abuse.ts 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248
  1. import * as express from 'express'
  2. import { logger } from '@server/helpers/logger'
  3. import { createAccountAbuse, createVideoAbuse, createVideoCommentAbuse } from '@server/lib/moderation'
  4. import { Notifier } from '@server/lib/notifier'
  5. import { AbuseModel } from '@server/models/abuse/abuse'
  6. import { AbuseMessageModel } from '@server/models/abuse/abuse-message'
  7. import { getServerActor } from '@server/models/application/application'
  8. import { abusePredefinedReasonsMap } from '@shared/core-utils/abuse'
  9. import { HttpStatusCode } from '@shared/core-utils/miscs/http-error-codes'
  10. import { AbuseCreate, AbuseState, UserRight } from '../../../shared'
  11. import { getFormattedObjects } from '../../helpers/utils'
  12. import { sequelizeTypescript } from '../../initializers/database'
  13. import {
  14. abuseGetValidator,
  15. abuseListForAdminsValidator,
  16. abuseReportValidator,
  17. abusesSortValidator,
  18. abuseUpdateValidator,
  19. addAbuseMessageValidator,
  20. asyncMiddleware,
  21. asyncRetryTransactionMiddleware,
  22. authenticate,
  23. checkAbuseValidForMessagesValidator,
  24. deleteAbuseMessageValidator,
  25. ensureUserHasRight,
  26. getAbuseValidator,
  27. paginationValidator,
  28. setDefaultPagination,
  29. setDefaultSort
  30. } from '../../middlewares'
  31. import { AccountModel } from '../../models/account/account'
  32. const abuseRouter = express.Router()
  33. abuseRouter.get('/',
  34. authenticate,
  35. ensureUserHasRight(UserRight.MANAGE_ABUSES),
  36. paginationValidator,
  37. abusesSortValidator,
  38. setDefaultSort,
  39. setDefaultPagination,
  40. abuseListForAdminsValidator,
  41. asyncMiddleware(listAbusesForAdmins)
  42. )
  43. abuseRouter.put('/:id',
  44. authenticate,
  45. ensureUserHasRight(UserRight.MANAGE_ABUSES),
  46. asyncMiddleware(abuseUpdateValidator),
  47. asyncRetryTransactionMiddleware(updateAbuse)
  48. )
  49. abuseRouter.post('/',
  50. authenticate,
  51. asyncMiddleware(abuseReportValidator),
  52. asyncRetryTransactionMiddleware(reportAbuse)
  53. )
  54. abuseRouter.delete('/:id',
  55. authenticate,
  56. ensureUserHasRight(UserRight.MANAGE_ABUSES),
  57. asyncMiddleware(abuseGetValidator),
  58. asyncRetryTransactionMiddleware(deleteAbuse)
  59. )
  60. abuseRouter.get('/:id/messages',
  61. authenticate,
  62. asyncMiddleware(getAbuseValidator),
  63. checkAbuseValidForMessagesValidator,
  64. asyncRetryTransactionMiddleware(listAbuseMessages)
  65. )
  66. abuseRouter.post('/:id/messages',
  67. authenticate,
  68. asyncMiddleware(getAbuseValidator),
  69. checkAbuseValidForMessagesValidator,
  70. addAbuseMessageValidator,
  71. asyncRetryTransactionMiddleware(addAbuseMessage)
  72. )
  73. abuseRouter.delete('/:id/messages/:messageId',
  74. authenticate,
  75. asyncMiddleware(getAbuseValidator),
  76. checkAbuseValidForMessagesValidator,
  77. asyncMiddleware(deleteAbuseMessageValidator),
  78. asyncRetryTransactionMiddleware(deleteAbuseMessage)
  79. )
  80. // ---------------------------------------------------------------------------
  81. export {
  82. abuseRouter
  83. }
  84. // ---------------------------------------------------------------------------
  85. async function listAbusesForAdmins (req: express.Request, res: express.Response) {
  86. const user = res.locals.oauth.token.user
  87. const serverActor = await getServerActor()
  88. const resultList = await AbuseModel.listForAdminApi({
  89. start: req.query.start,
  90. count: req.query.count,
  91. sort: req.query.sort,
  92. id: req.query.id,
  93. filter: req.query.filter,
  94. predefinedReason: req.query.predefinedReason,
  95. search: req.query.search,
  96. state: req.query.state,
  97. videoIs: req.query.videoIs,
  98. searchReporter: req.query.searchReporter,
  99. searchReportee: req.query.searchReportee,
  100. searchVideo: req.query.searchVideo,
  101. searchVideoChannel: req.query.searchVideoChannel,
  102. serverAccountId: serverActor.Account.id,
