abuse.ts 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250
  1. import express from 'express'
  2. import { logger } from '@server/helpers/logger'
  3. import { createAccountAbuse, createVideoAbuse, createVideoCommentAbuse } from '@server/lib/moderation'
  4. import { Notifier } from '@server/lib/notifier'
  5. import { AbuseModel } from '@server/models/abuse/abuse'
  6. import { AbuseMessageModel } from '@server/models/abuse/abuse-message'
  7. import { getServerActor } from '@server/models/application/application'
  8. import { abusePredefinedReasonsMap } from '@shared/core-utils/abuse'
  9. import { HttpStatusCode } from '@shared/models'
  10. import { AbuseCreate, AbuseState, UserRight } from '../../../shared'
  11. import { getFormattedObjects } from '../../helpers/utils'
  12. import { sequelizeTypescript } from '../../initializers/database'
  13. import {
  14. abuseGetValidator,
  15. abuseListForAdminsValidator,
  16. abuseReportValidator,
  17. abusesSortValidator,
  18. abuseUpdateValidator,
  19. addAbuseMessageValidator,
  20. asyncMiddleware,
  21. asyncRetryTransactionMiddleware,
  22. authenticate,
  23. checkAbuseValidForMessagesValidator,
  24. deleteAbuseMessageValidator,
  25. ensureUserHasRight,
  26. getAbuseValidator,
  27. openapiOperationDoc,
  28. paginationValidator,
  29. setDefaultPagination,
  30. setDefaultSort
  31. } from '../../middlewares'
  32. import { AccountModel } from '../../models/account/account'
  33. const abuseRouter = express.Router()
  34. abuseRouter.get('/',
  35. openapiOperationDoc({ operationId: 'getAbuses' }),
  36. authenticate,
  37. ensureUserHasRight(UserRight.MANAGE_ABUSES),
  38. paginationValidator,
  39. abusesSortValidator,
  40. setDefaultSort,
  41. setDefaultPagination,
  42. abuseListForAdminsValidator,
  43. asyncMiddleware(listAbusesForAdmins)
  44. )
  45. abuseRouter.put('/:id',
  46. authenticate,
  47. ensureUserHasRight(UserRight.MANAGE_ABUSES),
  48. asyncMiddleware(abuseUpdateValidator),
  49. asyncRetryTransactionMiddleware(updateAbuse)
  50. )
  51. abuseRouter.post('/',
  52. authenticate,
  53. asyncMiddleware(abuseReportValidator),
  54. asyncRetryTransactionMiddleware(reportAbuse)
  55. )
  56. abuseRouter.delete('/:id',
  57. authenticate,
  58. ensureUserHasRight(UserRight.MANAGE_ABUSES),
  59. asyncMiddleware(abuseGetValidator),
  60. asyncRetryTransactionMiddleware(deleteAbuse)
  61. )
  62. abuseRouter.get('/:id/messages',
  63. authenticate,
  64. asyncMiddleware(getAbuseValidator),
  65. checkAbuseValidForMessagesValidator,
  66. asyncRetryTransactionMiddleware(listAbuseMessages)
  67. )
  68. abuseRouter.post('/:id/messages',
  69. authenticate,
  70. asyncMiddleware(getAbuseValidator),
  71. checkAbuseValidForMessagesValidator,
  72. addAbuseMessageValidator,
  73. asyncRetryTransactionMiddleware(addAbuseMessage)
  74. )
  75. abuseRouter.delete('/:id/messages/:messageId',
  76. authenticate,
  77. asyncMiddleware(getAbuseValidator),
  78. checkAbuseValidForMessagesValidator,
  79. asyncMiddleware(deleteAbuseMessageValidator),
  80. asyncRetryTransactionMiddleware(deleteAbuseMessage)
  81. )
  82. // ---------------------------------------------------------------------------
  83. export {
  84. abuseRouter
  85. }
  86. // ---------------------------------------------------------------------------
  87. async function listAbusesForAdmins (req: express.Request, res: express.Response) {
  88. const user = res.locals.oauth.token.user
  89. const serverActor = await getServerActor()
  90. const resultList = await AbuseModel.listForAdminApi({
  91. start: req.query.start,
  92. count: req.query.count,
  93. sort: req.query.sort,
  94. id: req.query.id,
  95. filter: req.query.filter,
  96. predefinedReason: req.query.predefinedReason,
  97. search: req.query.search,
  98. state: req.query.state,
  99. videoIs: req.query.videoIs,
  100. searchReporter: req.query.searchReporter,
  101. searchReportee: req.query.searchReportee,
  102. searchVideo: req.query.searchVideo,
  103. searchVideoChannel: req.query.searchVideoChannel,
  104. serverAccountId: serverActor.Account.id,
