable()
  254. table.boolean('isEnabled').notNullable().defaultTo(false)
  255. table.jsonb('config').notNullable()
  256. table.timestamp('createdAt').notNullable().defaultTo(knex.fn.now())
  257. })
  258. // STORAGE -----------------------------
  259. .createTable('storage', table => {
  260. table.uuid('id').notNullable().primary().defaultTo(knex.raw('gen_random_uuid()'))
  261. table.string('module').notNullable()
  262. table.boolean('isEnabled').notNullable().defaultTo(false)
  263. table.jsonb('contentTypes')
  264. table.jsonb('assetDelivery')
  265. table.jsonb('versioning')
  266. table.jsonb('schedule')
  267. table.jsonb('config')
  268. table.jsonb('state')
  269. })
  270. // TAGS --------------------------------
  271. .createTable('tags', table => {
  272. table.uuid('id').notNullable().primary().defaultTo(knex.raw('gen_random_uuid()'))
  273. table.string('tag').notNullable()
  274. table.jsonb('display').notNullable().defaultTo('{}')
  275. table.timestamp('createdAt').notNullable().defaultTo(knex.fn.now())
  276. table.timestamp('updatedAt').notNullable().defaultTo(knex.fn.now())
  277. })
  278. // USER AVATARS ------------------------
  279. .createTable('userAvatars', table => {
  280. table.uuid('id').notNullable().primary()
  281. table.binary('data').notNullable()
  282. })
  283. // USER KEYS ---------------------------
  284. .createTable('userKeys', table => {
  285. table.uuid('id').notNullable().primary().defaultTo(knex.raw('gen_random_uuid()'))
  286. table.string('kind').notNullable()
  287. table.string('token').notNullable()
  288. table.jsonb('meta').notNullable().defaultTo('{}')
  289. table.timestamp('validUntil').notNullable()
  290. table.timestamp('createdAt').notNullable().defaultTo(knex.fn.now())
  291. })
  292. // USERS -------------------------------
  293. .createTable('users', table => {
  294. table.uuid('id').notNullable().primary().defaultTo(knex.raw('gen_random_uuid()'))
  295. table.string('email').notNullable()
  296. table.string('name').notNullable()
  297. table.jsonb('auth').notNullable().defaultTo('{}')
  298. table.jsonb('meta').notNullable().defaultTo('{}')
  299. table.jsonb('prefs').notNullable().defaultTo('{}')
  300. table.string('pictureUrl')
  301. table.boolean('isSystem').notNullable().defaultTo(false)
  302. table.boolean('isActive').notNullable().defaultTo(false)
  303. table.boolean('isVerified').notNullable().defaultTo(false)
  304. table.timestamp('lastLoginAt').index()
  305. table.timestamp('createdAt').notNullable().defaultTo(knex.fn.now())
  306. table.timestamp('updatedAt').notNullable().defaultTo(knex.fn.now())
  307. })
  308. // =====================================
  309. // RELATION TABLES
  310. // =====================================
  311. // PAGE TAGS ---------------------------
  312. .createTable('pageTags', table => {
  313. table.increments('id').primary()
  314. table.uuid('pageId').references('id').inTable('pages').onDelete('CASCADE')
  315. table.uuid('tagId').references('id').inTable('tags').onDelete('CASCADE')
  316. })
  317. // USER GROUPS -------------------------
  318. .createTable('userGroups', table => {
  319. table.increments('id').primary()
  320. table.uuid('userId').references('id').inTable('users').onDelete('CASCADE')
  321. table.uuid('groupId').references('id').inTable('groups').onDelete('CASCADE')
  322. })
  323. // =====================================
  324. // REFERENCES
