2
0

common.js 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556
  1. const express = require('express')
  2. const router = express.Router()
  3. const pageHelper = require('../helpers/page')
  4. const _ = require('lodash')
  5. const CleanCSS = require('clean-css')
  6. const moment = require('moment')
  7. const path = require('path')
  8. const tmplCreateRegex = /^[0-9]+(,[0-9]+)?$/
  9. const siteAssetsPath = path.resolve(WIKI.ROOTPATH, WIKI.config.dataPath, 'assets')
  10. /**
  11. * Robots.txt
  12. */
  13. router.get('/robots.txt', (req, res, next) => {
  14. res.type('text/plain')
  15. if (_.includes(WIKI.config.seo.robots, 'noindex')) {
  16. res.send('User-agent: *\nDisallow: /')
  17. } else {
  18. res.status(200).end()
  19. }
  20. })
  21. /**
  22. * Health Endpoint
  23. */
  24. router.get('/healthz', (req, res, next) => {
  25. if (WIKI.db.knex.client.pool.numFree() < 1 && WIKI.db.knex.client.pool.numUsed() < 1) {
  26. res.status(503).json({ ok: false }).end()
  27. } else {
  28. res.status(200).json({ ok: true }).end()
  29. }
  30. })
  31. /**
  32. * Site Asset
  33. */
  34. router.get('/_site/:siteId?/:resource', async (req, res, next) => {
  35. const site = req.params.siteId ? WIKI.sites[req.params.siteId] : await WIKI.db.sites.getSiteByHostname({ hostname: req.hostname })
  36. if (!site) {
  37. return res.status(404).send('Site Not Found')
  38. }
  39. switch (req.params.resource) {
  40. case 'logo': {
  41. if (site.config.assets.logo) {
  42. res.sendFile(path.join(siteAssetsPath, `logo-${site.id}.${site.config.assets.logoExt}`))
  43. } else {
  44. res.sendFile(path.join(WIKI.ROOTPATH, 'assets/_assets/logo-wikijs.svg'))
  45. }
  46. break
  47. }
  48. case 'favicon': {
  49. if (site.config.assets.favicon) {
  50. res.sendFile(path.join(siteAssetsPath, `favicon-${site.id}.${site.config.assets.faviconExt}`))
  51. } else {
  52. res.sendFile(path.join(WIKI.ROOTPATH, 'assets/_assets/logo-wikijs.svg'))
  53. }
  54. break
  55. }
  56. case 'loginbg': {
  57. if (site.config.assets.loginBg) {
  58. res.sendFile(path.join(siteAssetsPath, `loginbg-${site.id}.jpg`))
  59. } else {
  60. res.sendFile(path.join(WIKI.ROOTPATH, 'assets/_assets/bg/login.jpg'))
  61. }
  62. break
  63. }
  64. default: {
  65. return res.status(404).send('Invalid Site Resource')
  66. }
  67. }
  68. })
  69. /**
  70. * New v3 vue app
  71. */
  72. router.get([
  73. '/_admin',
  74. '/_admin/*',
  75. '/_profile',
  76. '/_profile/*',
  77. '/_error',
  78. '/_error/*',
  79. '/_welcome'
  80. ], (req, res, next) => {
  81. res.sendFile(path.join(WIKI.ROOTPATH, 'assets/index.html'))
  82. })
  83. // router.get(['/_admin', '/_admin/*'], (req, res, next) => {
  84. // if (!WIKI.auth.checkAccess(req.user, [
  85. // 'manage:system',
  86. // 'write:users',
  87. // 'manage:users',
  88. // 'write:groups',
  89. // 'manage:groups',
  90. // 'manage:navigation',
  91. // 'manage:theme',
  92. // 'manage:api'
  93. // ])) {
  94. // _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  95. // return res.status(403).render('unauthorized', { action: 'view' })
  96. // }
  97. // _.set(res.locals, 'pageMeta.title', 'Admin')
  98. // res.render('admin')
  99. // })
  100. /**
  101. * Download Page / Version
  102. */
  103. router.get(['/d', '/d/*'], async (req, res, next) => {
  104. const pageArgs = pageHelper.parsePath(req.path, { stripExt: true })
  105. const versionId = (req.query.v) ? _.toSafeInteger(req.query.v) : 0
  106. const page = await WIKI.db.pages.getPageFromDb({
