2017-12-03 22:29:23 -05:00
|
|
|
const setupRoute = require('./setup');
|
2018-12-23 22:28:57 +01:00
|
|
|
const loginRoute = require('./login');
|
|
|
|
const indexRoute = require('./index');
|
2018-03-30 15:34:07 -04:00
|
|
|
const multer = require('multer')();
|
2017-11-03 23:00:35 -04:00
|
|
|
|
|
|
|
// API routes
|
|
|
|
const treeApiRoute = require('./api/tree');
|
|
|
|
const notesApiRoute = require('./api/notes');
|
2018-04-01 20:33:10 -04:00
|
|
|
const branchesApiRoute = require('./api/branches');
|
2018-04-18 00:26:42 -04:00
|
|
|
const autocompleteApiRoute = require('./api/autocomplete');
|
2018-01-13 18:02:41 -05:00
|
|
|
const cloningApiRoute = require('./api/cloning');
|
2018-03-25 20:52:38 -04:00
|
|
|
const noteRevisionsApiRoute = require('./api/note_revisions');
|
2017-11-03 23:00:35 -04:00
|
|
|
const recentChangesApiRoute = require('./api/recent_changes');
|
2018-04-01 17:41:28 -04:00
|
|
|
const optionsApiRoute = require('./api/options');
|
2017-11-03 23:00:35 -04:00
|
|
|
const passwordApiRoute = require('./api/password');
|
|
|
|
const syncApiRoute = require('./api/sync');
|
|
|
|
const loginApiRoute = require('./api/login');
|
|
|
|
const eventLogRoute = require('./api/event_log');
|
2017-11-04 23:46:50 -04:00
|
|
|
const recentNotesRoute = require('./api/recent_notes');
|
2017-11-21 00:25:53 -05:00
|
|
|
const appInfoRoute = require('./api/app_info');
|
2017-12-02 21:48:22 -05:00
|
|
|
const exportRoute = require('./api/export');
|
2017-12-02 23:41:18 -05:00
|
|
|
const importRoute = require('./api/import');
|
2017-12-03 22:29:23 -05:00
|
|
|
const setupApiRoute = require('./api/setup');
|
2017-12-14 20:38:56 -05:00
|
|
|
const sqlRoute = require('./api/sql');
|
2017-12-16 00:05:37 -05:00
|
|
|
const anonymizationRoute = require('./api/anonymization');
|
2017-12-23 09:35:00 -05:00
|
|
|
const cleanupRoute = require('./api/cleanup');
|
2018-01-05 23:54:02 -05:00
|
|
|
const imageRoute = require('./api/image');
|
2018-08-02 22:48:21 +02:00
|
|
|
const attributesRoute = require('./api/attributes');
|
2018-01-23 21:59:30 -05:00
|
|
|
const scriptRoute = require('./api/script');
|
2018-02-11 00:18:59 -05:00
|
|
|
const senderRoute = require('./api/sender');
|
2018-03-27 22:11:06 -04:00
|
|
|
const filesRoute = require('./api/file_upload');
|
2018-03-23 23:08:29 -04:00
|
|
|
const searchRoute = require('./api/search');
|
2019-04-14 12:18:52 +02:00
|
|
|
const dateNotesRoute = require('./api/date_notes');
|
2017-11-03 23:00:35 -04:00
|
|
|
|
2018-03-30 13:20:36 -04:00
|
|
|
const log = require('../services/log');
|
2018-03-30 12:57:22 -04:00
|
|
|
const express = require('express');
|
|
|
|
const router = express.Router();
|
|
|
|
const auth = require('../services/auth');
|
|
|
|
const cls = require('../services/cls');
|
|
|
|
const sql = require('../services/sql');
