memos/server/resource.go

338 lines
12 KiB
Go
Raw Normal View History

2022-02-03 15:32:03 +08:00
package server
import (
"bytes"
"encoding/json"
2022-02-03 15:32:03 +08:00
"fmt"
2022-08-20 11:36:24 +08:00
"io"
2022-02-03 15:32:03 +08:00
"net/http"
"net/url"
2022-02-03 15:32:03 +08:00
"strconv"
2023-01-07 10:51:34 +08:00
"strings"
"time"
2022-02-03 15:32:03 +08:00
2023-01-02 23:18:12 +08:00
"github.com/pkg/errors"
2022-06-27 22:09:06 +08:00
"github.com/usememos/memos/api"
"github.com/usememos/memos/common"
2023-01-05 20:56:50 +08:00
metric "github.com/usememos/memos/plugin/metrics"
2022-06-27 22:09:06 +08:00
2022-02-03 15:32:03 +08:00
"github.com/labstack/echo/v4"
)
const (
// The max file size is 32MB.
maxFileSize = 32 << 20
)
2022-02-03 15:32:03 +08:00
func (s *Server) registerResourceRoutes(g *echo.Group) {
g.POST("/resource", func(c echo.Context) error {
2022-08-07 10:17:12 +08:00
ctx := c.Request().Context()
2022-07-28 20:09:25 +08:00
userID, ok := c.Get(getUserIDContextKey()).(int)
if !ok {
return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
}
2022-02-03 15:32:03 +08:00
resourceCreate := &api.ResourceCreate{}
if err := json.NewDecoder(c.Request().Body).Decode(resourceCreate); err != nil {
return echo.NewHTTPError(http.StatusBadRequest, "Malformatted post resource request").SetInternal(err)
}
resourceCreate.CreatorID = userID
2023-02-11 17:34:29 +08:00
// Only allow those external links with http prefix.
if resourceCreate.ExternalLink != "" && !strings.HasPrefix(resourceCreate.ExternalLink, "http") {
return echo.NewHTTPError(http.StatusBadRequest, "Invalid external link")
}
resource, err := s.Store.CreateResource(ctx, resourceCreate)
if err != nil {
return echo.NewHTTPError(http.StatusInternalServerError, "Failed to create resource").SetInternal(err)
}
if err := s.createResourceCreateActivity(c, resource); err != nil {
return echo.NewHTTPError(http.StatusInternalServerError, "Failed to create activity").SetInternal(err)
}
c.Response().Header().Set(echo.HeaderContentType, echo.MIMEApplicationJSONCharsetUTF8)
if err := json.NewEncoder(c.Response().Writer).Encode(composeResponse(resource)); err != nil {
return echo.NewHTTPError(http.StatusInternalServerError, "Failed to encode resource response").SetInternal(err)
}
return nil
})
g.POST("/resource/blob", func(c echo.Context) error {
ctx := c.Request().Context()
userID, ok := c.Get(getUserIDContextKey()).(int)
if !ok {
return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
}
if err := c.Request().ParseMultipartForm(maxFileSize); err != nil {
2022-02-03 15:32:03 +08:00
return echo.NewHTTPError(http.StatusBadRequest, "Upload file overload max size").SetInternal(err)
}
file, err := c.FormFile("file")
if err != nil {
return echo.NewHTTPError(http.StatusInternalServerError, "Failed to get uploading file").SetInternal(err)
}
if file == nil {
2022-02-03 15:32:03 +08:00
return echo.NewHTTPError(http.StatusBadRequest, "Upload file not found").SetInternal(err)
}
filename := file.Filename
filetype := file.Header.Get("Content-Type")
size := file.Size
src, err := file.Open()
if err != nil {
2022-02-04 18:54:24 +08:00
return echo.NewHTTPError(http.StatusInternalServerError, "Failed to open file").SetInternal(err)
2022-02-03 15:32:03 +08:00
}
defer src.Close()
2022-08-20 11:36:24 +08:00
fileBytes, err := io.ReadAll(src)
2022-02-03 15:32:03 +08:00
if err != nil {
2022-02-04 18:54:24 +08:00
return echo.NewHTTPError(http.StatusInternalServerError, "Failed to read file").SetInternal(err)
2022-02-03 15:32:03 +08:00
}
resourceCreate := &api.ResourceCreate{
2022-12-28 20:22:52 +08:00
CreatorID: userID,
