mirror of
https://github.com/NodeBB/NodeBB.git
synced 2026-01-25 08:49:51 +01:00
* feat: webpack 5 part 1 * fix: gruntfile fixes * fix: fix taskbar warning add app.importScript copy public/src/modules to build folder * refactor: remove commented old code * feat: reenable admin * fix: acp settings pages, fix sortable on manage categories embedded require in html not allowed * fix: bundle serialize/deserizeli so plugins dont break * test: fixe util tests * test: fix require path * test: more test fixes * test: require correct utils module * test: require correct utils * test: log stack * test: fix db require blowing up tests * test: move and disable bundle test * refactor: add aliases * test: disable testing route * fix: move webpack modules necessary for build, into `dependencies` * test: fix one more test remove 500-embed.tpl * fix: restore use of assets/nodebb.min.js, at least for now * fix: remove unnecessary line break * fix: point to proper ACP bundle * test: maybe fix build test * test: composer * refactor: dont need dist * refactor: more cleanup use everything from build/public folder * get rid of conditional import in app.js * fix: ace * refactor: cropper alias * test: lint and test fixes * lint: fix * refactor: rename function to app.require * refactor: go back to using app.require * chore: use github branch * chore: use webpack branch * feat: webpack webinstaller * feat: add chunkFile name with contenthash * refactor: move hooks to top * refactor: get rid of template500Function * fix(deps): use webpack5 branch of 2factor plugin * chore: tagging v2.0.0-beta.0 pre-release version 💥 :shipit: 🎉 🚀 * refactor: disable cache on templates loadTemplate is called once by benchpress and the result is cache internally * refactor: add server side helpers.js * feat: deprecate /plugins shorthand route, closes #10343 * refactor: use build/public for webpack * test: fix filename * fix: more specific selector * lint: ignore * refactor: fix comments * test: add debug for random failing test * refactor: cleanup remove test page, remove dupe functions in utils.common * lint: use relative path for now * chore: bump prerelease version * feat: add translateKeys * fix: optional params * fix: get rid of extra timeago files * refactor: cleanup, require timeago locale earlier remove translator.prepareDOM, it is in header.tpl html tag * refactor: privileges system to use a Map in the backend instead of separate objects for keys and labels (#10378) * refactor: privileges system to use a Map in the backend instead of separate objects for keys and labels - Existing hooks are preserved (to be deprecated at a later date, possibly) - New init hooks are called on NodeBB start, and provide a one-stop shop to add new privileges, instead of having to add to four different hooks * docs: fix typo in comment * test: spec changes * refactor: privileges system to use a Map in the backend instead of separate objects for keys and labels (#10378) * refactor: privileges system to use a Map in the backend instead of separate objects for keys and labels - Existing hooks are preserved (to be deprecated at a later date, possibly) - New init hooks are called on NodeBB start, and provide a one-stop shop to add new privileges, instead of having to add to four different hooks * docs: fix typo in comment * test: spec changes * feat: allow app.require('bootbox'/'benchpressjs') * refactor: require server side utils * test: jquery ready * change istaller to use build/public * test: use document.addEventListener * refactor: closes #10301 * refactor: generateTopicClass * fix: column counts for other privileges * fix: #10443, regression where sorted-list items did not render into the DOM in the predicted order [breaking] * fix: typo in hook name * refactor: introduce a generic autocomplete.init() method that can be called to add nodebb-style autocompletion but using different data sources (e.g. not user/groups/tags) * fix: crash if `delay` not passed in (as it cannot be destructured) * refactor: replace substr * feat: set --panel-offset style in html element