entry_handlers.go 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564
  1. // SPDX-FileCopyrightText: Copyright The Miniflux Authors. All rights reserved.
  2. // SPDX-License-Identifier: Apache-2.0
  3. package api // import "miniflux.app/v2/internal/api"
  4. import (
  5. json_parser "encoding/json"
  6. "errors"
  7. "net/http"
  8. "strconv"
  9. "time"
  10. "miniflux.app/v2/internal/config"
  11. "miniflux.app/v2/internal/crypto"
  12. "miniflux.app/v2/internal/http/request"
  13. "miniflux.app/v2/internal/http/response"
  14. "miniflux.app/v2/internal/integration"
  15. "miniflux.app/v2/internal/mediaproxy"
  16. "miniflux.app/v2/internal/model"
  17. "miniflux.app/v2/internal/reader/processor"
  18. "miniflux.app/v2/internal/reader/readingtime"
  19. "miniflux.app/v2/internal/reader/sanitizer"
  20. "miniflux.app/v2/internal/storage"
  21. "miniflux.app/v2/internal/validator"
  22. )
  23. func (h *handler) getEntryFromBuilder(w http.ResponseWriter, r *http.Request, b *storage.EntryQueryBuilder) {
  24. entry, err := b.GetEntry()
  25. if err != nil {
  26. response.JSONServerError(w, r, err)
  27. return
  28. }
  29. if entry == nil {
  30. response.JSONNotFound(w, r)
  31. return
  32. }
  33. entry.Content = mediaproxy.RewriteDocumentWithAbsoluteProxyURL(entry.Content)
  34. entry.Enclosures.ProxifyEnclosureURL(config.Opts.MediaProxyMode(), config.Opts.MediaProxyResourceTypes())
  35. response.JSON(w, r, entry)
  36. }
  37. func (h *handler) getFeedEntryHandler(w http.ResponseWriter, r *http.Request) {
  38. feedID := request.RouteInt64Param(r, "feedID")
  39. if feedID == 0 {
  40. response.JSONBadRequest(w, r, errors.New("invalid feed ID"))
  41. return
  42. }
  43. entryID := request.RouteInt64Param(r, "entryID")
  44. if entryID == 0 {
  45. response.JSONBadRequest(w, r, errors.New("invalid entry ID"))
  46. return
  47. }
  48. builder := h.store.NewEntryQueryBuilder(request.UserID(r))
  49. builder.WithFeedID(feedID)
  50. builder.WithEntryID(entryID)
  51. builder.WithoutStatus(model.EntryStatusRemoved)
  52. h.getEntryFromBuilder(w, r, builder)
  53. }
  54. func (h *handler) getCategoryEntryHandler(w http.ResponseWriter, r *http.Request) {
  55. categoryID := request.RouteInt64Param(r, "categoryID")
  56. if categoryID == 0 {
  57. response.JSONBadRequest(w, r, errors.New("invalid category ID"))
  58. return
  59. }
  60. entryID := request.RouteInt64Param(r, "entryID")
  61. if entryID == 0 {
  62. response.JSONBadRequest(w, r, errors.New("invalid entry ID"))
  63. return
  64. }
  65. builder := h.store.NewEntryQueryBuilder(request.UserID(r))
  66. builder.WithCategoryID(categoryID)
  67. builder.WithEntryID(entryID)
  68. builder.WithoutStatus(model.EntryStatusRemoved)
  69. h.getEntryFromBuilder(w, r, builder)
  70. }
  71. func (h *handler) getEntryHandler(w http.ResponseWriter, r *http.Request) {
  72. entryID := request.RouteInt64Param(r, "entryID")
  73. if entryID == 0 {
  74. response.JSONBadRequest(w, r, errors.New("invalid entry ID"))
  75. return
  76. }
  77. builder := h.store.NewEntryQueryBuilder(request.UserID(r))
  78. builder.WithEntryID(entryID)
  79. builder.WithoutStatus(model.EntryStatusRemoved)
  80. h.getEntryFromBuilder(w, r, builder)
  81. }
  82. func (h *handler) getFeedEntriesHandler(w http.ResponseWriter, r *http.Request) {
  83. feedID := request.RouteInt64Param(r, "feedID")
  84. if feedID == 0 {
  85. response.JSONBadRequest(w, r, errors.New("invalid feed ID"))
  86. return
  87. }
  88. h.findEntries(w, r, feedID, 0)
  89. }
  90. func (h *handler) getCategoryEntriesHandler(w http.ResponseWriter, r *http.Request) {