|
2018-03-31 08:53:52 -04:00
|
|
|
const protectedSessionService = require('../services/protected_session');
|
2019-03-24 22:41:53 +01:00
|
|
|
const csurf = require('csurf');
|
|
|
|
|
2019-03-24 23:03:30 +01:00
|
|
|
const csrfMiddleware = csurf({
|
|
|
|
cookie: true,
|
|
|
|
path: '' // nothing so cookie is valid only for current path
|
|
|
|
});
|
2018-03-30 12:57:22 -04:00
|
|
|
|
2018-04-05 23:35:49 -04:00
|
|
|
function apiResultHandler(req, res, result) {
|
2018-03-30 17:07:41 -04:00
|
|
|
// if it's an array and first element is integer then we consider this to be [statusCode, response] format
|
|
|
|
if (Array.isArray(result) && result.length > 0 && Number.isInteger(result[0])) {
|
|
|
|
const [statusCode, response] = result;
|
|
|
|
|
|
|
|
res.status(statusCode).send(response);
|
|
|
|
|
2018-04-05 23:35:49 -04:00
|
|
|
if (statusCode !== 200 && statusCode !== 201 && statusCode !== 204) {
|
|
|
|
log.info(`${req.method} ${req.originalUrl} returned ${statusCode} with response ${JSON.stringify(response)}`);
|
2018-03-30 12:57:22 -04:00
|
|
|
}
|
2018-03-30 17:07:41 -04:00
|
|
|
}
|
|
|
|
else if (result === undefined) {
|
2018-04-01 11:05:09 -04:00
|
|
|
res.status(204).send();
|
2018-03-30 17:07:41 -04:00
|
|
|
}
|
|
|
|
else {
|
2018-04-05 19:29:27 -04:00
|
|
|
res.send(result);
|
2018-03-30 17:07:41 -04:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
function apiRoute(method, path, routeHandler) {
|
2019-03-24 22:41:53 +01:00
|
|
|
route(method, path, [auth.checkApiAuth, csrfMiddleware], routeHandler, apiResultHandler);
|
2018-03-30 15:34:07 -04:00
|
|
|
}
|
|
|
|
|
2018-07-22 19:56:20 +02:00
|
|
|
function route(method, path, middleware, routeHandler, resultHandler, transactional = true) {
|
2018-03-30 15:34:07 -04:00
|
|
|
router[method](path, ...middleware, async (req, res, next) => {
|
|
|
|
try {
|
|
|
|
const result = await cls.init(async () => {
|
2018-11-30 15:49:35 +01:00
|
|
|
cls.namespace.set('sourceId', req.headers['trilium-source-id']);
|
2018-03-31 08:53:52 -04:00
|
|
|
protectedSessionService.setProtectedSessionId(req);
|
2018-03-30 15:34:07 -04:00
|
|
|
|
2018-07-22 19:56:20 +02:00
|
|
|
if (transactional) {
|
|
|
|
return await sql.transactional(async () => {
|
|
|
|
return await routeHandler(req, res, next);
|
|
|
|
});
|
|
|
|
}
|
|
|
|
else {
|
2018-03-30 15:34:07 -04:00
|
|
|
return await routeHandler(req, res, next);
|
2018-07-22 19:56:20 +02:00
|
|
|
}
|
2018-03-30 15:34:07 -04:00
|
|
|
});
|
|
|
|
|
|
|
|
if (resultHandler) {
|
2018-04-05 23:35:49 -04:00
|
|
|
resultHandler(req, res, result);
|
2018-03-30 15:34:07 -04:00
|
|
|
}
|
|
|
|
}
|
2018-03-30 12:57:22 -04:00
|
|
|
catch (e) {
|
2018-08-27 23:04:52 +02:00
|
|
|
log.error(`${method} ${path} threw exception: ` + e.stack);
|
2018-03-30 13:56:46 -04:00
|
|
|
|
2018-03-30 15:34:07 -04:00