  325. // =====================================
  326. .table('activityLogs', table => {
  327. table.uuid('userId').notNullable().references('id').inTable('users')
  328. })
  329. .table('analytics', table => {
  330. table.uuid('siteId').notNullable().references('id').inTable('sites')
  331. })
  332. .table('assets', table => {
  333. table.uuid('folderId').notNullable().references('id').inTable('assetFolders').index()
  334. table.uuid('authorId').notNullable().references('id').inTable('users')
  335. table.uuid('siteId').notNullable().references('id').inTable('sites').index()
  336. })
  337. .table('assetFolders', table => {
  338. table.uuid('parentId').references('id').inTable('assetFolders').index()
  339. })
  340. .table('commentProviders', table => {
  341. table.uuid('siteId').notNullable().references('id').inTable('sites')
  342. })
  343. .table('comments', table => {
  344. table.uuid('pageId').notNullable().references('id').inTable('pages').index()
  345. table.uuid('authorId').notNullable().references('id').inTable('users').index()
  346. })
  347. .table('navigation', table => {
  348. table.uuid('siteId').notNullable().references('id').inTable('sites').index()
  349. })
  350. .table('pageHistory', table => {
  351. table.string('localeCode', 5).references('code').inTable('locales')
  352. table.uuid('authorId').notNullable().references('id').inTable('users')
  353. table.uuid('siteId').notNullable().references('id').inTable('sites').index()
  354. })
  355. .table('pageLinks', table => {
  356. table.uuid('pageId').notNullable().references('id').inTable('pages').onDelete('CASCADE')
  357. table.index(['path', 'localeCode'])
  358. })
  359. .table('pages', table => {
  360. table.string('localeCode', 5).references('code').inTable('locales').index()
  361. table.uuid('authorId').notNullable().references('id').inTable('users').index()
  362. table.uuid('creatorId').notNullable().references('id').inTable('users').index()
  363. table.uuid('siteId').notNullable().references('id').inTable('sites').index()
  364. })
  365. .table('pageTree', table => {
  366. table.integer('parent').unsigned().references('id').inTable('pageTree').onDelete('CASCADE')
  367. table.uuid('pageId').notNullable().references('id').inTable('pages').onDelete('CASCADE')
  368. table.string('localeCode', 5).references('code').inTable('locales')
  369. })
  370. .table('renderers', table => {
  371. table.uuid('siteId').notNullable().references('id').inTable('sites')
  372. })
  373. .table('storage', table => {
  374. table.uuid('siteId').notNullable().references('id').inTable('sites')
  375. })
  376. .table('tags', table => {
  377. table.uuid('siteId').notNullable().references('id').inTable('sites')
  378. table.unique(['siteId', 'tag'])
  379. })
  380. .table('userKeys', table => {
  381. table.uuid('userId').notNullable().references('id').inTable('users')
  382. })
  383. .table('users', table => {
  384. table.string('localeCode', 5).references('code').inTable('locales').notNullable().defaultTo('en')
  385. })
  386. // =====================================
  387. // DEFAULT DATA
  388. // =====================================
  389. // -> GENERATE IDS
  390. const groupAdminId = uuid()
  391. const groupGuestId = '10000000-0000-4000-8000-000000000001'
  392. const siteId = uuid()
  393. const authModuleId = uuid()
  394. const userAdminId = uuid()
  395. const userGuestId = uuid()
