12b36a1c081cb9c24d8f85a951c0ee12cee5463e
[akkoma] / lib / pleroma / web / admin_api / admin_api_controller.ex
1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2019 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
4
5 defmodule Pleroma.Web.AdminAPI.AdminAPIController do
6 @users_page_size 50
7
8 use Pleroma.Web, :controller
9 alias Pleroma.User
10 alias Pleroma.Web.ActivityPub.Relay
11 alias Pleroma.Web.MastodonAPI.Admin.AccountView
12
13 import Pleroma.Web.ControllerHelper, only: [json_response: 3]
14
15 require Logger
16
17 action_fallback(:errors)
18
19 def user_delete(conn, %{"nickname" => nickname}) do
20 User.get_by_nickname(nickname)
21 |> User.delete()
22
23 conn
24 |> json(nickname)
25 end
26
27 def user_create(
28 conn,
29 %{"nickname" => nickname, "email" => email, "password" => password}
30 ) do
31 user_data = %{
32 nickname: nickname,
33 name: nickname,
34 email: email,
35 password: password,
36 password_confirmation: password,
37 bio: "."
38 }
39
40 changeset = User.register_changeset(%User{}, user_data, confirmed: true)
41 {:ok, user} = User.register(changeset)
42
43 conn
44 |> json(user.nickname)
45 end
46
47 def user_toggle_activation(conn, %{"nickname" => nickname}) do
48 user = User.get_by_nickname(nickname)
49
50 {:ok, updated_user} = User.deactivate(user, !user.info.deactivated)
51
52 conn
53 |> json(AccountView.render("show.json", %{user: updated_user}))
54 end
55
56 def tag_users(conn, %{"nicknames" => nicknames, "tags" => tags}) do
57 with {:ok, _} <- User.tag(nicknames, tags),
58 do: json_response(conn, :no_content, "")
59 end
60
61 def untag_users(conn, %{"nicknames" => nicknames, "tags" => tags}) do
62 with {:ok, _} <- User.untag(nicknames, tags),
63 do: json_response(conn, :no_content, "")
64 end
65
66 # def list_users(conn, params) do
67 # {page, page_size} = page_params(params)
68
69 # with {:ok, users, count} <- User.all_for_admin(page, page_size),
70 # do:
71 # conn
72 # |> json(
73 # AccountView.render("index.json",
74 # users: users,
75 # count: count,
76 # page_size: page_size
77 # )
78 # )
79 # end
80
81 def list_users(%{assigns: %{user: admin}} = conn, params) do
82 {page, page_size} = page_params(params)
83
84 with {:ok, users, count} <-
85 User.search_for_admin(%{
86 query: params["query"],
87 admin: admin,
88 local: params["local_only"] == "true",
89 page: page,
90 page_size: page_size
91 }),
92 do:
93 conn
94 |> json(
95 AccountView.render("index.json",
96 users: users,
97 count: count,
98 page_size: page_size
99 )
100 )
101 end
102
103 def right_add(conn, %{"permission_group" => permission_group, "nickname" => nickname})
104 when permission_group in ["moderator", "admin"] do
105 user = User.get_by_nickname(nickname)
106
107 info =
108 %{}
109 |> Map.put("is_" <> permission_group, true)
110
111 info_cng = User.Info.admin_api_update(user.info, info)
112
113 cng =
114 user
115 |> Ecto.Changeset.change()
116 |> Ecto.Changeset.put_embed(:info, info_cng)
117
118 {:ok, _user} = User.update_and_set_cache(cng)
119
120 json(conn, info)
121 end
122
123 def right_add(conn, _) do
124 conn
125 |> put_status(404)
126 |> json(%{error: "No such permission_group"})
127 end
128
129 def right_get(conn, %{"nickname" => nickname}) do
130 user = User.get_by_nickname(nickname)
131
132 conn
133 |> json(%{
134 is_moderator: user.info.is_moderator,
135 is_admin: user.info.is_admin
136 })
137 end
138
139 def right_delete(
140 %{assigns: %{user: %User{:nickname => admin_nickname}}} = conn,
