2017-02-18 01:56:23 -07:00
|
|
|
'use strict';
|
2014-03-02 22:12:08 -05:00
|
|
|
|
2019-08-21 23:02:50 -04:00
|
|
|
const nconf = require('nconf');
|
|
|
|
|
const validator = require('validator');
|
2016-01-06 12:49:14 +02:00
|
|
|
|
2019-08-21 23:02:50 -04:00
|
|
|
const meta = require('../meta');
|
|
|
|
|
const user = require('../user');
|
|
|
|
|
const plugins = require('../plugins');
|
2025-01-06 10:22:31 -05:00
|
|
|
const privilegesHelpers = require('../privileges/helpers');
|
2019-08-21 23:02:50 -04:00
|
|
|
const helpers = require('./helpers');
|
2014-02-27 14:56:14 -05:00
|
|
|
|
2019-08-21 23:02:50 -04:00
|
|
|
const Controllers = module.exports;
|
2017-03-02 14:57:33 +03:00
|
|
|
|
2018-01-25 11:50:33 -05:00
|
|
|
Controllers.ping = require('./ping');
|
2017-11-04 08:51:44 -06:00
|
|
|
Controllers.home = require('./home');
|
2017-03-02 14:57:33 +03:00
|
|
|
Controllers.topics = require('./topics');
|
|
|
|
|
Controllers.posts = require('./posts');
|
|
|
|
|
Controllers.categories = require('./categories');
|
|
|
|
|
Controllers.category = require('./category');
|
|
|
|
|
Controllers.unread = require('./unread');
|
|
|
|
|
Controllers.recent = require('./recent');
|
|
|
|
|
Controllers.popular = require('./popular');
|
2017-12-08 19:58:12 -05:00
|
|
|
Controllers.top = require('./top');
|
2017-03-02 14:57:33 +03:00
|
|
|
Controllers.tags = require('./tags');
|
|
|
|
|
Controllers.search = require('./search');
|
2017-03-02 16:11:11 +03:00
|
|
|
Controllers.user = require('./user');
|
2017-03-02 14:57:33 +03:00
|
|
|
Controllers.users = require('./users');
|
|
|
|
|
Controllers.groups = require('./groups');
|
|
|
|
|
Controllers.accounts = require('./accounts');
|
|
|
|
|
Controllers.authentication = require('./authentication');
|
|
|
|
|
Controllers.api = require('./api');
|
|
|
|
|
Controllers.admin = require('./admin');
|
|
|
|
|
Controllers.globalMods = require('./globalmods');
|
|
|
|
|
Controllers.mods = require('./mods');
|
|
|
|
|
Controllers.sitemap = require('./sitemap');
|
2017-03-06 21:00:20 +01:00
|
|
|
Controllers.osd = require('./osd');
|
2024-09-25 12:40:56 -04:00
|
|
|
Controllers['service-worker'] = require('./service-worker');
|
2017-03-02 14:57:33 +03:00
|
|
|
Controllers['404'] = require('./404');
|
|
|
|
|
Controllers.errors = require('./errors');
|
2017-11-05 14:05:21 -05:00
|
|
|
Controllers.composer = require('./composer');
|
2014-02-27 14:56:14 -05:00
|
|
|
|
2020-03-30 13:16:29 -04:00
|
|
|
Controllers.write = require('./write');
|
|
|
|
|
|
2020-11-14 20:18:47 -05:00
|
|
|
Controllers.reset = async function (req, res) {
|
2019-05-09 15:51:36 -04:00
|
|
|
if (meta.config['password:disableEdit']) {
|
|
|
|
|
return helpers.notAllowed(req, res);
|
|
|
|
|
}
|
|
|
|
|
|
2019-03-27 17:10:56 -04:00
|
|
|
res.locals.metaTags = {
|
|
|
|
|
...res.locals.metaTags,
|
|
|
|
|
name: 'robots',
|
|
|
|
|
content: 'noindex',
|
|
|
|
|
};
|
|
|
|
|
|
2018-07-04 09:52:20 -04:00
|
|
|
const renderReset = function (code, valid) {
|
|
|
|
|
res.render('reset_code', {
|
|
|
|
|
valid: valid,
|
|
|
|
|
displayExpiryNotice: req.session.passwordExpired,
|
|
|
|
|
code: code,
|
2018-10-21 16:47:51 -04:00
|
|
|
minimumPasswordLength: meta.config.minimumPasswordLength,
|
|
|
|
|
minimumPasswordStrength: meta.config.minimumPasswordStrength,
|
2018-07-04 09:52:20 -04:00
|
|
|
breadcrumbs: helpers.buildBreadcrumbs([
|
|
|
|
|
{
|
2023-10-05 12:48:50 -04:00
|
|
|
text: '[[reset_password:reset-password]]',
|
2018-07-04 09:52:20 -04:00
|
|
|
url: '/reset',
|
|
|
|
|
},
|
|
|
|
|
{
|
2023-10-05 12:48:50 -04:00
|
|
|
text: '[[reset_password:update-password]]',
|
2018-07-04 09:52:20 -04:00
|
|
|
},
|
|
|
|
|
]),
|
|
|
|
|
title: '[[pages:reset]]',
|
|
|
|
|
});
|
|
|
|
|
delete req.session.passwordExpired;
|
|
|
|
|
};
|
|
|
|
|
|
2015-01-29 01:06:48 -05:00
|
|
|
if (req.params.code) {
|
2018-07-04 09:52:20 -04:00
|
|
|
req.session.reset_code = req.params.code;
|
2019-03-20 16:30:33 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
if (req.session.reset_code) {
|
2018-07-04 09:52:20 -04:00
|
|
|
// Validate and save to local variable before removing from session
|
2020-11-14 20:18:47 -05:00
|
|
