trilium/src/routes/routes.js

287 lines
15 KiB
JavaScript
Raw Normal View History

"use strict";
2017-12-04 11:29:23 +08:00
const setupRoute = require('./setup');
2018-12-24 05:28:57 +08:00
const loginRoute = require('./login');
const indexRoute = require('./index');
const utils = require('../services/utils');
2018-03-31 03:34:07 +08:00
const multer = require('multer')();
2017-11-04 11:00:35 +08:00
// API routes
const treeApiRoute = require('./api/tree');
const notesApiRoute = require('./api/notes');
2018-04-02 08:33:10 +08:00
const branchesApiRoute = require('./api/branches');
2018-04-18 12:26:42 +08:00
const autocompleteApiRoute = require('./api/autocomplete');
2018-01-14 07:02:41 +08:00
const cloningApiRoute = require('./api/cloning');
const noteRevisionsApiRoute = require('./api/note_revisions');
2017-11-04 11:00:35 +08:00
const recentChangesApiRoute = require('./api/recent_changes');
const optionsApiRoute = require('./api/options');
2017-11-04 11:00:35 +08:00
const passwordApiRoute = require('./api/password');
const syncApiRoute = require('./api/sync');
const loginApiRoute = require('./api/login');
2017-11-05 11:46:50 +08:00
const recentNotesRoute = require('./api/recent_notes');
2017-11-21 13:25:53 +08:00
const appInfoRoute = require('./api/app_info');
2017-12-03 10:48:22 +08:00
const exportRoute = require('./api/export');
2017-12-03 12:41:18 +08:00
const importRoute = require('./api/import');
2017-12-04 11:29:23 +08:00
const setupApiRoute = require('./api/setup');
2017-12-15 09:38:56 +08:00
const sqlRoute = require('./api/sql');
const databaseRoute = require('./api/database');
const imageRoute = require('./api/image');
const attributesRoute = require('./api/attributes');
const scriptRoute = require('./api/script');
2018-02-11 13:18:59 +08:00
const senderRoute = require('./api/sender');
2019-11-09 18:58:52 +08:00
const filesRoute = require('./api/files');
const searchRoute = require('./api/search');
const dateNotesRoute = require('./api/date_notes');
2019-06-04 04:55:59 +08:00
const linkMapRoute = require('./api/link_map');
2019-06-23 01:49:48 +08:00
const clipperRoute = require('./api/clipper');
2019-11-20 06:02:54 +08:00
const similarNotesRoute = require('./api/similar_notes');
2019-11-20 03:53:04 +08:00
const keysRoute = require('./api/keys');
2019-12-06 04:25:36 +08:00
const backendLogRoute = require('./api/backend_log');
2017-11-04 11:00:35 +08:00
2018-03-31 01:20:36 +08:00
const log = require('../services/log');
2018-03-31 00:57:22 +08:00
const express = require('express');
const router = express.Router();
const auth = require('../services/auth');
const cls = require('../services/cls');
const sql = require('../services/sql');
const protectedSessionService = require('../services/protected_session');
2020-03-10 05:32:26 +08:00
const syncTableService = require('../services/sync_table');
const csurf = require('csurf');
const csrfMiddleware = csurf({
cookie: true,
path: '' // nothing so cookie is valid only for current path
});
2018-03-31 00:57:22 +08:00
2018-04-06 11:35:49 +08:00
function apiResultHandler(req, res, result) {
2020-03-10 05:32:26 +08:00
res.setHeader('trilium-max-sync-id', syncTableService.getMaxSyncId());
// if it's an array and first element is integer then we consider this to be [statusCode, response] format
if (Array.isArray(result) && result.length > 0 && Number.isInteger(result[0])) {
const [statusCode, response] = result;
res.status(statusCode).send(response);
2018-04-06 11:35:49 +08:00
if (statusCode !== 200 && statusCode !== 201 && statusCode !== 204) {
