1
0

admin.py 22 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620
  1. # -*- coding: utf-8 -*-
  2. # Copyright 2014-2016 OpenMarket Ltd
  3. # Copyright 2018 New Vector Ltd
  4. #
  5. # Licensed under the Apache License, Version 2.0 (the "License");
  6. # you may not use this file except in compliance with the License.
  7. # You may obtain a copy of the License at
  8. #
  9. # http://www.apache.org/licenses/LICENSE-2.0
  10. #
  11. # Unless required by applicable law or agreed to in writing, software
  12. # distributed under the License is distributed on an "AS IS" BASIS,
  13. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  14. # See the License for the specific language governing permissions and
  15. # limitations under the License.
  16. from twisted.internet import defer
  17. from synapse.api.constants import Membership
  18. from synapse.api.errors import AuthError, SynapseError, Codes, NotFoundError
  19. from synapse.types import UserID, create_requester
  20. from synapse.http.servlet import parse_json_object_from_request
  21. from .base import ClientV1RestServlet, client_path_patterns
  22. import logging
  23. logger = logging.getLogger(__name__)
  24. class UsersRestServlet(ClientV1RestServlet):
  25. PATTERNS = client_path_patterns("/admin/users/(?P<user_id>[^/]*)")
  26. def __init__(self, hs):
  27. super(UsersRestServlet, self).__init__(hs)
  28. self.handlers = hs.get_handlers()
  29. @defer.inlineCallbacks
  30. def on_GET(self, request, user_id):
  31. target_user = UserID.from_string(user_id)
  32. requester = yield self.auth.get_user_by_req(request)
  33. is_admin = yield self.auth.is_server_admin(requester.user)
  34. if not is_admin:
  35. raise AuthError(403, "You are not a server admin")
  36. # To allow all users to get the users list
  37. # if not is_admin and target_user != auth_user:
  38. # raise AuthError(403, "You are not a server admin")
  39. if not self.hs.is_mine(target_user):
  40. raise SynapseError(400, "Can only users a local user")
  41. ret = yield self.handlers.admin_handler.get_users()
  42. defer.returnValue((200, ret))
  43. class WhoisRestServlet(ClientV1RestServlet):
  44. PATTERNS = client_path_patterns("/admin/whois/(?P<user_id>[^/]*)")
  45. def __init__(self, hs):
  46. super(WhoisRestServlet, self).__init__(hs)
  47. self.handlers = hs.get_handlers()
  48. @defer.inlineCallbacks
  49. def on_GET(self, request, user_id):
  50. target_user = UserID.from_string(user_id)
  51. requester = yield self.auth.get_user_by_req(request)
  52. auth_user = requester.user
  53. is_admin = yield self.auth.is_server_admin(requester.user)
  54. if not is_admin and target_user != auth_user:
  55. raise AuthError(403, "You are not a server admin")
  56. if not self.hs.is_mine(target_user):
  57. raise SynapseError(400, "Can only whois a local user")
  58. ret = yield self.handlers.admin_handler.get_whois(target_user)
  59. defer.returnValue((200, ret))
  60. class PurgeMediaCacheRestServlet(ClientV1RestServlet):
  61. PATTERNS = client_path_patterns("/admin/purge_media_cache")
  62. def __init__(self, hs):
  63. self.media_repository = hs.get_media_repository()
  64. super(PurgeMediaCacheRestServlet, self).__init__(hs)
  65. @defer.inlineCallbacks
  66. def on_POST(self, request):
  67. requester = yield self.auth.get_user_by_req(request)
  68. is_admin = yield self.auth.is_server_admin(requester.user)
  69. if not is_admin:
  70. raise AuthError(403, "You are not a server admin")
  71. before_ts = request.args.get("before_ts", None)
  72. if not before_ts:
  73. raise SynapseError(400, "Missing 'before_ts' arg")
  74. logger.info("before_ts: %r", before_ts[0])
  75. try:
  76. before_ts = int(before_ts[0])
  77. except Exception:
  78. raise SynapseError(400, "Invalid 'before_ts' arg")
  79. ret = yield self.media_repository.delete_old_remote_media(before_ts)
  80. defer.returnValue((200, ret))
  81. class PurgeHistoryRestServlet(ClientV1RestServlet):
  82. PATTERNS = client_path_patterns(
  83. "/admin/purge_history/(?P<room_id>[^/]*)(/(?P<event_id>[^/]+))?"
