| 
									
										
										
										
											2023-03-12 16:00:57 +01:00
										 |  |  | // GoToSocial | 
					
						
							|  |  |  | // Copyright (C) GoToSocial Authors admin@gotosocial.org | 
					
						
							|  |  |  | // SPDX-License-Identifier: AGPL-3.0-or-later | 
					
						
							|  |  |  | // | 
					
						
							|  |  |  | // This program is free software: you can redistribute it and/or modify | 
					
						
							|  |  |  | // it under the terms of the GNU Affero General Public License as published by | 
					
						
							|  |  |  | // the Free Software Foundation, either version 3 of the License, or | 
					
						
							|  |  |  | // (at your option) any later version. | 
					
						
							|  |  |  | // | 
					
						
							|  |  |  | // This program is distributed in the hope that it will be useful, | 
					
						
							|  |  |  | // but WITHOUT ANY WARRANTY; without even the implied warranty of | 
					
						
							|  |  |  | // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the | 
					
						
							|  |  |  | // GNU Affero General Public License for more details. | 
					
						
							|  |  |  | // | 
					
						
							|  |  |  | // You should have received a copy of the GNU Affero General Public License | 
					
						
							|  |  |  | // along with this program.  If not, see <http://www.gnu.org/licenses/>. | 
					
						
							| 
									
										
										
										
											2022-07-18 12:55:06 +02:00
										 |  |  | 
 | 
					
						
							|  |  |  | package web | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | import ( | 
					
						
							| 
									
										
										
										
											2023-02-07 14:57:09 +01:00
										 |  |  | 	"context" | 
					
						
							| 
									
										
										
										
											2022-07-18 12:55:06 +02:00
										 |  |  | 	"net/http" | 
					
						
							| 
									
										
										
										
											2023-02-07 14:57:09 +01:00
										 |  |  | 	"net/url" | 
					
						
							| 
									
										
										
										
											2022-07-18 12:55:06 +02:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-11-15 18:45:15 +00:00
										 |  |  | 	"codeberg.org/gruf/go-cache/v3" | 
					
						
							| 
									
										
										
										
											2022-07-18 12:55:06 +02:00
										 |  |  | 	"github.com/gin-gonic/gin" | 
					
						
							| 
									
										
										
										
											2023-07-31 15:47:35 +02:00
										 |  |  | 	apiutil "github.com/superseriousbusiness/gotosocial/internal/api/util" | 
					
						
							| 
									
										
										
										
											2023-02-07 14:57:09 +01:00
										 |  |  | 	"github.com/superseriousbusiness/gotosocial/internal/db" | 
					
						
							|  |  |  | 	"github.com/superseriousbusiness/gotosocial/internal/middleware" | 
					
						
							| 
									
										
										
										
											2022-07-18 12:55:06 +02:00
										 |  |  | 	"github.com/superseriousbusiness/gotosocial/internal/processing" | 
					
						
							|  |  |  | 	"github.com/superseriousbusiness/gotosocial/internal/router" | 
					
						
							|  |  |  | 	"github.com/superseriousbusiness/gotosocial/internal/uris" | 
					
						
							|  |  |  | ) | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | const ( | 
					
						
							| 
									
										
										
										
											2024-12-02 06:24:48 -05:00
										 |  |  | 	confirmEmailPath      = "/" + uris.ConfirmEmailPath | 
					
						
							|  |  |  | 	profileGroupPath      = "/@:username" | 
					
						
							|  |  |  | 	statusPath            = "/statuses/:" + apiutil.WebStatusIDKey // leave out the '/@:username' prefix as this will be served within the profile group | 
					
						
							|  |  |  | 	tagsPath              = "/tags/:" + apiutil.TagNameKey | 
					
						
							|  |  |  | 	customCSSPath         = profileGroupPath + "/custom.css" | 
					
						
							|  |  |  | 	instanceCustomCSSPath = "/custom.css" | 
					
						
							|  |  |  | 	rssFeedPath           = profileGroupPath + "/feed.rss" | 
					
						
							|  |  |  | 	assetsPathPrefix      = "/assets" | 
					
						
							|  |  |  | 	distPathPrefix        = assetsPathPrefix + "/dist" | 
					
						
							|  |  |  | 	themesPathPrefix      = assetsPathPrefix + "/themes" | 
					
						
							|  |  |  | 	settingsPathPrefix    = "/settings" | 
					
						
							|  |  |  | 	settingsPanelGlob     = settingsPathPrefix + "/*panel" | 
					
						
							|  |  |  | 	userPanelPath         = settingsPathPrefix + "/user" | 
					
						
							|  |  |  | 	adminPanelPath        = settingsPathPrefix + "/admin" | 
					
						
							|  |  |  | 	signupPath            = "/signup" | 
					
						
							| 
									
										
										
