allow users to disable their own account
[akkoma] / lib / pleroma / web / admin_api / admin_api_controller.ex
1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2019 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
4
5 defmodule Pleroma.Web.AdminAPI.AdminAPIController do
6 @users_page_size 50
7
8 use Pleroma.Web, :controller
9 alias Pleroma.User
10 alias Pleroma.Web.ActivityPub.Relay
11 alias Pleroma.Web.MastodonAPI.Admin.AccountView
12
13 import Pleroma.Web.ControllerHelper, only: [json_response: 3]
14
15 require Logger
16
17 action_fallback(:errors)
18
19 def user_delete(conn, %{"nickname" => nickname}) do
20 User.get_by_nickname(nickname)
21 |> User.delete()
22
23 conn
24 |> json(nickname)
25 end
26
27 def user_create(
28 conn,
29 %{"nickname" => nickname, "email" => email, "password" => password}
30 ) do
31 user_data = %{
32 nickname: nickname,
33 name: nickname,
34 email: email,
35 password: password,
36 password_confirmation: password,
37 bio: "."
38 }
39
40 changeset = User.register_changeset(%User{}, user_data, confirmed: true)
41 {:ok, user} = User.register(changeset)
42
43 conn
44 |> json(user.nickname)
45 end
46
47 def user_toggle_disabled(conn, %{"nickname" => nickname}) do
48 user = User.get_by_nickname(nickname)
49
50 {:ok, updated_user} = User.disable(user, !user.info.disabled)
51
52 conn
53 |> put_view(AccountView)
54 |> render("show.json", %{user: updated_user})
55 end
56
57 def user_toggle_activation(conn, %{"nickname" => nickname}) do
58 user = User.get_by_nickname(nickname)
59
60 {:ok, updated_user} = User.deactivate(user, !user.info.deactivated)
61
62 conn
63 |> json(AccountView.render("show.json", %{user: updated_user}))
64 end
65
66 def tag_users(conn, %{"nicknames" => nicknames, "tags" => tags}) do
67 with {:ok, _} <- User.tag(nicknames, tags),
68 do: json_response(conn, :no_content, "")
69 end
70
71 def untag_users(conn, %{"nicknames" => nicknames, "tags" => tags}) do
72 with {:ok, _} <- User.untag(nicknames, tags),
73 do: json_response(conn, :no_content, "")
74 end
75
76 def list_users(conn, params) do
77 {page, page_size} = page_params(params)
78
79 with {:ok, users, count} <- User.all_for_admin(page, page_size),
80 do:
81 conn
82 |> json(
83 AccountView.render("index.json",
84 users: users,
85 count: count,
86 page_size: page_size
87 )
88 )
89 end
90
91 def search_users(%{assigns: %{user: admin}} = conn, %{"query" => query} = params) do
92 {page, page_size} = page_params(params)
93
94 with {:ok, users, count} <-
95 User.search_for_admin(query, %{
96 admin: admin,
97 local: params["local"] == "true",
98 page: page,
99 page_size: page_size
100 }),
101 do:
102 conn
103 |> json(
104 AccountView.render("index.json",
105 users: users,
106 count: count,
107 page_size: page_size
108 )
109 )
110 end
111
112 def right_add(conn, %{"permission_group" => permission_group, "nickname" => nickname})
113 when permission_group in ["moderator", "admin"] do
114 user = User.get_by_nickname(nickname)
115
116 info =
117 %{}
118 |> Map.put("is_" <> permission_group, true)
119
120 info_cng = User.Info.admin_api_update(user.info, info)
121
122 cng =
123 user
124 |> Ecto.Changeset.change()
125 |> Ecto.Changeset.put_embed(:info, info_cng)
126
127 {:ok, _user} = User.update_and_set_cache(cng)
128
129 json(conn, info)
130 end
131
132 def right_add(conn, _) do
133 conn
134 |> put_status(404)
135 |> json(%{error: "No such permission_group"})
136 end
137
138 def right_get(conn, %{"nickname" => nickname}) do
139 user = User.get_by_nickname(nickname)
140
141 conn
142 |> json(%{
143 is_moderator: user.info.is_moderator,
