common.js 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543
  1. const express = require('express')
  2. const router = express.Router()
  3. const pageHelper = require('../helpers/page')
  4. const _ = require('lodash')
  5. const CleanCSS = require('clean-css')
  6. const moment = require('moment')
  7. const path = require('path')
  8. const siteAssetsPath = path.resolve(WIKI.ROOTPATH, WIKI.config.dataPath, 'assets')
  9. /**
  10. * Robots.txt
  11. */
  12. router.get('/robots.txt', (req, res, next) => {
  13. res.type('text/plain')
  14. if (_.includes(WIKI.config.seo.robots, 'noindex')) {
  15. res.send('User-agent: *\nDisallow: /')
  16. } else {
  17. res.status(200).end()
  18. }
  19. })
  20. /**
  21. * Health Endpoint
  22. */
  23. router.get('/healthz', (req, res, next) => {
  24. if (WIKI.db.knex.client.pool.numFree() < 1 && WIKI.db.knex.client.pool.numUsed() < 1) {
  25. res.status(503).json({ ok: false }).end()
  26. } else {
  27. res.status(200).json({ ok: true }).end()
  28. }
  29. })
  30. /**
  31. * Site Asset
  32. */
  33. router.get('/_site/:siteId?/:resource', async (req, res, next) => {
  34. const site = req.params.siteId ? WIKI.sites[req.params.siteId] : await WIKI.db.sites.getSiteByHostname({ hostname: req.hostname })
  35. if (!site) {
  36. return res.status(404).send('Site Not Found')
  37. }
  38. switch (req.params.resource) {
  39. case 'logo': {
  40. if (site.config.assets.logo) {
  41. // TODO: Fetch from db if not in disk cache
  42. res.sendFile(path.join(siteAssetsPath, `logo-${site.id}.${site.config.assets.logoExt}`))
  43. } else {
  44. res.sendFile(path.join(WIKI.ROOTPATH, 'assets/_assets/logo-wikijs.svg'))
  45. }
  46. break
  47. }
  48. case 'favicon': {
  49. if (site.config.assets.favicon) {
  50. // TODO: Fetch from db if not in disk cache
  51. res.sendFile(path.join(siteAssetsPath, `favicon-${site.id}.${site.config.assets.faviconExt}`))
  52. } else {
  53. res.sendFile(path.join(WIKI.ROOTPATH, 'assets/_assets/logo-wikijs.svg'))
  54. }
  55. break
  56. }
  57. case 'loginbg': {
  58. if (site.config.assets.loginBg) {
  59. // TODO: Fetch from db if not in disk cache
  60. res.sendFile(path.join(siteAssetsPath, `loginbg-${site.id}.jpg`))
  61. } else {
  62. res.sendFile(path.join(WIKI.ROOTPATH, 'assets/_assets/bg/login.jpg'))
  63. }
  64. break
  65. }
  66. default: {
  67. return res.status(404).send('Invalid Site Resource')
  68. }
  69. }
  70. })
  71. /**
  72. * Asset Thumbnails / Download
  73. */
  74. router.get('/_thumb/:id.webp', async (req, res, next) => {
  75. const thumb = await WIKI.db.assets.getThumbnail({
  76. id: req.params.id
  77. })
  78. if (thumb) {
  79. // TODO: Check permissions
  80. switch (thumb.previewState) {
  81. case 'pending': {
  82. res.redirect('/_assets/illustrations/fileman-pending.svg')
  83. break
  84. }
  85. case 'ready': {
  86. res.set('Content-Type', 'image/webp')
  87. res.send(thumb.preview)
  88. break
  89. }
  90. case 'failed': {
  91. res.redirect('/_assets/illustrations/fileman-failed.svg')
  92. break
  93. }
  94. default: {
  95. return res.status(500).send('Invalid Thumbnail Preview State')
  96. }
  97. }
  98. } else {
  99. return res.sendStatus(404)
  100. }
  101. })
  102. /**
  103. * New v3 vue app
  104. */