|
const valid = await user.reset.validate(req.session.reset_code);
|
|
|
|
|
renderReset(req.session.reset_code, valid);
|
|
|
|
|
delete req.session.reset_code;
|
2015-01-29 01:06:48 -05:00
|
|
|
} else {
|
|
|
|
|
res.render('reset', {
|
2016-10-18 15:32:28 +03:00
|
|
|
code: null,
|
2017-04-07 20:57:00 +00:00
|
|
|
breadcrumbs: helpers.buildBreadcrumbs([{
|
2023-10-05 12:48:50 -04:00
|
|
|
text: '[[reset_password:reset-password]]',
|
2017-04-07 20:57:00 +00:00
|
|
|
}]),
|
2017-02-17 19:31:21 -07:00
|
|
|
title: '[[pages:reset]]',
|
2015-01-29 01:06:48 -05:00
|
|
|
});
|
|
|
|
|
}
|
2014-03-03 17:16:53 -05:00
|
|
|
};
|
2014-02-27 14:56:14 -05:00
|
|
|
|
2020-11-14 20:18:47 -05:00
|
|
|
Controllers.login = async function (req, res) {
|
|
|
|
|
const data = { loginFormEntry: [] };
|
|
|
|
|
const loginStrategies = require('../routes/authentication').getLoginStrategies();
|
|
|
|
|
const registrationType = meta.config.registrationType || 'normal';
|
|
|
|
|
const allowLoginWith = (meta.config.allowLoginWith || 'username-email');
|
2015-06-27 21:26:19 -04:00
|
|
|
|
2020-11-14 20:18:47 -05:00
|
|
|
let errorText;
|
2016-05-09 11:40:42 -04:00
|
|
|
if (req.query.error === 'csrf-invalid') {
|
|
|
|
|
errorText = '[[error:csrf-invalid]]';
|
2016-07-25 12:15:02 -04:00
|
|
|
} else if (req.query.error) {
|
2016-08-30 13:19:04 +03:00
|
|
|
errorText = validator.escape(String(req.query.error));
|
2016-05-09 11:40:42 -04:00
|
|
|
}
|
|
|
|
|
|
2021-03-04 10:16:16 -05:00
|
|
|
if (req.headers['x-return-to']) {
|
|
|
|
|
req.session.returnTo = req.headers['x-return-to'];
|
2016-10-25 16:52:03 -04:00
|
|
|
}
|
|
|
|
|
|
2021-03-08 14:03:22 -05:00
|
|
|
// Occasionally, x-return-to is passed a full url.
|
2021-03-04 10:58:27 -05:00
|
|
|
req.session.returnTo = req.session.returnTo && req.session.returnTo.replace(nconf.get('base_url'), '').replace(nconf.get('relative_path'), '');
|
2021-03-04 10:16:16 -05:00
|
|
|
|
2014-11-12 16:15:44 -05:00
|
|
|
data.alternate_logins = loginStrategies.length > 0;
|
|
|
|
|
data.authentication = loginStrategies;
|
2019-06-04 11:10:20 -04:00
|
|
|
data.allowRegistration = registrationType === 'normal';
|
2021-02-03 23:59:08 -07:00
|
|
|
data.allowLoginWith = `[[login:${allowLoginWith}]]`;
|
2017-04-07 20:57:00 +00:00
|
|
|
data.breadcrumbs = helpers.buildBreadcrumbs([{
|
|
|
|
|
text: '[[global:login]]',
|
|
|
|
|
}]);
|
2016-05-09 11:40:42 -04:00
|
|
|
data.error = req.flash('error')[0] || errorText;
|
2015-08-26 15:54:54 -04:00
|
|
|
data.title = '[[pages:login]]';
|
2019-05-09 15:51:36 -04:00
|
|
|
data.allowPasswordReset = !meta.config['password:disableEdit'];
|
2014-02-27 16:52:46 -05:00
|
|
|
|
2025-01-06 10:55:10 -05:00
|
|
|
const loginPrivileges = await privilegesHelpers.getGroupPrivileges(0, ['groups:local:login']);
|
2025-01-06 10:22:31 -05:00
|
|
|
const hasLoginPrivilege = !!loginPrivileges.find(privilege => privilege.privileges['groups:local:login']);
|
2020-11-14 20:18:47 -05:00
|
|
|
data.allowLocalLogin = hasLoginPrivilege || parseInt(req.query.local, 10) === 1;
|
2018-09-29 06:49:41 -04:00
|
|
|
|
2020-11-14 20:18:47 -05:00
|
|
|
if (!data.allowLocalLogin && !data.allowRegistration && data.alternate_logins && data.authentication.length === 1) {
|
2020-12-03 10:29:18 -05:00
|
|
|
return helpers.redirect(res, { external: data.authentication[0].url });
|
2020-11-14 20:18:47 -05:00
|
|
|
}
|
|
|
|
|
|
2021-11-23 14:46:24 -05:00
|
|
|
// Re-auth challenge, pre-fill username
|
2020-11-14 20:18:47 -05:00
|
|
|
if (req.loggedIn) {
|
2021-11-23 14:46:24 -05:00
|
|
|
const userData = await user.getUserFields(req.uid, ['username']);
|
|
|
|
|
data.username = userData.username;
|
2020-11-14 20:18:47 -05:00
|
|
|
data.alternate_logins = false;
|
|
|
|
|
}
|
|
|
|
|
res.render('login', data);
|
2014-02-27 16:52:46 -05:00
|
|
|
};
|
|
|
|
|
|
2019-08-21 23:02:50 -04:00
|
|
|
Controllers.register = async function (req, res, next) {
|
|
|
|
|
const registrationType = meta.config.registrationType || 'normal';
|
2015-06-27 21:26:19 -04:00
|
|
|
|
|
|
|
|
if (registrationType === 'disabled') {
|
2019-06-04 11:10:20 -04:00
|
|
|
return setImmediate(next);
|
2014-09-25 11:29:53 -04:00