|
|
|
res.sendStatus(500);
|
2018-03-30 12:57:22 -04:00
|
|
|
}
|
|
|
|
});
|
|
|
|
}
|
|
|
|
|
|
|
|
const GET = 'get', POST = 'post', PUT = 'put', DELETE = 'delete';
|
2018-03-30 17:29:13 -04:00
|
|
|
const uploadMiddleware = multer.single('upload');
|
2018-03-30 12:57:22 -04:00
|
|
|
|
2017-11-03 23:00:35 -04:00
|
|
|
function register(app) {
|
2019-03-24 22:41:53 +01:00
|
|
|
route(GET, '/', [auth.checkAuth, csrfMiddleware], indexRoute.index);
|
2018-07-24 20:35:03 +02:00
|
|
|
route(GET, '/login', [auth.checkAppInitialized], loginRoute.loginPage);
|
2018-03-30 19:31:22 -04:00
|
|
|
route(POST, '/login', [], loginRoute.login);
|
2019-03-24 22:41:53 +01:00
|
|
|
route(POST, '/logout', [csrfMiddleware, auth.checkAuth], loginRoute.logout);
|
2018-03-30 19:31:22 -04:00
|
|
|
route(GET, '/setup', [auth.checkAppNotInitialized], setupRoute.setupPage);
|
2017-11-03 23:00:35 -04:00
|
|
|
|
2018-03-30 12:57:22 -04:00
|
|
|
apiRoute(GET, '/api/tree', treeApiRoute.getTree);
|
2018-04-16 20:40:18 -04:00
|
|
|
apiRoute(POST, '/api/tree/load', treeApiRoute.load);
|
2018-04-01 20:33:10 -04:00
|
|
|
apiRoute(PUT, '/api/branches/:branchId/set-prefix', branchesApiRoute.setPrefix);
|
2018-03-30 12:57:22 -04:00
|
|
|
|
2018-04-01 20:33:10 -04:00
|
|
|
apiRoute(PUT, '/api/branches/:branchId/move-to/:parentNoteId', branchesApiRoute.moveBranchToParent);
|
|
|
|
apiRoute(PUT, '/api/branches/:branchId/move-before/:beforeBranchId', branchesApiRoute.moveBranchBeforeNote);
|
|
|
|
apiRoute(PUT, '/api/branches/:branchId/move-after/:afterBranchId', branchesApiRoute.moveBranchAfterNote);
|
|
|
|
apiRoute(PUT, '/api/branches/:branchId/expanded/:expanded', branchesApiRoute.setExpanded);
|
|
|
|
apiRoute(DELETE, '/api/branches/:branchId', branchesApiRoute.deleteBranch);
|
2018-03-30 12:57:22 -04:00
|
|
|
|
2018-04-18 00:26:42 -04:00
|
|
|
apiRoute(GET, '/api/autocomplete', autocompleteApiRoute.getAutocomplete);
|
|
|
|
|
2018-03-30 12:57:22 -04:00
|
|
|
apiRoute(GET, '/api/notes/:noteId', notesApiRoute.getNote);
|
|
|
|
apiRoute(PUT, '/api/notes/:noteId', notesApiRoute.updateNote);
|
2018-11-14 23:30:28 +01:00
|
|
|
apiRoute(DELETE, '/api/notes/:noteId', notesApiRoute.deleteNote);
|
2018-03-30 12:57:22 -04:00
|
|
|
apiRoute(POST, '/api/notes/:parentNoteId/children', notesApiRoute.createNote);
|
2018-10-21 10:26:14 +02:00
|
|
|
apiRoute(GET, '/api/notes/:parentNoteId/children', notesApiRoute.getChildren);
|
2018-03-30 12:57:22 -04:00
|
|
|
apiRoute(PUT, '/api/notes/:noteId/sort', notesApiRoute.sortNotes);
|
2018-08-31 18:22:53 +02:00
|
|
|
apiRoute(PUT, '/api/notes/:noteId/protect/:isProtected', notesApiRoute.protectSubtree);
|
2018-03-30 12:57:22 -04:00
|
|
|
apiRoute(PUT, /\/api\/notes\/(.*)\/type\/(.*)\/mime\/(.*)/, notesApiRoute.setNoteTypeMime);
|
2018-04-01 20:33:10 -04:00
|
|
|