  105. router.get([
  106. '/_admin',
  107. '/_admin/*',
  108. '/_profile',
  109. '/_profile/*',
  110. '/_error',
  111. '/_error/*',
  112. '/_welcome'
  113. ], (req, res, next) => {
  114. res.sendFile(path.join(WIKI.ROOTPATH, 'assets/index.html'))
  115. })
  116. // router.get(['/_admin', '/_admin/*'], (req, res, next) => {
  117. // if (!WIKI.auth.checkAccess(req.user, [
  118. // 'manage:system',
  119. // 'write:users',
  120. // 'manage:users',
  121. // 'write:groups',
  122. // 'manage:groups',
  123. // 'manage:navigation',
  124. // 'manage:theme',
  125. // 'manage:api'
  126. // ])) {
  127. // _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  128. // return res.status(403).render('unauthorized', { action: 'view' })
  129. // }
  130. // _.set(res.locals, 'pageMeta.title', 'Admin')
  131. // res.render('admin')
  132. // })
  133. /**
  134. * Download Page / Version
  135. */
  136. router.get(['/d', '/d/*'], async (req, res, next) => {
  137. const pageArgs = pageHelper.parsePath(req.path, { stripExt: true })
  138. const versionId = (req.query.v) ? _.toSafeInteger(req.query.v) : 0
  139. const page = await WIKI.db.pages.getPageFromDb({
  140. path: pageArgs.path,
  141. locale: pageArgs.locale,
  142. userId: req.user.id,
  143. isPrivate: false
  144. })
  145. pageArgs.tags = _.get(page, 'tags', [])
  146. if (versionId > 0) {
  147. if (!WIKI.auth.checkAccess(req.user, ['read:history'], pageArgs)) {
  148. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  149. return res.render('unauthorized', { action: 'downloadVersion' })
  150. }
  151. } else {
  152. if (!WIKI.auth.checkAccess(req.user, ['read:source'], pageArgs)) {
  153. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  154. return res.render('unauthorized', { action: 'download' })
  155. }
  156. }
  157. if (page) {
  158. const fileName = _.last(page.path.split('/')) + '.' + pageHelper.getFileExtension(page.contentType)
  159. res.attachment(fileName)
  160. if (versionId > 0) {
  161. const pageVersion = await WIKI.db.pageHistory.getVersion({ pageId: page.id, versionId })
  162. res.send(pageHelper.injectPageMetadata(pageVersion))
  163. } else {
  164. res.send(pageHelper.injectPageMetadata(page))
  165. }
  166. } else {
  167. res.status(404).end()
  168. }
  169. })
  170. /**
  171. * Create/Edit document
  172. */
  173. router.get(['/_edit', '/_edit/*'], async (req, res, next) => {
  174. const pageArgs = pageHelper.parsePath(req.path, { stripExt: true })
  175. const site = await WIKI.db.sites.getSiteByHostname({ hostname: req.hostname })
  176. if (!site) {
  177. throw new Error('INVALID_SITE')
  178. }
  179. if (pageArgs.path === '') {
  180. return res.redirect(`/_edit/home`)
  181. }
  182. // if (WIKI.config.lang.namespacing && !pageArgs.explicitLocale) {
  183. // return res.redirect(`/_edit/${pageArgs.locale}/${pageArgs.path}`)
  184. // }
  185. // req.i18n.changeLanguage(pageArgs.locale)
  186. // -> Set Editor Lang
  187. _.set(res, 'locals.siteConfig.lang', pageArgs.locale)
  188. // _.set(res, 'locals.siteConfig.rtl', req.i18n.dir() === 'rtl')
  189. // -> Check for reserved path
  190. if (pageHelper.isReservedPath(pageArgs.path)) {
  191. return next(new Error('Cannot create this page because it starts with a system reserved path.'))