log.info(`${req.method} ${req.originalUrl} returned ${statusCode} with response ${JSON.stringify(response)}`);
2018-03-31 00:57:22 +08:00
}
}
else if (result === undefined) {
res.status(204).send();
}
else {
2018-04-06 07:29:27 +08:00
res.send(result);
}
}
function apiRoute(method, path, routeHandler) {
route(method, path, [auth.checkApiAuth, csrfMiddleware], routeHandler, apiResultHandler);
2018-03-31 03:34:07 +08:00
}
function route(method, path, middleware, routeHandler, resultHandler, transactional = true) {
2020-06-20 18:31:38 +08:00
router[method](path, ...middleware, (req, res, next) => {
2020-06-21 03:42:41 +08:00
const start = Date.now();
2018-03-31 03:34:07 +08:00
try {
2020-06-15 23:56:53 +08:00
cls.namespace.bindEmitter(req);
cls.namespace.bindEmitter(res);
2020-06-20 18:31:38 +08:00
const result = cls.init(() => {
2020-06-15 23:56:53 +08:00
cls.set('sourceId', req.headers['trilium-source-id']);
cls.set('localNowDateTime', req.headers['`trilium-local-now-datetime`']);
protectedSessionService.setProtectedSessionId(req);
2018-03-31 03:34:07 +08:00
2020-06-20 19:18:03 +08:00
const cb = () => routeHandler(req, res, next);
return transactional ? sql.transactional(cb) : cb();
2018-03-31 03:34:07 +08:00
});
if (resultHandler) {
if (result && result.then) {
result.then(actualResult => resultHandler(req, res, actualResult))
}
else {
resultHandler(req, res, result);
}
2018-03-31 03:34:07 +08:00
}
}
2018-03-31 00:57:22 +08:00
catch (e) {
2018-08-28 05:04:52 +08:00
log.error(`${method} ${path} threw exception: ` + e.stack);
2018-03-31 03:34:07 +08:00
res.sendStatus(500);
2020-06-21 03:42:41 +08:00
}
const time = Date.now() - start;
if (time >= 10) {
console.log(`Slow request: ${time}ms - ${method} ${path}`);
2018-03-31 00:57:22 +08:00
}
});
}
const GET = 'get', POST = 'post', PUT = 'put', DELETE = 'delete';
const uploadMiddleware = multer.single('upload');
2018-03-31 00:57:22 +08:00
2017-11-04 11:00:35 +08:00
function register(app) {
route(GET, '/', [auth.checkAuth, csrfMiddleware], indexRoute.index);
route(GET, '/login', [auth.checkAppInitialized], loginRoute.loginPage);
route(POST, '/login', [], loginRoute.login);
route(POST, '/logout', [csrfMiddleware, auth.checkAuth], loginRoute.logout);
route(GET, '/setup', [], setupRoute.setupPage);
2017-11-04 11:00:35 +08:00
2018-03-31 00:57:22 +08:00
apiRoute(GET, '/api/tree', treeApiRoute.getTree);
apiRoute(POST, '/api/tree/load', treeApiRoute.load);
2018-04-02 08:33:10 +08:00
apiRoute(PUT, '/api/branches/:branchId/set-prefix', branchesApiRoute.setPrefix);
2018-03-31 00:57:22 +08:00
2020-05-30 16:30:21 +08:00
apiRoute(PUT, '/api/branches/:branchId/move-to/:parentBranchId', branchesApiRoute.moveBranchToParent);
2018-04-02 08:33:10 +08:00
apiRoute(PUT, '/api/branches/:branchId/move-before/:beforeBranchId', branchesApiRoute.moveBranchBeforeNote);
apiRoute(PUT, '/api/branches/:branchId/move-after/:afterBranchId', branchesApiRoute.moveBranchAfterNote);
apiRoute(PUT, '/api/branches/:branchId/expanded/:expanded', branchesApiRoute.setExpanded);
apiRoute(PUT, '/api/branches/:branchId/expanded-subtree/:expanded', branchesApiRoute.setExpandedForSubtree);
2018-04-02 08:33:10 +08:00
apiRoute(DELETE, '/api/branches/:branchId', branchesApiRoute.deleteBranch);
2018-03-31 00:57:22 +08:00
2018-04-18 12:26:42 +08:00
apiRoute(GET, '/api/autocomplete', autocompleteApiRoute.getAutocomplete);
2018-03-31 00:57:22 +08:00
apiRoute(GET, '/api/notes/:noteId', notesApiRoute.getNote);