|
|
|
}
|
2014-03-11 04:10:00 -04:00
|
|
|
|
2019-08-21 23:02:50 -04:00
|
|
|
let errorText;
|
2021-02-05 11:05:21 -05:00
|
|
|
const returnTo = (req.headers['x-return-to'] || '').replace(nconf.get('base_url') + nconf.get('relative_path'), '');
|
2016-05-09 11:40:42 -04:00
|
|
|
if (req.query.error === 'csrf-invalid') {
|
|
|
|
|
errorText = '[[error:csrf-invalid]]';
|
|
|
|
|
}
|
2019-08-21 23:02:50 -04:00
|
|
|
try {
|
|
|
|
|
if (registrationType === 'invite-only' || registrationType === 'admin-invite-only') {
|
2021-01-24 13:59:00 -05:00
|
|
|
try {
|
|
|
|
|
await user.verifyInvitation(req.query);
|
|
|
|
|
} catch (e) {
|
2021-01-24 14:01:16 -05:00
|
|
|
return res.render('400', {
|
2021-01-24 13:59:00 -05:00
|
|
|
error: e.message,
|
|
|
|
|
});
|
|
|
|
|
}
|
2019-08-21 23:02:50 -04:00
|
|
|
}
|
2019-09-12 10:21:18 -04:00
|
|
|
|
2021-02-05 11:05:21 -05:00
|
|
|
if (returnTo) {
|
|
|
|
|
req.session.returnTo = returnTo;
|
|
|
|
|
}
|
|
|
|
|
|
2019-08-21 23:02:50 -04:00
|
|
|
const loginStrategies = require('../routes/authentication').getLoginStrategies();
|
|
|
|
|
res.render('register', {
|
|
|
|
|
'register_window:spansize': loginStrategies.length ? 'col-md-6' : 'col-md-12',
|
|
|
|
|
alternate_logins: !!loginStrategies.length,
|
|
|
|
|
authentication: loginStrategies,
|
|
|
|
|
|
|
|
|
|
minimumUsernameLength: meta.config.minimumUsernameLength,
|
|
|
|
|
maximumUsernameLength: meta.config.maximumUsernameLength,
|
|
|
|
|
minimumPasswordLength: meta.config.minimumPasswordLength,
|
|
|
|
|
minimumPasswordStrength: meta.config.minimumPasswordStrength,
|
|
|
|
|
breadcrumbs: helpers.buildBreadcrumbs([{
|
2017-11-05 14:05:21 -05:00
|
|
|
text: '[[register:register]]',
|
2019-08-21 23:02:50 -04:00
|
|
|
}]),
|
|
|
|
|
regFormEntry: [],
|
|
|
|
|
error: req.flash('error')[0] || errorText,
|
|
|
|
|
title: '[[pages:register]]',
|
|
|
|
|
});
|
|
|
|
|
} catch (err) {
|
|
|
|
|
next(err);
|
|
|
|
|
}
|
2014-02-27 16:52:46 -05:00
|
|
|
};
|
|
|
|
|
|
2019-08-21 23:02:50 -04:00
|
|
|
Controllers.registerInterstitial = async function (req, res, next) {
|
2016-06-08 16:05:40 -04:00
|
|
|
if (!req.session.hasOwnProperty('registration')) {
|
2021-02-03 23:59:08 -07:00
|
|
|
return res.redirect(`${nconf.get('relative_path')}/register`);
|
2016-06-08 16:05:40 -04:00
|
|
|
}
|
2019-08-21 23:02:50 -04:00
|
|
|
try {
|
Bootstrap5 (#10894)
* chore: up deps
* chore: up composer
* fix(deps): bump 2factor to v7
* chore: up harmony
* chore: up harmony
* fix: missing await
* feat: allow middlewares to pass in template values via res.locals
* feat: buildAccountData middleware automatically added ot all account routes
* fix: properly allow values in res.locals.templateValues to be added to the template data
* refactor: user/blocks
* refactor(accounts): categories and consent
* feat: automatically 404 if exposeUid or exposeGroupName come up empty
* refactor: remove calls to getUserDataByUserSlug for most account routes, since it is populated via middleware now
* fix: allow exposeUid and exposeGroupName to work with slugs with mixed capitalization
* fix: move reputation removal check to accountHelpers method
* test: skip i18n tests if ref branch when present is not develop
* fix(deps): bump theme versions
* fix(deps): bump ntfy and 2factor
* chore: up harmony
* fix: add missing return
* fix: #11191, only focus on search input on md environments and up
* feat: allow file uploads on mobile chat
closes https://github.com/NodeBB/NodeBB/issues/11217
* chore: up themes
* chore: add lang string
* fix(deps): bump ntfy to 1.0.15
* refactor: use new if/each syntax
* chore: up composer
* fix: regression from user helper refactor
* chore: up harmony
* chore: up composer
* chore: up harmony
* chore: up harmony
* chore: up harmony
* chore: fix composer version
* feat: add increment helper
* chore: up harmony
* fix: #11228 no timestamps in future :hourglass:
* chore: up harmony
* check config.theme as well
fire action:posts.loaded after processing dom
* chore: up harmony
* chore: up harmony
* chore: up harmony
* chore: up themes
* chore: up harmony
* remove extra class
* refactor: move these to core from harmony
* chore: up widgets