  107. path: pageArgs.path,
  108. locale: pageArgs.locale,
  109. userId: req.user.id,
  110. isPrivate: false
  111. })
  112. pageArgs.tags = _.get(page, 'tags', [])
  113. if (versionId > 0) {
  114. if (!WIKI.auth.checkAccess(req.user, ['read:history'], pageArgs)) {
  115. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  116. return res.render('unauthorized', { action: 'downloadVersion' })
  117. }
  118. } else {
  119. if (!WIKI.auth.checkAccess(req.user, ['read:source'], pageArgs)) {
  120. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  121. return res.render('unauthorized', { action: 'download' })
  122. }
  123. }
  124. if (page) {
  125. const fileName = _.last(page.path.split('/')) + '.' + pageHelper.getFileExtension(page.contentType)
  126. res.attachment(fileName)
  127. if (versionId > 0) {
  128. const pageVersion = await WIKI.db.pageHistory.getVersion({ pageId: page.id, versionId })
  129. res.send(pageHelper.injectPageMetadata(pageVersion))
  130. } else {
  131. res.send(pageHelper.injectPageMetadata(page))
  132. }
  133. } else {
  134. res.status(404).end()
  135. }
  136. })
  137. /**
  138. * Create/Edit document
  139. */
  140. router.get(['/_edit', '/_edit/*'], async (req, res, next) => {
  141. const pageArgs = pageHelper.parsePath(req.path, { stripExt: true })
  142. if (pageArgs.path === '') {
  143. return res.redirect(`/_edit/home`)
  144. }
  145. // if (WIKI.config.lang.namespacing && !pageArgs.explicitLocale) {
  146. // return res.redirect(`/_edit/${pageArgs.locale}/${pageArgs.path}`)
  147. // }
  148. // req.i18n.changeLanguage(pageArgs.locale)
  149. // -> Set Editor Lang
  150. _.set(res, 'locals.siteConfig.lang', pageArgs.locale)
  151. // _.set(res, 'locals.siteConfig.rtl', req.i18n.dir() === 'rtl')
  152. // -> Check for reserved path
  153. if (pageHelper.isReservedPath(pageArgs.path)) {
  154. return next(new Error('Cannot create this page because it starts with a system reserved path.'))
  155. }
  156. // -> Get page data from DB
  157. let page = await WIKI.db.pages.getPageFromDb({
  158. path: pageArgs.path,
  159. locale: pageArgs.locale,
  160. userId: req.user.id,
  161. isPrivate: false
  162. })
  163. pageArgs.tags = _.get(page, 'tags', [])
  164. // -> Effective Permissions
  165. const effectivePermissions = WIKI.auth.getEffectivePermissions(req, pageArgs)
  166. const injectCode = {
  167. css: '', // WIKI.config.theming.injectCSS,
  168. head: '', // WIKI.config.theming.injectHead,
  169. body: '' // WIKI.config.theming.injectBody
  170. }
  171. if (page) {
  172. // -> EDIT MODE
  173. if (!(effectivePermissions.pages.write || effectivePermissions.pages.manage)) {
  174. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  175. return res.render('unauthorized', { action: 'edit' })
  176. }
  177. // -> Get page tags
  178. await page.$relatedQuery('tags')
  179. page.tags = _.map(page.tags, 'tag')
  180. // Handle missing extra field
  181. page.extra = page.extra || { css: '', js: '' }
  182. // -> Beautify Script CSS
  183. if (!_.isEmpty(page.extra.css)) {
  184. page.extra.css = new CleanCSS({ format: 'beautify' }).minify(page.extra.css).styles
  185. }
  186. _.set(res.locals, 'pageMeta.title', `Edit ${page.title}`)
  187. _.set(res.locals, 'pageMeta.description', page.description)
  188. page.mode = 'update'
  189. page.isPublished = (page.isPublished === true || page.isPublished === 1) ? 'true' : 'false'
  190. page.content = Buffer.from(page.content).toString('base64')
  191. } else {
  192. // -> CREATE MODE
