2020-11-05 16:58:23 +00:00
|
|
|
import { PaginationOrderDir } from '../../models/utils/types';
|
|
|
|
import { ErrorMethodNotAllowed, ErrorForbidden, ErrorBadRequest, ErrorNotFound } from './utils/errors';
|
|
|
|
|
|
|
|
import route_folders from './routes/folders';
|
|
|
|
import route_notes from './routes/notes';
|
|
|
|
import route_resources from './routes/resources';
|
|
|
|
import route_tags from './routes/tags';
|
|
|
|
import route_master_keys from './routes/master_keys';
|
|
|
|
import route_search from './routes/search';
|
|
|
|
import route_ping from './routes/ping';
|
|
|
|
|
|
|
|
const { ltrimSlashes } = require('../../path-utils');
|
|
|
|
const md5 = require('md5');
|
|
|
|
|
|
|
|
export enum RequestMethod {
|
|
|
|
GET = 'GET',
|
|
|
|
POST = 'POST',
|
|
|
|
PUT = 'PUT',
|
|
|
|
DELETE = 'DELETE',
|
|
|
|
}
|
|
|
|
|
|
|
|
interface RequestFile {
|
2020-11-12 19:29:22 +00:00
|
|
|
path: string;
|
2020-11-05 16:58:23 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
interface RequestQuery {
|
2020-11-12 19:29:22 +00:00
|
|
|
fields?: string[] | string;
|
|
|
|
token?: string;
|
|
|
|
nounce?: string;
|
|
|
|
page?: number;
|
2020-11-05 16:58:23 +00:00
|
|
|
|
|
|
|
// Search engine query
|
2020-11-12 19:29:22 +00:00
|
|
|
query?: string;
|
|
|
|
type?: string; // Model type as a string (eg. "note", "folder")
|
2020-11-05 16:58:23 +00:00
|
|
|
|
2020-11-12 19:29:22 +00:00
|
|
|
as_tree?: number;
|
2020-11-05 16:58:23 +00:00
|
|
|
|
|
|
|
// Pagination
|
2020-11-12 19:29:22 +00:00
|
|
|
limit?: number;
|
|
|
|
order_dir?: PaginationOrderDir;
|
|
|
|
order_by?: string;
|
2020-11-05 16:58:23 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
export interface Request {
|
2020-11-12 19:29:22 +00:00
|
|
|
method: RequestMethod;
|
|
|
|
path: string;
|
|
|
|
query: RequestQuery;
|
|
|
|
body: any;
|
|
|
|
bodyJson_: any;
|
|
|
|
bodyJson: any;
|
|
|
|
files: RequestFile[];
|
|
|
|
params: any[];
|
|
|
|
action?: any;
|
2020-11-05 16:58:23 +00:00
|
|
|
}
|
|
|
|
|
2020-11-12 19:13:28 +00:00
|
|
|
type RouteFunction = (request: Request, id: string, link: string)=> Promise<any | void>;
|
2020-11-05 16:58:23 +00:00
|
|
|
|
|
|
|
interface ResourceNameToRoute {
|
2020-11-12 19:13:28 +00:00
|
|
|
[key: string]: RouteFunction;
|
2020-11-05 16:58:23 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
export default class Api {
|
|
|
|
|
2020-11-12 19:13:28 +00:00
|
|
|
private token_: string | Function;
|
|
|
|
private knownNounces_: any = {};
|
|
|
|
private actionApi_: any;
|
|
|
|
private resourceNameToRoute_: ResourceNameToRoute = {};
|
2020-11-05 16:58:23 +00:00
|
|
|
|
2020-11-12 19:13:28 +00:00
|
|
|
public constructor(token: string = null, actionApi: any = null) {
|
2020-11-05 16:58:23 +00:00
|
|
|
this.token_ = token;
|
|
|
|
this.actionApi_ = actionApi;
|
|
|
|
|
|
|
|
this.resourceNameToRoute_ = {
|
|
|
|
ping: route_ping,
|
|
|
|
notes: route_notes,
|
|
|
|
folders: route_folders,
|
|
|
|
tags: route_tags,
|
|
|
|
resources: route_resources,
|
|
|
|
master_keys: route_master_keys,
|
|
|
|
search: route_search,
|
|
|
|
services: this.action_services.bind(this),
|
|
|
|
};
|
|
|
|
}
|
|
|
|
|
|
|
|
public get token() {
|
|
|
|
return typeof this.token_ === 'function' ? this.token_() : this.token_;
|
|
|
|
}
|
|
|
|
|
2020-11-12 19:13:28 +00:00
|
|
|
private parsePath(path: string) {
|
2020-11-05 16:58:23 +00:00
|
|
|
path = ltrimSlashes(path);
|
|
|
|
if (!path) return { fn: null, params: [] };
|
|
|
|
|
|
|
|
const pathParts = path.split('/');
|
|
|
|
const callSuffix = pathParts.splice(0, 1)[0];
|
|
|
|
const fn = this.resourceNameToRoute_[callSuffix];
|
|
|
|
|
|
|
|
return {
|
|
|
|
fn: fn,
|
|
|
|
params: pathParts,
|
|
|
|
};
|
|
|
|
}
|
|
|
|
|
|
|
|
// Response can be any valid JSON object, so a string, and array or an object (key/value pairs).
