admin.py 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519
  1. # -*- coding: utf-8 -*-
  2. # Copyright 2014-2016 OpenMarket Ltd
  3. # Copyright 2018 New Vector Ltd
  4. #
  5. # Licensed under the Apache License, Version 2.0 (the "License");
  6. # you may not use this file except in compliance with the License.
  7. # You may obtain a copy of the License at
  8. #
  9. # http://www.apache.org/licenses/LICENSE-2.0
  10. #
  11. # Unless required by applicable law or agreed to in writing, software
  12. # distributed under the License is distributed on an "AS IS" BASIS,
  13. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  14. # See the License for the specific language governing permissions and
  15. # limitations under the License.
  16. from twisted.internet import defer
  17. from synapse.api.constants import Membership
  18. from synapse.api.errors import AuthError, SynapseError
  19. from synapse.types import UserID, create_requester
  20. from synapse.http.servlet import parse_json_object_from_request
  21. from .base import ClientV1RestServlet, client_path_patterns
  22. import logging
  23. logger = logging.getLogger(__name__)
  24. class UsersRestServlet(ClientV1RestServlet):
  25. PATTERNS = client_path_patterns("/admin/users/(?P<user_id>[^/]*)")
  26. def __init__(self, hs):
  27. super(UsersRestServlet, self).__init__(hs)
  28. self.handlers = hs.get_handlers()
  29. @defer.inlineCallbacks
  30. def on_GET(self, request, user_id):
  31. target_user = UserID.from_string(user_id)
  32. requester = yield self.auth.get_user_by_req(request)
  33. is_admin = yield self.auth.is_server_admin(requester.user)
  34. if not is_admin:
  35. raise AuthError(403, "You are not a server admin")
  36. # To allow all users to get the users list
  37. # if not is_admin and target_user != auth_user:
  38. # raise AuthError(403, "You are not a server admin")
  39. if not self.hs.is_mine(target_user):
  40. raise SynapseError(400, "Can only users a local user")
  41. ret = yield self.handlers.admin_handler.get_users()
  42. defer.returnValue((200, ret))
  43. class WhoisRestServlet(ClientV1RestServlet):
  44. PATTERNS = client_path_patterns("/admin/whois/(?P<user_id>[^/]*)")
  45. def __init__(self, hs):
  46. super(WhoisRestServlet, self).__init__(hs)
  47. self.handlers = hs.get_handlers()
  48. @defer.inlineCallbacks
  49. def on_GET(self, request, user_id):
  50. target_user = UserID.from_string(user_id)
  51. requester = yield self.auth.get_user_by_req(request)
  52. auth_user = requester.user
  53. is_admin = yield self.auth.is_server_admin(requester.user)
  54. if not is_admin and target_user != auth_user:
  55. raise AuthError(403, "You are not a server admin")
  56. if not self.hs.is_mine(target_user):
  57. raise SynapseError(400, "Can only whois a local user")
  58. ret = yield self.handlers.admin_handler.get_whois(target_user)
  59. defer.returnValue((200, ret))
  60. class PurgeMediaCacheRestServlet(ClientV1RestServlet):
  61. PATTERNS = client_path_patterns("/admin/purge_media_cache")
  62. def __init__(self, hs):
  63. self.media_repository = hs.get_media_repository()
  64. super(PurgeMediaCacheRestServlet, self).__init__(hs)
  65. @defer.inlineCallbacks
  66. def on_POST(self, request):
  67. requester = yield self.auth.get_user_by_req(request)
  68. is_admin = yield self.auth.is_server_admin(requester.user)
  69. if not is_admin:
  70. raise AuthError(403, "You are not a server admin")
  71. before_ts = request.args.get("before_ts", None)
  72. if not before_ts:
  73. raise SynapseError(400, "Missing 'before_ts' arg")
  74. logger.info("before_ts: %r", before_ts[0])