  105. user
  106. })
  107. return res.json({
  108. total: resultList.total,
  109. data: resultList.data.map(d => d.toFormattedAdminJSON())
  110. })
  111. }
  112. async function updateAbuse (req: express.Request, res: express.Response) {
  113. const abuse = res.locals.abuse
  114. let stateUpdated = false
  115. if (req.body.moderationComment !== undefined) abuse.moderationComment = req.body.moderationComment
  116. if (req.body.state !== undefined) {
  117. abuse.state = req.body.state
  118. stateUpdated = true
  119. }
  120. await sequelizeTypescript.transaction(t => {
  121. return abuse.save({ transaction: t })
  122. })
  123. if (stateUpdated === true) {
  124. AbuseModel.loadFull(abuse.id)
  125. .then(abuseFull => Notifier.Instance.notifyOnAbuseStateChange(abuseFull))
  126. .catch(err => logger.error('Cannot notify on abuse state change', { err }))
  127. }
  128. // Do not send the delete to other instances, we updated OUR copy of this abuse
  129. return res.status(HttpStatusCode.NO_CONTENT_204).end()
  130. }
  131. async function deleteAbuse (req: express.Request, res: express.Response) {
  132. const abuse = res.locals.abuse
  133. await sequelizeTypescript.transaction(t => {
  134. return abuse.destroy({ transaction: t })
  135. })
  136. // Do not send the delete to other instances, we delete OUR copy of this abuse
  137. return res.status(HttpStatusCode.NO_CONTENT_204).end()
  138. }
  139. async function reportAbuse (req: express.Request, res: express.Response) {
  140. const videoInstance = res.locals.videoAll
  141. const commentInstance = res.locals.videoCommentFull
  142. const accountInstance = res.locals.account
  143. const body: AbuseCreate = req.body
  144. const { id } = await sequelizeTypescript.transaction(async t => {
  145. const reporterAccount = await AccountModel.load(res.locals.oauth.token.User.Account.id, t)
  146. const predefinedReasons = body.predefinedReasons?.map(r => abusePredefinedReasonsMap[r])
  147. const baseAbuse = {
  148. reporterAccountId: reporterAccount.id,
  149. reason: body.reason,
  150. state: AbuseState.PENDING,
  151. predefinedReasons
  152. }
  153. if (body.video) {
  154. return createVideoAbuse({
  155. baseAbuse,
  156. videoInstance,
  157. reporterAccount,
  158. transaction: t,
  159. startAt: body.video.startAt,
  160. endAt: body.video.endAt
  161. })
  162. }
  163. if (body.comment) {
  164. return createVideoCommentAbuse({
  165. baseAbuse,
  166. commentInstance,
  167. reporterAccount,
  168. transaction: t
  169. })
  170. }
  171. // Account report
  172. return createAccountAbuse({
  173. baseAbuse,
  174. accountInstance,
  175. reporterAccount,
  176. transaction: t
  177. })
  178. })
  179. return res.json({ abuse: { id } })
  180. }
  181. async function listAbuseMessages (req: express.Request, res: express.Response) {
  182. const abuse = res.locals.abuse
  183. const resultList = await AbuseMessageModel.listForApi(abuse.id)
  184. return res.json(getFormattedObjects(resultList.data, resultList.total))
  185. }
  186. async function addAbuseMessage (req: express.Request, res: express.Response) {
  187. const abuse = res.locals.abuse
  188. const user = res.locals.oauth.token.user
  189. const abuseMessage = await AbuseMessageModel.create({
  190. message: req.body.message,
  191. byModerator: abuse.reporterAccountId !== user.Account.id,
  192. accountId: user.Account.id,
  193. abuseId: abuse.id
  194. })
  195. AbuseModel.loadFull(abuse.id)
  196. .then(abuseFull => Notifier.Instance.notifyOnAbuseMessage(abuseFull, abuseMessage))
  197. .catch(err => logger.error('Cannot notify on new abuse message', { err }))
  198. return res.json({
  199. abuseMessage: {
  200. id: abuseMessage.id
  201. }
  202. })
  203. }
  204. async function deleteAbuseMessage (req: express.Request, res: express.Response) {
  205. const abuseMessage = res.locals.abuseMessage
  206. await sequelizeTypescript.transaction(t => {
  207. return abuseMessage.destroy({ transaction: t })
  208. })
  209. return res.status(HttpStatusCode.NO_CONTENT_204).end()
  210. }