* chore: up widgets
* height auto
* fix: closes #11238
* dont focus inputs, annoying on mobile
* fix: dont focus twice, only focus on chat input on desktop
dont wrap widget footer in row
* chore: up harmony
* chore: up harmony
* update chat window
* chore: up themes
* fix cache buster for skins
* chat fixes
* chore: up harmony
* chore: up composer
* refactor: change hook logs to debug
* fix: scroll to post right after adding to dom
* fix: hash scrolling and highlighting correct post
* test: re-enable read API schema tests
* fix: add back schema changes for 179faa2270f2ad955dcc4a7b04755acce59e6ffd and c3920ccb10d8ead2dcd9914bb1784bed3f6adfd4
* fix: schema changes from 488f0978a4aa1ca1e4d2a1f2e8c7ef7a681f2f27
* fix: schema changes for f4cf482a874701ce80c0f306c49d8788cec66f87
* fix: schema update for be6bbabd0e2551fbe9571dcf3ee40ad721764543
* fix: schema changes for 69c96078ea78ee2c45885a90a6f6a59f9042a33c
* fix: schema changes for d1364c313021e48a879a818b24947e1457c062f7
* fix: schema changes for 84ff1152f7552dd866e25a90972d970b9861107e
* fix: schema changes for b860c2605c209e0650ef98f4c80d842ea23a51ce
* fix: schema changes for 23cb67a1126481848fac39aafd1e253441e76d7f
* fix: schema changes for b916e42f400dac8aa51670b15e439f87f0eb8939
* fix: schema change for a9bbb586fcb3a1c61b5fb69052236e78cdf7d743
* fix: schema changes for 4b738c8cd36c936a1dbe2bb900c694bf6c5520ec
* fix: schema changes for 58b5781cea9acb129e6604a82ab5a5bfc0d8394d
* fix: schema changes for 794bf01b21709c4be06584d576d706b3d6342057
* fix: schema changes for 80ea12c1c1963f5b39fb64841e4f3c8da3c87af2, e368feef51e0766f119c9710fb4db8f64724725c, and 52ead114bec961c62fa2eb0786540e229f6e4873
* fix: composer-default object in config?
* fix: schema changes for 9acdc6808c070555352951c651921df181b10993 and 093093420027999df3c67bf0ea6024f6dbf81d2d
* fix: schema changes for c0a52924f1f7ef8caeaacda67363ac269b56042c
* fix: schema change for aba420a3f3b774e949c2539c73f3dc0e1ae79a38, move loggedInUser to optional props
* fix: schema changes for 8c67031609da30d788561459f8bb76e9a69253de
* fix: schema changes for 27e53b42f3ce48fa61d3754375715cd41ffe808d
* fix: schema changes for 28359665187b0a3b9ec6226dca1234ebdbd725a5
* fix: breaking test for email confirmation API call
* fix: schema changes for refactored search page
* fix: schema changes for user object
* fix: schema changes for 9f531f957e08eabb4bae844ddd67bde14d9b59f0
* fix: schema changes for c4042c70decd628e5b880bd109515b47e4e16164 and 23175110a29640e6fa052db1079bfedb34a61055
* fix: schema changes for 9b3616b10392e247974eb0c1e6225a1582bf6c69
* fix: schema changes for 5afd5de07d42fd33f039a6f85ded3b4992200e5a
* fix: schema change for 1d7baf12171cffbd3af8914bef4e6297d1160d49
* fix: schema changes for 57bfb37c55a839662144e684875003ab52315ecc and be6bbabd0e2551fbe9571dcf3ee40ad721764543
* fix: schema changes for 6e86b4afa20d662af8b9f1c07518df2d8c258105 and 3efad2e13b7319eb9a1f4fda7af047be43ebc11f and 68f66223e73a72f378f193c83a9b5546bede2cda
* fix: allowing optional qs prop in pagination keys (not sure why this didn't break before)
* fix: re-login on email change
* fix: schema changes for c926358d734a2fa410de87f4e4a91744215fc14a
* fix: schema changes for 388a8270c9882892bad5c8141f65da8d59eac0fd
* fix: schema change for 2658bcc821c22e137a6eeb9bb74098856a642eaf
* fix: no need to call account middlewares for chats routes
* fix: schema changes for 71743affc3e58dc85d4ffa15ce043d4d9ddd3d67
* fix: final schema changes
* test: support for anyOf and oneOf
* fix: check thumb
* dont scroll to top on back press
* remove group log
* fix: add top margin to merged and deleted alerts
* chore: up widgets
* fix: improve fix-lists mixin
* chore: up harmony/composer
* feat: allow hiding quicksearch results during search
* dont record searches made by composer
* chore: up 54
* chore: up spam be gone
* feat: add prev/next page and page count into mobile paginator
* chore: up harmony
* chore: up harmony
* use old style for IS
* fix: hide entire toolbar row if no posts or not singlePost
* fix: updated messaging for post-queue template, #11206
* fix: btn-sm on post queue back button
* fix: bump harmony, closes #11206
* fix: remove unused alert module import