144 is_admin: user.info.is_admin
145 })
146 end
147
148 def right_delete(
149 %{assigns: %{user: %User{:nickname => admin_nickname}}} = conn,
150 %{
151 "permission_group" => permission_group,
152 "nickname" => nickname
153 }
154 )
155 when permission_group in ["moderator", "admin"] do
156 if admin_nickname == nickname do
157 conn
158 |> put_status(403)
159 |> json(%{error: "You can't revoke your own admin status."})
160 else
161 user = User.get_by_nickname(nickname)
162
163 info =
164 %{}
165 |> Map.put("is_" <> permission_group, false)
166
167 info_cng = User.Info.admin_api_update(user.info, info)
168
169 cng =
170 Ecto.Changeset.change(user)
171 |> Ecto.Changeset.put_embed(:info, info_cng)
172
173 {:ok, _user} = User.update_and_set_cache(cng)
174
175 json(conn, info)
176 end
177 end
178
179 def right_delete(conn, _) do
180 conn
181 |> put_status(404)
182 |> json(%{error: "No such permission_group"})
183 end
184
185 def set_activation_status(conn, %{"nickname" => nickname, "status" => status}) do
186 with {:ok, status} <- Ecto.Type.cast(:boolean, status),
187 %User{} = user <- User.get_by_nickname(nickname),
188 {:ok, _} <- User.deactivate(user, !status),
189 do: json_response(conn, :no_content, "")
190 end
191
192 def relay_follow(conn, %{"relay_url" => target}) do
193 with {:ok, _message} <- Relay.follow(target) do
194 json(conn, target)
195 else
196 _ ->
197 conn
198 |> put_status(500)
199 |> json(target)
200 end
201 end
202
203 def relay_unfollow(conn, %{"relay_url" => target}) do
204 with {:ok, _message} <- Relay.unfollow(target) do
205 json(conn, target)
206 else
207 _ ->
208 conn
209 |> put_status(500)
210 |> json(target)
211 end
212 end
213
214 @doc "Sends registration invite via email"
215 def email_invite(%{assigns: %{user: user}} = conn, %{"email" => email} = params) do
216 with true <-
217 Pleroma.Config.get([:instance, :invites_enabled]) &&
218 !Pleroma.Config.get([:instance, :registrations_open]),
219 {:ok, invite_token} <- Pleroma.UserInviteToken.create_token(),
220 email <-
221 Pleroma.UserEmail.user_invitation_email(user, invite_token, email, params["name"]),
222 {:ok, _} <- Pleroma.Mailer.deliver(email) do
223 json_response(conn, :no_content, "")
224 end
225 end
226
227 @doc "Get a account registeration invite token (base64 string)"
228 def get_invite_token(conn, _params) do
229 {:ok, token} = Pleroma.UserInviteToken.create_token()
230
231 conn
232 |> json(token.token)
233 end
234
235 @doc "Get a password reset token (base64 string) for given nickname"
236 def get_password_reset(conn, %{"nickname" => nickname}) do
237 (%User{local: true} = user) = User.get_by_nickname(nickname)
238 {:ok, token} = Pleroma.PasswordResetToken.create_token(user)
239
240 conn
241 |> json(token.token)
242 end
243
244 def errors(conn, {:param_cast, _}) do
245 conn
246 |> put_status(400)
247 |> json("Invalid parameters")
248 end
249
250 def errors(conn, _) do
251 conn
252 |> put_status(500)
253 |> json("Something went wrong")
254 end
255
256 defp page_params(params) do
257 {get_page(params["page"]), get_page_size(params["page_size"])}
258 end
259
260 defp get_page(page_string) when is_nil(page_string), do: 1
261
262 defp get_page(page_string) do
263 case Integer.parse(page_string) do
264 {page, _} -> page
265 :error -> 1
266 end
267 end
268
269 defp get_page_size(page_size_string) when is_nil(page_size_string), do: @users_page_size
270
271 defp get_page_size(page_size_string) do
272 case Integer.parse(page_size_string) do
273 {page_size, _} -> page_size
274 :error -> @users_page_size
275 end
276 end
277 end