apiRoute(GET, '/api/notes/:noteId/revisions', noteRevisionsApiRoute.getNoteRevisions);
|
2018-10-25 12:06:36 +02:00
|
|
|
apiRoute(POST, '/api/notes/relation-map', notesApiRoute.getRelationMap);
|
2018-10-30 22:18:20 +01:00
|
|
|
apiRoute(PUT, '/api/notes/:noteId/change-title', notesApiRoute.changeTitle);
|
2018-03-30 12:57:22 -04:00
|
|
|
|
2018-04-01 20:33:10 -04:00
|
|
|
apiRoute(PUT, '/api/notes/:noteId/clone-to/:parentNoteId', cloningApiRoute.cloneNoteToParent);
|
2018-03-30 13:20:36 -04:00
|
|
|
apiRoute(PUT, '/api/notes/:noteId/clone-after/:afterBranchId', cloningApiRoute.cloneNoteAfter);
|
|
|
|
|
2019-02-16 23:33:40 +01:00
|
|
|
route(GET, '/api/notes/:branchId/export/:type/:format/:version/:exportId', [auth.checkApiAuthOrElectron], exportRoute.exportBranch);
|
2019-03-24 22:41:53 +01:00
|
|
|
route(POST, '/api/notes/:parentNoteId/import', [auth.checkApiAuthOrElectron, uploadMiddleware, csrfMiddleware], importRoute.importToBranch, apiResultHandler);
|
2018-04-01 20:50:58 -04:00
|
|
|
|
2019-03-24 22:41:53 +01:00
|
|
|
route(POST, '/api/notes/:parentNoteId/upload', [auth.checkApiAuthOrElectron, uploadMiddleware, csrfMiddleware],
|
2018-04-01 20:50:58 -04:00
|
|
|
filesRoute.uploadFile, apiResultHandler);
|
|
|
|
|
|
|
|
route(GET, '/api/notes/:noteId/download', [auth.checkApiAuthOrElectron], filesRoute.downloadFile);
|
2019-01-27 22:34:41 +01:00
|
|
|
// this "hacky" path is used for easier referencing of CSS resources
|
|
|
|
route(GET, '/api/notes/download/:noteId', [auth.checkApiAuthOrElectron], filesRoute.downloadFile);
|
2018-04-01 20:33:10 -04:00
|
|
|
|
2018-08-06 08:59:26 +02:00
|
|
|
apiRoute(GET, '/api/notes/:noteId/attributes', attributesRoute.getEffectiveNoteAttributes);
|
2018-08-02 22:48:21 +02:00
|
|
|
apiRoute(PUT, '/api/notes/:noteId/attributes', attributesRoute.updateNoteAttributes);
|
2018-08-06 14:43:42 +02:00
|
|
|
apiRoute(PUT, '/api/notes/:noteId/attribute', attributesRoute.updateNoteAttribute);
|
2018-10-29 22:38:51 +01:00
|
|
|
apiRoute(PUT, '/api/notes/:noteId/relations/:name/to/:targetNoteId', attributesRoute.createRelation);
|
2018-10-30 10:36:19 +01:00
|
|
|
apiRoute(DELETE, '/api/notes/:noteId/relations/:name/to/:targetNoteId', attributesRoute.deleteRelation);
|
2018-08-06 17:24:35 +02:00
|
|
|
apiRoute(DELETE, '/api/notes/:noteId/attributes/:attributeId', attributesRoute.deleteNoteAttribute);
|
2018-08-03 11:11:57 +02:00
|
|
|
apiRoute(GET, '/api/attributes/names', attributesRoute.getAttributeNames);
|
2018-08-02 22:48:21 +02:00
|
|
|
apiRoute(GET, '/api/attributes/values/:attributeName', attributesRoute.getValuesForAttribute);
|
|
|
|
|
2019-04-14 12:18:52 +02:00
|
|
|
apiRoute(GET, '/api/date-notes/date/:date', dateNotesRoute.getDateNote);
|
|
|
|
apiRoute(GET, '/api/date-notes/month/:month', dateNotesRoute.getMonthNote);
|
|
|
|
apiRoute(GET, '/api/date-notes/year/:year', dateNotesRoute.getYearNote);