  75. try:
  76. before_ts = int(before_ts[0])
  77. except Exception:
  78. raise SynapseError(400, "Invalid 'before_ts' arg")
  79. ret = yield self.media_repository.delete_old_remote_media(before_ts)
  80. defer.returnValue((200, ret))
  81. class PurgeHistoryRestServlet(ClientV1RestServlet):
  82. PATTERNS = client_path_patterns(
  83. "/admin/purge_history/(?P<room_id>[^/]*)/(?P<event_id>[^/]*)"
  84. )
  85. def __init__(self, hs):
  86. super(PurgeHistoryRestServlet, self).__init__(hs)
  87. self.handlers = hs.get_handlers()
  88. @defer.inlineCallbacks
  89. def on_POST(self, request, room_id, event_id):
  90. requester = yield self.auth.get_user_by_req(request)
  91. is_admin = yield self.auth.is_server_admin(requester.user)
  92. if not is_admin:
  93. raise AuthError(403, "You are not a server admin")
  94. body = parse_json_object_from_request(request, allow_empty_body=True)
  95. delete_local_events = bool(body.get("delete_local_events", False))
  96. yield self.handlers.message_handler.purge_history(
  97. room_id, event_id,
  98. delete_local_events=delete_local_events,
  99. )
  100. defer.returnValue((200, {}))
  101. class DeactivateAccountRestServlet(ClientV1RestServlet):
  102. PATTERNS = client_path_patterns("/admin/deactivate/(?P<target_user_id>[^/]*)")
  103. def __init__(self, hs):
  104. super(DeactivateAccountRestServlet, self).__init__(hs)
  105. self._deactivate_account_handler = hs.get_deactivate_account_handler()
  106. @defer.inlineCallbacks
  107. def on_POST(self, request, target_user_id):
  108. UserID.from_string(target_user_id)
  109. requester = yield self.auth.get_user_by_req(request)
  110. is_admin = yield self.auth.is_server_admin(requester.user)
  111. if not is_admin:
  112. raise AuthError(403, "You are not a server admin")
  113. yield self._deactivate_account_handler.deactivate_account(target_user_id)
  114. defer.returnValue((200, {}))
  115. class ShutdownRoomRestServlet(ClientV1RestServlet):
  116. """Shuts down a room by removing all local users from the room and blocking
  117. all future invites and joins to the room. Any local aliases will be repointed
  118. to a new room created by `new_room_user_id` and kicked users will be auto
  119. joined to the new room.
  120. """
  121. PATTERNS = client_path_patterns("/admin/shutdown_room/(?P<room_id>[^/]+)")
  122. DEFAULT_MESSAGE = (
  123. "Sharing illegal content on this server is not permitted and rooms in"
  124. " violation will be blocked."
  125. )
  126. def __init__(self, hs):
  127. super(ShutdownRoomRestServlet, self).__init__(hs)
  128. self.store = hs.get_datastore()
  129. self.handlers = hs.get_handlers()
  130. self.state = hs.get_state_handler()
  131. self.event_creation_handler = hs.get_event_creation_handler()
  132. @defer.inlineCallbacks
  133. def on_POST(self, request, room_id):
  134. requester = yield self.auth.get_user_by_req(request)
  135. is_admin = yield self.auth.is_server_admin(requester.user)
  136. if not is_admin:
  137. raise AuthError(403, "You are not a server admin")
  138. content = parse_json_object_from_request(request)
  139. new_room_user_id = content.get("new_room_user_id")
  140. if not new_room_user_id:
  141. raise SynapseError(400, "Please provide field `new_room_user_id`")
  142. room_creator_requester = create_requester(new_room_user_id)
  143. message = content.get("message", self.DEFAULT_MESSAGE)
  144. room_name = content.get("room_name", "Content Violation Notification")
  145. info = yield self.handlers.room_creation_handler.create_room(
  146. room_creator_requester,
  147. config={
  148. "preset": "public_chat",
