2022-02-27 02:07:39 +00:00
|
|
|
import Koa from 'koa';
|
2016-12-28 22:49:51 +00:00
|
|
|
|
2022-07-02 06:12:11 +00:00
|
|
|
import { User } from '@/models/entities/user.js';
|
|
|
|
import { UserIps } from '@/models/index.js';
|
|
|
|
import { fetchMeta } from '@/misc/fetch-meta.js';
|
2022-02-27 02:07:39 +00:00
|
|
|
import { IEndpoint } from './endpoints.js';
|
|
|
|
import authenticate, { AuthenticationError } from './authenticate.js';
|
|
|
|
import call from './call.js';
|
|
|
|
import { ApiError } from './error.js';
|
2016-12-28 22:49:51 +00:00
|
|
|
|
2022-07-02 06:12:11 +00:00
|
|
|
const userIpHistories = new Map<User['id'], Set<string>>();
|
|
|
|
|
|
|
|
setInterval(() => {
|
|
|
|
userIpHistories.clear();
|
|
|
|
}, 1000 * 60 * 60);
|
|
|
|
|
2022-02-19 05:05:32 +00:00
|
|
|
export default (endpoint: IEndpoint, ctx: Koa.Context) => new Promise<void>((res) => {
|
2022-06-25 09:26:31 +00:00
|
|
|
const body = ctx.is('multipart/form-data')
|
2022-06-26 08:38:50 +00:00
|
|
|
? (ctx.request as any).body
|
2022-06-25 09:26:31 +00:00
|
|
|
: ctx.method === 'GET'
|
|
|
|
? ctx.query
|
|
|
|
: ctx.request.body;
|
2018-04-13 02:44:39 +00:00
|
|
|
|
2019-02-22 02:46:58 +00:00
|
|
|
const reply = (x?: any, y?: ApiError) => {
|
|
|
|
if (x == null) {
|
2018-04-12 21:06:18 +00:00
|
|
|
ctx.status = 204;
|
2021-01-11 11:38:34 +00:00
|
|
|
} else if (typeof x === 'number' && y) {
|
2018-04-12 21:06:18 +00:00
|
|
|
ctx.status = x;
|
2019-02-23 06:45:03 +00:00
|
|
|
ctx.body = {
|
|
|
|
error: {
|
2019-04-12 16:43:22 +00:00
|
|
|
message: y!.message,
|
|
|
|
code: y!.code,
|
|
|
|
id: y!.id,
|
|
|
|
kind: y!.kind,
|
2021-12-09 14:58:30 +00:00
|
|
|
...(y!.info ? { info: y!.info } : {}),
|
|
|
|
},
|
2019-02-23 06:45:03 +00:00
|
|
|
};
|
2018-04-11 08:40:01 +00:00
|
|
|
} else {
|
2021-01-11 11:38:34 +00:00
|
|
|
// 文字列を返す場合は、JSON.stringify通さないとJSONと認識されない
|
|
|
|
ctx.body = typeof x === 'string' ? JSON.stringify(x) : x;
|
2018-04-11 08:40:01 +00:00
|
|
|
}
|
2019-02-22 05:46:49 +00:00
|
|
|
res();
|
2018-04-11 08:40:01 +00:00
|
|
|
};
|
|
|
|
|
2017-02-27 07:14:41 +00:00
|
|
|
// Authentication
|
2022-07-18 15:41:08 +00:00
|
|
|
// for GET requests, do not even pass on the body parameter as it is considered unsafe
|
|
|
|
authenticate(ctx.headers.authorization, ctx.method === 'GET' ? null : body['i']).then(([user, app]) => {
|
2019-02-22 05:46:49 +00:00
|
|
|
// API invoking
|
2022-01-30 16:40:27 +00:00
|
|
|
call(endpoint.name, user, app, body, ctx).then((res: any) => {
|
2022-06-25 09:26:31 +00:00
|
|
|
if (ctx.method === 'GET' && endpoint.meta.cacheSec && !body['i'] && !user) {
|
|
|
|
ctx.set('Cache-Control', `public, max-age=${endpoint.meta.cacheSec}`);
|
|
|
|
}
|
2019-02-22 05:46:49 +00:00
|
|
|
reply(res);
|
2019-04-12 16:43:22 +00:00
|
|
|
}).catch((e: ApiError) => {
|
2020-04-03 23:46:54 +00:00
|
|
|
reply(e.httpStatusCode ? e.httpStatusCode : e.kind === 'client' ? 400 : 500, e);
|
2019-02-22 05:46:49 +00:00
|
|
|
});
|
2022-07-02 06:12:11 +00:00
|
|
|
|
|
|
|
// Log IP
|
|
|
|
if (user) {
|
|
|
|
fetchMeta().then(meta => {
|
|
|
|
if (!meta.enableIpLogging) return;
|
|
|
|
const ip = ctx.ip;
|
|
|
|
const ips = userIpHistories.get(user.id);
|
|
|
|
if (ips == null || !ips.has(ip)) {
|
|
|
|
if (ips == null) {
|
|
|
|
userIpHistories.set(user.id, new Set([ip]));
|
|
|
|
} else {
|
|
|
|
ips.add(ip);
|
|
|
|
}
|
|
|
|
|
|
|
|
try {
|
2022-07-10 02:02:46 +00:00
|
|
|
UserIps.createQueryBuilder().insert().values({
|
2022-07-02 06:12:11 +00:00
|
|
|
createdAt: new Date(),
|
|
|
|
userId: user.id,
|
|
|
|
ip: ip,
|
2022-07-10 02:02:46 +00:00
|
|
|
}).orIgnore(true).execute();
|
2022-07-02 06:12:11 +00:00
|
|
|
} catch {
|
|
|
|
}
|
|
|
|
}
|
|
|
|
});
|
|
|
|
}
|
2021-07-17 15:53:16 +00:00
|
|
|
}).catch(e => {
|
|
|
|
if (e instanceof AuthenticationError) {
|
2022-07-18 15:42:14 +00:00
|
|
|
ctx.response.status = 403;
|
|
|
|
ctx.response.set('WWW-Authenticate', 'Bearer');
|
|
|
|
ctx.response.body = {
|
|
|
|
message: 'Authentication failed: ' + e.message,
|
2021-07-17 15:53:16 +00:00
|
|
|
code: 'AUTHENTICATION_FAILED',
|
2021-12-09 14:58:30 +00:00
|
|
|
id: 'b0a7f5f8-dc2f-4171-b91f-de88ad238e14',
|
2022-07-18 15:42:14 +00:00
|
|
|
kind: 'client',
|
|
|
|
};
|
|
|
|
res();
|
2021-07-17 15:53:16 +00:00
|
|
|
} else {
|
|
|
|
reply(500, new ApiError());
|
|
|
|
}
|
2019-02-22 05:46:49 +00:00
|
|
|
});
|
|
|
|
});
|