You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

286 lines
8.1 KiB

  1. const express = require('express')
  2. const router = express.Router()
  3. const pageHelper = require('../helpers/page')
  4. const _ = require('lodash')
  5. /* global WIKI */
  6. /**
  7. * Robots.txt
  8. */
  9. router.get('/robots.txt', (req, res, next) => {
  10. res.type('text/plain')
  11. if (_.includes(WIKI.config.seo.robots, 'noindex')) {
  12. res.send('User-agent: *\nDisallow: /')
  13. } else {
  14. res.status(200).end()
  15. }
  16. })
  17. /**
  18. * Health Endpoint
  19. */
  20. router.get('/healthz', (req, res, next) => {
  21. if (WIKI.models.knex.client.pool.numFree() < 1 && WIKI.models.knex.client.pool.numUsed() < 1) {
  22. res.status(503).json({ ok: false }).end()
  23. } else {
  24. res.status(200).json({ ok: true }).end()
  25. }
  26. })
  27. /**
  28. * Administration
  29. */
  30. router.get(['/a', '/a/*'], (req, res, next) => {
  31. _.set(res.locals, 'pageMeta.title', 'Admin')
  32. res.render('admin')
  33. })
  34. /**
  35. * Create/Edit document
  36. */
  37. router.get(['/e', '/e/*'], async (req, res, next) => {
  38. const pageArgs = pageHelper.parsePath(req.path, { stripExt: true })
  39. if (WIKI.config.lang.namespacing && !pageArgs.explicitLocale) {
  40. return res.redirect(`/e/${pageArgs.locale}/${pageArgs.path}`)
  41. }
  42. _.set(res, 'locals.siteConfig.lang', pageArgs.locale)
  43. if (pageHelper.isReservedPath(pageArgs.path)) {
  44. return next(new Error('Cannot create this page because it starts with a system reserved path.'))
  45. }
  46. let page = await WIKI.models.pages.getPageFromDb({
  47. path: pageArgs.path,
  48. locale: pageArgs.locale,
  49. userId: req.user.id,
  50. isPrivate: false
  51. })
  52. const injectCode = {
  53. css: WIKI.config.theming.injectCSS,
  54. head: WIKI.config.theming.injectHead,
  55. body: WIKI.config.theming.injectBody
  56. }
  57. if (page) {
  58. if (!WIKI.auth.checkAccess(req.user, ['write:pages', 'manage:pages'], pageArgs)) {
  59. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  60. return res.render('unauthorized', { action: 'edit' })
  61. }
  62. await page.$relatedQuery('tags')
  63. page.tags = _.map(page.tags, 'tag')
  64. _.set(res.locals, 'pageMeta.title', `Edit ${page.title}`)
  65. _.set(res.locals, 'pageMeta.description', page.description)
  66. page.mode = 'update'
  67. page.isPublished = (page.isPublished === true || page.isPublished === 1) ? 'true' : 'false'
  68. page.content = Buffer.from(page.content).toString('base64')
  69. } else {
  70. if (!WIKI.auth.checkAccess(req.user, ['write:pages'], pageArgs)) {
  71. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  72. return res.render('unauthorized', { action: 'create' })
  73. }
  74. _.set(res.locals, 'pageMeta.title', `New Page`)
  75. page = {
  76. path: pageArgs.path,
  77. localeCode: pageArgs.locale,
  78. editorKey: null,
  79. mode: 'create',
  80. content: null
  81. }
  82. }
  83. res.render('editor', { page, injectCode })
  84. })
  85. /**
  86. * History
  87. */
  88. router.get(['/h', '/h/*'], async (req, res, next) => {
  89. const pageArgs = pageHelper.parsePath(req.path, { stripExt: true })
  90. if (WIKI.config.lang.namespacing && !pageArgs.explicitLocale) {
  91. return res.redirect(`/h/${pageArgs.locale}/${pageArgs.path}`)
  92. }
  93. _.set(res, 'locals.siteConfig.lang', pageArgs.locale)
  94. if (!WIKI.auth.checkAccess(req.user, ['read:history'], pageArgs)) {
  95. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  96. return res.render('unauthorized', { action: 'history' })
  97. }
  98. const page = await WIKI.models.pages.getPageFromDb({
  99. path: pageArgs.path,
  100. locale: pageArgs.locale,
  101. userId: req.user.id,
  102. isPrivate: false
  103. })
  104. if (page) {
  105. _.set(res.locals, 'pageMeta.title', page.title)
  106. _.set(res.locals, 'pageMeta.description', page.description)
  107. res.render('history', { page })
  108. } else {
  109. res.redirect(`/${pageArgs.path}`)
  110. }
  111. })
  112. /**
  113. * Page ID redirection
  114. */
  115. router.get(['/i', '/i/:id'], async (req, res, next) => {
  116. const pageId = _.toSafeInteger(req.params.id)
  117. if (pageId <= 0) {
  118. return res.redirect('/')
  119. }
  120. const page = await WIKI.models.pages.query().column(['path', 'localeCode', 'isPrivate', 'privateNS']).findById(pageId)
  121. if (!page) {
  122. _.set(res.locals, 'pageMeta.title', 'Page Not Found')
  123. return res.status(404).render('notfound', { action: 'view' })