  396. // -> SYSTEM CONFIG
  397. WIKI.logger.info('Generating certificates...')
  398. const secret = crypto.randomBytes(32).toString('hex')
  399. const certs = crypto.generateKeyPairSync('rsa', {
  400. modulusLength: 2048,
  401. publicKeyEncoding: {
  402. type: 'pkcs1',
  403. format: 'pem'
  404. },
  405. privateKeyEncoding: {
  406. type: 'pkcs1',
  407. format: 'pem',
  408. cipher: 'aes-256-cbc',
  409. passphrase: secret
  410. }
  411. })
  412. await knex('settings').insert([
  413. {
  414. key: 'auth',
  415. value: {
  416. audience: 'urn:wiki.js',
  417. tokenExpiration: '30m',
  418. tokenRenewal: '14d',
  419. certs: {
  420. jwk: pem2jwk(certs.publicKey),
  421. public: certs.publicKey,
  422. private: certs.privateKey
  423. },
  424. secret,
  425. rootAdminUserId: userAdminId,
  426. guestUserId: userGuestId
  427. }
  428. },
  429. {
  430. key: 'mail',
  431. value: {
  432. senderName: '',
  433. senderEmail: '',
  434. host: '',
  435. port: 465,
  436. name: '',
  437. secure: true,
  438. verifySSL: true,
  439. user: '',
  440. pass: '',
  441. useDKIM: false,
  442. dkimDomainName: '',
  443. dkimKeySelector: '',
  444. dkimPrivateKey: ''
  445. }
  446. },
  447. {
  448. key: 'security',
  449. value: {
  450. corsConfig: '',
  451. corsMode: 'OFF',
  452. cspDirectives: '',
  453. disallowFloc: true,
  454. disallowIframe: true,
  455. disallowOpenRedirect: true,
  456. enforceCsp: false,
  457. enforceHsts: false,
  458. enforceSameOriginReferrerPolicy: true,
  459. forceAssetDownload: true,
  460. hstsDuration: 0,
  461. trustProxy: false,
  462. authJwtAudience: 'urn:wiki.js',
  463. authJwtExpiration: '30m',
  464. authJwtRenewablePeriod: '14d',
  465. uploadMaxFileSize: 10485760,
  466. uploadMaxFiles: 20,
  467. uploadScanSVG: true
  468. }
  469. },
  470. {
  471. key: 'update',
  472. value: {
  473. locales: true
  474. }
  475. }
  476. ])
  477. // -> DEFAULT LOCALE
  478. await knex('locales').insert({
  479. code: 'en',
  480. strings: {},
  481. isRTL: false,
  482. name: 'English',
  483. nativeName: 'English'
  484. })
  485. // -> DEFAULT SITE
  486. await knex('sites').insert({
  487. id: siteId,
  488. hostname: '*',
  489. isEnabled: true,
  490. config: {
  491. title: 'My Wiki Site',
  492. description: '',
  493. company: '',
  494. contentLicense: '',
  495. footerExtra: '',
  496. pageExtensions: ['md', 'html', 'txt'],
  497. defaults: {
  498. timezone: 'America/New_York',
  499. dateFormat: 'YYYY-MM-DD',
  500. timeFormat: '12h'
  501. },
  502. features: {
  503. ratings: false,
  504. ratingsMode: 'off',
  505. comments: false,
  506. contributions: false,
  507. profile: true,
  508. search: true
  509. },
  510. logoText: true,
  511. sitemap: true,
  512. robots: {
  513. index: true,
  514. follow: true
  515. },
  516. authStrategies: [{ id: authModuleId, order: 0, isVisible: true }],
  517. locale: 'en',
  518. localeNamespacing: false,
  519. localeNamespaces: [],
  520. assets: {
  521. logo: false,
  522. logoExt: 'svg',
  523. favicon: false,
  524. faviconExt: 'svg',
  525. loginBg: false
  526. },
  527. theme: {
  528. dark: false,
  529. colorPrimary: '#1976D2',
  530. colorSecondary: '#02C39A',
  531. colorAccent: '#FF9800',
  532. colorHeader: '#000000',
  533. colorSidebar: '#1976D2',
  534. injectCSS: '',
  535. injectHead: '',
  536. injectBody: '',
  537. contentWidth: 'full',
  538. sidebarPosition: 'left',
  539. tocPosition: 'right',