  91. categoryID := request.RouteInt64Param(r, "categoryID")
  92. if categoryID == 0 {
  93. response.JSONBadRequest(w, r, errors.New("invalid category ID"))
  94. return
  95. }
  96. h.findEntries(w, r, 0, categoryID)
  97. }
  98. func (h *handler) getEntriesHandler(w http.ResponseWriter, r *http.Request) {
  99. h.findEntries(w, r, 0, 0)
  100. }
  101. func (h *handler) findEntries(w http.ResponseWriter, r *http.Request, feedID int64, categoryID int64) {
  102. statuses := request.QueryStringParamList(r, "status")
  103. for _, status := range statuses {
  104. if err := validator.ValidateEntryStatus(status); err != nil {
  105. response.JSONBadRequest(w, r, err)
  106. return
  107. }
  108. }
  109. order := request.QueryStringParam(r, "order", model.DefaultSortingOrder)
  110. if err := validator.ValidateEntryOrder(order); err != nil {
  111. response.JSONBadRequest(w, r, err)
  112. return
  113. }
  114. direction := request.QueryStringParam(r, "direction", model.DefaultSortingDirection)
  115. if err := validator.ValidateDirection(direction); err != nil {
  116. response.JSONBadRequest(w, r, err)
  117. return
  118. }
  119. limit := request.QueryIntParam(r, "limit", 100)
  120. offset := request.QueryIntParam(r, "offset", 0)
  121. if err := validator.ValidateRange(offset, limit); err != nil {
  122. response.JSONBadRequest(w, r, err)
  123. return
  124. }
  125. userID := request.UserID(r)
  126. categoryID = request.QueryInt64Param(r, "category_id", categoryID)
  127. if categoryID > 0 && !h.store.CategoryIDExists(userID, categoryID) {
  128. response.JSONBadRequest(w, r, errors.New("invalid category ID"))
  129. return
  130. }
  131. feedID = request.QueryInt64Param(r, "feed_id", feedID)
  132. if feedID > 0 && !h.store.FeedExists(userID, feedID) {
  133. response.JSONBadRequest(w, r, errors.New("invalid feed ID"))
  134. return
  135. }
  136. tags := request.QueryStringParamList(r, "tags")
  137. builder := h.store.NewEntryQueryBuilder(userID)
  138. builder.WithFeedID(feedID)
  139. builder.WithCategoryID(categoryID)
  140. builder.WithStatuses(statuses)
  141. builder.WithSorting(order, direction)
  142. builder.WithOffset(offset)
  143. builder.WithLimit(limit)
  144. builder.WithTags(tags)
  145. builder.WithEnclosures()
  146. builder.WithoutStatus(model.EntryStatusRemoved)
  147. if request.HasQueryParam(r, "globally_visible") {
  148. globallyVisible := request.QueryBoolParam(r, "globally_visible", true)
  149. if globallyVisible {
  150. builder.WithGloballyVisible()
  151. }
  152. }
  153. configureFilters(builder, r)
  154. entries, err := builder.GetEntries()
  155. if err != nil {
  156. response.JSONServerError(w, r, err)
  157. return
  158. }
  159. count, err := builder.CountEntries()
  160. if err != nil {
  161. response.JSONServerError(w, r, err)
  162. return
  163. }
  164. for i := range entries {
  165. entries[i].Content = mediaproxy.RewriteDocumentWithAbsoluteProxyURL(entries[i].Content)
  166. }
  167. response.JSON(w, r, &entriesResponse{Total: count, Entries: entries})
  168. }
  169. func (h *handler) setEntryStatusHandler(w http.ResponseWriter, r *http.Request) {
  170. var entriesStatusUpdateRequest model.EntriesStatusUpdateRequest
  171. if err := json_parser.NewDecoder(r.Body).Decode(&entriesStatusUpdateRequest); err != nil {
  172. response.JSONBadRequest(w, r, err)
  173. return
  174. }
  175. if err := validator.ValidateEntriesStatusUpdateRequest(&entriesStatusUpdateRequest); err != nil {
  176. response.JSONBadRequest(w, r, err)
  177. return