  149. "name": room_name,
  150. "power_level_content_override": {
  151. "users_default": -10,
  152. },
  153. },
  154. ratelimit=False,
  155. )
  156. new_room_id = info["room_id"]
  157. requester_user_id = requester.user.to_string()
  158. logger.info("Shutting down room %r", room_id)
  159. yield self.store.block_room(room_id, requester_user_id)
  160. users = yield self.state.get_current_user_in_room(room_id)
  161. kicked_users = []
  162. for user_id in users:
  163. if not self.hs.is_mine_id(user_id):
  164. continue
  165. logger.info("Kicking %r from %r...", user_id, room_id)
  166. target_requester = create_requester(user_id)
  167. yield self.handlers.room_member_handler.update_membership(
  168. requester=target_requester,
  169. target=target_requester.user,
  170. room_id=room_id,
  171. action=Membership.LEAVE,
  172. content={},
  173. ratelimit=False
  174. )
  175. yield self.handlers.room_member_handler.forget(target_requester.user, room_id)
  176. yield self.handlers.room_member_handler.update_membership(
  177. requester=target_requester,
  178. target=target_requester.user,
  179. room_id=new_room_id,
  180. action=Membership.JOIN,
  181. content={},
  182. ratelimit=False
  183. )
  184. kicked_users.append(user_id)
  185. yield self.event_creation_handler.create_and_send_nonmember_event(
  186. room_creator_requester,
  187. {
  188. "type": "m.room.message",
  189. "content": {"body": message, "msgtype": "m.text"},
  190. "room_id": new_room_id,
  191. "sender": new_room_user_id,
  192. },
  193. ratelimit=False,
  194. )
  195. aliases_for_room = yield self.store.get_aliases_for_room(room_id)
  196. yield self.store.update_aliases_for_room(
  197. room_id, new_room_id, requester_user_id
  198. )
  199. defer.returnValue((200, {
  200. "kicked_users": kicked_users,
  201. "local_aliases": aliases_for_room,
  202. "new_room_id": new_room_id,
  203. }))
  204. class QuarantineMediaInRoom(ClientV1RestServlet):
  205. """Quarantines all media in a room so that no one can download it via
  206. this server.
  207. """
  208. PATTERNS = client_path_patterns("/admin/quarantine_media/(?P<room_id>[^/]+)")
  209. def __init__(self, hs):
  210. super(QuarantineMediaInRoom, self).__init__(hs)
  211. self.store = hs.get_datastore()
  212. @defer.inlineCallbacks
  213. def on_POST(self, request, room_id):
  214. requester = yield self.auth.get_user_by_req(request)
  215. is_admin = yield self.auth.is_server_admin(requester.user)
  216. if not is_admin:
  217. raise AuthError(403, "You are not a server admin")
  218. num_quarantined = yield self.store.quarantine_media_ids_in_room(
  219. room_id, requester.user.to_string(),
  220. )
  221. defer.returnValue((200, {"num_quarantined": num_quarantined}))
  222. class ListMediaInRoom(ClientV1RestServlet):
  223. """Lists all of the media in a given room.
  224. """
  225. PATTERNS = client_path_patterns("/admin/room/(?P<room_id>[^/]+)/media")
  226. def __init__(self, hs):
  227. super(ListMediaInRoom, self).__init__(hs)
  228. self.store = hs.get_datastore()
  229. @defer.inlineCallbacks
  230. def on_GET(self, request, room_id):
  231. requester = yield self.auth.get_user_by_req(request)
  232. is_admin = yield self.auth.is_server_admin(requester.user)
  233. if not is_admin:
  234. raise AuthError(403, "You are not a server admin")
  235. local_mxcs, remote_mxcs = yield self.store.get_media_mxcs_in_room(room_id)
  236. defer.returnValue((200, {"local": local_mxcs, "remote": remote_mxcs}))
  237. class ResetPasswordRestServlet(ClientV1RestServlet):
  238. """Post request to allow an administrator reset password for a user.