  84. )
  85. def __init__(self, hs):
  86. """
  87. Args:
  88. hs (synapse.server.HomeServer)
  89. """
  90. super(PurgeHistoryRestServlet, self).__init__(hs)
  91. self.handlers = hs.get_handlers()
  92. self.store = hs.get_datastore()
  93. @defer.inlineCallbacks
  94. def on_POST(self, request, room_id, event_id):
  95. requester = yield self.auth.get_user_by_req(request)
  96. is_admin = yield self.auth.is_server_admin(requester.user)
  97. if not is_admin:
  98. raise AuthError(403, "You are not a server admin")
  99. body = parse_json_object_from_request(request, allow_empty_body=True)
  100. delete_local_events = bool(body.get("delete_local_events", False))
  101. # establish the topological ordering we should keep events from. The
  102. # user can provide an event_id in the URL or the request body, or can
  103. # provide a timestamp in the request body.
  104. if event_id is None:
  105. event_id = body.get('purge_up_to_event_id')
  106. if event_id is not None:
  107. event = yield self.store.get_event(event_id)
  108. if event.room_id != room_id:
  109. raise SynapseError(400, "Event is for wrong room.")
  110. token = yield self.store.get_topological_token_for_event(event_id)
  111. logger.info(
  112. "[purge] purging up to token %s (event_id %s)",
  113. token, event_id,
  114. )
  115. elif 'purge_up_to_ts' in body:
  116. ts = body['purge_up_to_ts']
  117. if not isinstance(ts, int):
  118. raise SynapseError(
  119. 400, "purge_up_to_ts must be an int",
  120. errcode=Codes.BAD_JSON,
  121. )
  122. stream_ordering = (
  123. yield self.store.find_first_stream_ordering_after_ts(ts)
  124. )
  125. r = (
  126. yield self.store.get_room_event_after_stream_ordering(
  127. room_id, stream_ordering,
  128. )
  129. )
  130. if not r:
  131. logger.warn(
  132. "[purge] purging events not possible: No event found "
  133. "(received_ts %i => stream_ordering %i)",
  134. ts, stream_ordering,
  135. )
  136. raise SynapseError(
  137. 404,
  138. "there is no event to be purged",
  139. errcode=Codes.NOT_FOUND,
  140. )
  141. (stream, topo, _event_id) = r
  142. token = "t%d-%d" % (topo, stream)
  143. logger.info(
  144. "[purge] purging up to token %s (received_ts %i => "
  145. "stream_ordering %i)",
  146. token, ts, stream_ordering,
  147. )
  148. else:
  149. raise SynapseError(
  150. 400,
  151. "must specify purge_up_to_event_id or purge_up_to_ts",
  152. errcode=Codes.BAD_JSON,
  153. )
  154. purge_id = yield self.handlers.message_handler.start_purge_history(
  155. room_id, token,
  156. delete_local_events=delete_local_events,
  157. )
  158. defer.returnValue((200, {
  159. "purge_id": purge_id,
  160. }))
  161. class PurgeHistoryStatusRestServlet(ClientV1RestServlet):
  162. PATTERNS = client_path_patterns(
  163. "/admin/purge_history_status/(?P<purge_id>[^/]+)"
  164. )
  165. def __init__(self, hs):
  166. """
  167. Args:
  168. hs (synapse.server.HomeServer)
  169. """
  170. super(PurgeHistoryStatusRestServlet, self).__init__(hs)
  171. self.handlers = hs.get_handlers()
  172. @defer.inlineCallbacks
  173. def on_GET(self, request, purge_id):
  174. requester = yield self.auth.get_user_by_req(request)
  175. is_admin = yield self.auth.is_server_admin(requester.user)
  176. if not is_admin:
  177. raise AuthError(403, "You are not a server admin")
  178. purge_status = self.handlers.message_handler.get_purge_status(purge_id)
  179. if purge_status is None:
  180. raise NotFoundError("purge id '%s' not found" % purge_id)
  181. defer.returnValue((200, purge_status.asdict()))
  182. class DeactivateAccountRestServlet(ClientV1RestServlet):
  183. PATTERNS = client_path_patterns("/admin/deactivate/(?P<target_user_id>[^/]*)")
  184. def __init__(self, hs):
  185. super(DeactivateAccountRestServlet, self).__init__(hs)
  186. self._deactivate_account_handler = hs.get_deactivate_account_handler()
  187. @defer.inlineCallbacks
  188. def on_POST(self, request, target_user_id):
  189. UserID.from_string(target_user_id)
  190. requester = yield self.auth.get_user_by_req(request)
  191. is_admin = yield self.auth.is_server_admin(requester.user)
  192. if not is_admin:
  193. raise AuthError(403, "You are not a server admin")
  194. yield self._deactivate_account_handler.deactivate_account(
  195. target_user_id, False,
  196. )
  197. defer.returnValue((200, {}))
  198. class ShutdownRoomRestServlet(ClientV1RestServlet):
  199. """Shuts down a room by removing all local users from the room and blocking
  200. all future invites and joins to the room. Any local aliases will be repointed
  201. to a new room created by `new_room_user_id` and kicked users will be auto
  202. joined to the new room.