|
2020-11-12 19:13:28 +00:00
|
|
|
public async route(method: RequestMethod, path: string, query: RequestQuery = null, body: any = null, files: RequestFile[] = null): Promise<any> {
|
2020-11-05 16:58:23 +00:00
|
|
|
if (!files) files = [];
|
|
|
|
if (!query) query = {};
|
|
|
|
|
|
|
|
const parsedPath = this.parsePath(path);
|
|
|
|
if (!parsedPath.fn) throw new ErrorNotFound(); // Nothing at the root yet
|
|
|
|
|
|
|
|
if (query && query.nounce) {
|
|
|
|
const requestMd5 = md5(JSON.stringify([method, path, body, query, files.length]));
|
|
|
|
if (this.knownNounces_[query.nounce] === requestMd5) {
|
|
|
|
throw new ErrorBadRequest('Duplicate Nounce');
|
|
|
|
}
|
|
|
|
this.knownNounces_[query.nounce] = requestMd5;
|
|
|
|
}
|
|
|
|
|
|
|
|
let id = null;
|
|
|
|
let link = null;
|
|
|
|
const params = parsedPath.params;
|
|
|
|
|
|
|
|
if (params.length >= 1) {
|
|
|
|
id = params[0];
|
|
|
|
params.splice(0, 1);
|
|
|
|
if (params.length >= 1) {
|
|
|
|
link = params[0];
|
|
|
|
params.splice(0, 1);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-11-12 19:13:28 +00:00
|
|
|
const request: Request = {
|
2020-11-05 16:58:23 +00:00
|
|
|
method,
|
|
|
|
path: ltrimSlashes(path),
|
|
|
|
query: query ? query : {},
|
|
|
|
body,
|
|
|
|
bodyJson_: null,
|
2020-11-12 19:13:28 +00:00
|
|
|
bodyJson: function(disallowedProperties: string[] = null) {
|
2020-11-05 16:58:23 +00:00
|
|
|
if (!this.bodyJson_) this.bodyJson_ = JSON.parse(this.body);
|
|
|
|
|
|
|
|
if (disallowedProperties) {
|
|
|
|
const filteredBody = Object.assign({}, this.bodyJson_);
|
|
|
|
for (let i = 0; i < disallowedProperties.length; i++) {
|
|
|
|
const n = disallowedProperties[i];
|
|
|
|
delete filteredBody[n];
|
|
|
|
}
|
|
|
|
return filteredBody;
|
|
|
|
}
|
|
|
|
|
|
|
|
return this.bodyJson_;
|
|
|
|
},
|
|
|
|
files,
|
|
|
|
params,
|
|
|
|
};
|
|
|
|
|
|
|
|
this.checkToken_(request);
|
|
|
|
|
|
|
|
try {
|
|
|
|
return await parsedPath.fn(request, id, link);
|
|
|
|
} catch (error) {
|
|
|
|
if (!error.httpCode) error.httpCode = 500;
|
|
|
|
throw error;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-11-12 19:13:28 +00:00
|
|
|
private checkToken_(request: Request) {
|
2020-11-05 16:58:23 +00:00
|
|
|
// For now, whitelist some calls to allow the web clipper to work
|
|
|
|
// without an extra auth step
|
|
|
|
const whiteList = [['GET', 'ping'], ['GET', 'tags'], ['GET', 'folders'], ['POST', 'notes']];
|
|
|
|
|
|
|
|
for (let i = 0; i < whiteList.length; i++) {
|
|
|
|
if (whiteList[i][0] === request.method && whiteList[i][1] === request.path) return;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!this.token) return;
|
|
|
|
if (!request.query || !request.query.token) throw new ErrorForbidden('Missing "token" parameter');
|
|
|
|
if (request.query.token !== this.token) throw new ErrorForbidden('Invalid "token" parameter');
|
|
|
|
}
|
|
|
|
|
2020-11-12 19:13:28 +00:00
|
|
|
private async execServiceActionFromRequest_(externalApi: any, request: Request) {
|
2020-11-05 16:58:23 +00:00
|
|
|
const action = externalApi[request.action];
|
|
|
|
if (!action) throw new ErrorNotFound(`Invalid action: ${request.action}`);
|
|
|
|
const args = Object.assign({}, request);
|
|
|
|
delete args.action;
|
|
|
|
return action(args);
|
|
|
|
}
|
|
|
|
|
2020-11-12 19:13:28 +00:00
|
|
|
private async action_services(request: Request, serviceName: string) {
|
2020-11-05 16:58:23 +00:00
|
|
|
if (request.method !== RequestMethod.POST) throw new ErrorMethodNotAllowed();
|
|
|
|
if (!this.actionApi_) throw new ErrorNotFound('No action API has been setup!');
|
|
|
|
if (!this.actionApi_[serviceName]) throw new ErrorNotFound(`No such service: ${serviceName}`);
|
|
|
|
|
|
|
|
const externalApi = this.actionApi_[serviceName]();
|
|
|
|
return this.execServiceActionFromRequest_(externalApi, JSON.parse(request.body));
|
|
|
|
}
|
|
|
|
|
|
|
|
}
|