  239. This needs user to have administrator access in Synapse.
  240. Example:
  241. http://localhost:8008/_matrix/client/api/v1/admin/reset_password/
  242. @user:to_reset_password?access_token=admin_access_token
  243. JsonBodyToSend:
  244. {
  245. "new_password": "secret"
  246. }
  247. Returns:
  248. 200 OK with empty object if success otherwise an error.
  249. """
  250. PATTERNS = client_path_patterns("/admin/reset_password/(?P<target_user_id>[^/]*)")
  251. def __init__(self, hs):
  252. self.store = hs.get_datastore()
  253. super(ResetPasswordRestServlet, self).__init__(hs)
  254. self.hs = hs
  255. self.auth = hs.get_auth()
  256. self._set_password_handler = hs.get_set_password_handler()
  257. @defer.inlineCallbacks
  258. def on_POST(self, request, target_user_id):
  259. """Post request to allow an administrator reset password for a user.
  260. This needs user to have administrator access in Synapse.
  261. """
  262. UserID.from_string(target_user_id)
  263. requester = yield self.auth.get_user_by_req(request)
  264. is_admin = yield self.auth.is_server_admin(requester.user)
  265. if not is_admin:
  266. raise AuthError(403, "You are not a server admin")
  267. params = parse_json_object_from_request(request)
  268. new_password = params['new_password']
  269. if not new_password:
  270. raise SynapseError(400, "Missing 'new_password' arg")
  271. logger.info("new_password: %r", new_password)
  272. yield self._set_password_handler.set_password(
  273. target_user_id, new_password, requester
  274. )
  275. defer.returnValue((200, {}))
  276. class GetUsersPaginatedRestServlet(ClientV1RestServlet):
  277. """Get request to get specific number of users from Synapse.
  278. This needs user to have administrator access in Synapse.
  279. Example:
  280. http://localhost:8008/_matrix/client/api/v1/admin/users_paginate/
  281. @admin:user?access_token=admin_access_token&start=0&limit=10
  282. Returns:
  283. 200 OK with json object {list[dict[str, Any]], count} or empty object.
  284. """
  285. PATTERNS = client_path_patterns("/admin/users_paginate/(?P<target_user_id>[^/]*)")
  286. def __init__(self, hs):
  287. self.store = hs.get_datastore()
  288. super(GetUsersPaginatedRestServlet, self).__init__(hs)
  289. self.hs = hs
  290. self.auth = hs.get_auth()
  291. self.handlers = hs.get_handlers()
  292. @defer.inlineCallbacks
  293. def on_GET(self, request, target_user_id):
  294. """Get request to get specific number of users from Synapse.
  295. This needs user to have administrator access in Synapse.
  296. """
  297. target_user = UserID.from_string(target_user_id)
  298. requester = yield self.auth.get_user_by_req(request)
  299. is_admin = yield self.auth.is_server_admin(requester.user)
  300. if not is_admin:
  301. raise AuthError(403, "You are not a server admin")
  302. # To allow all users to get the users list
  303. # if not is_admin and target_user != auth_user:
  304. # raise AuthError(403, "You are not a server admin")
  305. if not self.hs.is_mine(target_user):
  306. raise SynapseError(400, "Can only users a local user")
  307. order = "name" # order by name in user table
  308. start = request.args.get("start")[0]
  309. limit = request.args.get("limit")[0]
  310. if not limit:
  311. raise SynapseError(400, "Missing 'limit' arg")
  312. if not start:
  313. raise SynapseError(400, "Missing 'start' arg")
  314. logger.info("limit: %s, start: %s", limit, start)
  315. ret = yield self.handlers.admin_handler.get_users_paginate(
  316. order, start, limit
  317. )
  318. defer.returnValue((200, ret))
  319. @defer.inlineCallbacks
  320. def on_POST(self, request, target_user_id):
  321. """Post request to get specific number of users from Synapse..