  178. }
  179. if err := h.store.SetEntriesStatus(request.UserID(r), entriesStatusUpdateRequest.EntryIDs, entriesStatusUpdateRequest.Status); err != nil {
  180. response.JSONServerError(w, r, err)
  181. return
  182. }
  183. response.NoContent(w, r)
  184. }
  185. func (h *handler) toggleStarredHandler(w http.ResponseWriter, r *http.Request) {
  186. entryID := request.RouteInt64Param(r, "entryID")
  187. if entryID == 0 {
  188. response.JSONBadRequest(w, r, errors.New("invalid entry ID"))
  189. return
  190. }
  191. if err := h.store.ToggleStarred(request.UserID(r), entryID); err != nil {
  192. response.JSONServerError(w, r, err)
  193. return
  194. }
  195. response.NoContent(w, r)
  196. }
  197. func (h *handler) saveEntryHandler(w http.ResponseWriter, r *http.Request) {
  198. entryID := request.RouteInt64Param(r, "entryID")
  199. if entryID == 0 {
  200. response.JSONBadRequest(w, r, errors.New("invalid entry ID"))
  201. return
  202. }
  203. builder := h.store.NewEntryQueryBuilder(request.UserID(r))
  204. builder.WithEntryID(entryID)
  205. builder.WithoutStatus(model.EntryStatusRemoved)
  206. if !h.store.HasSaveEntry(request.UserID(r)) {
  207. response.JSONBadRequest(w, r, errors.New("no third-party integration enabled"))
  208. return
  209. }
  210. entry, err := builder.GetEntry()
  211. if err != nil {
  212. response.JSONServerError(w, r, err)
  213. return
  214. }
  215. if entry == nil {
  216. response.JSONNotFound(w, r)
  217. return
  218. }
  219. settings, err := h.store.Integration(request.UserID(r))
  220. if err != nil {
  221. response.JSONServerError(w, r, err)
  222. return
  223. }
  224. go integration.SendEntry(entry, settings)
  225. response.JSONAccepted(w, r)
  226. }
  227. func (h *handler) updateEntryHandler(w http.ResponseWriter, r *http.Request) {
  228. var entryUpdateRequest model.EntryUpdateRequest
  229. if err := json_parser.NewDecoder(r.Body).Decode(&entryUpdateRequest); err != nil {
  230. response.JSONBadRequest(w, r, err)
  231. return
  232. }
  233. if err := validator.ValidateEntryModification(&entryUpdateRequest); err != nil {
  234. response.JSONBadRequest(w, r, err)
  235. return
  236. }
  237. entryID := request.RouteInt64Param(r, "entryID")
  238. if entryID == 0 {
  239. response.JSONBadRequest(w, r, errors.New("invalid entry ID"))
  240. return
  241. }
  242. loggedUserID := request.UserID(r)
  243. entryBuilder := h.store.NewEntryQueryBuilder(loggedUserID)
  244. entryBuilder.WithEntryID(entryID)
  245. entryBuilder.WithoutStatus(model.EntryStatusRemoved)
  246. entry, err := entryBuilder.GetEntry()
  247. if err != nil {
  248. response.JSONServerError(w, r, err)
  249. return
  250. }
  251. if entry == nil {
  252. response.JSONNotFound(w, r)
  253. return
  254. }
  255. user, err := h.store.UserByID(loggedUserID)
  256. if err != nil {
  257. response.JSONServerError(w, r, err)
  258. return
  259. }
  260. if user == nil {
  261. response.JSONNotFound(w, r)
  262. return
  263. }
  264. if entryUpdateRequest.Content != nil {
  265. sanitizedContent := sanitizer.SanitizeHTML(entry.URL, *entryUpdateRequest.Content, &sanitizer.SanitizerOptions{OpenLinksInNewTab: user.OpenExternalLinksInNewTab})
  266. entryUpdateRequest.Content = &sanitizedContent
  267. }
  268. entryUpdateRequest.Patch(entry)
  269. if user.ShowReadingTime {
  270. entry.ReadingTime = readingtime.EstimateReadingTime(entry.Content, user.DefaultReadingSpeed, user.CJKReadingSpeed)
  271. }
  272. if err := h.store.UpdateEntryTitleAndContent(entry); err != nil {
  273. response.JSONServerError(w, r, err)