|
|
|
|
|
2018-11-08 10:30:35 +01:00
|
|
|
route(GET, '/api/images/:noteId/:filename', [auth.checkApiAuthOrElectron], imageRoute.returnImage);
|
2019-03-24 22:41:53 +01:00
|
|
|
route(POST, '/api/images', [auth.checkApiAuthOrElectron, uploadMiddleware, csrfMiddleware], imageRoute.uploadImage, apiResultHandler);
|
2018-04-01 20:50:58 -04:00
|
|
|
|
2018-03-30 13:56:46 -04:00
|
|
|
apiRoute(GET, '/api/recent-changes', recentChangesApiRoute.getRecentChanges);
|
|
|
|
|
2018-04-01 20:33:10 -04:00
|
|
|
apiRoute(GET, '/api/options', optionsApiRoute.getOptions);
|
2019-02-17 20:59:52 +01:00
|
|
|
// FIXME: possibly change to sending value in the body to avoid host of HTTP server issues with slashes
|
2018-12-13 23:28:48 +01:00
|
|
|
apiRoute(PUT, '/api/options/:name/:value*', optionsApiRoute.updateOption);
|
2018-07-22 22:21:16 +02:00
|
|
|
apiRoute(PUT, '/api/options', optionsApiRoute.updateOptions);
|
2019-01-27 21:18:11 +01:00
|
|
|
apiRoute(GET, '/api/options/user-themes', optionsApiRoute.getUserThemes);
|
2018-03-30 13:56:46 -04:00
|
|
|
|
|
|
|
apiRoute(POST, '/api/password/change', passwordApiRoute.changePassword);
|
|
|
|
|
2018-07-23 10:29:17 +02:00
|
|
|
apiRoute(POST, '/api/sync/test', syncApiRoute.testSync);
|
2018-03-30 14:27:41 -04:00
|
|
|
apiRoute(GET, '/api/sync/check', syncApiRoute.checkSync);
|
|
|
|
apiRoute(POST, '/api/sync/now', syncApiRoute.syncNow);
|
|
|
|
apiRoute(POST, '/api/sync/fill-sync-rows', syncApiRoute.fillSyncRows);
|
|
|
|
apiRoute(POST, '/api/sync/force-full-sync', syncApiRoute.forceFullSync);
|
|
|
|
apiRoute(POST, '/api/sync/force-note-sync/:noteId', syncApiRoute.forceNoteSync);
|
2019-03-27 21:04:25 +01:00
|
|
|
route(GET, '/api/sync/changed', [auth.checkApiAuth], syncApiRoute.getChanged, apiResultHandler);
|
|
|
|
route(PUT, '/api/sync/update', [auth.checkApiAuth], syncApiRoute.update, apiResultHandler);
|
|
|
|
route(POST, '/api/sync/finished', [auth.checkApiAuth], syncApiRoute.syncFinished, apiResultHandler);
|
2018-07-23 21:15:32 +02:00
|
|
|
route(GET, '/api/sync/stats', [], syncApiRoute.getStats, apiResultHandler);
|
2018-03-30 14:27:41 -04:00
|
|
|
|
2018-03-30 15:34:07 -04:00
|
|
|
apiRoute(GET, '/api/event-log', eventLogRoute.getEventLog);
|
|
|
|
|
2019-02-17 20:49:51 +01:00
|
|
|
apiRoute(POST, '/api/recent-notes', recentNotesRoute.addRecentNote);
|
2018-03-30 15:34:07 -04:00
|
|
|
apiRoute(GET, '/api/app-info', appInfoRoute.getAppInfo);
|
|
|
|
|
2019-03-24 22:41:53 +01:00
|
|
|
// group of services below are meant to be executed from outside
|
2018-09-10 20:05:10 +02:00
|
|
|
route(GET, '/api/setup/status', [], setupApiRoute.getStatus, apiResultHandler);
|
2018-07-22 19:56:20 +02:00
|
|
|
route(POST, '/api/setup/new-document', [auth.checkAppNotInitialized], setupApiRoute.setupNewDocument, apiResultHandler);
|
|
|