based on stored value in localStorage * refactor: addDropupHandler() logic to be less naive - Take into account height of the menu - Don't apply dropUp logic if there's nothing in the dropdown - Remove 'hidden' class (added by default in Persona for post tools) when menu items are added closes #10423 * refactor: simplify utils.params [breaking] Retrospective analysis of the usage of this method suggests that the options passed in are superfluous, and that only `url` is required. Using a browser built-in makes more sense to accomplish what this method sets out to do. * feat: add support for returning full URLSearchParams for utils.params * fix: utils.params() fallback handling * fix: default empty obj for params() * fix: remove \'loggedin\' and \'register\' qs parameters once they have been used, delay invocation of messages until ajaxify.end * fix: utils.params() not allowing relative paths to be passed in * refactor(DRY): new assertPasswordValidity utils method * fix: incorrect error message returned on insufficient privilege on flag edit * fix: read/update/delete access to flags API should be limited for moderators to only post flags in categories they moderate - added failing tests and patched up middleware.assert.flags to fix * refactor: flag api v3 tests to create new post and flags on every round * fix: missing error:no-flag language key * refactor: flags.canView to check flag existence, simplify middleware.assert.flag * feat: flag deletion API endpoint, #10426 * feat: UI for flag deletion, closes #10426 * chore: update plugin versions * chore: up emoji * chore: update markdown * chore: up emoji-android * fix: regression caused by utils.params() refactor, supports arrays and pipes all values through utils.toType, adjusts tests to type check Co-authored-by: Julian Lam <julian@nodebb.org>
177 lines
5.7 KiB
JavaScript
177 lines
5.7 KiB
JavaScript
'use strict';
|
|
|
|
const winston = require('winston');
|
|
const jsesc = require('jsesc');
|
|
const nconf = require('nconf');
|
|
const semver = require('semver');
|
|
|
|
const user = require('../user');
|
|
const meta = require('../meta');
|
|
const plugins = require('../plugins');
|
|
const privileges = require('../privileges');
|
|
const utils = require('../utils');
|
|
const versions = require('../admin/versions');
|
|
const helpers = require('./helpers');
|
|
|
|
const controllers = {
|
|
api: require('../controllers/api'),
|
|
helpers: require('../controllers/helpers'),
|
|
};
|
|
|
|
const middleware = module.exports;
|
|
|
|
middleware.buildHeader = helpers.try(async (req, res, next) => {
|
|
res.locals.renderAdminHeader = true;
|
|
if (req.method === 'GET') {
|
|
await require('./index').applyCSRFasync(req, res);
|
|
}
|
|
|
|
res.locals.config = await controllers.api.loadConfig(req);
|
|
next();
|
|
});
|
|
|
|
middleware.renderHeader = async (req, res, data) => {
|
|
const custom_header = {
|
|
plugins: [],
|
|
authentication: [],
|
|
};
|
|
res.locals.config = res.locals.config || {};
|
|
|
|
const results = await utils.promiseParallel({
|
|
userData: user.getUserFields(req.uid, ['username', 'userslug', 'email', 'picture', 'email:confirmed']),
|
|
scripts: getAdminScripts(),
|
|
custom_header: plugins.hooks.fire('filter:admin.header.build', custom_header),
|
|
configs: meta.configs.list(),
|
|
latestVersion: getLatestVersion(),
|
|
privileges: privileges.admin.get(req.uid),
|
|
tags: meta.tags.parse(req, {}, [], []),
|
|
});
|
|
|
|
const { userData } = results;
|
|
userData.uid = req.uid;
|
|
userData['email:confirmed'] = userData['email:confirmed'] === 1;
|
|
userData.privileges = results.privileges;
|
|
|
|
let acpPath = req.path.slice(1).split('/');
|
|
acpPath.forEach((path, i) => {
|
|
acpPath[i] = path.charAt(0).toUpperCase() + path.slice(1);
|
|
});
|
|
acpPath = acpPath.join(' > ');
|
|
|
|
const version = nconf.get('version');
|
|
|
|
res.locals.config.userLang = res.locals.config.acpLang || res.locals.config.userLang;
|
|
let templateValues = {
|
|
config: res.locals.config,
|
|
configJSON: jsesc(JSON.stringify(res.locals.config), { isScriptContext: true }),