apiRoute(PUT, '/api/notes/:noteId', notesApiRoute.updateNote);
apiRoute(DELETE, '/api/notes/:noteId', notesApiRoute.deleteNote);
2020-01-03 20:14:43 +08:00
apiRoute(PUT, '/api/notes/:noteId/undelete', notesApiRoute.undeleteNote);
2018-03-31 00:57:22 +08:00
apiRoute(POST, '/api/notes/:parentNoteId/children', notesApiRoute.createNote);
apiRoute(PUT, '/api/notes/:noteId/sort', notesApiRoute.sortNotes);
apiRoute(PUT, '/api/notes/:noteId/protect/:isProtected', notesApiRoute.protectNote);
2018-03-31 00:57:22 +08:00
apiRoute(PUT, /\/api\/notes\/(.*)\/type\/(.*)\/mime\/(.*)/, notesApiRoute.setNoteTypeMime);
2018-04-02 08:33:10 +08:00
apiRoute(GET, '/api/notes/:noteId/revisions', noteRevisionsApiRoute.getNoteRevisions);
2019-11-09 22:21:14 +08:00
apiRoute(DELETE, '/api/notes/:noteId/revisions', noteRevisionsApiRoute.eraseAllNoteRevisions);
2019-11-02 02:21:48 +08:00
apiRoute(GET, '/api/notes/:noteId/revisions/:noteRevisionId', noteRevisionsApiRoute.getNoteRevision);
2019-11-09 22:21:14 +08:00
apiRoute(DELETE, '/api/notes/:noteId/revisions/:noteRevisionId', noteRevisionsApiRoute.eraseNoteRevision);
2019-11-09 15:53:13 +08:00
route(GET, '/api/notes/:noteId/revisions/:noteRevisionId/download', [auth.checkApiAuthOrElectron], noteRevisionsApiRoute.downloadNoteRevision);
2020-05-08 05:34:13 +08:00
apiRoute(PUT, '/api/notes/:noteId/restore-revision/:noteRevisionId', noteRevisionsApiRoute.restoreNoteRevision);
2018-10-25 18:06:36 +08:00
apiRoute(POST, '/api/notes/relation-map', notesApiRoute.getRelationMap);
apiRoute(PUT, '/api/notes/:noteId/change-title', notesApiRoute.changeTitle);
2019-10-19 18:36:16 +08:00
apiRoute(POST, '/api/notes/:noteId/duplicate/:parentNoteId', notesApiRoute.duplicateNote);
2018-03-31 00:57:22 +08:00
2019-09-07 16:11:59 +08:00
apiRoute(GET, '/api/edited-notes/:date', noteRevisionsApiRoute.getEditedNotesOnDate);
apiRoute(PUT, '/api/notes/:noteId/clone-to/:parentBranchId', cloningApiRoute.cloneNoteToParent);
2018-03-31 01:20:36 +08:00
apiRoute(PUT, '/api/notes/:noteId/clone-after/:afterBranchId', cloningApiRoute.cloneNoteAfter);
2019-10-19 04:27:38 +08:00
route(GET, '/api/notes/:branchId/export/:type/:format/:version/:taskId', [auth.checkApiAuthOrElectron], exportRoute.exportBranch);
route(POST, '/api/notes/:parentNoteId/import', [auth.checkApiAuthOrElectron, uploadMiddleware, csrfMiddleware], importRoute.importToBranch, apiResultHandler);
2018-04-02 08:50:58 +08:00
2019-11-09 18:58:52 +08:00
route(PUT, '/api/notes/:noteId/file', [auth.checkApiAuthOrElectron, uploadMiddleware, csrfMiddleware],
filesRoute.updateFile, apiResultHandler);
2018-04-02 08:50:58 +08:00
route(GET, '/api/notes/:noteId/open', [auth.checkApiAuthOrElectron], filesRoute.openFile);
2018-04-02 08:50:58 +08:00
route(GET, '/api/notes/:noteId/download', [auth.checkApiAuthOrElectron], filesRoute.downloadFile);
// this "hacky" path is used for easier referencing of CSS resources
route(GET, '/api/notes/download/:noteId', [auth.checkApiAuthOrElectron], filesRoute.downloadFile);
2018-04-02 08:33:10 +08:00
apiRoute(GET, '/api/notes/:noteId/attributes', attributesRoute.getEffectiveNoteAttributes);
apiRoute(PUT, '/api/notes/:noteId/attributes', attributesRoute.updateNoteAttributes);
apiRoute(PUT, '/api/notes/:noteId/attributes2', attributesRoute.updateNoteAttributes2);
apiRoute(PUT, '/api/notes/:noteId/attribute', attributesRoute.updateNoteAttribute);
apiRoute(PUT, '/api/notes/:noteId/relations/:name/to/:targetNoteId', attributesRoute.createRelation);
apiRoute(DELETE, '/api/notes/:noteId/relations/:name/to/:targetNoteId', attributesRoute.deleteRelation);