  193. if (!effectivePermissions.pages.write) {
  194. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  195. return res.render('unauthorized', { action: 'create' })
  196. }
  197. _.set(res.locals, 'pageMeta.title', `New Page`)
  198. page = {
  199. path: pageArgs.path,
  200. localeCode: pageArgs.locale,
  201. editorKey: null,
  202. mode: 'create',
  203. content: null,
  204. title: null,
  205. description: null,
  206. updatedAt: new Date().toISOString(),
  207. extra: {
  208. css: '',
  209. js: ''
  210. }
  211. }
  212. }
  213. res.render('editor', { page, injectCode, effectivePermissions })
  214. })
  215. /**
  216. * History
  217. */
  218. router.get(['/h', '/h/*'], async (req, res, next) => {
  219. const pageArgs = pageHelper.parsePath(req.path, { stripExt: true })
  220. if (WIKI.config.lang.namespacing && !pageArgs.explicitLocale) {
  221. return res.redirect(`/h/${pageArgs.locale}/${pageArgs.path}`)
  222. }
  223. req.i18n.changeLanguage(pageArgs.locale)
  224. _.set(res, 'locals.siteConfig.lang', pageArgs.locale)
  225. _.set(res, 'locals.siteConfig.rtl', req.i18n.dir() === 'rtl')
  226. const page = await WIKI.db.pages.getPageFromDb({
  227. path: pageArgs.path,
  228. locale: pageArgs.locale,
  229. userId: req.user.id,
  230. isPrivate: false
  231. })
  232. if (!page) {
  233. _.set(res.locals, 'pageMeta.title', 'Page Not Found')
  234. return res.status(404).render('notfound', { action: 'history' })
  235. }
  236. pageArgs.tags = _.get(page, 'tags', [])
  237. const effectivePermissions = WIKI.auth.getEffectivePermissions(req, pageArgs)
  238. if (!effectivePermissions.history.read) {
  239. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  240. return res.render('unauthorized', { action: 'history' })
  241. }
  242. if (page) {
  243. _.set(res.locals, 'pageMeta.title', page.title)
  244. _.set(res.locals, 'pageMeta.description', page.description)
  245. res.render('history', { page, effectivePermissions })
  246. } else {
  247. res.redirect(`/${pageArgs.path}`)
  248. }
  249. })
  250. /**
  251. * Page ID redirection
  252. */
  253. router.get(['/i', '/i/:id'], async (req, res, next) => {
  254. const pageId = _.toSafeInteger(req.params.id)
  255. if (pageId <= 0) {
  256. return res.redirect('/')
  257. }
  258. const page = await WIKI.db.pages.query().column(['path', 'localeCode', 'isPrivate', 'privateNS']).findById(pageId)
  259. if (!page) {
  260. _.set(res.locals, 'pageMeta.title', 'Page Not Found')
  261. return res.status(404).render('notfound', { action: 'view' })
  262. }
  263. if (!WIKI.auth.checkAccess(req.user, ['read:pages'], {
  264. locale: page.localeCode,
  265. path: page.path,
  266. private: page.isPrivate,
  267. privateNS: page.privateNS,
  268. explicitLocale: false,
  269. tags: page.tags
  270. })) {
  271. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  272. return res.render('unauthorized', { action: 'view' })
  273. }
  274. if (WIKI.config.lang.namespacing) {
  275. return res.redirect(`/${page.localeCode}/${page.path}`)
  276. } else {
  277. return res.redirect(`/${page.path}`)
  278. }
  279. })
  280. /**
  281. * Source
  282. */
  283. router.get(['/s', '/s/*'], async (req, res, next) => {
  284. const pageArgs = pageHelper.parsePath(req.path, { stripExt: true })
  285. const versionId = (req.query.v) ? _.toSafeInteger(req.query.v) : 0
  286. const page = await WIKI.db.pages.getPageFromDb({
  287. path: pageArgs.path,
  288. locale: pageArgs.locale,
  289. userId: req.user.id,
  290. isPrivate: false
  291. })
  292. pageArgs.tags = _.get(page, 'tags', [])