2022-02-03 15:32:03 +08:00
Filename: filename,
Type: filetype,
Size: size,
2022-02-04 18:54:24 +08:00
Blob: fileBytes,
2022-02-03 15:32:03 +08:00
}
2022-08-07 10:17:12 +08:00
resource, err := s.Store.CreateResource(ctx, resourceCreate)
2022-02-03 15:32:03 +08:00
if err != nil {
return echo.NewHTTPError(http.StatusInternalServerError, "Failed to create resource").SetInternal(err)
}
2023-01-02 23:18:12 +08:00
if err := s.createResourceCreateActivity(c, resource); err != nil {
return echo.NewHTTPError(http.StatusInternalServerError, "Failed to create activity").SetInternal(err)
}
2022-02-03 15:32:03 +08:00
c.Response().Header().Set(echo.HeaderContentType, echo.MIMEApplicationJSONCharsetUTF8)
2022-02-04 17:06:04 +08:00
if err := json.NewEncoder(c.Response().Writer).Encode(composeResponse(resource)); err != nil {
2022-05-03 02:05:43 +08:00
return echo.NewHTTPError(http.StatusInternalServerError, "Failed to encode resource response").SetInternal(err)
2022-02-03 15:32:03 +08:00
}
return nil
})
2022-02-18 22:21:10 +08:00
2022-02-03 15:32:03 +08:00
g.GET("/resource", func(c echo.Context) error {
2022-08-07 10:17:12 +08:00
ctx := c.Request().Context()
2022-07-28 20:09:25 +08:00
userID, ok := c.Get(getUserIDContextKey()).(int)
if !ok {
return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
}
2022-02-03 15:32:03 +08:00
resourceFind := &api.ResourceFind{
2022-05-03 02:05:43 +08:00
CreatorID: &userID,
2022-02-03 15:32:03 +08:00
}
2022-08-07 10:17:12 +08:00
list, err := s.Store.FindResourceList(ctx, resourceFind)
2022-02-03 15:32:03 +08:00
if err != nil {
return echo.NewHTTPError(http.StatusInternalServerError, "Failed to fetch resource list").SetInternal(err)
}
for _, resource := range list {
2022-11-26 14:23:29 +08:00
memoResourceList, err := s.Store.FindMemoResourceList(ctx, &api.MemoResourceFind{
ResourceID: &resource.ID,
})
if err != nil {
return echo.NewHTTPError(http.StatusInternalServerError, "Failed to find memo resource list").SetInternal(err)
}
2022-11-26 14:23:29 +08:00
resource.LinkedMemoAmount = len(memoResourceList)
}
2022-02-03 15:32:03 +08:00
c.Response().Header().Set(echo.HeaderContentType, echo.MIMEApplicationJSONCharsetUTF8)
2022-02-04 17:06:04 +08:00
if err := json.NewEncoder(c.Response().Writer).Encode(composeResponse(list)); err != nil {
2022-02-05 11:43:25 +08:00
return echo.NewHTTPError(http.StatusInternalServerError, "Failed to encode resource list response").SetInternal(err)
2022-02-03 15:32:03 +08:00
}
2022-06-22 19:16:31 +08:00
return nil
})
g.GET("/resource/:resourceId", func(c echo.Context) error {
2022-08-07 10:17:12 +08:00
ctx := c.Request().Context()
2022-06-22 19:16:31 +08:00
resourceID, err := strconv.Atoi(c.Param("resourceId"))
if err != nil {
return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("ID is not a number: %s", c.Param("resourceId"))).SetInternal(err)
}
2022-07-28 20:09:25 +08:00
userID, ok := c.Get(getUserIDContextKey()).(int)
if !ok {
return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
}
2022-06-22 19:16:31 +08:00
resourceFind := &api.ResourceFind{
ID: &resourceID,
CreatorID: &userID,
GetBlob: true,
2022-06-22 19:16:31 +08:00
}
2022-08-07 10:17:12 +08:00
resource, err := s.Store.FindResource(ctx, resourceFind)
2022-06-22 19:16:31 +08:00
if err != nil {
return echo.NewHTTPError(http.StatusInternalServerError, "Failed to fetch resource").SetInternal(err)
}
2022-02-03 15:32:03 +08:00
2022-06-22 19:16:31 +08:00
c.Response().Header().Set(echo.HeaderContentType, echo.MIMEApplicationJSONCharsetUTF8)
if err := json.NewEncoder(c.Response().Writer).Encode(composeResponse(resource)); err != nil {