141 %{
142 "permission_group" => permission_group,
143 "nickname" => nickname
144 }
145 )
146 when permission_group in ["moderator", "admin"] do
147 if admin_nickname == nickname do
148 conn
149 |> put_status(403)
150 |> json(%{error: "You can't revoke your own admin status."})
151 else
152 user = User.get_by_nickname(nickname)
153
154 info =
155 %{}
156 |> Map.put("is_" <> permission_group, false)
157
158 info_cng = User.Info.admin_api_update(user.info, info)
159
160 cng =
161 Ecto.Changeset.change(user)
162 |> Ecto.Changeset.put_embed(:info, info_cng)
163
164 {:ok, _user} = User.update_and_set_cache(cng)
165
166 json(conn, info)
167 end
168 end
169
170 def right_delete(conn, _) do
171 conn
172 |> put_status(404)
173 |> json(%{error: "No such permission_group"})
174 end
175
176 def set_activation_status(conn, %{"nickname" => nickname, "status" => status}) do
177 with {:ok, status} <- Ecto.Type.cast(:boolean, status),
178 %User{} = user <- User.get_by_nickname(nickname),
179 {:ok, _} <- User.deactivate(user, !status),
180 do: json_response(conn, :no_content, "")
181 end
182
183 def relay_follow(conn, %{"relay_url" => target}) do
184 with {:ok, _message} <- Relay.follow(target) do
185 json(conn, target)
186 else
187 _ ->
188 conn
189 |> put_status(500)
190 |> json(target)
191 end
192 end
193
194 def relay_unfollow(conn, %{"relay_url" => target}) do
195 with {:ok, _message} <- Relay.unfollow(target) do
196 json(conn, target)
197 else
198 _ ->
199 conn
200 |> put_status(500)
201 |> json(target)
202 end
203 end
204
205 @doc "Sends registration invite via email"
206 def email_invite(%{assigns: %{user: user}} = conn, %{"email" => email} = params) do
207 with true <-
208 Pleroma.Config.get([:instance, :invites_enabled]) &&
209 !Pleroma.Config.get([:instance, :registrations_open]),
210 {:ok, invite_token} <- Pleroma.UserInviteToken.create_token(),
211 email <-
212 Pleroma.UserEmail.user_invitation_email(user, invite_token, email, params["name"]),
213 {:ok, _} <- Pleroma.Mailer.deliver(email) do
214 json_response(conn, :no_content, "")
215 end
216 end
217
218 @doc "Get a account registeration invite token (base64 string)"
219 def get_invite_token(conn, _params) do
220 {:ok, token} = Pleroma.UserInviteToken.create_token()
221
222 conn
223 |> json(token.token)
224 end
225
226 @doc "Get a password reset token (base64 string) for given nickname"
227 def get_password_reset(conn, %{"nickname" => nickname}) do
228 (%User{local: true} = user) = User.get_by_nickname(nickname)
229 {:ok, token} = Pleroma.PasswordResetToken.create_token(user)
230
231 conn
232 |> json(token.token)
233 end
234
235 def errors(conn, {:param_cast, _}) do
236 conn
237 |> put_status(400)
238 |> json("Invalid parameters")
239 end
240
241 def errors(conn, _) do
242 conn
243 |> put_status(500)
244 |> json("Something went wrong")
245 end
246
247 defp page_params(params) do
248 {get_page(params["page"]), get_page_size(params["page_size"])}
249 end
250
251 defp get_page(page_string) when is_nil(page_string), do: 1
252
253 defp get_page(page_string) do
254 case Integer.parse(page_string) do
255 {page, _} -> page
256 :error -> 1
257 end
258 end
259
260 defp get_page_size(page_size_string) when is_nil(page_size_string), do: @users_page_size
261
262 defp get_page_size(page_size_string) do
263 case Integer.parse(page_size_string) do
264 {page_size, _} -> page_size
265 :error -> @users_page_size
266 end
267 end
268 end