  274. return
  275. }
  276. response.JSONCreated(w, r, entry)
  277. }
  278. func (h *handler) importFeedEntryHandler(w http.ResponseWriter, r *http.Request) {
  279. userID := request.UserID(r)
  280. feedID := request.RouteInt64Param(r, "feedID")
  281. if feedID <= 0 {
  282. response.JSONBadRequest(w, r, errors.New("invalid feed ID"))
  283. return
  284. }
  285. if !h.store.FeedExists(userID, feedID) {
  286. response.JSONBadRequest(w, r, errors.New("feed does not exist"))
  287. return
  288. }
  289. var importRequest entryImportRequest
  290. if err := json_parser.NewDecoder(r.Body).Decode(&importRequest); err != nil {
  291. response.JSONBadRequest(w, r, err)
  292. return
  293. }
  294. if importRequest.URL == "" {
  295. response.JSONBadRequest(w, r, errors.New("url is required"))
  296. return
  297. }
  298. if importRequest.Status == "" {
  299. importRequest.Status = model.EntryStatusRead
  300. }
  301. if err := validator.ValidateEntryStatus(importRequest.Status); err != nil {
  302. response.JSONBadRequest(w, r, err)
  303. return
  304. }
  305. entry := model.NewEntry()
  306. entry.URL = importRequest.URL
  307. entry.CommentsURL = importRequest.CommentsURL
  308. entry.Author = importRequest.Author
  309. entry.Tags = importRequest.Tags
  310. if importRequest.PublishedAt > 0 {
  311. entry.Date = time.Unix(importRequest.PublishedAt, 0).UTC()
  312. } else {
  313. entry.Date = time.Now().UTC()
  314. }
  315. if importRequest.Title == "" {
  316. entry.Title = entry.URL
  317. } else {
  318. entry.Title = importRequest.Title
  319. }
  320. hashInput := importRequest.ExternalID
  321. if hashInput == "" {
  322. hashInput = importRequest.URL
  323. }
  324. entry.Hash = crypto.HashFromBytes([]byte(hashInput))
  325. user, err := h.store.UserByID(userID)
  326. if err != nil {
  327. response.JSONServerError(w, r, err)
  328. return
  329. }
  330. if user == nil {
  331. response.JSONNotFound(w, r)
  332. return
  333. }
  334. if importRequest.Content != "" {
  335. entry.Content = sanitizer.SanitizeHTML(entry.URL, importRequest.Content, &sanitizer.SanitizerOptions{OpenLinksInNewTab: user.OpenExternalLinksInNewTab})
  336. }
  337. if user.ShowReadingTime {
  338. entry.ReadingTime = readingtime.EstimateReadingTime(entry.Content, user.DefaultReadingSpeed, user.CJKReadingSpeed)
  339. }
  340. created, err := h.store.InsertEntryForFeed(userID, feedID, entry)
  341. if err != nil {
  342. response.JSONServerError(w, r, err)
  343. return
  344. }
  345. if err := h.store.SetEntriesStatus(userID, []int64{entry.ID}, importRequest.Status); err != nil {
  346. response.JSONServerError(w, r, err)
  347. return
  348. }
  349. entry.Status = importRequest.Status
  350. if importRequest.Starred {
  351. if err := h.store.SetEntriesStarredState(userID, []int64{entry.ID}, true); err != nil {
  352. response.JSONServerError(w, r, err)
  353. return
  354. }
  355. entry.Starred = true
  356. }
  357. if created {
  358. response.JSONCreated(w, r, entryIDResponse{ID: entry.ID})
  359. } else {
  360. response.JSON(w, r, entryIDResponse{ID: entry.ID})
  361. }
  362. }
  363. func (h *handler) fetchContentHandler(w http.ResponseWriter, r *http.Request) {
  364. loggedUserID := request.UserID(r)
  365. entryID := request.RouteInt64Param(r, "entryID")
  366. if entryID == 0 {
  367. response.JSONBadRequest(w, r, errors.New("invalid entry ID"))
  368. return
  369. }
  370. entryBuilder := h.store.NewEntryQueryBuilder(loggedUserID)
  371. entryBuilder.WithEntryID(entryID)
  372. entryBuilder.WithoutStatus(model.EntryStatusRemoved)