* fix: bump harmony
* fix: bump harmony
* chore: up harmony
* refactor: IS scrolltop
* fix: update users:search-user-for-chat source string
* feat: support for mark-read toggle on chats dropdown and recent chats list
* feat: api v3 calls to mark chat read/unread
* feat: send event:chats.mark socket event on mark read or unread
* refactor: allow frontend to mark chats as unread, use new API v3 routes instead of socket calls, better frontend event handling
* docs: openapi schema updates for chat marking
* fix: allow unread state toggling in chats dropdown too
* fix: issue where repeated openings of the chats dropdown would continually add events for mark-read/unread
* fix: debug log
* refactor: move userSearch filter to a module
* feat(routes): allow remounting /categories (#11230)
* feat: send flags count to frontend on flags list page
* refactor: filter form client-side js to extract out some logic
* fix: applyFilters to not take any arguments, update selectedCids in updateButton instead of onHidden
* fix: use userFilter module for assignee, reporterId, targetUid
* fix(openapi): schema changes for updated flags page
* fix: dont allow adding duplicates to userFilter
* use same var
* remove log
* fix: closes #11282
* feat: lang key for x-topics
* chore: up harmony
* chore: up emoji
* chore: up harmony
* fix: update userFilter to allow new option `selectedBlock`
* fix: wrong block name passed to userFilter
* fix: https://github.com/NodeBB/NodeBB/issues/11283
* fix: chats, allow multiple dropdowns like in harmony
* chore: up harmony
* refactor: flag note adding/editing, closes #11285
* fix: remove old prepareEdit logic
* chore: add caveat about hacky code block in userFilter module
* fix: placeholders for userFilter module
* refactor: navigator so it works with multiple thumbs/navigators
* chore: up harmony
* fix: closes #11287, destroy quick reply autocomplete
on navigation
* fix: filter disabled categories on user categories page count
* chore: up harmony
* docs: update openapi spec to include info about passing in timestamps for topic creation, removing timestamp as valid request param for topic replying
* fix: send back null values on ACP search dashboard for startDate and endDate if not expicitly passed in, fix tests
* fix: tweak table order in ACP dash searches
* fix: only invoke navigator click drag on left mouse button
* feat: add back unread indicator to navigator
* clear bookmark on mark unread
* fix: navigator crash on ajaxify
* better thumb top calculation
* fix: reset user bookmark when topic is marked unread
* Revert "fix: reset user bookmark when topic is marked unread"
This reverts commit 9bcd85c2c6848c3d325d32027261809da6e11c9e.
* fix: update unread indicator on scroll, add unread count
* chore: bump harmony
* fix: crash on navigator unread update when backing out of a topic
* fix: closes #11183
* fix: update topics:recent zset when rescheduling a topic
* fix: dupe quote button, increase delay, hide immediately on empty selection
* fix: navigator not showing up on first load
* refactor: remove glance
assorted fixes to navigator
dont reduce remaning count if user scrolls down and up quickly
only call topic.navigatorCallback when index changes
* more sanity checks for bookmark
dont allow setting bookmark higher than topic postcount
* closes #11218, :train:
* Revert "fix: update topics:recent zset when rescheduling a topic"
This reverts commit 737973cca9e94b6cb3867492a09e1e0b1af391d5.
* fix: #11306, show proper error if queued post doesn't exist
was showing no-privileges if someone else accepted the post
* https://github.com/NodeBB/NodeBB/issues/11307
dont use li
* chore: up harmony
* chore: bump version string
* fix: copy paste fail
* feat: closes #7382, tag filtering
add client side support for filtering by tags on /category, /recent and /unread
* chore: up harmony
* chore: up harmony
* Revert "fix: add back req.query fallback for backwards compatibility" [breaking]
This reverts commit cf6cc2c454dc35c330393c62ee8ce67b42d8eefb.
This commit is no longer required as passing in a CSRF token via query parameter is no longer supported as of NodeBB v3.x
This is a breaking change.