return echo.NewHTTPError(http.StatusInternalServerError, "Failed to encode resource response").SetInternal(err)
}
return nil
})
g.GET("/resource/:resourceId/blob", func(c echo.Context) error {
2022-08-07 10:17:12 +08:00
ctx := c.Request().Context()
2022-06-22 19:16:31 +08:00
resourceID, err := strconv.Atoi(c.Param("resourceId"))
if err != nil {
return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("ID is not a number: %s", c.Param("resourceId"))).SetInternal(err)
}
2022-07-28 20:09:25 +08:00
userID, ok := c.Get(getUserIDContextKey()).(int)
if !ok {
return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
}
2022-06-22 19:16:31 +08:00
resourceFind := &api.ResourceFind{
ID: &resourceID,
CreatorID: &userID,
GetBlob: true,
2022-06-22 19:16:31 +08:00
}
2022-08-07 10:17:12 +08:00
resource, err := s.Store.FindResource(ctx, resourceFind)
2022-06-22 19:16:31 +08:00
if err != nil {
return echo.NewHTTPError(http.StatusInternalServerError, "Failed to fetch resource").SetInternal(err)
}
2023-02-11 17:34:29 +08:00
return c.Stream(http.StatusOK, resource.Type, bytes.NewReader(resource.Blob))
2022-02-03 15:32:03 +08:00
})
2022-02-18 22:21:10 +08:00
2022-12-19 18:45:17 +08:00
g.PATCH("/resource/:resourceId", func(c echo.Context) error {
2022-08-07 10:17:12 +08:00
ctx := c.Request().Context()
2022-08-07 01:30:48 +08:00
userID, ok := c.Get(getUserIDContextKey()).(int)
if !ok {
return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
}
2022-05-03 02:05:43 +08:00
resourceID, err := strconv.Atoi(c.Param("resourceId"))
2022-02-03 15:32:03 +08:00
if err != nil {
return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("ID is not a number: %s", c.Param("resourceId"))).SetInternal(err)
}
2022-12-19 18:45:17 +08:00
resourceFind := &api.ResourceFind{
2022-12-28 20:22:52 +08:00
ID: &resourceID,
2022-11-06 12:21:58 +08:00
}
2022-12-28 20:22:52 +08:00
resource, err := s.Store.FindResource(ctx, resourceFind)
if err != nil {
2022-12-19 18:45:17 +08:00
return echo.NewHTTPError(http.StatusInternalServerError, "Failed to find resource").SetInternal(err)
2022-11-06 12:21:58 +08:00
}
2022-12-28 20:22:52 +08:00
if resource.CreatorID != userID {
return echo.NewHTTPError(http.StatusUnauthorized, "Unauthorized")
}
2022-11-06 12:21:58 +08:00
2022-12-19 18:45:17 +08:00
currentTs := time.Now().Unix()
resourcePatch := &api.ResourcePatch{
UpdatedTs: &currentTs,
2022-02-03 15:32:03 +08:00
}
2022-12-19 18:45:17 +08:00
if err := json.NewDecoder(c.Request().Body).Decode(resourcePatch); err != nil {
return echo.NewHTTPError(http.StatusBadRequest, "Malformatted patch resource request").SetInternal(err)
2022-02-03 15:32:03 +08:00
}
2023-02-09 23:20:36 +08:00
resourcePatch.ID = resourceID
2022-12-28 20:22:52 +08:00
resource, err = s.Store.PatchResource(ctx, resourcePatch)
2022-12-19 18:45:17 +08:00
if err != nil {
return echo.NewHTTPError(http.StatusInternalServerError, "Failed to patch resource").SetInternal(err)
}
c.Response().Header().Set(echo.HeaderContentType, echo.MIMEApplicationJSONCharsetUTF8)
if err := json.NewEncoder(c.Response().Writer).Encode(composeResponse(resource)); err != nil {
return echo.NewHTTPError(http.StatusInternalServerError, "Failed to encode resource response").SetInternal(err)
}
return nil
2022-02-03 15:32:03 +08:00
})
2022-12-19 18:45:17 +08:00
g.DELETE("/resource/:resourceId", func(c echo.Context) error {
ctx := c.Request().Context()
userID, ok := c.Get(getUserIDContextKey()).(int)
if !ok {
return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
}
resourceID, err := strconv.Atoi(c.Param("resourceId"))
if err != nil {
