PeerTube/server/middlewares/validators/videos/video-comments.ts

234 lines
8.2 KiB
TypeScript
Raw Normal View History

2017-12-22 03:50:07 -06:00
import * as express from 'express'
import { body, param } from 'express-validator/check'
2018-10-05 04:15:06 -05:00
import { UserRight } from '../../../../shared'
import { isIdOrUUIDValid, isIdValid } from '../../../helpers/custom-validators/misc'
import { isValidVideoCommentText } from '../../../helpers/custom-validators/video-comments'
2019-03-19 03:26:50 -05:00
import { doesVideoExist } from '../../../helpers/custom-validators/videos'
2018-10-05 04:15:06 -05:00
import { logger } from '../../../helpers/logger'
import { UserModel } from '../../../models/account/user'
import { VideoModel } from '../../../models/video/video'
import { VideoCommentModel } from '../../../models/video/video-comment'
import { areValidationErrors } from '../utils'
2019-07-18 07:28:37 -05:00
import { Hooks } from '../../../lib/plugins/hooks'
import { isLocalVideoThreadAccepted, isLocalVideoCommentReplyAccepted, AcceptResult } from '../../../lib/moderation'
2017-12-22 03:50:07 -06:00
const listVideoCommentThreadsValidator = [
param('videoId').custom(isIdOrUUIDValid).not().isEmpty().withMessage('Should have a valid videoId'),
async (req: express.Request, res: express.Response, next: express.NextFunction) => {
2017-12-22 05:10:40 -06:00
logger.debug('Checking listVideoCommentThreads parameters.', { parameters: req.params })
2017-12-22 03:50:07 -06:00
if (areValidationErrors(req, res)) return
2019-03-19 03:26:50 -05:00
if (!await doesVideoExist(req.params.videoId, res, 'only-video')) return
2017-12-22 03:50:07 -06:00
return next()
}
]
const listVideoThreadCommentsValidator = [
param('videoId').custom(isIdOrUUIDValid).not().isEmpty().withMessage('Should have a valid videoId'),
param('threadId').custom(isIdValid).not().isEmpty().withMessage('Should have a valid threadId'),
async (req: express.Request, res: express.Response, next: express.NextFunction) => {
2017-12-22 05:10:40 -06:00
logger.debug('Checking listVideoThreadComments parameters.', { parameters: req.params })
2017-12-22 03:50:07 -06:00
if (areValidationErrors(req, res)) return
2019-03-19 03:26:50 -05:00
if (!await doesVideoExist(req.params.videoId, res, 'only-video')) return
if (!await doesVideoCommentThreadExist(req.params.threadId, res.locals.video, res)) return
2017-12-22 03:50:07 -06:00
return next()
}
]
const addVideoCommentThreadValidator = [
param('videoId').custom(isIdOrUUIDValid).not().isEmpty().withMessage('Should have a valid videoId'),
body('text').custom(isValidVideoCommentText).not().isEmpty().withMessage('Should have a valid comment text'),
async (req: express.Request, res: express.Response, next: express.NextFunction) => {
2018-02-20 03:41:11 -06:00
logger.debug('Checking addVideoCommentThread parameters.', { parameters: req.params, body: req.body })
2017-12-22 03:50:07 -06:00
if (areValidationErrors(req, res)) return
2019-03-19 03:26:50 -05:00
if (!await doesVideoExist(req.params.videoId, res)) return
2018-01-03 03:12:36 -06:00
if (!isVideoCommentsEnabled(res.locals.video, res)) return
2019-07-18 07:28:37 -05:00
if (!await isVideoCommentAccepted(req, res, false)) return
2017-12-22 03:50:07 -06:00
return next()
}
]
const addVideoCommentReplyValidator = [
param('videoId').custom(isIdOrUUIDValid).not().isEmpty().withMessage('Should have a valid videoId'),
param('commentId').custom(isIdValid).not().isEmpty().withMessage('Should have a valid commentId'),
body('text').custom(isValidVideoCommentText).not().isEmpty().withMessage('Should have a valid comment text'),
async (req: express.Request, res: express.Response, next: express.NextFunction) => {
2018-02-20 03:41:11 -06:00
logger.debug('Checking addVideoCommentReply parameters.', { parameters: req.params, body: req.body })
2017-12-22 03:50:07 -06:00
if (areValidationErrors(req, res)) return
2019-03-19 03:26:50 -05:00
if (!await doesVideoExist(req.params.videoId, res)) return
2018-01-03 03:12:36 -06:00
if (!isVideoCommentsEnabled(res.locals.video, res)) return
2019-03-19 03:26:50 -05:00
if (!await doesVideoCommentExist(req.params.commentId, res.locals.video, res)) return
2019-07-18 07:28:37 -05:00
if (!await isVideoCommentAccepted(req, res, true)) return
2017-12-22 03:50:07 -06:00
return next()
}
]
2017-12-28 04:16:08 -06:00
const videoCommentGetValidator = [
param('videoId').custom(isIdOrUUIDValid).not().isEmpty().withMessage('Should have a valid videoId'),
param('commentId').custom(isIdValid).not().isEmpty().withMessage('Should have a valid commentId'),
async (req: express.Request, res: express.Response, next: express.NextFunction) => {