  293. if (WIKI.config.lang.namespacing && !pageArgs.explicitLocale) {
  294. return res.redirect(`/s/${pageArgs.locale}/${pageArgs.path}`)
  295. }
  296. // -> Effective Permissions
  297. const effectivePermissions = WIKI.auth.getEffectivePermissions(req, pageArgs)
  298. _.set(res, 'locals.siteConfig.lang', pageArgs.locale)
  299. _.set(res, 'locals.siteConfig.rtl', req.i18n.dir() === 'rtl')
  300. if (versionId > 0) {
  301. if (!effectivePermissions.history.read) {
  302. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  303. return res.render('unauthorized', { action: 'sourceVersion' })
  304. }
  305. } else {
  306. if (!effectivePermissions.source.read) {
  307. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  308. return res.render('unauthorized', { action: 'source' })
  309. }
  310. }
  311. if (page) {
  312. if (versionId > 0) {
  313. const pageVersion = await WIKI.db.pageHistory.getVersion({ pageId: page.id, versionId })
  314. _.set(res.locals, 'pageMeta.title', pageVersion.title)
  315. _.set(res.locals, 'pageMeta.description', pageVersion.description)
  316. res.render('source', {
  317. page: {
  318. ...page,
  319. ...pageVersion
  320. },
  321. effectivePermissions
  322. })
  323. } else {
  324. _.set(res.locals, 'pageMeta.title', page.title)
  325. _.set(res.locals, 'pageMeta.description', page.description)
  326. res.render('source', { page, effectivePermissions })
  327. }
  328. } else {
  329. res.redirect(`/${pageArgs.path}`)
  330. }
  331. })
  332. /**
  333. * Tags
  334. */
  335. router.get(['/t', '/t/*'], (req, res, next) => {
  336. _.set(res.locals, 'pageMeta.title', 'Tags')
  337. res.render('tags')
  338. })
  339. /**
  340. * User Avatar
  341. */
  342. router.get('/_userav/:uid', async (req, res, next) => {
  343. if (!WIKI.auth.checkAccess(req.user, ['read:pages'])) {
  344. return res.sendStatus(403)
  345. }
  346. const av = await WIKI.db.users.getUserAvatarData(req.params.uid)
  347. if (av) {
  348. res.set('Content-Type', 'image/jpeg')
  349. res.send(av)
  350. }
  351. return res.sendStatus(404)
  352. })
  353. /**
  354. * View document / asset
  355. */
  356. router.get('/*', async (req, res, next) => {
  357. const stripExt = _.some(WIKI.data.pageExtensions, ext => _.endsWith(req.path, `.${ext}`))
  358. const pageArgs = pageHelper.parsePath(req.path, { stripExt })
  359. const isPage = (stripExt || pageArgs.path.indexOf('.') === -1)
  360. if (isPage) {
  361. // if (WIKI.config.lang.namespacing && !pageArgs.explicitLocale) {
  362. // return res.redirect(`/${pageArgs.locale}/${pageArgs.path}`)
  363. // }
  364. // req.i18n.changeLanguage(pageArgs.locale)
  365. try {
  366. // -> Get Page from cache
  367. const page = await WIKI.db.pages.getPage({
  368. path: pageArgs.path,
  369. locale: pageArgs.locale,
  370. userId: req.user.id
  371. })
  372. pageArgs.tags = _.get(page, 'tags', [])
  373. // -> Effective Permissions
  374. const effectivePermissions = WIKI.auth.getEffectivePermissions(req, pageArgs)
  375. // -> Check User Access
  376. if (!effectivePermissions.pages.read) {
  377. if (req.user.id === WIKI.auth.guest.id) {
  378. res.cookie('loginRedirect', req.path, {
  379. maxAge: 15 * 60 * 1000
  380. })
  381. }
  382. if (pageArgs.path === 'home' && req.user.id === WIKI.auth.guest.id) {
  383. return res.redirect('/login')
  384. }
  385. return res.redirect(`/_error/unauthorized?from=${req.path}`)
  386. }
  387. _.set(res, 'locals.siteConfig.lang', pageArgs.locale)