  203. """
  204. PATTERNS = client_path_patterns("/admin/shutdown_room/(?P<room_id>[^/]+)")
  205. DEFAULT_MESSAGE = (
  206. "Sharing illegal content on this server is not permitted and rooms in"
  207. " violation will be blocked."
  208. )
  209. def __init__(self, hs):
  210. super(ShutdownRoomRestServlet, self).__init__(hs)
  211. self.store = hs.get_datastore()
  212. self.state = hs.get_state_handler()
  213. self._room_creation_handler = hs.get_room_creation_handler()
  214. self.event_creation_handler = hs.get_event_creation_handler()
  215. self.room_member_handler = hs.get_room_member_handler()
  216. @defer.inlineCallbacks
  217. def on_POST(self, request, room_id):
  218. requester = yield self.auth.get_user_by_req(request)
  219. is_admin = yield self.auth.is_server_admin(requester.user)
  220. if not is_admin:
  221. raise AuthError(403, "You are not a server admin")
  222. content = parse_json_object_from_request(request)
  223. new_room_user_id = content.get("new_room_user_id")
  224. if not new_room_user_id:
  225. raise SynapseError(400, "Please provide field `new_room_user_id`")
  226. room_creator_requester = create_requester(new_room_user_id)
  227. message = content.get("message", self.DEFAULT_MESSAGE)
  228. room_name = content.get("room_name", "Content Violation Notification")
  229. info = yield self._room_creation_handler.create_room(
  230. room_creator_requester,
  231. config={
  232. "preset": "public_chat",
  233. "name": room_name,
  234. "power_level_content_override": {
  235. "users_default": -10,
  236. },
  237. },
  238. ratelimit=False,
  239. )
  240. new_room_id = info["room_id"]
  241. yield self.event_creation_handler.create_and_send_nonmember_event(
  242. room_creator_requester,
  243. {
  244. "type": "m.room.message",
  245. "content": {"body": message, "msgtype": "m.text"},
  246. "room_id": new_room_id,
  247. "sender": new_room_user_id,
  248. },
  249. ratelimit=False,
  250. )
  251. requester_user_id = requester.user.to_string()
  252. logger.info("Shutting down room %r", room_id)
  253. yield self.store.block_room(room_id, requester_user_id)
  254. users = yield self.state.get_current_user_in_room(room_id)
  255. kicked_users = []
  256. for user_id in users:
  257. if not self.hs.is_mine_id(user_id):
  258. continue
  259. logger.info("Kicking %r from %r...", user_id, room_id)
  260. target_requester = create_requester(user_id)
  261. yield self.room_member_handler.update_membership(
  262. requester=target_requester,
  263. target=target_requester.user,
  264. room_id=room_id,
  265. action=Membership.LEAVE,
  266. content={},
  267. ratelimit=False
  268. )
  269. yield self.room_member_handler.forget(target_requester.user, room_id)
  270. yield self.room_member_handler.update_membership(
  271. requester=target_requester,
  272. target=target_requester.user,
  273. room_id=new_room_id,
  274. action=Membership.JOIN,
  275. content={},
  276. ratelimit=False
  277. )
  278. kicked_users.append(user_id)
  279. aliases_for_room = yield self.store.get_aliases_for_room(room_id)
  280. yield self.store.update_aliases_for_room(
  281. room_id, new_room_id, requester_user_id
  282. )
  283. defer.returnValue((200, {
  284. "kicked_users": kicked_users,
  285. "local_aliases": aliases_for_room,
  286. "new_room_id": new_room_id,
  287. }))
  288. class QuarantineMediaInRoom(ClientV1RestServlet):
  289. """Quarantines all media in a room so that no one can download it via
  290. this server.