apiRoute(DELETE, '/api/notes/:noteId/attributes/:attributeId', attributesRoute.deleteNoteAttribute);
apiRoute(GET, '/api/attributes/names', attributesRoute.getAttributeNames);
apiRoute(GET, '/api/attributes/values/:attributeName', attributesRoute.getValuesForAttribute);
apiRoute(POST, '/api/notes/:noteId/link-map', linkMapRoute.getLinkMap);
2019-06-02 23:12:18 +08:00
apiRoute(GET, '/api/date-notes/date/:date', dateNotesRoute.getDateNote);
apiRoute(GET, '/api/date-notes/month/:month', dateNotesRoute.getMonthNote);
apiRoute(GET, '/api/date-notes/year/:year', dateNotesRoute.getYearNote);
apiRoute(GET, '/api/date-notes/notes-for-month/:month', dateNotesRoute.getDateNotesForMonth);
apiRoute(POST, '/api/sql-console', dateNotesRoute.createSqlConsole);
2018-11-08 17:30:35 +08:00
route(GET, '/api/images/:noteId/:filename', [auth.checkApiAuthOrElectron], imageRoute.returnImage);
route(POST, '/api/images', [auth.checkApiAuthOrElectron, uploadMiddleware, csrfMiddleware], imageRoute.uploadImage, apiResultHandler);
2019-11-09 05:34:30 +08:00
route(PUT, '/api/images/:noteId', [auth.checkApiAuthOrElectron, uploadMiddleware, csrfMiddleware], imageRoute.updateImage, apiResultHandler);
2018-04-02 08:50:58 +08:00
apiRoute(GET, '/api/recent-changes/:ancestorNoteId', recentChangesApiRoute.getRecentChanges);
2018-04-02 08:33:10 +08:00
apiRoute(GET, '/api/options', optionsApiRoute.getOptions);
// FIXME: possibly change to sending value in the body to avoid host of HTTP server issues with slashes
apiRoute(PUT, '/api/options/:name/:value*', optionsApiRoute.updateOption);
apiRoute(PUT, '/api/options', optionsApiRoute.updateOptions);
2019-01-28 04:18:11 +08:00
apiRoute(GET, '/api/options/user-themes', optionsApiRoute.getUserThemes);
apiRoute(POST, '/api/password/change', passwordApiRoute.changePassword);
2018-07-23 16:29:17 +08:00
apiRoute(POST, '/api/sync/test', syncApiRoute.testSync);
2018-03-31 02:27:41 +08:00
apiRoute(POST, '/api/sync/now', syncApiRoute.syncNow);
apiRoute(POST, '/api/sync/fill-sync-rows', syncApiRoute.fillSyncRows);
apiRoute(POST, '/api/sync/force-full-sync', syncApiRoute.forceFullSync);
apiRoute(POST, '/api/sync/force-note-sync/:noteId', syncApiRoute.forceNoteSync);
route(GET, '/api/sync/check', [auth.checkApiAuth], syncApiRoute.checkSync, apiResultHandler);
2019-03-28 04:04:25 +08:00
route(GET, '/api/sync/changed', [auth.checkApiAuth], syncApiRoute.getChanged, apiResultHandler);
route(PUT, '/api/sync/update', [auth.checkApiAuth], syncApiRoute.update, apiResultHandler);
route(POST, '/api/sync/finished', [auth.checkApiAuth], syncApiRoute.syncFinished, apiResultHandler);
route(POST, '/api/sync/queue-sector/:entityName/:sector', [auth.checkApiAuth], syncApiRoute.queueSector, apiResultHandler);
route(GET, '/api/sync/stats', [], syncApiRoute.getStats, apiResultHandler);
2018-03-31 02:27:41 +08:00
apiRoute(POST, '/api/recent-notes', recentNotesRoute.addRecentNote);
2018-03-31 03:34:07 +08:00
apiRoute(GET, '/api/app-info', appInfoRoute.getAppInfo);
// group of services below are meant to be executed from outside
route(GET, '/api/setup/status', [], setupApiRoute.getStatus, apiResultHandler);
route(POST, '/api/setup/new-document', [auth.checkAppNotInitialized], setupApiRoute.setupNewDocument, apiResultHandler);
route(POST, '/api/setup/sync-from-server', [auth.checkAppNotInitialized], setupApiRoute.setupSyncFromServer, apiResultHandler, false);
2018-07-25 15:46:57 +08:00
route(GET, '/api/setup/sync-seed', [auth.checkBasicAuth], setupApiRoute.getSyncSeed, apiResultHandler);