* fix: pass csrf token in form data, re: NodeBB/NodeBB#11309
* chore: up deps
* fix: tests, use x-csrf-token query param removed
* test: fix csrf_token
* lint: remove unused
* feat: add itemprop="image" to avatar helper
* fix: get chat upload button in chat modal
* breaking: remove deprecated socket.io methods
* test: update messaging tests to not use sockets
* fix: parent post links
* fix: prevent post tooltip if mouse leaves before data/tpl is loaded
* chore: up harmony
* chore: up harmony
* chore: up harmony
* chore: up harmony
* fix: nested replies indices
* fix(deps): bump 2factor
* feat: add loggedIn user to all api routes
* chore: up themes
* refactor: audit admin v3 write api routes as per #11321
* refactor: audit category v3 write api routes as per #11321 [breaking]
docs: fix open api spec for #11321
* refactor: audit chat v3 write api routes as per #11321
* refactor: audit files v3 write api routes as per #11321
* refactor: audit flags v3 write api routes as per #11321
* refactor: audit posts v3 write api routes as per #11321
* refactor: audit topics v3 write api routes as per #11321
* refactor: audit users v3 write api routes as per #11321
* fix: lang string
* remove min height
* fix: empty topic/labels taking up space
* fix: tag filtering when changing filter to watched topics
or changing popular time limit to month
* chore: up harmony
* fix: closes #11354, show no post error if queued post already accepted/rejected
* test: #11354
* test: #11354
* fix(deps): bump 2factor
* fix: #11357 clear cache on thumb remove
* fix: thumb remove on windows, closes #11357
* test: openapi for thumbs
* test: fix openapi
---------
Co-authored-by: Julian Lam <julian@nodebb.org>
Co-authored-by: Opliko <opliko.reg@protonmail.com>
2023-03-17 11:58:31 -04:00
|
|
|
const data = await user.interstitials.get(req, req.session.registration);
|
2016-06-08 16:05:40 -04:00
|
|
|
|
2019-08-21 23:02:50 -04:00
|
|
|
if (!data.interstitials.length) {
|
|
|
|
|
// No interstitials, redirect to home
|
|
|
|
|
const returnTo = req.session.returnTo || req.session.registration.returnTo;
|
|
|
|
|
delete req.session.registration;
|
|
|
|
|
return helpers.redirect(res, returnTo || '/');
|
|
|
|
|
}
|
2016-08-16 19:46:59 +02:00
|
|
|
|
2021-03-11 11:22:26 -05:00
|
|
|
const errors = req.flash('errors');
|
2021-02-04 02:07:29 -07:00
|
|
|
const renders = data.interstitials.map(
|
2021-03-11 11:22:26 -05:00
|
|
|
interstitial => req.app.renderAsync(interstitial.template, { ...interstitial.data || {}, errors })
|
2021-02-04 02:07:29 -07:00
|
|
|
);
|
2019-08-21 23:02:50 -04:00
|
|
|
const sections = await Promise.all(renders);
|
2017-02-28 16:42:10 +03:00
|
|
|
|
2019-08-21 23:02:50 -04:00
|
|
|
res.render('registerComplete', {
|
|
|
|
|
title: '[[pages:registration-complete]]',
|
2021-06-16 14:57:26 -04:00
|
|
|
register: data.userData.register,
|
|
|
|
|
sections,
|
2021-03-11 11:22:26 -05:00
|
|
|
errors,
|
2019-08-21 23:02:50 -04:00
|
|
|
});
|
|
|
|
|
} catch (err) {
|
|
|
|
|
next(err);
|
|
|
|
|
}
|
2016-06-08 16:05:40 -04:00
|
|
|
};
|
|
|
|
|
|
2024-08-26 14:47:43 -04:00
|
|
|
Controllers.confirmEmail = async (req, res) => {
|
|
|
|
|
function renderPage(opts = {}) {
|
|
|
|
|
res.render('confirm', {
|
|
|
|
|
title: '[[pages:confirm]]',
|
|
|
|
|
...opts,
|
|
|
|
|
});
|
|
|
|
|
}
|
2021-07-28 14:49:24 -04:00
|
|
|
try {
|
2024-08-26 14:52:30 -04:00
|
|
|
if (req.loggedIn) {
|
2024-08-26 14:47:43 -04:00
|
|
|
const emailValidated = await user.getUserField(req.uid, 'email:confirmed');
|
|
|
|
|
if (emailValidated) {
|
|
|
|
|
return renderPage({ alreadyValidated: true });