  291. """
  292. PATTERNS = client_path_patterns("/admin/quarantine_media/(?P<room_id>[^/]+)")
  293. def __init__(self, hs):
  294. super(QuarantineMediaInRoom, self).__init__(hs)
  295. self.store = hs.get_datastore()
  296. @defer.inlineCallbacks
  297. def on_POST(self, request, room_id):
  298. requester = yield self.auth.get_user_by_req(request)
  299. is_admin = yield self.auth.is_server_admin(requester.user)
  300. if not is_admin:
  301. raise AuthError(403, "You are not a server admin")
  302. num_quarantined = yield self.store.quarantine_media_ids_in_room(
  303. room_id, requester.user.to_string(),
  304. )
  305. defer.returnValue((200, {"num_quarantined": num_quarantined}))
  306. class ListMediaInRoom(ClientV1RestServlet):
  307. """Lists all of the media in a given room.
  308. """
  309. PATTERNS = client_path_patterns("/admin/room/(?P<room_id>[^/]+)/media")
  310. def __init__(self, hs):
  311. super(ListMediaInRoom, self).__init__(hs)
  312. self.store = hs.get_datastore()
  313. @defer.inlineCallbacks
  314. def on_GET(self, request, room_id):
  315. requester = yield self.auth.get_user_by_req(request)
  316. is_admin = yield self.auth.is_server_admin(requester.user)
  317. if not is_admin:
  318. raise AuthError(403, "You are not a server admin")
  319. local_mxcs, remote_mxcs = yield self.store.get_media_mxcs_in_room(room_id)
  320. defer.returnValue((200, {"local": local_mxcs, "remote": remote_mxcs}))
  321. class ResetPasswordRestServlet(ClientV1RestServlet):
  322. """Post request to allow an administrator reset password for a user.
  323. This needs user to have administrator access in Synapse.
  324. Example:
  325. http://localhost:8008/_matrix/client/api/v1/admin/reset_password/
  326. @user:to_reset_password?access_token=admin_access_token
  327. JsonBodyToSend:
  328. {
  329. "new_password": "secret"
  330. }
  331. Returns:
  332. 200 OK with empty object if success otherwise an error.
  333. """
  334. PATTERNS = client_path_patterns("/admin/reset_password/(?P<target_user_id>[^/]*)")
  335. def __init__(self, hs):
  336. self.store = hs.get_datastore()
  337. super(ResetPasswordRestServlet, self).__init__(hs)
  338. self.hs = hs
  339. self.auth = hs.get_auth()
  340. self._set_password_handler = hs.get_set_password_handler()
  341. @defer.inlineCallbacks
  342. def on_POST(self, request, target_user_id):
  343. """Post request to allow an administrator reset password for a user.
  344. This needs user to have administrator access in Synapse.
  345. """
  346. UserID.from_string(target_user_id)
  347. requester = yield self.auth.get_user_by_req(request)
  348. is_admin = yield self.auth.is_server_admin(requester.user)
  349. if not is_admin:
  350. raise AuthError(403, "You are not a server admin")
  351. params = parse_json_object_from_request(request)
  352. new_password = params['new_password']
  353. if not new_password:
  354. raise SynapseError(400, "Missing 'new_password' arg")
  355. logger.info("new_password: %r", new_password)
  356. yield self._set_password_handler.set_password(
  357. target_user_id, new_password, requester
  358. )
  359. defer.returnValue((200, {}))
  360. class GetUsersPaginatedRestServlet(ClientV1RestServlet):
  361. """Get request to get specific number of users from Synapse.
  362. This needs user to have administrator access in Synapse.
  363. Example:
  364. http://localhost:8008/_matrix/client/api/v1/admin/users_paginate/
  365. @admin:user?access_token=admin_access_token&start=0&limit=10
  366. Returns:
  367. 200 OK with json object {list[dict[str, Any]], count} or empty object.
  368. """
  369. PATTERNS = client_path_patterns("/admin/users_paginate/(?P<target_user_id>[^/]*)")
  370. def __init__(self, hs):
  371. self.store = hs.get_datastore()
  372. super(GetUsersPaginatedRestServlet, self).__init__(hs)
  373. self.hs = hs
  374. self.auth = hs.get_auth()
  375. self.handlers = hs.get_handlers()
  376. @defer.inlineCallbacks
  377. def on_GET(self, request, target_user_id):
  378. """Get request to get specific number of users from Synapse.