										
											2022-07-18 12:55:06 +02:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-10-08 14:00:39 +02:00
										 |  |  | 	cacheControlHeader    = "Cache-Control"     // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cache-Control | 
					
						
							|  |  |  | 	cacheControlNoCache   = "no-cache"          // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Cache-Control#response_directives | 
					
						
							|  |  |  | 	ifModifiedSinceHeader = "If-Modified-Since" // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/If-Modified-Since | 
					
						
							|  |  |  | 	ifNoneMatchHeader     = "If-None-Match"     // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/If-None-Match | 
					
						
							|  |  |  | 	eTagHeader            = "ETag"              // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/ETag | 
					
						
							|  |  |  | 	lastModifiedHeader    = "Last-Modified"     // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Last-Modified | 
					
						
							| 
									
										
										
										
											2023-12-27 11:23:52 +01:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2025-03-26 16:59:39 +01:00
										 |  |  | 	cssFA             = assetsPathPrefix + "/Fork-Awesome/css/fork-awesome.min.css" | 
					
						
							|  |  |  | 	cssAbout          = distPathPrefix + "/about.css" | 
					
						
							|  |  |  | 	cssIndex          = distPathPrefix + "/index.css" | 
					
						
							|  |  |  | 	cssLoginInfo      = distPathPrefix + "/login-info.css" | 
					
						
							|  |  |  | 	cssStatus         = distPathPrefix + "/status.css" | 
					
						
							|  |  |  | 	cssThread         = distPathPrefix + "/thread.css" | 
					
						
							|  |  |  | 	cssProfile        = distPathPrefix + "/profile.css" | 
					
						
							|  |  |  | 	cssProfileGallery = distPathPrefix + "/profile-gallery.css" | 
					
						
							|  |  |  | 	cssSettings       = distPathPrefix + "/settings-style.css" | 
					
						
							|  |  |  | 	cssTag            = distPathPrefix + "/tag.css" | 
					
						
							| 
									
										
										
										
											2023-12-27 11:23:52 +01:00
										 |  |  | 
 | 
					
						
							|  |  |  | 	jsFrontend = distPathPrefix + "/frontend.js" // Progressive enhancement frontend JS. | 
					
						
							| 
									
										
										
										
											2025-03-31 15:51:17 +02:00
										 |  |  | 	jsBlurhash = distPathPrefix + "/blurhash.js" // Blurhash rendering JS. | 
					
						
							| 
									
										
										
										
											2023-12-27 11:23:52 +01:00
										 |  |  | 	jsSettings = distPathPrefix + "/settings.js" // Settings panel React application. | 
					
						
							| 
									
										
										
										
											2022-07-18 12:55:06 +02:00
										 |  |  | ) | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | type Module struct { | 
					
						
							| 
									
										
										
										
											2023-02-22 16:05:26 +01:00
										 |  |  | 	processor    *processing.Processor | 
					
						
							| 
									
										
										
										
											2023-02-07 14:57:09 +01:00
										 |  |  | 	eTagCache    cache.Cache[string, eTagCacheEntry] | 
					
						
							| 
									
										
										
										
											2023-07-25 09:34:05 +01:00
										 |  |  | 	isURIBlocked func(context.Context, *url.URL) (bool, error) | 
					
						
							| 
									
										
										
										
											2022-07-18 12:55:06 +02:00
										 |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2023-02-22 16:05:26 +01:00
										 |  |  | func New(db db.DB, processor *processing.Processor) *Module { | 
					
						
							| 
									
										
										
										
											2022-07-18 12:55:06 +02:00
										 |  |  | 	return &Module{ | 
					
						
							| 
									
										
										
										
											2023-02-07 14:57:09 +01:00
										 |  |  | 		processor:    processor, | 
					
						
							|  |  |  | 		eTagCache:    newETagCache(), | 
					
						
							|  |  |  | 		isURIBlocked: db.IsURIBlocked, | 
					
						
							| 
									
										
										
										
											2022-09-04 14:41:42 +02:00
										 |  |  | 	} | 
					
						
							| 
									
										
										
										
											2022-07-18 12:55:06 +02:00
										 |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2025-01-29 16:57:04 +01:00
										 |  |  | // ETagCache implements withETagCache. | 
					
						
							|  |  |  | func (m *Module) ETagCache() cache.Cache[string, eTagCacheEntry] { | 
					
						
							|  |  |  | 	return m.eTagCache | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | // Route attaches the assets filesystem and profile, | 
					
						
							|  |  |  | // status, and other web handlers to the router. | 
					
						
							| 
									
										
										
										
											2023-11-13 19:48:51 +01:00
										 |  |  | func (m *Module) Route(r *router.Router, mi ...gin.HandlerFunc) { | 
					
						
							| 
									
										
										