  192. }
  193. // -> Get page data from DB
  194. let page = await WIKI.db.pages.getPageFromDb({
  195. siteId: site.id,
  196. path: pageArgs.path,
  197. locale: pageArgs.locale,
  198. userId: req.user.id
  199. })
  200. pageArgs.tags = _.get(page, 'tags', [])
  201. // -> Effective Permissions
  202. const effectivePermissions = WIKI.auth.getEffectivePermissions(req, pageArgs)
  203. const injectCode = {
  204. css: '', // WIKI.config.theming.injectCSS,
  205. head: '', // WIKI.config.theming.injectHead,
  206. body: '' // WIKI.config.theming.injectBody
  207. }
  208. if (page) {
  209. // -> EDIT MODE
  210. if (!(effectivePermissions.pages.write || effectivePermissions.pages.manage)) {
  211. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  212. return res.render('unauthorized', { action: 'edit' })
  213. }
  214. // -> Get page tags
  215. await page.$relatedQuery('tags')
  216. page.tags = _.map(page.tags, 'tag')
  217. // Handle missing extra field
  218. page.extra = page.extra || { css: '', js: '' }
  219. // -> Beautify Script CSS
  220. if (!_.isEmpty(page.extra.css)) {
  221. page.extra.css = new CleanCSS({ format: 'beautify' }).minify(page.extra.css).styles
  222. }
  223. _.set(res.locals, 'pageMeta.title', `Edit ${page.title}`)
  224. _.set(res.locals, 'pageMeta.description', page.description)
  225. page.mode = 'update'
  226. page.isPublished = (page.isPublished === true || page.isPublished === 1) ? 'true' : 'false'
  227. page.content = Buffer.from(page.content).toString('base64')
  228. } else {
  229. // -> CREATE MODE
  230. if (!effectivePermissions.pages.write) {
  231. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  232. return res.render('unauthorized', { action: 'create' })
  233. }
  234. _.set(res.locals, 'pageMeta.title', `New Page`)
  235. page = {
  236. path: pageArgs.path,
  237. localeCode: pageArgs.locale,
  238. editorKey: null,
  239. mode: 'create',
  240. content: null,
  241. title: null,
  242. description: null,
  243. updatedAt: new Date().toISOString(),
  244. extra: {
  245. css: '',
  246. js: ''
  247. }
  248. }
  249. }
  250. res.render('editor', { page, injectCode, effectivePermissions })
  251. })
  252. /**
  253. * History
  254. */
  255. router.get(['/h', '/h/*'], async (req, res, next) => {
  256. const pageArgs = pageHelper.parsePath(req.path, { stripExt: true })
  257. if (WIKI.config.lang.namespacing && !pageArgs.explicitLocale) {
  258. return res.redirect(`/h/${pageArgs.locale}/${pageArgs.path}`)
  259. }
  260. req.i18n.changeLanguage(pageArgs.locale)
  261. _.set(res, 'locals.siteConfig.lang', pageArgs.locale)
  262. _.set(res, 'locals.siteConfig.rtl', req.i18n.dir() === 'rtl')
  263. const page = await WIKI.db.pages.getPageFromDb({
  264. path: pageArgs.path,
  265. locale: pageArgs.locale,
  266. userId: req.user.id,
  267. isPrivate: false
  268. })
  269. if (!page) {
  270. _.set(res.locals, 'pageMeta.title', 'Page Not Found')
  271. return res.status(404).render('notfound', { action: 'history' })
  272. }
  273. pageArgs.tags = _.get(page, 'tags', [])
  274. const effectivePermissions = WIKI.auth.getEffectivePermissions(req, pageArgs)
  275. if (!effectivePermissions.history.read) {
  276. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  277. return res.render('unauthorized', { action: 'history' })
  278. }
  279. if (page) {
  280. _.set(res.locals, 'pageMeta.title', page.title)
  281. _.set(res.locals, 'pageMeta.description', page.description)