route(POST, '/api/setup/sync-seed', [auth.checkAppNotInitialized], setupApiRoute.saveSyncSeed, apiResultHandler, false);
apiRoute(GET, '/api/sql/schema', sqlRoute.getSchema);
apiRoute(POST, '/api/sql/execute', sqlRoute.execute);
2020-06-03 05:13:55 +08:00
route(POST, '/api/database/anonymize', [auth.checkApiAuthOrElectron, csrfMiddleware], databaseRoute.anonymize, apiResultHandler, false);
// backup requires execution outside of transaction
route(POST, '/api/database/backup-database', [auth.checkApiAuthOrElectron, csrfMiddleware], databaseRoute.backupDatabase, apiResultHandler, false);
2018-08-15 00:03:36 +08:00
// VACUUM requires execution outside of transaction
route(POST, '/api/database/vacuum-database', [auth.checkApiAuthOrElectron, csrfMiddleware], databaseRoute.vacuumDatabase, apiResultHandler, false);
route(POST, '/api/database/find-and-fix-consistency-issues', [auth.checkApiAuthOrElectron, csrfMiddleware], databaseRoute.findAndFixConsistencyIssues, apiResultHandler, false);
2019-12-11 05:03:00 +08:00
apiRoute(POST, '/api/script/exec', scriptRoute.exec);
apiRoute(POST, '/api/script/run/:noteId', scriptRoute.run);
apiRoute(GET, '/api/script/startup', scriptRoute.getStartupBundles);
2020-03-17 04:16:09 +08:00
apiRoute(GET, '/api/script/widgets', scriptRoute.getWidgetBundles);
apiRoute(GET, '/api/script/bundle/:noteId', scriptRoute.getBundle);
apiRoute(GET, '/api/script/relation/:noteId/:relationName', scriptRoute.getRelationBundles);
// no CSRF since this is called from android app
2019-06-24 03:22:08 +08:00
route(POST, '/api/sender/login', [], loginApiRoute.token, apiResultHandler);
route(POST, '/api/sender/image', [auth.checkToken, uploadMiddleware], senderRoute.uploadImage, apiResultHandler);
route(POST, '/api/sender/note', [auth.checkToken], senderRoute.saveNote, apiResultHandler);
apiRoute(GET, '/api/search/:searchString', searchRoute.searchNotes);
apiRoute(GET, '/api/search-note/:noteId', searchRoute.searchFromNote);
2020-06-26 05:56:06 +08:00
apiRoute(POST, '/api/search-related', searchRoute.getRelatedNotes);
route(POST, '/api/login/sync', [], loginApiRoute.loginSync, apiResultHandler);
// this is for entering protected mode so user has to be already logged-in (that's the reason we don't require username)
apiRoute(POST, '/api/login/protected', loginApiRoute.loginToProtectedSession);
2019-06-24 03:22:08 +08:00
route(POST, '/api/login/token', [], loginApiRoute.token, apiResultHandler);
// in case of local electron, local calls are allowed unauthenticated, for server they need auth
const clipperMiddleware = utils.isElectron() ? [] : [auth.checkToken];
route(GET, '/api/clipper/handshake', clipperMiddleware, clipperRoute.handshake, apiResultHandler);
route(POST, '/api/clipper/clippings', clipperMiddleware, clipperRoute.addClipping, apiResultHandler);
route(POST, '/api/clipper/notes', clipperMiddleware, clipperRoute.createNote, apiResultHandler);
route(POST, '/api/clipper/open/:noteId', clipperMiddleware, clipperRoute.openNote, apiResultHandler);
2019-06-23 01:49:48 +08:00
2019-11-20 03:53:04 +08:00
apiRoute(GET, '/api/similar-notes/:noteId', similarNotesRoute.getSimilarNotes);
apiRoute(GET, '/api/keyboard-actions', keysRoute.getKeyboardActions);
apiRoute(GET, '/api/keyboard-shortcuts-for-notes', keysRoute.getShortcutsForNotes);
2019-12-06 04:25:36 +08:00
apiRoute(GET, '/api/backend-log', backendLogRoute.getBackendLog);
app.use('', router);
2017-11-04 11:00:35 +08:00
}
module.exports = {
register
};