return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("ID is not a number: %s", c.Param("resourceId"))).SetInternal(err)
}
2022-12-19 18:45:17 +08:00
resource, err := s.Store.FindResource(ctx, &api.ResourceFind{
ID: &resourceID,
CreatorID: &userID,
2022-12-19 18:45:17 +08:00
})
if err != nil {
return echo.NewHTTPError(http.StatusInternalServerError, "Failed to find resource").SetInternal(err)
}
2022-12-28 20:22:52 +08:00
if resource.CreatorID != userID {
return echo.NewHTTPError(http.StatusUnauthorized, "Unauthorized")
}
2022-12-19 18:45:17 +08:00
resourceDelete := &api.ResourceDelete{
ID: resourceID,
}
2022-12-19 18:45:17 +08:00
if err := s.Store.DeleteResource(ctx, resourceDelete); err != nil {
if common.ErrorCode(err) == common.NotFound {
return echo.NewHTTPError(http.StatusNotFound, fmt.Sprintf("Resource ID not found: %d", resourceID))
}
return echo.NewHTTPError(http.StatusInternalServerError, "Failed to delete resource").SetInternal(err)
}
2022-12-19 18:45:17 +08:00
return c.JSON(http.StatusOK, true)
})
2022-02-03 15:32:03 +08:00
}
2022-09-09 00:50:58 +08:00
func (s *Server) registerResourcePublicRoutes(g *echo.Group) {
g.GET("/r/:resourceId/:filename", func(c echo.Context) error {
ctx := c.Request().Context()
resourceID, err := strconv.Atoi(c.Param("resourceId"))
if err != nil {
return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("ID is not a number: %s", c.Param("resourceId"))).SetInternal(err)
}
filename, err := url.QueryUnescape(c.Param("filename"))
if err != nil {
return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("filename is invalid: %s", c.Param("filename"))).SetInternal(err)
}
2022-09-09 00:50:58 +08:00
resourceFind := &api.ResourceFind{
ID: &resourceID,
Filename: &filename,
GetBlob: true,
2022-09-09 00:50:58 +08:00
}
resource, err := s.Store.FindResource(ctx, resourceFind)
if err != nil {
2023-02-11 17:34:29 +08:00
return echo.NewHTTPError(http.StatusInternalServerError, fmt.Sprintf("Failed to find resource by ID: %v", resourceID)).SetInternal(err)
2022-09-09 00:50:58 +08:00
}
2022-11-21 23:23:05 +08:00
c.Response().Writer.Header().Set(echo.HeaderCacheControl, "max-age=31536000, immutable")
c.Response().Writer.Header().Set(echo.HeaderContentSecurityPolicy, "default-src 'self'")
2023-02-11 17:34:29 +08:00
resourceType := strings.ToLower(resource.Type)
if strings.HasPrefix(resourceType, "text") {
resourceType = echo.MIMETextPlainCharsetUTF8
} else if strings.HasPrefix(resourceType, "video") || strings.HasPrefix(resourceType, "audio") {
http.ServeContent(c.Response(), c.Request(), resource.Filename, time.Unix(resource.UpdatedTs, 0), bytes.NewReader(resource.Blob))
return nil
}
return c.Stream(http.StatusOK, resourceType, bytes.NewReader(resource.Blob))
2022-09-09 00:50:58 +08:00
})
}
2023-01-02 23:18:12 +08:00
func (s *Server) createResourceCreateActivity(c echo.Context, resource *api.Resource) error {
ctx := c.Request().Context()
payload := api.ActivityResourceCreatePayload{
Filename: resource.Filename,
Type: resource.Type,
Size: resource.Size,
}
payloadStr, err := json.Marshal(payload)
if err != nil {
return errors.Wrap(err, "failed to marshal activity payload")
}
2023-01-05 20:56:50 +08:00
activity, err := s.Store.CreateActivity(ctx, &api.ActivityCreate{
2023-01-02 23:18:12 +08:00
CreatorID: resource.CreatorID,
Type: api.ActivityResourceCreate,
Level: api.ActivityInfo,
Payload: string(payloadStr),
})
2023-01-07 11:49:58 +08:00
if err != nil || activity == nil {
return errors.Wrap(err, "failed to create activity")
}
2023-01-05 20:56:50 +08:00
s.Collector.Collect(ctx, &metric.Metric{
Name: string(activity.Type),
})
2023-01-02 23:18:12 +08:00
return err
}