  282. res.render('history', { page, effectivePermissions })
  283. } else {
  284. res.redirect(`/${pageArgs.path}`)
  285. }
  286. })
  287. /**
  288. * Page ID redirection
  289. */
  290. router.get(['/i', '/i/:id'], async (req, res, next) => {
  291. const pageId = _.toSafeInteger(req.params.id)
  292. if (pageId <= 0) {
  293. return res.redirect('/')
  294. }
  295. const page = await WIKI.db.pages.query().column(['path', 'localeCode', 'isPrivate', 'privateNS']).findById(pageId)
  296. if (!page) {
  297. _.set(res.locals, 'pageMeta.title', 'Page Not Found')
  298. return res.status(404).render('notfound', { action: 'view' })
  299. }
  300. if (!WIKI.auth.checkAccess(req.user, ['read:pages'], {
  301. locale: page.localeCode,
  302. path: page.path,
  303. private: page.isPrivate,
  304. privateNS: page.privateNS,
  305. explicitLocale: false,
  306. tags: page.tags
  307. })) {
  308. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  309. return res.render('unauthorized', { action: 'view' })
  310. }
  311. if (WIKI.config.lang.namespacing) {
  312. return res.redirect(`/${page.localeCode}/${page.path}`)
  313. } else {
  314. return res.redirect(`/${page.path}`)
  315. }
  316. })
  317. /**
  318. * Source
  319. */
  320. router.get(['/s', '/s/*'], async (req, res, next) => {
  321. const pageArgs = pageHelper.parsePath(req.path, { stripExt: true })
  322. const versionId = (req.query.v) ? _.toSafeInteger(req.query.v) : 0
  323. const page = await WIKI.db.pages.getPageFromDb({
  324. path: pageArgs.path,
  325. locale: pageArgs.locale,
  326. userId: req.user.id,
  327. isPrivate: false
  328. })
  329. pageArgs.tags = _.get(page, 'tags', [])
  330. if (WIKI.config.lang.namespacing && !pageArgs.explicitLocale) {
  331. return res.redirect(`/s/${pageArgs.locale}/${pageArgs.path}`)
  332. }
  333. // -> Effective Permissions
  334. const effectivePermissions = WIKI.auth.getEffectivePermissions(req, pageArgs)
  335. _.set(res, 'locals.siteConfig.lang', pageArgs.locale)
  336. _.set(res, 'locals.siteConfig.rtl', req.i18n.dir() === 'rtl')
  337. if (versionId > 0) {
  338. if (!effectivePermissions.history.read) {
  339. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  340. return res.render('unauthorized', { action: 'sourceVersion' })
  341. }
  342. } else {
  343. if (!effectivePermissions.source.read) {
  344. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  345. return res.render('unauthorized', { action: 'source' })
  346. }
  347. }
  348. if (page) {
  349. if (versionId > 0) {
  350. const pageVersion = await WIKI.db.pageHistory.getVersion({ pageId: page.id, versionId })
  351. _.set(res.locals, 'pageMeta.title', pageVersion.title)
  352. _.set(res.locals, 'pageMeta.description', pageVersion.description)
  353. res.render('source', {
  354. page: {
  355. ...page,
  356. ...pageVersion
  357. },
  358. effectivePermissions
  359. })
  360. } else {
  361. _.set(res.locals, 'pageMeta.title', page.title)
  362. _.set(res.locals, 'pageMeta.description', page.description)
  363. res.render('source', { page, effectivePermissions })
  364. }
  365. } else {
  366. res.redirect(`/${pageArgs.path}`)
  367. }
  368. })
  369. /**
  370. * Tags
  371. */
  372. router.get(['/t', '/t/*'], (req, res, next) => {
  373. _.set(res.locals, 'pageMeta.title', 'Tags')
  374. res.render('tags')
  375. })
  376. /**
  377. * User Avatar
  378. */
  379. router.get('/_user/:uid/avatar', async (req, res, next) => {
