entry.go 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513
  1. // SPDX-FileCopyrightText: Copyright The Miniflux Authors. All rights reserved.
  2. // SPDX-License-Identifier: Apache-2.0
  3. package api // import "miniflux.app/v2/internal/api"
  4. import (
  5. json_parser "encoding/json"
  6. "errors"
  7. "net/http"
  8. "strconv"
  9. "time"
  10. "miniflux.app/v2/internal/config"
  11. "miniflux.app/v2/internal/crypto"
  12. "miniflux.app/v2/internal/http/request"
  13. "miniflux.app/v2/internal/http/response/json"
  14. "miniflux.app/v2/internal/integration"
  15. "miniflux.app/v2/internal/mediaproxy"
  16. "miniflux.app/v2/internal/model"
  17. "miniflux.app/v2/internal/reader/processor"
  18. "miniflux.app/v2/internal/reader/readingtime"
  19. "miniflux.app/v2/internal/reader/sanitizer"
  20. "miniflux.app/v2/internal/storage"
  21. "miniflux.app/v2/internal/validator"
  22. )
  23. func (h *handler) getEntryFromBuilder(w http.ResponseWriter, r *http.Request, b *storage.EntryQueryBuilder) {
  24. entry, err := b.GetEntry()
  25. if err != nil {
  26. json.ServerError(w, r, err)
  27. return
  28. }
  29. if entry == nil {
  30. json.NotFound(w, r)
  31. return
  32. }
  33. entry.Content = mediaproxy.RewriteDocumentWithAbsoluteProxyURL(h.router, entry.Content)
  34. entry.Enclosures.ProxifyEnclosureURL(h.router, config.Opts.MediaProxyMode(), config.Opts.MediaProxyResourceTypes())
  35. json.OK(w, r, entry)
  36. }
  37. func (h *handler) getFeedEntry(w http.ResponseWriter, r *http.Request) {
  38. feedID := request.RouteInt64Param(r, "feedID")
  39. entryID := request.RouteInt64Param(r, "entryID")
  40. builder := h.store.NewEntryQueryBuilder(request.UserID(r))
  41. builder.WithFeedID(feedID)
  42. builder.WithEntryID(entryID)
  43. builder.WithoutStatus(model.EntryStatusRemoved)
  44. h.getEntryFromBuilder(w, r, builder)
  45. }
  46. func (h *handler) getCategoryEntry(w http.ResponseWriter, r *http.Request) {
  47. categoryID := request.RouteInt64Param(r, "categoryID")
  48. entryID := request.RouteInt64Param(r, "entryID")
  49. builder := h.store.NewEntryQueryBuilder(request.UserID(r))
  50. builder.WithCategoryID(categoryID)
  51. builder.WithEntryID(entryID)
  52. builder.WithoutStatus(model.EntryStatusRemoved)
  53. h.getEntryFromBuilder(w, r, builder)
  54. }
  55. func (h *handler) getEntry(w http.ResponseWriter, r *http.Request) {
  56. entryID := request.RouteInt64Param(r, "entryID")
  57. builder := h.store.NewEntryQueryBuilder(request.UserID(r))
  58. builder.WithEntryID(entryID)
  59. builder.WithoutStatus(model.EntryStatusRemoved)
  60. h.getEntryFromBuilder(w, r, builder)
  61. }
  62. func (h *handler) getFeedEntries(w http.ResponseWriter, r *http.Request) {
  63. feedID := request.RouteInt64Param(r, "feedID")
  64. h.findEntries(w, r, feedID, 0)
  65. }
  66. func (h *handler) getCategoryEntries(w http.ResponseWriter, r *http.Request) {
  67. categoryID := request.RouteInt64Param(r, "categoryID")
  68. h.findEntries(w, r, 0, categoryID)
  69. }
  70. func (h *handler) getEntries(w http.ResponseWriter, r *http.Request) {
  71. h.findEntries(w, r, 0, 0)
  72. }
  73. func (h *handler) findEntries(w http.ResponseWriter, r *http.Request, feedID int64, categoryID int64) {