  103. user
  104. })
  105. return res.json({
  106. total: resultList.total,
  107. data: resultList.data.map(d => d.toFormattedAdminJSON())
  108. })
  109. }
  110. async function updateAbuse (req: express.Request, res: express.Response) {
  111. const abuse = res.locals.abuse
  112. let stateUpdated = false
  113. if (req.body.moderationComment !== undefined) abuse.moderationComment = req.body.moderationComment
  114. if (req.body.state !== undefined) {
  115. abuse.state = req.body.state
  116. stateUpdated = true
  117. }
  118. await sequelizeTypescript.transaction(t => {
  119. return abuse.save({ transaction: t })
  120. })
  121. if (stateUpdated === true) {
  122. AbuseModel.loadFull(abuse.id)
  123. .then(abuseFull => Notifier.Instance.notifyOnAbuseStateChange(abuseFull))
  124. .catch(err => logger.error('Cannot notify on abuse state change', { err }))
  125. }
  126. // Do not send the delete to other instances, we updated OUR copy of this abuse
  127. return res.sendStatus(HttpStatusCode.NO_CONTENT_204)
  128. }
  129. async function deleteAbuse (req: express.Request, res: express.Response) {
  130. const abuse = res.locals.abuse
  131. await sequelizeTypescript.transaction(t => {
  132. return abuse.destroy({ transaction: t })
  133. })
  134. // Do not send the delete to other instances, we delete OUR copy of this abuse
  135. return res.sendStatus(HttpStatusCode.NO_CONTENT_204)
  136. }
  137. async function reportAbuse (req: express.Request, res: express.Response) {
  138. const videoInstance = res.locals.videoAll
  139. const commentInstance = res.locals.videoCommentFull
  140. const accountInstance = res.locals.account
  141. const body: AbuseCreate = req.body
  142. const { id } = await sequelizeTypescript.transaction(async t => {
  143. const reporterAccount = await AccountModel.load(res.locals.oauth.token.User.Account.id, t)
  144. const predefinedReasons = body.predefinedReasons?.map(r => abusePredefinedReasonsMap[r])
  145. const baseAbuse = {
  146. reporterAccountId: reporterAccount.id,
  147. reason: body.reason,
  148. state: AbuseState.PENDING,
  149. predefinedReasons
  150. }
  151. if (body.video) {
  152. return createVideoAbuse({
  153. baseAbuse,
  154. videoInstance,
  155. reporterAccount,
  156. transaction: t,
  157. startAt: body.video.startAt,
  158. endAt: body.video.endAt
  159. })
  160. }
  161. if (body.comment) {
  162. return createVideoCommentAbuse({
  163. baseAbuse,
  164. commentInstance,
  165. reporterAccount,
  166. transaction: t
  167. })
  168. }
  169. // Account report
  170. return createAccountAbuse({
  171. baseAbuse,
  172. accountInstance,
  173. reporterAccount,
  174. transaction: t
  175. })
  176. })
  177. return res.json({ abuse: { id } })
  178. }
  179. async function listAbuseMessages (req: express.Request, res: express.Response) {
  180. const abuse = res.locals.abuse
  181. const resultList = await AbuseMessageModel.listForApi(abuse.id)
  182. return res.json(getFormattedObjects(resultList.data, resultList.total))
  183. }
  184. async function addAbuseMessage (req: express.Request, res: express.Response) {
  185. const abuse = res.locals.abuse
  186. const user = res.locals.oauth.token.user
  187. const abuseMessage = await AbuseMessageModel.create({
  188. message: req.body.message,
  189. byModerator: abuse.reporterAccountId !== user.Account.id,
  190. accountId: user.Account.id,
  191. abuseId: abuse.id
  192. })
  193. AbuseModel.loadFull(abuse.id)
  194. .then(abuseFull => Notifier.Instance.notifyOnAbuseMessage(abuseFull, abuseMessage))
  195. .catch(err => logger.error('Cannot notify on new abuse message', { err }))
  196. return res.json({
  197. abuseMessage: {
  198. id: abuseMessage.id
  199. }
  200. })
  201. }
  202. async function deleteAbuseMessage (req: express.Request, res: express.Response) {
  203. const abuseMessage = res.locals.abuseMessage
  204. await sequelizeTypescript.transaction(t => {
  205. return abuseMessage.destroy({ transaction: t })
  206. })
  207. return res.sendStatus(HttpStatusCode.NO_CONTENT_204)
  208. }