|
|
relative_path: res.locals.config.relative_path,
|
|
adminConfigJSON: encodeURIComponent(JSON.stringify(results.configs)),
|
|
metaTags: results.tags.meta,
|
|
linkTags: results.tags.link,
|
|
user: userData,
|
|
userJSON: jsesc(JSON.stringify(userData), { isScriptContext: true }),
|
|
plugins: results.custom_header.plugins,
|
|
authentication: results.custom_header.authentication,
|
|
scripts: results.scripts,
|
|
'cache-buster': meta.config['cache-buster'] || '',
|
|
env: !!process.env.NODE_ENV,
|
|
title: `${acpPath || 'Dashboard'} | NodeBB Admin Control Panel`,
|
|
bodyClass: data.bodyClass,
|
|
version: version,
|
|
latestVersion: results.latestVersion,
|
|
upgradeAvailable: results.latestVersion && semver.gt(results.latestVersion, version),
|
|
showManageMenu: results.privileges.superadmin || ['categories', 'privileges', 'users', 'admins-mods', 'groups', 'tags', 'settings'].some(priv => results.privileges[`admin:${priv}`]),
|
|
};
|
|
|
|
templateValues.template = { name: res.locals.template };
|
|
templateValues.template[res.locals.template] = true;
|
|
({ templateData: templateValues } = await plugins.hooks.fire('filter:middleware.renderAdminHeader', {
|
|
req,
|
|
res,
|
|
templateData: templateValues,
|
|
data,
|
|
}));
|
|
|
|
return await req.app.renderAsync('admin/header', templateValues);
|
|
};
|
|
|
|
async function getAdminScripts() {
|
|
const scripts = await plugins.hooks.fire('filter:admin.scripts.get', []);
|
|
return scripts.map(script => ({ src: script }));
|
|
}
|
|
|
|
async function getLatestVersion() {
|
|
try {
|
|
const result = await versions.getLatestVersion();
|
|
return result;
|
|
} catch (err) {
|
|
winston.error(`[acp] Failed to fetch latest version${err.stack}`);
|
|
}
|
|
return null;
|
|
}
|
|
|
|
middleware.renderFooter = async function (req, res, data) {
|
|
return await req.app.renderAsync('admin/footer', data);
|
|
};
|
|
|
|
middleware.checkPrivileges = helpers.try(async (req, res, next) => {
|
|
// Kick out guests, obviously
|
|
if (req.uid <= 0) {
|
|
return controllers.helpers.notAllowed(req, res);
|
|
}
|
|
|
|
// Otherwise, check for privilege based on page (if not in mapping, deny access)
|
|
const path = req.path.replace(/^(\/api)?(\/v3)?\/admin\/?/g, '');
|
|
if (path) {
|
|
const privilege = privileges.admin.resolve(path);
|
|
if (!await privileges.admin.can(privilege, req.uid)) {
|
|
return controllers.helpers.notAllowed(req, res);
|
|
}
|
|
} else {
|
|
// If accessing /admin, check for any valid admin privs
|
|
const privilegeSet = await privileges.admin.get(req.uid);
|
|
if (!Object.values(privilegeSet).some(Boolean)) {
|
|
return controllers.helpers.notAllowed(req, res);
|
|
}
|
|
}
|
|
|
|
// If user does not have password
|
|
const hasPassword = await user.hasPassword(req.uid);
|
|
if (!hasPassword) {
|
|
return next();
|
|
}
|
|
|
|
// Reject if they need to re-login (due to ACP timeout), otherwise extend logout timer
|
|
const loginTime = req.session.meta ? req.session.meta.datetime : 0;
|
|
const adminReloginDuration = meta.config.adminReloginDuration * 60000;
|
|
const disabled = meta.config.adminReloginDuration === 0;
|
|
if (disabled || (loginTime && parseInt(loginTime, 10) > Date.now() - adminReloginDuration)) {
|
|
const timeLeft = parseInt(loginTime, 10) - (Date.now() - adminReloginDuration);
|
|
if (req.session.meta && timeLeft < Math.min(60000, adminReloginDuration)) {
|
|
req.session.meta.datetime += Math.min(60000, adminReloginDuration);
|
|
}
|
|
|
|
return next();
|
|
}
|
|
|
|
let returnTo = req.path;
|
|
if (nconf.get('relative_path')) {
|
|
returnTo = req.path.replace(new RegExp(`^${nconf.get('relative_path')}`), '');
|
|
}
|
|
returnTo = returnTo.replace(/^\/api/, '');
|
|
|
|
req.session.returnTo = returnTo;
|
|
req.session.forceLogin = 1;
|
|
|
|
await plugins.hooks.fire('response:auth.relogin', { req, res });
|
|
if (res.headersSent) {
|
|
return;
|
|
}
|
|
|
|
if (res.locals.isAPI) {
|
|
res.status(401).json({});
|
|
} else {
|
|
res.redirect(`${nconf.get('relative_path')}/login?local=1`);
|
|
}
|
|
});
|