  74. statuses := request.QueryStringParamList(r, "status")
  75. for _, status := range statuses {
  76. if err := validator.ValidateEntryStatus(status); err != nil {
  77. json.BadRequest(w, r, err)
  78. return
  79. }
  80. }
  81. order := request.QueryStringParam(r, "order", model.DefaultSortingOrder)
  82. if err := validator.ValidateEntryOrder(order); err != nil {
  83. json.BadRequest(w, r, err)
  84. return
  85. }
  86. direction := request.QueryStringParam(r, "direction", model.DefaultSortingDirection)
  87. if err := validator.ValidateDirection(direction); err != nil {
  88. json.BadRequest(w, r, err)
  89. return
  90. }
  91. limit := request.QueryIntParam(r, "limit", 100)
  92. offset := request.QueryIntParam(r, "offset", 0)
  93. if err := validator.ValidateRange(offset, limit); err != nil {
  94. json.BadRequest(w, r, err)
  95. return
  96. }
  97. userID := request.UserID(r)
  98. categoryID = request.QueryInt64Param(r, "category_id", categoryID)
  99. if categoryID > 0 && !h.store.CategoryIDExists(userID, categoryID) {
  100. json.BadRequest(w, r, errors.New("invalid category ID"))
  101. return
  102. }
  103. feedID = request.QueryInt64Param(r, "feed_id", feedID)
  104. if feedID > 0 && !h.store.FeedExists(userID, feedID) {
  105. json.BadRequest(w, r, errors.New("invalid feed ID"))
  106. return
  107. }
  108. tags := request.QueryStringParamList(r, "tags")
  109. builder := h.store.NewEntryQueryBuilder(userID)
  110. builder.WithFeedID(feedID)
  111. builder.WithCategoryID(categoryID)
  112. builder.WithStatuses(statuses)
  113. builder.WithSorting(order, direction)
  114. builder.WithOffset(offset)
  115. builder.WithLimit(limit)
  116. builder.WithTags(tags)
  117. builder.WithEnclosures()
  118. builder.WithoutStatus(model.EntryStatusRemoved)
  119. if request.HasQueryParam(r, "globally_visible") {
  120. globallyVisible := request.QueryBoolParam(r, "globally_visible", true)
  121. if globallyVisible {
  122. builder.WithGloballyVisible()
  123. }
  124. }
  125. configureFilters(builder, r)
  126. entries, err := builder.GetEntries()
  127. if err != nil {
  128. json.ServerError(w, r, err)
  129. return
  130. }
  131. count, err := builder.CountEntries()
  132. if err != nil {
  133. json.ServerError(w, r, err)
  134. return
  135. }
  136. for i := range entries {
  137. entries[i].Content = mediaproxy.RewriteDocumentWithAbsoluteProxyURL(h.router, entries[i].Content)
  138. }
  139. json.OK(w, r, &entriesResponse{Total: count, Entries: entries})
  140. }
  141. func (h *handler) setEntryStatus(w http.ResponseWriter, r *http.Request) {
  142. var entriesStatusUpdateRequest model.EntriesStatusUpdateRequest
  143. if err := json_parser.NewDecoder(r.Body).Decode(&entriesStatusUpdateRequest); err != nil {
  144. json.BadRequest(w, r, err)
  145. return
  146. }
  147. if err := validator.ValidateEntriesStatusUpdateRequest(&entriesStatusUpdateRequest); err != nil {
  148. json.BadRequest(w, r, err)
  149. return
  150. }
  151. if err := h.store.SetEntriesStatus(request.UserID(r), entriesStatusUpdateRequest.EntryIDs, entriesStatusUpdateRequest.Status); err != nil {
  152. json.ServerError(w, r, err)
  153. return
  154. }
  155. json.NoContent(w, r)
  156. }