  373. entry, err := entryBuilder.GetEntry()
  374. if err != nil {
  375. response.JSONServerError(w, r, err)
  376. return
  377. }
  378. if entry == nil {
  379. response.JSONNotFound(w, r)
  380. return
  381. }
  382. user, err := h.store.UserByID(loggedUserID)
  383. if err != nil {
  384. response.JSONServerError(w, r, err)
  385. return
  386. }
  387. if user == nil {
  388. response.JSONNotFound(w, r)
  389. return
  390. }
  391. feedBuilder := storage.NewFeedQueryBuilder(h.store, loggedUserID)
  392. feedBuilder.WithFeedID(entry.FeedID)
  393. feed, err := feedBuilder.GetFeed()
  394. if err != nil {
  395. response.JSONServerError(w, r, err)
  396. return
  397. }
  398. if feed == nil {
  399. response.JSONNotFound(w, r)
  400. return
  401. }
  402. if err := processor.ProcessEntryWebPage(feed, entry, user); err != nil {
  403. response.JSONServerError(w, r, err)
  404. return
  405. }
  406. shouldUpdateContent := request.QueryBoolParam(r, "update_content", false)
  407. if shouldUpdateContent {
  408. if err := h.store.UpdateEntryTitleAndContent(entry); err != nil {
  409. response.JSONServerError(w, r, err)
  410. return
  411. }
  412. }
  413. response.JSON(w, r, entryContentResponse{Content: mediaproxy.RewriteDocumentWithAbsoluteProxyURL(entry.Content), ReadingTime: entry.ReadingTime})
  414. }
  415. func (h *handler) flushHistoryHandler(w http.ResponseWriter, r *http.Request) {
  416. loggedUserID := request.UserID(r)
  417. go h.store.FlushHistory(loggedUserID)
  418. response.JSONAccepted(w, r)
  419. }
  420. func configureFilters(builder *storage.EntryQueryBuilder, r *http.Request) {
  421. if beforeEntryID := request.QueryInt64Param(r, "before_entry_id", 0); beforeEntryID > 0 {
  422. builder.BeforeEntryID(beforeEntryID)
  423. }
  424. if afterEntryID := request.QueryInt64Param(r, "after_entry_id", 0); afterEntryID > 0 {
  425. builder.AfterEntryID(afterEntryID)
  426. }
  427. if beforePublishedTimestamp := request.QueryInt64Param(r, "before", 0); beforePublishedTimestamp > 0 {
  428. builder.BeforePublishedDate(time.Unix(beforePublishedTimestamp, 0))
  429. }
  430. if afterPublishedTimestamp := request.QueryInt64Param(r, "after", 0); afterPublishedTimestamp > 0 {
  431. builder.AfterPublishedDate(time.Unix(afterPublishedTimestamp, 0))
  432. }
  433. if beforePublishedTimestamp := request.QueryInt64Param(r, "published_before", 0); beforePublishedTimestamp > 0 {
  434. builder.BeforePublishedDate(time.Unix(beforePublishedTimestamp, 0))
  435. }
  436. if afterPublishedTimestamp := request.QueryInt64Param(r, "published_after", 0); afterPublishedTimestamp > 0 {
  437. builder.AfterPublishedDate(time.Unix(afterPublishedTimestamp, 0))
  438. }
  439. if beforeChangedTimestamp := request.QueryInt64Param(r, "changed_before", 0); beforeChangedTimestamp > 0 {
  440. builder.BeforeChangedDate(time.Unix(beforeChangedTimestamp, 0))
  441. }
  442. if afterChangedTimestamp := request.QueryInt64Param(r, "changed_after", 0); afterChangedTimestamp > 0 {
  443. builder.AfterChangedDate(time.Unix(afterChangedTimestamp, 0))
  444. }
  445. if categoryID := request.QueryInt64Param(r, "category_id", 0); categoryID > 0 {
  446. builder.WithCategoryID(categoryID)
  447. }
  448. if request.HasQueryParam(r, "starred") {
  449. starred, err := strconv.ParseBool(r.URL.Query().Get("starred"))
  450. if err == nil {
  451. builder.WithStarred(starred)
  452. }
  453. }
  454. if searchQuery := request.QueryStringParam(r, "search", ""); searchQuery != "" {
  455. builder.WithSearchQuery(searchQuery)
  456. }
  457. }