  388. // _.set(res, 'locals.siteConfig.rtl', req.i18n.dir() === 'rtl')
  389. if (page) {
  390. _.set(res.locals, 'pageMeta.title', page.title)
  391. _.set(res.locals, 'pageMeta.description', page.description)
  392. // -> Check Publishing State
  393. let pageIsPublished = page.isPublished
  394. if (pageIsPublished && !_.isEmpty(page.publishStartDate)) {
  395. pageIsPublished = moment(page.publishStartDate).isSameOrBefore()
  396. }
  397. if (pageIsPublished && !_.isEmpty(page.publishEndDate)) {
  398. pageIsPublished = moment(page.publishEndDate).isSameOrAfter()
  399. }
  400. if (!pageIsPublished && !effectivePermissions.pages.write) {
  401. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  402. return res.status(403).render('unauthorized', {
  403. action: 'view'
  404. })
  405. }
  406. // -> Build sidebar navigation
  407. let sdi = 1
  408. const sidebar = (await WIKI.db.navigation.getTree({ cache: true, locale: pageArgs.locale, groups: req.user.groups })).map(n => ({
  409. i: `sdi-${sdi++}`,
  410. k: n.kind,
  411. l: n.label,
  412. c: n.icon,
  413. y: n.targetType,
  414. t: n.target
  415. }))
  416. // -> Build theme code injection
  417. const injectCode = {
  418. css: '', // WIKI.config.theming.injectCSS,
  419. head: '', // WIKI.config.theming.injectHead,
  420. body: '' // WIKI.config.theming.injectBody
  421. }
  422. // Handle missing extra field
  423. page.extra = page.extra || { css: '', js: '' }
  424. if (!_.isEmpty(page.extra.css)) {
  425. injectCode.css = `${injectCode.css}\n${page.extra.css}`
  426. }
  427. if (!_.isEmpty(page.extra.js)) {
  428. injectCode.body = `${injectCode.body}\n${page.extra.js}`
  429. }
  430. // -> Convert page TOC
  431. if (!_.isString(page.toc)) {
  432. page.toc = JSON.stringify(page.toc)
  433. }
  434. // -> Inject comments variables
  435. const commentTmpl = {
  436. codeTemplate: '', // WIKI.data.commentProvider.codeTemplate,
  437. head: '', // WIKI.data.commentProvider.head,
  438. body: '', // WIKI.data.commentProvider.body,
  439. main: '' // WIKI.data.commentProvider.main
  440. }
  441. if (false && WIKI.config.features.featurePageComments && WIKI.data.commentProvider.codeTemplate) {
  442. [
  443. { key: 'pageUrl', value: `${WIKI.config.host}/i/${page.id}` },
  444. { key: 'pageId', value: page.id }
  445. ].forEach((cfg) => {
  446. commentTmpl.head = _.replace(commentTmpl.head, new RegExp(`{{${cfg.key}}}`, 'g'), cfg.value)
  447. commentTmpl.body = _.replace(commentTmpl.body, new RegExp(`{{${cfg.key}}}`, 'g'), cfg.value)
  448. commentTmpl.main = _.replace(commentTmpl.main, new RegExp(`{{${cfg.key}}}`, 'g'), cfg.value)
  449. })
  450. }
  451. // -> Render view
  452. res.sendFile(path.join(WIKI.ROOTPATH, 'assets/index.html'))
  453. // res.render('page', {
  454. // page,
  455. // sidebar,
  456. // injectCode,
  457. // comments: commentTmpl,
  458. // effectivePermissions
  459. // })
  460. } else if (pageArgs.path === 'home') {
  461. res.redirect('/_welcome')
  462. } else {
  463. _.set(res.locals, 'pageMeta.title', 'Page Not Found')
  464. if (effectivePermissions.pages.write) {
  465. res.status(404).render('new', { path: pageArgs.path, locale: pageArgs.locale })
  466. } else {
  467. res.status(404).render('notfound', { action: 'view' })
  468. }
  469. }
  470. } catch (err) {
  471. next(err)
  472. }
  473. } else {
  474. if (!WIKI.auth.checkAccess(req.user, ['read:assets'], pageArgs)) {
  475. return res.sendStatus(403)
  476. }
  477. await WIKI.db.assets.getAsset(pageArgs.path, res)
  478. }
  479. })
  480. module.exports = router