  380. if (!WIKI.auth.checkAccess(req.user, ['read:pages'])) {
  381. return res.sendStatus(403)
  382. }
  383. const av = await WIKI.db.users.getUserAvatarData(req.params.uid)
  384. if (av) {
  385. res.set('Content-Type', 'image/jpeg')
  386. return res.send(av)
  387. }
  388. return res.sendStatus(404)
  389. })
  390. /**
  391. * View document / asset
  392. */
  393. router.get('/*', async (req, res, next) => {
  394. const stripExt = _.some(WIKI.data.pageExtensions, ext => _.endsWith(req.path, `.${ext}`))
  395. const pageArgs = pageHelper.parsePath(req.path, { stripExt })
  396. const isPage = (stripExt || pageArgs.path.indexOf('.') === -1)
  397. const site = await WIKI.db.sites.getSiteByHostname({ hostname: req.hostname })
  398. if (!site) {
  399. throw new Error('INVALID_SITE')
  400. }
  401. if (isPage) {
  402. // if (WIKI.config.lang.namespacing && !pageArgs.explicitLocale) {
  403. // return res.redirect(`/${pageArgs.locale}/${pageArgs.path}`)
  404. // }
  405. // req.i18n.changeLanguage(pageArgs.locale)
  406. try {
  407. // -> Get Page from cache
  408. const page = await WIKI.db.pages.getPage({
  409. siteId: site.id,
  410. path: pageArgs.path,
  411. locale: pageArgs.locale,
  412. userId: req.user.id
  413. })
  414. pageArgs.tags = _.get(page, 'tags', [])
  415. // -> Effective Permissions
  416. const effectivePermissions = WIKI.auth.getEffectivePermissions(req, pageArgs)
  417. // -> Check User Access
  418. if (!effectivePermissions.pages.read) {
  419. if (req.user.id === WIKI.auth.guest.id) {
  420. res.cookie('loginRedirect', req.path, {
  421. maxAge: 15 * 60 * 1000
  422. })
  423. }
  424. if (pageArgs.path === 'home' && req.user.id === WIKI.auth.guest.id) {
  425. return res.redirect('/login')
  426. }
  427. return res.redirect(`/_error/unauthorized?from=${req.path}`)
  428. }
  429. _.set(res, 'locals.siteConfig.lang', pageArgs.locale)
  430. // _.set(res, 'locals.siteConfig.rtl', req.i18n.dir() === 'rtl')
  431. if (page) {
  432. _.set(res.locals, 'pageMeta.title', page.title)
  433. _.set(res.locals, 'pageMeta.description', page.description)
  434. // -> Check Publishing State
  435. let pageIsPublished = page.isPublished
  436. if (pageIsPublished && !_.isEmpty(page.publishStartDate)) {
  437. pageIsPublished = moment(page.publishStartDate).isSameOrBefore()
  438. }
  439. if (pageIsPublished && !_.isEmpty(page.publishEndDate)) {
  440. pageIsPublished = moment(page.publishEndDate).isSameOrAfter()
  441. }
  442. if (!pageIsPublished && !effectivePermissions.pages.write) {
  443. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  444. return res.status(403).render('unauthorized', {
  445. action: 'view'
  446. })
  447. }
  448. // -> Render view
  449. res.sendFile(path.join(WIKI.ROOTPATH, 'assets/index.html'))
  450. } else if (pageArgs.path === 'home') {
  451. res.redirect('/_welcome')
  452. } else {
  453. _.set(res.locals, 'pageMeta.title', 'Page Not Found')
  454. if (effectivePermissions.pages.write) {
  455. res.status(404).render('new', { path: pageArgs.path, locale: pageArgs.locale })
  456. } else {
  457. res.status(404).render('notfound', { action: 'view' })
  458. }
  459. }
  460. } catch (err) {
  461. next(err)
  462. }
  463. } else {
  464. if (!WIKI.auth.checkAccess(req.user, ['read:assets'], pageArgs)) {
  465. return res.sendStatus(403)
  466. }
  467. await WIKI.db.assets.getAsset(pageArgs.path, res)
  468. }
  469. })
  470. module.exports = router