  540. showSharingMenu: true,
  541. showPrintBtn: true,
  542. baseFont: 'roboto',
  543. contentFont: 'roboto'
  544. }
  545. }
  546. })
  547. // -> DEFAULT GROUPS
  548. await knex('groups').insert([
  549. {
  550. id: groupAdminId,
  551. name: 'Administrators',
  552. permissions: JSON.stringify(['manage:system']),
  553. rules: JSON.stringify([]),
  554. isSystem: true
  555. },
  556. {
  557. id: groupGuestId,
  558. name: 'Guests',
  559. permissions: JSON.stringify(['read:pages', 'read:assets', 'read:comments']),
  560. rules: JSON.stringify([
  561. {
  562. id: uuid(),
  563. name: 'Default Rule',
  564. roles: ['read:pages', 'read:assets', 'read:comments'],
  565. match: 'START',
  566. mode: 'DENY',
  567. path: '',
  568. locales: [],
  569. sites: []
  570. }
  571. ]),
  572. isSystem: true
  573. }
  574. ])
  575. // -> AUTHENTICATION MODULE
  576. await knex('authentication').insert({
  577. id: authModuleId,
  578. module: 'local',
  579. isEnabled: true,
  580. displayName: 'Local Authentication'
  581. })
  582. // -> USERS
  583. await knex('users').insert([
  584. {
  585. id: userAdminId,
  586. email: process.env.ADMIN_EMAIL ?? 'admin@example.com',
  587. auth: {
  588. [authModuleId]: {
  589. password: await bcrypt.hash(process.env.ADMIN_PASS || '12345678', 12),
  590. mustChangePwd: !process.env.ADMIN_PASS,
  591. restrictLogin: false,
  592. tfaRequired: false,
  593. tfaSecret: ''
  594. }
  595. },
  596. name: 'Administrator',
  597. isSystem: false,
  598. isActive: true,
  599. isVerified: true,
  600. meta: {
  601. location: '',
  602. jobTitle: '',
  603. pronouns: ''
  604. },
  605. prefs: {
  606. timezone: 'America/New_York',
  607. dateFormat: 'YYYY-MM-DD',
  608. timeFormat: '12h',
  609. appearance: 'site'
  610. },
  611. localeCode: 'en'
  612. },
  613. {
  614. id: userGuestId,
  615. email: 'guest@example.com',
  616. auth: {},
  617. name: 'Guest',
  618. isSystem: true,
  619. isActive: true,
  620. isVerified: true,
  621. meta: {},
  622. prefs: {
  623. timezone: 'America/New_York',
  624. dateFormat: 'YYYY-MM-DD',
  625. timeFormat: '12h',
  626. appearance: 'site'
  627. },
  628. localeCode: 'en'
  629. }
  630. ])
  631. await knex('userGroups').insert([
  632. {
  633. userId: userAdminId,
  634. groupId: groupAdminId
  635. },
  636. {
  637. userId: userGuestId,
  638. groupId: groupGuestId
  639. }
  640. ])
  641. // -> STORAGE MODULE
  642. await knex('storage').insert({
  643. module: 'db',
  644. siteId,
  645. isEnabled: true,
  646. contentTypes: {
  647. activeTypes: ['pages', 'images', 'documents', 'others', 'large'],
  648. largeThreshold: '5MB'
  649. },
  650. assetDelivery: {
  651. streaming: true,
  652. directAccess: false
  653. },
  654. versioning: {
  655. enabled: false
  656. },
  657. state: {
  658. current: 'ok'
  659. }
  660. })
  661. // -> SCHEDULED JOBS
  662. await knex('jobSchedule').insert([
  663. {
  664. task: 'checkVersion',
  665. cron: '0 0 * * *',
  666. type: 'system'
  667. },
  668. {
  669. task: 'cleanJobHistory',
  670. cron: '5 0 * * *',
  671. type: 'system'
  672. },
  673. {
  674. task: 'updateLocales',
  675. cron: '0 0 * * *',
  676. type: 'system'
  677. }
  678. ])
  679. await knex('jobLock').insert({
  680. key: 'cron',
  681. lastCheckedBy: 'init',
  682. lastCheckedAt: DateTime.utc().minus({ hours: 1 }).toISO()
  683. })
  684. WIKI.logger.info('Completed 3.0.0 database migration.')
  685. }
  686. exports.down = knex => { }