Files
NodeBB/src/controllers/uploads.js

191 lines
5.7 KiB
JavaScript
Raw Normal View History

2017-02-18 01:56:23 -07:00
'use strict';
2015-01-10 16:40:54 -05:00
2019-09-12 12:41:59 -04:00
const path = require('path');
const nconf = require('nconf');
const validator = require('validator');
2015-01-10 16:40:54 -05:00
2019-09-12 12:41:59 -04:00
const db = require('../database');
const meta = require('../meta');
const file = require('../file');
const plugins = require('../plugins');
const image = require('../image');
const privileges = require('../privileges');
2015-01-10 16:40:54 -05:00
const helpers = require('./helpers');
2019-09-12 12:41:59 -04:00
const uploadsController = module.exports;
2015-01-10 16:40:54 -05:00
2019-09-12 12:41:59 -04:00
uploadsController.upload = async function (req, res, filesIterator) {
let files = req.files.files;
2015-01-10 16:40:54 -05:00
// These checks added because of odd behaviour by request: https://github.com/request/request/issues/2445
2015-01-10 16:40:54 -05:00
if (!Array.isArray(files)) {
return helpers.formatApiResponse(500, res, new Error('[[error:invalid-file]]'));
2015-01-10 16:40:54 -05:00
}
if (Array.isArray(files[0])) {
files = files[0];
}
2019-09-12 12:41:59 -04:00
try {
2020-07-27 11:46:14 -04:00
const images = [];
for (const fileObj of files) {
/* eslint-disable no-await-in-loop */
images.push(await filesIterator(fileObj));
}
helpers.formatApiResponse(200, res, { images });
return images;
2019-09-12 12:41:59 -04:00
} catch (err) {
return helpers.formatApiResponse(500, res, err);
2019-09-12 12:41:59 -04:00
} finally {
deleteTempFiles(files);
}
2015-01-10 16:40:54 -05:00
};
2019-09-12 12:41:59 -04:00
uploadsController.uploadPost = async function (req, res) {
await uploadsController.upload(req, res, async function (uploadedFile) {
const isImage = uploadedFile.type.match(/image./);
2016-07-12 19:58:59 +03:00
if (isImage) {
2019-09-12 12:41:59 -04:00
return await uploadAsImage(req, uploadedFile);
2015-11-11 13:52:29 -05:00
}
2019-09-12 12:41:59 -04:00
return await uploadAsFile(req, uploadedFile);
});
2016-07-12 19:58:59 +03:00
};
2016-03-23 12:19:29 +02:00
2019-09-12 12:41:59 -04:00
async function uploadAsImage(req, uploadedFile) {
const canUpload = await privileges.global.can('upload:post:image', req.uid);
if (!canUpload) {
throw new Error('[[error:no-privileges]]');
}
await image.checkDimensions(uploadedFile.path);
await image.stripEXIF(uploadedFile.path);
if (plugins.hooks.hasListeners('filter:uploadImage')) {
return await plugins.hooks.fire('filter:uploadImage', {
2019-09-12 12:41:59 -04:00
image: uploadedFile,
uid: req.uid,
folder: 'files',
2019-09-12 12:41:59 -04:00
});
}
await image.isFileTypeAllowed(uploadedFile.path);
2019-09-12 12:41:59 -04:00
let fileObj = await uploadsController.uploadFile(req.uid, uploadedFile);
if (meta.config.resizeImageWidth === 0 || meta.config.resizeImageWidthThreshold === 0) {
return fileObj;
}
fileObj = await resizeImage(fileObj);
return { url: fileObj.url };
2016-07-12 19:58:59 +03:00
}
2016-04-20 13:58:25 -04:00
2019-09-12 12:41:59 -04:00
async function uploadAsFile(req, uploadedFile) {
const canUpload = await privileges.global.can('upload:post:file', req.uid);
if (!canUpload) {
throw new Error('[[error:no-privileges]]');
}
const fileObj = await uploadsController.uploadFile(req.uid, uploadedFile);
return {
url: fileObj.url,
name: fileObj.name,
};
2016-07-12 19:58:59 +03:00
}
2015-01-10 16:40:54 -05:00
2019-09-12 12:41:59 -04:00
async function resizeImage(fileObj) {
const imageData = await image.size(fileObj.path);
if (imageData.width < meta.config.resizeImageWidthThreshold || meta.config.resizeImageWidth > meta.config.resizeImageWidthThreshold) {
return fileObj;
}
await image.resizeImage({