logger.debug('Checking videoCommentGetValidator parameters.', { parameters: req.params })
if (areValidationErrors(req, res)) return
2019-03-19 03:26:50 -05:00
if (!await doesVideoExist(req.params.videoId, res, 'id')) return
if (!await doesVideoCommentExist(req.params.commentId, res.locals.video, res)) return
2017-12-28 04:16:08 -06:00
return next()
}
]
2018-01-04 04:19:16 -06:00
const removeVideoCommentValidator = [
param('videoId').custom(isIdOrUUIDValid).not().isEmpty().withMessage('Should have a valid videoId'),
param('commentId').custom(isIdValid).not().isEmpty().withMessage('Should have a valid commentId'),
async (req: express.Request, res: express.Response, next: express.NextFunction) => {
logger.debug('Checking removeVideoCommentValidator parameters.', { parameters: req.params })
if (areValidationErrors(req, res)) return
2019-03-19 03:26:50 -05:00
if (!await doesVideoExist(req.params.videoId, res)) return
if (!await doesVideoCommentExist(req.params.commentId, res.locals.video, res)) return
2018-01-04 04:19:16 -06:00
// Check if the user who did the request is able to delete the video
if (!checkUserCanDeleteVideoComment(res.locals.oauth.token.User, res.locals.videoComment, res)) return
return next()
}
]
2017-12-22 03:50:07 -06:00
// ---------------------------------------------------------------------------
export {
listVideoCommentThreadsValidator,
listVideoThreadCommentsValidator,
addVideoCommentThreadValidator,
2017-12-28 04:16:08 -06:00
addVideoCommentReplyValidator,
2018-01-04 04:19:16 -06:00
videoCommentGetValidator,
removeVideoCommentValidator
2017-12-22 03:50:07 -06:00
}
// ---------------------------------------------------------------------------
2019-03-19 03:26:50 -05:00
async function doesVideoCommentThreadExist (id: number, video: VideoModel, res: express.Response) {
2017-12-22 03:50:07 -06:00
const videoComment = await VideoCommentModel.loadById(id)
if (!videoComment) {
res.status(404)
.json({ error: 'Video comment thread not found' })
.end()
return false
}
2017-12-22 05:10:40 -06:00
if (videoComment.videoId !== video.id) {
2017-12-22 03:50:07 -06:00
res.status(400)
.json({ error: 'Video comment is associated to this video.' })
.end()
return false
}
if (videoComment.inReplyToCommentId !== null) {
res.status(400)
.json({ error: 'Video comment is not a thread.' })
.end()
return false
}
res.locals.videoCommentThread = videoComment
return true
}
2019-03-19 03:26:50 -05:00
async function doesVideoCommentExist (id: number, video: VideoModel, res: express.Response) {
2017-12-28 04:16:08 -06:00
const videoComment = await VideoCommentModel.loadByIdAndPopulateVideoAndAccountAndReply(id)
2017-12-22 03:50:07 -06:00
if (!videoComment) {
res.status(404)
.json({ error: 'Video comment thread not found' })
.end()
return false
}
2017-12-22 05:10:40 -06:00
if (videoComment.videoId !== video.id) {
2017-12-22 03:50:07 -06:00
res.status(400)
.json({ error: 'Video comment is associated to this video.' })
.end()
return false
}
res.locals.videoComment = videoComment
return true
}
2018-01-03 03:12:36 -06:00
function isVideoCommentsEnabled (video: VideoModel, res: express.Response) {
if (video.commentsEnabled !== true) {
res.status(409)
.json({ error: 'Video comments are disabled for this video.' })
.end()
return false
}
return true
}
2018-01-04 04:19:16 -06:00
function checkUserCanDeleteVideoComment (user: UserModel, videoComment: VideoCommentModel, res: express.Response) {
const account = videoComment.Account
if (user.hasRight(UserRight.REMOVE_ANY_VIDEO_COMMENT) === false && account.userId !== user.id) {
res.status(403)
.json({ error: 'Cannot remove video comment of another user' })
.end()
return false
}
return true
}
2019-07-18 07:28:37 -05:00
async function isVideoCommentAccepted (req: express.Request, res: express.Response, isReply: boolean) {
const acceptParameters = {
video: res.locals.video,
commentBody: req.body,
user: res.locals.oauth.token.User
}
let acceptedResult: AcceptResult
if (isReply) {
const acceptReplyParameters = Object.assign(acceptParameters, { parentComment: res.locals.videoComment })
acceptedResult = await Hooks.wrapObject(
isLocalVideoCommentReplyAccepted(acceptReplyParameters),
'filter:api.video-comment-reply.create.accept.result'
)
} else {
acceptedResult = await Hooks.wrapObject(
isLocalVideoThreadAccepted(acceptParameters),
'filter:api.video-thread.create.accept.result'
)
}
if (!acceptedResult || acceptedResult.accepted !== true) {
logger.info('Refused local comment.', { acceptedResult, acceptParameters })
res.status(403)
.json({ error: acceptedResult.errorMessage || 'Refused local comment' })
return false
}
return true
}