|
|
|
|
|
}
|
|
|
|
|
}
|
2021-07-28 14:49:24 -04:00
|
|
|
await user.email.confirmByCode(req.params.code, req.session.id);
|
2023-05-11 11:34:24 -04:00
|
|
|
if (req.session.registration) {
|
|
|
|
|
// After confirmation, no need to send user back to email change form
|
|
|
|
|
delete req.session.registration.updateEmail;
|
|
|
|
|
}
|
|
|
|
|
|
2024-08-26 14:47:43 -04:00
|
|
|
renderPage();
|
2021-07-28 14:49:24 -04:00
|
|
|
} catch (e) {
|
2024-08-26 14:47:43 -04:00
|
|
|
if (e.message === '[[error:invalid-data]]' || e.message === '[[error:confirm-email-expired]]') {
|
|
|
|
|
renderPage({ error: true });
|
|
|
|
|
return;
|
2021-07-28 14:49:24 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
throw e;
|
|
|
|
|
}
|
2014-02-27 17:04:41 -05:00
|
|
|
};
|
2014-02-27 15:06:39 -05:00
|
|
|
|
2014-02-27 17:16:06 -05:00
|
|
|
Controllers.robots = function (req, res) {
|
|
|
|
|
res.set('Content-Type', 'text/plain');
|
|
|
|
|
|
2017-07-10 14:55:57 -04:00
|
|
|
if (meta.config['robots:txt']) {
|
|
|
|
|
res.send(meta.config['robots:txt']);
|
2014-02-27 17:16:06 -05:00
|
|
|
} else {
|
2021-02-03 23:59:08 -07:00
|
|
|
res.send(`${'User-agent: *\n' +
|
|
|
|
|
'Disallow: '}${nconf.get('relative_path')}/admin/\n` +
|
|
|
|
|
`Disallow: ${nconf.get('relative_path')}/reset/\n` +
|
|
|
|
|
`Disallow: ${nconf.get('relative_path')}/compose\n` +
|
|
|
|
|
`Sitemap: ${nconf.get('url')}/sitemap.xml`);
|
2014-02-27 17:16:06 -05:00
|
|
|
}
|
|
|
|
|
};
|
|
|
|
|
|
2020-11-14 20:18:47 -05:00
|
|
|
Controllers.manifest = async function (req, res) {
|
|
|
|
|
const manifest = {
|
2016-10-18 15:32:28 +03:00
|
|
|
name: meta.config.title || 'NodeBB',
|
2020-04-19 19:32:49 +02:00
|
|
|
short_name: meta.config['title:short'] || meta.config.title || 'NodeBB',
|
2020-09-28 17:06:25 -04:00
|
|
|
start_url: nconf.get('url'),
|
2016-10-18 15:32:28 +03:00
|
|
|
display: 'standalone',
|
|
|
|
|
orientation: 'portrait',
|
2020-04-19 19:32:49 +02:00
|
|
|
theme_color: meta.config.themeColor || '#ffffff',
|
|
|
|
|
background_color: meta.config.backgroundColor || '#ffffff',
|
2017-02-17 19:31:21 -07:00
|
|
|
icons: [],
|
2016-10-18 15:32:28 +03:00
|
|
|
};
|
2015-09-24 12:04:24 -04:00
|
|
|
|
|
|
|
|
if (meta.config['brand:touchIcon']) {
|
|
|
|
|
manifest.icons.push({
|
2021-02-03 23:59:08 -07:00
|
|
|
src: `${nconf.get('relative_path')}/assets/uploads/system/touchicon-36.png`,
|
2015-09-24 12:04:24 -04:00
|
|
|
sizes: '36x36',
|
|
|
|
|
type: 'image/png',
|
2017-02-17 19:31:21 -07:00
|
|
|
density: 0.75,
|
2015-09-24 12:04:24 -04:00
|
|
|
}, {
|
2021-02-03 23:59:08 -07:00
|
|
|
src: `${nconf.get('relative_path')}/assets/uploads/system/touchicon-48.png`,
|
2015-09-24 12:04:24 -04:00
|
|
|
sizes: '48x48',
|
|
|
|
|
type: 'image/png',
|
2017-02-17 19:31:21 -07:00
|
|
|
density: 1.0,
|
2015-09-24 12:04:24 -04:00
|
|
|
}, {
|
2021-02-03 23:59:08 -07:00
|
|
|
src: `${nconf.get('relative_path')}/assets/uploads/system/touchicon-72.png`,
|
2015-09-24 12:04:24 -04:00
|
|
|
sizes: '72x72',
|
|
|
|
|
type: 'image/png',
|
2017-02-17 19:31:21 -07:00
|
|
|
density: 1.5,
|
2015-09-24 12:04:24 -04:00
|
|
|
}, {
|
2021-02-03 23:59:08 -07:00
|
|
|
src: `${nconf.get('relative_path')}/assets/uploads/system/touchicon-96.png`,
|
2015-09-24 12:04:24 -04:00
|
|
|
sizes: '96x96',
|
|
|
|
|
type: 'image/png',
|
2017-02-17 19:31:21 -07:00
|
|
|
density: 2.0,
|
2015-09-24 12:04:24 -04:00
|
|
|
}, {
|
2021-02-03 23:59:08 -07:00
|
|
|
src: `${nconf.get('relative_path')}/assets/uploads/system/touchicon-144.png`,
|
2015-09-24 12:04:24 -04:00
|
|
|
sizes: '144x144',
|
|
|
|
|
type: 'image/png',