  157. func (h *handler) toggleStarred(w http.ResponseWriter, r *http.Request) {
  158. entryID := request.RouteInt64Param(r, "entryID")
  159. if err := h.store.ToggleStarred(request.UserID(r), entryID); err != nil {
  160. json.ServerError(w, r, err)
  161. return
  162. }
  163. json.NoContent(w, r)
  164. }
  165. func (h *handler) saveEntry(w http.ResponseWriter, r *http.Request) {
  166. entryID := request.RouteInt64Param(r, "entryID")
  167. builder := h.store.NewEntryQueryBuilder(request.UserID(r))
  168. builder.WithEntryID(entryID)
  169. builder.WithoutStatus(model.EntryStatusRemoved)
  170. if !h.store.HasSaveEntry(request.UserID(r)) {
  171. json.BadRequest(w, r, errors.New("no third-party integration enabled"))
  172. return
  173. }
  174. entry, err := builder.GetEntry()
  175. if err != nil {
  176. json.ServerError(w, r, err)
  177. return
  178. }
  179. if entry == nil {
  180. json.NotFound(w, r)
  181. return
  182. }
  183. settings, err := h.store.Integration(request.UserID(r))
  184. if err != nil {
  185. json.ServerError(w, r, err)
  186. return
  187. }
  188. go integration.SendEntry(entry, settings)
  189. json.Accepted(w, r)
  190. }
  191. func (h *handler) updateEntry(w http.ResponseWriter, r *http.Request) {
  192. var entryUpdateRequest model.EntryUpdateRequest
  193. if err := json_parser.NewDecoder(r.Body).Decode(&entryUpdateRequest); err != nil {
  194. json.BadRequest(w, r, err)
  195. return
  196. }
  197. if err := validator.ValidateEntryModification(&entryUpdateRequest); err != nil {
  198. json.BadRequest(w, r, err)
  199. return
  200. }
  201. loggedUserID := request.UserID(r)
  202. entryID := request.RouteInt64Param(r, "entryID")
  203. entryBuilder := h.store.NewEntryQueryBuilder(loggedUserID)
  204. entryBuilder.WithEntryID(entryID)
  205. entryBuilder.WithoutStatus(model.EntryStatusRemoved)
  206. entry, err := entryBuilder.GetEntry()
  207. if err != nil {
  208. json.ServerError(w, r, err)
  209. return
  210. }
  211. if entry == nil {
  212. json.NotFound(w, r)
  213. return
  214. }
  215. user, err := h.store.UserByID(loggedUserID)
  216. if err != nil {
  217. json.ServerError(w, r, err)
  218. return
  219. }
  220. if user == nil {
  221. json.NotFound(w, r)
  222. return
  223. }
  224. if entryUpdateRequest.Content != nil {
  225. sanitizedContent := sanitizer.SanitizeHTML(entry.URL, *entryUpdateRequest.Content, &sanitizer.SanitizerOptions{OpenLinksInNewTab: user.OpenExternalLinksInNewTab})
  226. entryUpdateRequest.Content = &sanitizedContent
  227. }
  228. entryUpdateRequest.Patch(entry)
  229. if user.ShowReadingTime {
  230. entry.ReadingTime = readingtime.EstimateReadingTime(entry.Content, user.DefaultReadingSpeed, user.CJKReadingSpeed)
  231. }
  232. if err := h.store.UpdateEntryTitleAndContent(entry); err != nil {
  233. json.ServerError(w, r, err)
  234. return
  235. }
  236. json.Created(w, r, entry)
  237. }
  238. func (h *handler) importFeedEntry(w http.ResponseWriter, r *http.Request) {
  239. userID := request.UserID(r)
  240. feedID := request.RouteInt64Param(r, "feedID")
  241. if feedID <= 0 {
  242. json.BadRequest(w, r, errors.New("invalid feed ID"))
  243. return
  244. }
  245. if !h.store.FeedExists(userID, feedID) {
