Add more admin actions
[akkoma] / lib / pleroma / web / admin_api / admin_api_controller.ex
1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2019 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
4
5 defmodule Pleroma.Web.AdminAPI.AdminAPIController do
6 use Pleroma.Web, :controller
7 alias Pleroma.User
8 alias Pleroma.Web.ActivityPub.Relay
9 alias Pleroma.Web.TwitterAPI.UserView
10
11 import Pleroma.Web.ControllerHelper, only: [json_response: 3]
12
13 require Logger
14
15 action_fallback(:errors)
16
17 def user_delete(conn, %{"nickname" => nickname}) do
18 User.get_by_nickname(nickname)
19 |> User.delete()
20
21 conn
22 |> json(nickname)
23 end
24
25 def user_create(
26 conn,
27 %{"nickname" => nickname, "email" => email, "password" => password}
28 ) do
29 user_data = %{
30 nickname: nickname,
31 name: nickname,
32 email: email,
33 password: password,
34 password_confirmation: password,
35 bio: "."
36 }
37
38 changeset = User.register_changeset(%User{}, user_data, confirmed: true)
39 {:ok, user} = User.register(changeset)
40
41 conn
42 |> json(user.nickname)
43 end
44
45 def user_toggle_activation(conn, %{"nickname" => nickname}) do
46 user = User.get_by_nickname(nickname)
47
48 {:ok, updated_user} = User.deactivate(user, !user.info.deactivated)
49
50 conn
51 |> json(UserView.render("show_for_admin.json", %{user: updated_user}))
52 end
53
54 def tag_users(conn, %{"nicknames" => nicknames, "tags" => tags}) do
55 with {:ok, _} <- User.tag(nicknames, tags),
56 do: json_response(conn, :no_content, "")
57 end
58
59 def untag_users(conn, %{"nicknames" => nicknames, "tags" => tags}) do
60 with {:ok, _} <- User.untag(nicknames, tags),
61 do: json_response(conn, :no_content, "")
62 end
63
64 def list_users(%{assigns: %{user: admin}} = conn, _data) do
65 users = User.all_except_one(admin)
66
67 conn
68 |> json(UserView.render("index_for_admin.json", %{users: users}))
69 end
70
71 def right_add(conn, %{"permission_group" => permission_group, "nickname" => nickname})
72 when permission_group in ["moderator", "admin"] do
73 user = User.get_by_nickname(nickname)
74
75 info =
76 %{}
77 |> Map.put("is_" <> permission_group, true)
78
79 info_cng = User.Info.admin_api_update(user.info, info)
80
81 cng =
82 user
83 |> Ecto.Changeset.change()
84 |> Ecto.Changeset.put_embed(:info, info_cng)
85
86 {:ok, _user} = User.update_and_set_cache(cng)
87
88 json(conn, info)
89 end
90
91 def right_add(conn, _) do
92 conn
93 |> put_status(404)
94 |> json(%{error: "No such permission_group"})
95 end
96
97 def right_get(conn, %{"nickname" => nickname}) do
98 user = User.get_by_nickname(nickname)
99
100 conn
101 |> json(%{
102 is_moderator: user.info.is_moderator,
103 is_admin: user.info.is_admin
104 })
105 end
106
107 def right_delete(
108 %{assigns: %{user: %User{:nickname => admin_nickname}}} = conn,
109 %{
110 "permission_group" => permission_group,
111 "nickname" => nickname
112 }
113 )
114 when permission_group in ["moderator", "admin"] do
115 if admin_nickname == nickname do
116 conn
117 |> put_status(403)
118 |> json(%{error: "You can't revoke your own admin status."})
119 else
120 user = User.get_by_nickname(nickname)
121
122 info =
123 %{}
124 |> Map.put("is_" <> permission_group, false)
125
126 info_cng = User.Info.admin_api_update(user.info, info)
127
128 cng =
129 Ecto.Changeset.change(user)
130 |> Ecto.Changeset.put_embed(:info, info_cng)
131
132 {:ok, _user} = User.update_and_set_cache(cng)
133
134 json(conn, info)
135 end
136 end
137
138 def right_delete(conn, _) do
139 conn
140 |> put_status(404)
141 |> json(%{error: "No such permission_group"})
142 end
143
144 def set_activation_status(conn, %{"nickname" => nickname, "status" => status}) do
145 with {:ok, status} <- Ecto.Type.cast(:boolean, status),
146 %User{} = user <- User.get_by_nickname(nickname),
147 {:ok, _} <- User.deactivate(user, !status),
148 do: json_response(conn, :no_content, "")
149 end
150
151 def relay_follow(conn, %{"relay_url" => target}) do
152 with {:ok, _message} <- Relay.follow(target) do
153 json(conn, target)
154 else
155 _ ->
156 conn
157 |> put_status(500)
158 |> json(target)
159 end
160 end
161
162 def relay_unfollow(conn, %{"relay_url" => target}) do
163 with {:ok, _message} <- Relay.unfollow(target) do
164 json(conn, target)
165 else
166 _ ->
167 conn
168 |> put_status(500)
169 |> json(target)
170 end
171 end
172
173 @doc "Sends registration invite via email"
174 def email_invite(%{assigns: %{user: user}} = conn, %{"email" => email} = params) do
175 with true <-
176 Pleroma.Config.get([:instance, :invites_enabled]) &&
177 !Pleroma.Config.get([:instance, :registrations_open]),
178 {:ok, invite_token} <- Pleroma.UserInviteToken.create_token(),
179 email <-
180 Pleroma.UserEmail.user_invitation_email(user, invite_token, email, params["name"]),
181 {:ok, _} <- Pleroma.Mailer.deliver(email) do
182 json_response(conn, :no_content, "")
183 end
184 end
185
186 @doc "Get a account registeration invite token (base64 string)"
187 def get_invite_token(conn, _params) do
188 {:ok, token} = Pleroma.UserInviteToken.create_token()
189
190 conn
191 |> json(token.token)
192 end
193
194 @doc "Get a password reset token (base64 string) for given nickname"
195 def get_password_reset(conn, %{"nickname" => nickname}) do
196 (%User{local: true} = user) = User.get_by_nickname(nickname)
197 {:ok, token} = Pleroma.PasswordResetToken.create_token(user)
198
199 conn
200 |> json(token.token)
201 end
202
203 def errors(conn, {:param_cast, _}) do
204 conn
205 |> put_status(400)
206 |> json("Invalid parameters")
207 end
208
209 def errors(conn, _) do
210 conn
211 |> put_status(500)
212 |> json("Something went wrong")
213 end
214 end