										
											2025-01-29 16:57:04 +01:00
										 |  |  | 	// Route static assets. | 
					
						
							|  |  |  | 	routeAssets(m, r, mi...) | 
					
						
							| 
									
										
										
										
											2022-10-08 14:00:39 +02:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2025-01-29 16:57:04 +01:00
										 |  |  | 	// Handlers that serve profiles and statuses should use | 
					
						
							|  |  |  | 	// the SignatureCheck middleware, so that requests with | 
					
						
							|  |  |  | 	// content-type application/activity+json can be served | 
					
						
							| 
									
										
										
										
											2023-02-07 14:57:09 +01:00
										 |  |  | 	profileGroup := r.AttachGroup(profileGroupPath) | 
					
						
							|  |  |  | 	profileGroup.Use(mi...) | 
					
						
							| 
									
										
										
										
											2023-07-13 21:27:25 +02:00
										 |  |  | 	profileGroup.Use(middleware.SignatureCheck(m.isURIBlocked), middleware.CacheControl(middleware.CacheControlConfig{ | 
					
						
							|  |  |  | 		Directives: []string{"no-store"}, | 
					
						
							|  |  |  | 	})) | 
					
						
							| 
									
										
										
										
											2023-02-07 14:57:09 +01:00
										 |  |  | 	profileGroup.Handle(http.MethodGet, "", m.profileGETHandler) // use empty path here since it's the base of the group | 
					
						
							|  |  |  | 	profileGroup.Handle(http.MethodGet, statusPath, m.threadGETHandler) | 
					
						
							| 
									
										
										
										
											2022-07-18 12:55:06 +02:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2025-02-05 12:47:13 +01:00
										 |  |  | 	// Group for all other web handlers. | 
					
						
							|  |  |  | 	everythingElseGroup := r.AttachGroup("") | 
					
						
							|  |  |  | 	everythingElseGroup.Use(mi...) | 
					
						
							|  |  |  | 	everythingElseGroup.Handle(http.MethodGet, "/", m.indexHandler) // front-page | 
					
						
							|  |  |  | 	everythingElseGroup.Handle(http.MethodGet, settingsPathPrefix, m.SettingsPanelHandler) | 
					
						
							|  |  |  | 	everythingElseGroup.Handle(http.MethodGet, settingsPanelGlob, m.SettingsPanelHandler) | 
					
						
							|  |  |  | 	everythingElseGroup.Handle(http.MethodGet, customCSSPath, m.customCSSGETHandler) | 
					
						
							|  |  |  | 	everythingElseGroup.Handle(http.MethodGet, instanceCustomCSSPath, m.instanceCustomCSSGETHandler) | 
					
						
							|  |  |  | 	everythingElseGroup.Handle(http.MethodGet, rssFeedPath, m.rssFeedGETHandler) | 
					
						
							|  |  |  | 	everythingElseGroup.Handle(http.MethodGet, confirmEmailPath, m.confirmEmailGETHandler) | 
					
						
							|  |  |  | 	everythingElseGroup.Handle(http.MethodPost, confirmEmailPath, m.confirmEmailPOSTHandler) | 
					
						
							|  |  |  | 	everythingElseGroup.Handle(http.MethodGet, aboutPath, m.aboutGETHandler) | 
					
						
							|  |  |  | 	everythingElseGroup.Handle(http.MethodGet, loginPath, m.loginGETHandler) | 
					
						
							|  |  |  | 	everythingElseGroup.Handle(http.MethodGet, domainBlockListPath, m.domainBlockListGETHandler) | 
					
						
							|  |  |  | 	everythingElseGroup.Handle(http.MethodGet, tagsPath, m.tagGETHandler) | 
					
						
							|  |  |  | 	everythingElseGroup.Handle(http.MethodGet, signupPath, m.signupGETHandler) | 
					
						
							|  |  |  | 	everythingElseGroup.Handle(http.MethodPost, signupPath, m.signupPOSTHandler) | 
					
						
							| 
									
										
										
										
											2023-01-25 18:06:41 +01:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2025-02-05 12:47:13 +01:00
										 |  |  | 	// Redirects from old endpoints for back compat. | 
					
						
							| 
									
										
										
										
											2023-01-02 13:10:50 +01:00
										 |  |  | 	r.AttachHandler(http.MethodGet, "/auth/edit", func(c *gin.Context) { c.Redirect(http.StatusMovedPermanently, userPanelPath) }) | 
					
						
							|  |  |  | 	r.AttachHandler(http.MethodGet, "/user", func(c *gin.Context) { c.Redirect(http.StatusMovedPermanently, userPanelPath) }) | 
					
						
							|  |  |  | 	r.AttachHandler(http.MethodGet, "/admin", func(c *gin.Context) { c.Redirect(http.StatusMovedPermanently, adminPanelPath) }) | 
					
						
							| 
									
										
										
										
											2022-07-18 12:55:06 +02:00
										 |  |  | } |