path: fileObj.path,
target: file.appendToFileName(fileObj.path, '-resized'),
width: meta.config.resizeImageWidth,
quality: meta.config.resizeImageQuality,
});
// Return the resized version to the composer/postData
fileObj.url = file.appendToFileName(fileObj.url, '-resized');
return fileObj;
2016-05-01 12:44:43 +03:00
}
uploadsController.uploadThumb = async function (req, res) {
if (!meta.config.allowTopicsThumbnail) {
2015-01-10 16:40:54 -05:00
deleteTempFiles(req.files.files);
return helpers.formatApiResponse(503, res, new Error('[[error:topic-thumbnails-are-disabled]]'));
2015-01-10 16:40:54 -05:00
}
return await uploadsController.upload(req, res, async function (uploadedFile) {
2019-09-12 12:41:59 -04:00
if (!uploadedFile.type.match(/image./)) {
throw new Error('[[error:invalid-file]]');
}
await image.isFileTypeAllowed(uploadedFile.path);
await image.checkDimensions(uploadedFile.path);
2019-09-12 12:41:59 -04:00
await image.resizeImage({
path: uploadedFile.path,
width: meta.config.topicThumbSize,
height: meta.config.topicThumbSize,
});
if (plugins.hooks.hasListeners('filter:uploadImage')) {
return await plugins.hooks.fire('filter:uploadImage', {
2019-09-12 12:41:59 -04:00
image: uploadedFile,
uid: req.uid,
folder: 'files',
2019-09-12 12:41:59 -04:00
});
}
return await uploadsController.uploadFile(req.uid, uploadedFile);
});
2015-01-10 16:40:54 -05:00
};
2019-09-12 12:41:59 -04:00
uploadsController.uploadFile = async function (uid, uploadedFile) {
if (plugins.hooks.hasListeners('filter:uploadFile')) {
return await plugins.hooks.fire('filter:uploadFile', {
2017-02-17 19:57:18 +00:00
file: uploadedFile,
2017-02-18 19:14:39 -07:00
uid: uid,
folder: 'files',
2019-09-12 12:41:59 -04:00
});
2015-01-10 16:40:54 -05:00
}
2015-02-18 21:09:33 -05:00
if (!uploadedFile) {
2019-09-12 12:41:59 -04:00
throw new Error('[[error:invalid-file]]');
2015-01-10 16:40:54 -05:00
}
if (uploadedFile.size > meta.config.maximumFileSize * 1024) {
2019-09-12 12:41:59 -04:00
throw new Error('[[error:file-too-big, ' + meta.config.maximumFileSize + ']]');
2015-01-10 16:40:54 -05:00
}
2019-09-12 12:41:59 -04:00
const allowed = file.allowedExtensions();
2017-05-01 20:58:34 -04:00
2019-09-12 12:41:59 -04:00
const extension = path.extname(uploadedFile.name).toLowerCase();
if (allowed.length > 0 && (!extension || extension === '.' || !allowed.includes(extension))) {
2019-09-12 12:41:59 -04:00
throw new Error('[[error:invalid-file-type, ' + allowed.join('&#44; ') + ']]');
}
return await saveFileToLocal(uid, 'files', uploadedFile);
2017-03-02 20:51:03 +03:00
};
2016-01-11 10:27:26 +02:00
async function saveFileToLocal(uid, folder, uploadedFile) {
2019-09-12 12:41:59 -04:00
const name = uploadedFile.name || 'upload';
const extension = path.extname(name) || '';
const filename = Date.now() + '-' + validator.escape(name.substr(0, name.length - extension.length)).substr(0, 255) + extension;
const upload = await file.saveFileToLocal(filename, folder, uploadedFile.path);
2019-09-12 12:41:59 -04:00
const storedFile = {
url: nconf.get('relative_path') + upload.url,
path: upload.path,
name: uploadedFile.name,
};
const fileKey = upload.url.replace(nconf.get('upload_url'), '');
await db.sortedSetAdd('uid:' + uid + ':uploads', Date.now(), fileKey);
const data = await plugins.hooks.fire('filter:uploadStored', { uid: uid, uploadedFile: uploadedFile, storedFile: storedFile });
2019-09-12 12:41:59 -04:00
return data.storedFile;
2015-01-10 16:40:54 -05:00
}
function deleteTempFiles(files) {
2019-09-12 12:41:59 -04:00
files.forEach(fileObj => file.delete(fileObj.path));
2015-01-10 16:40:54 -05:00
}
2019-09-12 12:41:59 -04:00
require('../promisify')(uploadsController, ['upload', 'uploadPost', 'uploadThumb']);