|
route(POST, '/api/setup/sync-from-server', [auth.checkAppNotInitialized], setupApiRoute.setupSyncFromServer, apiResultHandler, false);
|
2018-07-25 09:46:57 +02:00
|
|
|
route(GET, '/api/setup/sync-seed', [auth.checkBasicAuth], setupApiRoute.getSyncSeed, apiResultHandler);
|
|
|
|
route(POST, '/api/setup/sync-seed', [auth.checkAppNotInitialized], setupApiRoute.saveSyncSeed, apiResultHandler, false);
|
2018-03-30 17:07:41 -04:00
|
|
|
|
2019-02-10 10:38:18 +01:00
|
|
|
apiRoute(GET, '/api/sql/schema', sqlRoute.getSchema);
|
2018-03-30 17:07:41 -04:00
|
|
|
apiRoute(POST, '/api/sql/execute', sqlRoute.execute);
|
|
|
|
apiRoute(POST, '/api/anonymization/anonymize', anonymizationRoute.anonymize);
|
|
|
|
|
|
|
|
apiRoute(POST, '/api/cleanup/cleanup-unused-images', cleanupRoute.cleanupUnusedImages);
|
2018-08-14 18:03:36 +02:00
|
|
|
// VACUUM requires execution outside of transaction
|
2019-03-24 22:41:53 +01:00
|
|
|
route(POST, '/api/cleanup/vacuum-database', [auth.checkApiAuthOrElectron, csrfMiddleware], cleanupRoute.vacuumDatabase, apiResultHandler, false);
|
2018-03-30 17:07:41 -04:00
|
|
|
|
2018-03-30 17:29:13 -04:00
|
|
|
apiRoute(POST, '/api/script/exec', scriptRoute.exec);
|
|
|
|
apiRoute(POST, '/api/script/run/:noteId', scriptRoute.run);
|
|
|
|
apiRoute(GET, '/api/script/startup', scriptRoute.getStartupBundles);
|
|
|
|
apiRoute(GET, '/api/script/bundle/:noteId', scriptRoute.getBundle);
|
2018-07-29 18:39:10 +02:00
|
|
|
apiRoute(GET, '/api/script/relation/:noteId/:relationName', scriptRoute.getRelationBundles);
|
2018-03-30 17:29:13 -04:00
|
|
|
|
2019-03-24 22:41:53 +01:00
|
|
|
// no CSRF since this is called from android app
|
2018-03-30 17:29:13 -04:00
|
|
|
route(POST, '/api/sender/login', [], senderRoute.login, apiResultHandler);
|
2019-02-19 21:24:35 +01:00
|
|
|
route(POST, '/api/sender/image', [auth.checkSenderToken, uploadMiddleware], senderRoute.uploadImage, apiResultHandler);
|
2018-03-30 17:29:13 -04:00
|
|
|
route(POST, '/api/sender/note', [auth.checkSenderToken], senderRoute.saveNote, apiResultHandler);
|
|
|
|
|
|
|
|
apiRoute(GET, '/api/search/:searchString', searchRoute.searchNotes);
|
2019-03-20 22:28:54 +01:00
|
|
|
apiRoute(GET, '/api/search-note/:noteId', searchRoute.searchFromNote);
|
2018-03-30 13:56:46 -04:00
|
|
|
|
2018-03-30 19:31:22 -04:00
|
|
|
route(POST, '/api/login/sync', [], loginApiRoute.loginSync, apiResultHandler);
|
|
|
|
// this is for entering protected mode so user has to be already logged-in (that's the reason we don't require username)
|
|
|
|
apiRoute(POST, '/api/login/protected', loginApiRoute.loginToProtectedSession);
|
2018-03-30 13:56:46 -04:00
|
|
|
|
2018-03-30 19:31:22 -04:00
|
|
|
app.use('', router);
|
2017-11-03 23:00:35 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
module.exports = {
|
|
|
|
register
|
|
|
|
};
|