  246. json.BadRequest(w, r, errors.New("feed does not exist"))
  247. return
  248. }
  249. var importRequest entryImportRequest
  250. if err := json_parser.NewDecoder(r.Body).Decode(&importRequest); err != nil {
  251. json.BadRequest(w, r, err)
  252. return
  253. }
  254. if importRequest.URL == "" {
  255. json.BadRequest(w, r, errors.New("url is required"))
  256. return
  257. }
  258. if importRequest.Status == "" {
  259. importRequest.Status = model.EntryStatusRead
  260. }
  261. if err := validator.ValidateEntryStatus(importRequest.Status); err != nil {
  262. json.BadRequest(w, r, err)
  263. return
  264. }
  265. entry := model.NewEntry()
  266. entry.URL = importRequest.URL
  267. entry.CommentsURL = importRequest.CommentsURL
  268. entry.Author = importRequest.Author
  269. entry.Tags = importRequest.Tags
  270. if importRequest.PublishedAt > 0 {
  271. entry.Date = time.Unix(importRequest.PublishedAt, 0).UTC()
  272. } else {
  273. entry.Date = time.Now().UTC()
  274. }
  275. if importRequest.Title == "" {
  276. entry.Title = entry.URL
  277. } else {
  278. entry.Title = importRequest.Title
  279. }
  280. hashInput := importRequest.ExternalID
  281. if hashInput == "" {
  282. hashInput = importRequest.URL
  283. }
  284. entry.Hash = crypto.HashFromBytes([]byte(hashInput))
  285. user, err := h.store.UserByID(userID)
  286. if err != nil {
  287. json.ServerError(w, r, err)
  288. return
  289. }
  290. if user == nil {
  291. json.NotFound(w, r)
  292. return
  293. }
  294. if importRequest.Content != "" {
  295. entry.Content = sanitizer.SanitizeHTML(entry.URL, importRequest.Content, &sanitizer.SanitizerOptions{OpenLinksInNewTab: user.OpenExternalLinksInNewTab})
  296. }
  297. if user.ShowReadingTime {
  298. entry.ReadingTime = readingtime.EstimateReadingTime(entry.Content, user.DefaultReadingSpeed, user.CJKReadingSpeed)
  299. }
  300. created, err := h.store.InsertEntryForFeed(userID, feedID, entry)
  301. if err != nil {
  302. json.ServerError(w, r, err)
  303. return
  304. }
  305. if err := h.store.SetEntriesStatus(userID, []int64{entry.ID}, importRequest.Status); err != nil {
  306. json.ServerError(w, r, err)
  307. return
  308. }
  309. entry.Status = importRequest.Status
  310. if importRequest.Starred {
  311. if err := h.store.SetEntriesStarredState(userID, []int64{entry.ID}, true); err != nil {
  312. json.ServerError(w, r, err)
  313. return
  314. }
  315. entry.Starred = true
  316. }
  317. if created {
  318. json.Created(w, r, entryIDResponse{ID: entry.ID})
  319. } else {
  320. json.OK(w, r, entryIDResponse{ID: entry.ID})
  321. }
  322. }
  323. func (h *handler) fetchContent(w http.ResponseWriter, r *http.Request) {
  324. loggedUserID := request.UserID(r)
  325. entryID := request.RouteInt64Param(r, "entryID")
  326. entryBuilder := h.store.NewEntryQueryBuilder(loggedUserID)
  327. entryBuilder.WithEntryID(entryID)
  328. entryBuilder.WithoutStatus(model.EntryStatusRemoved)
  329. entry, err := entryBuilder.GetEntry()
  330. if err != nil {
  331. json.ServerError(w, r, err)
  332. return
  333. }
  334. if entry == nil {
  335. json.NotFound(w, r)
  336. return
  337. }
  338. user, err := h.store.UserByID(loggedUserID)