  124. }
  125. if (!WIKI.auth.checkAccess(req.user, ['read:pages'], {
  126. locale: page.localeCode,
  127. path: page.path,
  128. private: page.isPrivate,
  129. privateNS: page.privateNS,
  130. explicitLocale: false
  131. })) {
  132. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  133. return res.render('unauthorized', { action: 'view' })
  134. }
  135. if (WIKI.config.lang.namespacing) {
  136. return res.redirect(`/${page.localeCode}/${page.path}`)
  137. } else {
  138. return res.redirect(`/${page.path}`)
  139. }
  140. })
  141. /**
  142. * Profile
  143. */
  144. router.get(['/p', '/p/*'], (req, res, next) => {
  145. _.set(res.locals, 'pageMeta.title', 'User Profile')
  146. res.render('profile')
  147. })
  148. /**
  149. * Source
  150. */
  151. router.get(['/s', '/s/*'], async (req, res, next) => {
  152. const pageArgs = pageHelper.parsePath(req.path, { stripExt: true })
  153. if (WIKI.config.lang.namespacing && !pageArgs.explicitLocale) {
  154. return res.redirect(`/s/${pageArgs.locale}/${pageArgs.path}`)
  155. }
  156. _.set(res, 'locals.siteConfig.lang', pageArgs.locale)
  157. if (!WIKI.auth.checkAccess(req.user, ['read:source'], pageArgs)) {
  158. return res.render('unauthorized', { action: 'source' })
  159. }
  160. const page = await WIKI.models.pages.getPageFromDb({
  161. path: pageArgs.path,
  162. locale: pageArgs.locale,
  163. userId: req.user.id,
  164. isPrivate: false
  165. })
  166. if (page) {
  167. _.set(res.locals, 'pageMeta.title', page.title)
  168. _.set(res.locals, 'pageMeta.description', page.description)
  169. res.render('source', { page })
  170. } else {
  171. res.redirect(`/${pageArgs.path}`)
  172. }
  173. })
  174. /**
  175. * Tags
  176. */
  177. router.get(['/t', '/t/*'], (req, res, next) => {
  178. _.set(res.locals, 'pageMeta.title', 'Tags')
  179. res.render('tags')
  180. })
  181. /**
  182. * View document / asset
  183. */
  184. router.get('/*', async (req, res, next) => {
  185. const stripExt = _.some(WIKI.data.pageExtensions, ext => _.endsWith(req.path, `.${ext}`))
  186. const pageArgs = pageHelper.parsePath(req.path, { stripExt })
  187. const isPage = (stripExt || pageArgs.path.indexOf('.') === -1)
  188. if (isPage) {
  189. if (WIKI.config.lang.namespacing && !pageArgs.explicitLocale) {
  190. return res.redirect(`/${pageArgs.locale}/${pageArgs.path}`)
  191. }
  192. req.i18n.changeLanguage(pageArgs.locale)
  193. if (!WIKI.auth.checkAccess(req.user, ['read:pages'], pageArgs)) {
  194. if (pageArgs.path === 'home') {
  195. return res.redirect('/login')
  196. }
  197. _.set(res.locals, 'pageMeta.title', 'Unauthorized')
  198. return res.status(403).render('unauthorized', { action: 'view' })
  199. }
  200. try {
  201. const page = await WIKI.models.pages.getPage({
  202. path: pageArgs.path,
  203. locale: pageArgs.locale,
  204. userId: req.user.id,
  205. isPrivate: false
  206. })
  207. _.set(res, 'locals.siteConfig.lang', pageArgs.locale)
  208. if (page) {
  209. _.set(res.locals, 'pageMeta.title', page.title)
  210. _.set(res.locals, 'pageMeta.description', page.description)
  211. const sidebar = await WIKI.models.navigation.getTree({ cache: true })
  212. const injectCode = {
  213. css: WIKI.config.theming.injectCSS,
  214. head: WIKI.config.theming.injectHead,
  215. body: WIKI.config.theming.injectBody
  216. }
  217. if (req.query.legacy || req.get('user-agent').indexOf('Trident') >= 0) {
  218. if (_.isString(page.toc)) {
  219. page.toc = JSON.parse(page.toc)
  220. }
  221. res.render('legacy/page', { page, sidebar, injectCode, isAuthenticated: req.user && req.user.id !== 2 })
  222. } else {
  223. res.render('page', { page, sidebar, injectCode })
  224. }
  225. } else if (pageArgs.path === 'home') {
  226. _.set(res.locals, 'pageMeta.title', 'Welcome')
  227. res.render('welcome', { locale: pageArgs.locale })
  228. } else {
  229. _.set(res.locals, 'pageMeta.title', 'Page Not Found')
  230. if (WIKI.auth.checkAccess(req.user, ['write:pages'], pageArgs)) {
  231. res.status(404).render('new', { path: pageArgs.path, locale: pageArgs.locale })
  232. } else {
  233. res.status(404).render('notfound', { action: 'view' })
  234. }
  235. }
  236. } catch (err) {
  237. next(err)
  238. }
  239. } else {
  240. if (!WIKI.auth.checkAccess(req.user, ['read:assets'], pageArgs)) {
  241. return res.sendStatus(403)
  242. }
  243. await WIKI.models.assets.getAsset(pageArgs.path, res)
  244. }
  245. })
  246. module.exports = router