|
2017-02-17 19:31:21 -07:00
|
|
|
density: 3.0,
|
2015-09-24 12:04:24 -04:00
|
|
|
}, {
|
2021-02-03 23:59:08 -07:00
|
|
|
src: `${nconf.get('relative_path')}/assets/uploads/system/touchicon-192.png`,
|
2015-09-24 12:04:24 -04:00
|
|
|
sizes: '192x192',
|
|
|
|
|
type: 'image/png',
|
2017-02-17 19:31:21 -07:00
|
|
|
density: 4.0,
|
2020-04-19 19:32:49 +02:00
|
|
|
}, {
|
2021-02-03 23:59:08 -07:00
|
|
|
src: `${nconf.get('relative_path')}/assets/uploads/system/touchicon-512.png`,
|
2020-04-19 19:32:49 +02:00
|
|
|
sizes: '512x512',
|
|
|
|
|
type: 'image/png',
|
|
|
|
|
density: 10.0,
|
2016-01-06 12:49:14 +02:00
|
|
|
});
|
2015-09-24 12:04:24 -04:00
|
|
|
}
|
2020-09-29 07:49:21 -04:00
|
|
|
|
|
|
|
|
|
|
|
|
|
if (meta.config['brand:maskableIcon']) {
|
|
|
|
|
manifest.icons.push({
|
2021-02-03 23:59:08 -07:00
|
|
|
src: `${nconf.get('relative_path')}/assets/uploads/system/maskableicon-orig.png`,
|
2024-06-27 16:59:49 -04:00
|
|
|
sizes: '512x512',
|
2020-09-29 07:49:21 -04:00
|
|
|
type: 'image/png',
|
|
|
|
|
purpose: 'maskable',
|
|
|
|
|
});
|
|
|
|
|
} else if (meta.config['brand:touchIcon']) {
|
|
|
|
|
manifest.icons.push({
|
2021-02-03 23:59:08 -07:00
|
|
|
src: `${nconf.get('relative_path')}/assets/uploads/system/touchicon-orig.png`,
|
2024-06-27 16:59:49 -04:00
|
|
|
sizes: '512x512',
|
2020-09-29 07:49:21 -04:00
|
|
|
type: 'image/png',
|
|
|
|
|
purpose: 'maskable',
|
|
|
|
|
});
|
|
|
|
|
}
|
|
|
|
|
|
2020-11-20 16:06:26 -05:00
|
|
|
const data = await plugins.hooks.fire('filter:manifest.build', {
|
2020-11-14 20:18:47 -05:00
|
|
|
req: req,
|
|
|
|
|
res: res,
|
|
|
|
|
manifest: manifest,
|
2019-08-07 17:20:37 +02:00
|
|
|
});
|
2020-11-14 20:18:47 -05:00
|
|
|
res.status(200).json(data.manifest);
|
2015-09-24 12:04:24 -04:00
|
|
|
};
|
|
|
|
|
|
2017-03-02 14:57:33 +03:00
|
|
|
Controllers.outgoing = function (req, res, next) {
|
2020-11-14 20:18:47 -05:00
|
|
|
const url = req.query.url || '';
|
|
|
|
|
const allowedProtocols = [
|
|
|
|
|
'http', 'https', 'ftp', 'ftps', 'mailto', 'news', 'irc', 'gopher',
|
|
|
|
|
'nntp', 'feed', 'telnet', 'mms', 'rtsp', 'svn', 'tel', 'fax', 'xmpp', 'webcal',
|
|
|
|
|
];
|
|
|
|
|
const parsed = require('url').parse(url);
|
2017-03-02 14:57:33 +03:00
|
|
|
|
2017-11-28 14:20:16 -05:00
|
|
|
if (!url || !parsed.protocol || !allowedProtocols.includes(parsed.protocol.slice(0, -1))) {
|
2017-03-02 14:57:33 +03:00
|
|
|
return next();
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
res.render('outgoing', {
|
2016-09-05 22:12:02 +03:00
|
|
|
outgoing: validator.escape(String(url)),
|
2016-04-25 21:53:56 +03:00
|
|
|
title: meta.config.title,
|
2017-04-07 20:57:00 +00:00
|
|
|
breadcrumbs: helpers.buildBreadcrumbs([{
|
2023-10-05 12:48:50 -04:00
|
|
|
text: '[[notifications:outgoing-link]]',
|
2017-04-07 20:57:00 +00:00
|
|
|
}]),
|
2017-03-02 14:57:33 +03:00
|
|
|
});
|
2014-02-28 14:04:21 -05:00
|
|
|
};
|
|
|
|
|
|
2019-09-12 10:21:18 -04:00
|
|
|
Controllers.termsOfUse = async function (req, res, next) {
|
2014-11-14 12:17:24 -05:00
|
|
|
if (!meta.config.termsOfUse) {
|
2015-08-28 14:31:35 -04:00
|
|
|
return next();
|
2014-11-14 12:17:24 -05:00
|
|
|
}
|
2020-11-20 16:06:26 -05:00
|
|
|
const termsOfUse = await plugins.hooks.fire('filter:parse.post', {
|
2019-09-12 10:21:18 -04:00
|
|
|
postData: {
|
|
|
|
|
content: meta.config.termsOfUse || '',
|
|
|
|
|
},
|
|
|
|
|
});
|
2017-04-07 20:57:00 +00:00
|
|
|
res.render('tos', {
|
2019-09-12 10:21:18 -04:00
|
|
|
termsOfUse: termsOfUse.postData.content,
|
2017-04-07 20:57:00 +00:00
|
|
|
});
|
2014-11-14 12:17:24 -05:00
|
|
|
};
|