  322. This needs user to have administrator access in Synapse.
  323. Example:
  324. http://localhost:8008/_matrix/client/api/v1/admin/users_paginate/
  325. @admin:user?access_token=admin_access_token
  326. JsonBodyToSend:
  327. {
  328. "start": "0",
  329. "limit": "10
  330. }
  331. Returns:
  332. 200 OK with json object {list[dict[str, Any]], count} or empty object.
  333. """
  334. UserID.from_string(target_user_id)
  335. requester = yield self.auth.get_user_by_req(request)
  336. is_admin = yield self.auth.is_server_admin(requester.user)
  337. if not is_admin:
  338. raise AuthError(403, "You are not a server admin")
  339. order = "name" # order by name in user table
  340. params = parse_json_object_from_request(request)
  341. limit = params['limit']
  342. start = params['start']
  343. if not limit:
  344. raise SynapseError(400, "Missing 'limit' arg")
  345. if not start:
  346. raise SynapseError(400, "Missing 'start' arg")
  347. logger.info("limit: %s, start: %s", limit, start)
  348. ret = yield self.handlers.admin_handler.get_users_paginate(
  349. order, start, limit
  350. )
  351. defer.returnValue((200, ret))
  352. class SearchUsersRestServlet(ClientV1RestServlet):
  353. """Get request to search user table for specific users according to
  354. search term.
  355. This needs user to have administrator access in Synapse.
  356. Example:
  357. http://localhost:8008/_matrix/client/api/v1/admin/search_users/
  358. @admin:user?access_token=admin_access_token&term=alice
  359. Returns:
  360. 200 OK with json object {list[dict[str, Any]], count} or empty object.
  361. """
  362. PATTERNS = client_path_patterns("/admin/search_users/(?P<target_user_id>[^/]*)")
  363. def __init__(self, hs):
  364. self.store = hs.get_datastore()
  365. super(SearchUsersRestServlet, self).__init__(hs)
  366. self.hs = hs
  367. self.auth = hs.get_auth()
  368. self.handlers = hs.get_handlers()
  369. @defer.inlineCallbacks
  370. def on_GET(self, request, target_user_id):
  371. """Get request to search user table for specific users according to
  372. search term.
  373. This needs user to have a administrator access in Synapse.
  374. """
  375. target_user = UserID.from_string(target_user_id)
  376. requester = yield self.auth.get_user_by_req(request)
  377. is_admin = yield self.auth.is_server_admin(requester.user)
  378. if not is_admin:
  379. raise AuthError(403, "You are not a server admin")
  380. # To allow all users to get the users list
  381. # if not is_admin and target_user != auth_user:
  382. # raise AuthError(403, "You are not a server admin")
  383. if not self.hs.is_mine(target_user):
  384. raise SynapseError(400, "Can only users a local user")
  385. term = request.args.get("term")[0]
  386. if not term:
  387. raise SynapseError(400, "Missing 'term' arg")
  388. logger.info("term: %s ", term)
  389. ret = yield self.handlers.admin_handler.search_users(
  390. term
  391. )
  392. defer.returnValue((200, ret))
  393. def register_servlets(hs, http_server):
  394. WhoisRestServlet(hs).register(http_server)
  395. PurgeMediaCacheRestServlet(hs).register(http_server)
  396. DeactivateAccountRestServlet(hs).register(http_server)
  397. PurgeHistoryRestServlet(hs).register(http_server)
  398. UsersRestServlet(hs).register(http_server)
  399. ResetPasswordRestServlet(hs).register(http_server)
  400. GetUsersPaginatedRestServlet(hs).register(http_server)
  401. SearchUsersRestServlet(hs).register(http_server)
  402. ShutdownRoomRestServlet(hs).register(http_server)
  403. QuarantineMediaInRoom(hs).register(http_server)
  404. ListMediaInRoom(hs).register(http_server)