  379. This needs user to have administrator access in Synapse.
  380. """
  381. target_user = UserID.from_string(target_user_id)
  382. requester = yield self.auth.get_user_by_req(request)
  383. is_admin = yield self.auth.is_server_admin(requester.user)
  384. if not is_admin:
  385. raise AuthError(403, "You are not a server admin")
  386. # To allow all users to get the users list
  387. # if not is_admin and target_user != auth_user:
  388. # raise AuthError(403, "You are not a server admin")
  389. if not self.hs.is_mine(target_user):
  390. raise SynapseError(400, "Can only users a local user")
  391. order = "name" # order by name in user table
  392. start = request.args.get("start")[0]
  393. limit = request.args.get("limit")[0]
  394. if not limit:
  395. raise SynapseError(400, "Missing 'limit' arg")
  396. if not start:
  397. raise SynapseError(400, "Missing 'start' arg")
  398. logger.info("limit: %s, start: %s", limit, start)
  399. ret = yield self.handlers.admin_handler.get_users_paginate(
  400. order, start, limit
  401. )
  402. defer.returnValue((200, ret))
  403. @defer.inlineCallbacks
  404. def on_POST(self, request, target_user_id):
  405. """Post request to get specific number of users from Synapse..
  406. This needs user to have administrator access in Synapse.
  407. Example:
  408. http://localhost:8008/_matrix/client/api/v1/admin/users_paginate/
  409. @admin:user?access_token=admin_access_token
  410. JsonBodyToSend:
  411. {
  412. "start": "0",
  413. "limit": "10
  414. }
  415. Returns:
  416. 200 OK with json object {list[dict[str, Any]], count} or empty object.
  417. """
  418. UserID.from_string(target_user_id)
  419. requester = yield self.auth.get_user_by_req(request)
  420. is_admin = yield self.auth.is_server_admin(requester.user)
  421. if not is_admin:
  422. raise AuthError(403, "You are not a server admin")
  423. order = "name" # order by name in user table
  424. params = parse_json_object_from_request(request)
  425. limit = params['limit']
  426. start = params['start']
  427. if not limit:
  428. raise SynapseError(400, "Missing 'limit' arg")
  429. if not start:
  430. raise SynapseError(400, "Missing 'start' arg")
  431. logger.info("limit: %s, start: %s", limit, start)
  432. ret = yield self.handlers.admin_handler.get_users_paginate(
  433. order, start, limit
  434. )
  435. defer.returnValue((200, ret))
  436. class SearchUsersRestServlet(ClientV1RestServlet):
  437. """Get request to search user table for specific users according to
  438. search term.
  439. This needs user to have administrator access in Synapse.
  440. Example:
  441. http://localhost:8008/_matrix/client/api/v1/admin/search_users/
  442. @admin:user?access_token=admin_access_token&term=alice
  443. Returns:
  444. 200 OK with json object {list[dict[str, Any]], count} or empty object.
  445. """
  446. PATTERNS = client_path_patterns("/admin/search_users/(?P<target_user_id>[^/]*)")
  447. def __init__(self, hs):
  448. self.store = hs.get_datastore()
  449. super(SearchUsersRestServlet, self).__init__(hs)
  450. self.hs = hs
  451. self.auth = hs.get_auth()
  452. self.handlers = hs.get_handlers()
  453. @defer.inlineCallbacks
  454. def on_GET(self, request, target_user_id):
  455. """Get request to search user table for specific users according to
  456. search term.
  457. This needs user to have a administrator access in Synapse.
  458. """
  459. target_user = UserID.from_string(target_user_id)
  460. requester = yield self.auth.get_user_by_req(request)
  461. is_admin = yield self.auth.is_server_admin(requester.user)
  462. if not is_admin:
  463. raise AuthError(403, "You are not a server admin")
  464. # To allow all users to get the users list
  465. # if not is_admin and target_user != auth_user:
  466. # raise AuthError(403, "You are not a server admin")
  467. if not self.hs.is_mine(target_user):
  468. raise SynapseError(400, "Can only users a local user")
  469. term = request.args.get("term")[0]
  470. if not term:
  471. raise SynapseError(400, "Missing 'term' arg")
  472. logger.info("term: %s ", term)
  473. ret = yield self.handlers.admin_handler.search_users(
  474. term
  475. )
  476. defer.returnValue((200, ret))
  477. def register_servlets(hs, http_server):
  478. WhoisRestServlet(hs).register(http_server)
  479. PurgeMediaCacheRestServlet(hs).register(http_server)
  480. PurgeHistoryStatusRestServlet(hs).register(http_server)
  481. DeactivateAccountRestServlet(hs).register(http_server)
  482. PurgeHistoryRestServlet(hs).register(http_server)
  483. UsersRestServlet(hs).register(http_server)
  484. ResetPasswordRestServlet(hs).register(http_server)
  485. GetUsersPaginatedRestServlet(hs).register(http_server)
  486. SearchUsersRestServlet(hs).register(http_server)
  487. ShutdownRoomRestServlet(hs).register(http_server)
  488. QuarantineMediaInRoom(hs).register(http_server)
  489. ListMediaInRoom(hs).register(http_server)