  339. if err != nil {
  340. json.ServerError(w, r, err)
  341. return
  342. }
  343. if user == nil {
  344. json.NotFound(w, r)
  345. return
  346. }
  347. feedBuilder := storage.NewFeedQueryBuilder(h.store, loggedUserID)
  348. feedBuilder.WithFeedID(entry.FeedID)
  349. feed, err := feedBuilder.GetFeed()
  350. if err != nil {
  351. json.ServerError(w, r, err)
  352. return
  353. }
  354. if feed == nil {
  355. json.NotFound(w, r)
  356. return
  357. }
  358. if err := processor.ProcessEntryWebPage(feed, entry, user); err != nil {
  359. json.ServerError(w, r, err)
  360. return
  361. }
  362. shouldUpdateContent := request.QueryBoolParam(r, "update_content", false)
  363. if shouldUpdateContent {
  364. if err := h.store.UpdateEntryTitleAndContent(entry); err != nil {
  365. json.ServerError(w, r, err)
  366. return
  367. }
  368. }
  369. json.OK(w, r, entryContentResponse{Content: mediaproxy.RewriteDocumentWithAbsoluteProxyURL(h.router, entry.Content), ReadingTime: entry.ReadingTime})
  370. }
  371. func (h *handler) flushHistory(w http.ResponseWriter, r *http.Request) {
  372. loggedUserID := request.UserID(r)
  373. go h.store.FlushHistory(loggedUserID)
  374. json.Accepted(w, r)
  375. }
  376. func configureFilters(builder *storage.EntryQueryBuilder, r *http.Request) {
  377. if beforeEntryID := request.QueryInt64Param(r, "before_entry_id", 0); beforeEntryID > 0 {
  378. builder.BeforeEntryID(beforeEntryID)
  379. }
  380. if afterEntryID := request.QueryInt64Param(r, "after_entry_id", 0); afterEntryID > 0 {
  381. builder.AfterEntryID(afterEntryID)
  382. }
  383. if beforePublishedTimestamp := request.QueryInt64Param(r, "before", 0); beforePublishedTimestamp > 0 {
  384. builder.BeforePublishedDate(time.Unix(beforePublishedTimestamp, 0))
  385. }
  386. if afterPublishedTimestamp := request.QueryInt64Param(r, "after", 0); afterPublishedTimestamp > 0 {
  387. builder.AfterPublishedDate(time.Unix(afterPublishedTimestamp, 0))
  388. }
  389. if beforePublishedTimestamp := request.QueryInt64Param(r, "published_before", 0); beforePublishedTimestamp > 0 {
  390. builder.BeforePublishedDate(time.Unix(beforePublishedTimestamp, 0))
  391. }
  392. if afterPublishedTimestamp := request.QueryInt64Param(r, "published_after", 0); afterPublishedTimestamp > 0 {
  393. builder.AfterPublishedDate(time.Unix(afterPublishedTimestamp, 0))
  394. }
  395. if beforeChangedTimestamp := request.QueryInt64Param(r, "changed_before", 0); beforeChangedTimestamp > 0 {
  396. builder.BeforeChangedDate(time.Unix(beforeChangedTimestamp, 0))
  397. }
  398. if afterChangedTimestamp := request.QueryInt64Param(r, "changed_after", 0); afterChangedTimestamp > 0 {
  399. builder.AfterChangedDate(time.Unix(afterChangedTimestamp, 0))
  400. }
  401. if categoryID := request.QueryInt64Param(r, "category_id", 0); categoryID > 0 {
  402. builder.WithCategoryID(categoryID)
  403. }
  404. if request.HasQueryParam(r, "starred") {
  405. starred, err := strconv.ParseBool(r.URL.Query().Get("starred"))
  406. if err == nil {
  407. builder.WithStarred(starred)
  408. }
  409. }
  410. if searchQuery := request.QueryStringParam(r, "search", ""); searchQuery != "" {
  411. builder.WithSearchQuery(searchQuery)
  412. }
  413. }