You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

448 lines
14 KiB

8 years ago
7 years ago
Add Keybase integration (#10297) * create account_identity_proofs table * add endpoint for keybase to check local proofs * add async task to update validity and liveness of proofs from keybase * first pass keybase proof CRUD * second pass keybase proof creation * clean up proof list and add badges * add avatar url to keybase api * Always highlight the “Identity Proofs” navigation item when interacting with proofs. * Update translations. * Add profile URL. * Reorder proofs. * Add proofs to bio. * Update settings/identity_proofs front-end. * Use `link_to`. * Only encode query params if they exist. URLs without params had a trailing `?`. * Only show live proofs. * change valid to active in proof list and update liveness before displaying * minor fixes * add keybase config at well-known path * extremely naive feature flagging off the identity proof UI * fixes for rubocop * make identity proofs page resilient to potential keybase issues * normalize i18n * tweaks for brakeman * remove two unused translations * cleanup and add more localizations * make keybase_contacts an admin setting * fix ExternalProofService my_domain * use Addressable::URI in identity proofs * use active model serializer for keybase proof config * more cleanup of keybase proof config * rename proof is_valid and is_live to proof_valid and proof_live * cleanup * assorted tweaks for more robust communication with keybase * Clean up * Small fixes * Display verified identity identically to verified links * Clean up unused CSS * Add caching for Keybase avatar URLs * Remove keybase_contacts setting
5 years ago
Add Keybase integration (#10297) * create account_identity_proofs table * add endpoint for keybase to check local proofs * add async task to update validity and liveness of proofs from keybase * first pass keybase proof CRUD * second pass keybase proof creation * clean up proof list and add badges * add avatar url to keybase api * Always highlight the “Identity Proofs” navigation item when interacting with proofs. * Update translations. * Add profile URL. * Reorder proofs. * Add proofs to bio. * Update settings/identity_proofs front-end. * Use `link_to`. * Only encode query params if they exist. URLs without params had a trailing `?`. * Only show live proofs. * change valid to active in proof list and update liveness before displaying * minor fixes * add keybase config at well-known path * extremely naive feature flagging off the identity proof UI * fixes for rubocop * make identity proofs page resilient to potential keybase issues * normalize i18n * tweaks for brakeman * remove two unused translations * cleanup and add more localizations * make keybase_contacts an admin setting * fix ExternalProofService my_domain * use Addressable::URI in identity proofs * use active model serializer for keybase proof config * more cleanup of keybase proof config * rename proof is_valid and is_live to proof_valid and proof_live * cleanup * assorted tweaks for more robust communication with keybase * Clean up * Small fixes * Display verified identity identically to verified links * Clean up unused CSS * Add caching for Keybase avatar URLs * Remove keybase_contacts setting
5 years ago
Add Keybase integration (#10297) * create account_identity_proofs table * add endpoint for keybase to check local proofs * add async task to update validity and liveness of proofs from keybase * first pass keybase proof CRUD * second pass keybase proof creation * clean up proof list and add badges * add avatar url to keybase api * Always highlight the “Identity Proofs” navigation item when interacting with proofs. * Update translations. * Add profile URL. * Reorder proofs. * Add proofs to bio. * Update settings/identity_proofs front-end. * Use `link_to`. * Only encode query params if they exist. URLs without params had a trailing `?`. * Only show live proofs. * change valid to active in proof list and update liveness before displaying * minor fixes * add keybase config at well-known path * extremely naive feature flagging off the identity proof UI * fixes for rubocop * make identity proofs page resilient to potential keybase issues * normalize i18n * tweaks for brakeman * remove two unused translations * cleanup and add more localizations * make keybase_contacts an admin setting * fix ExternalProofService my_domain * use Addressable::URI in identity proofs * use active model serializer for keybase proof config * more cleanup of keybase proof config * rename proof is_valid and is_live to proof_valid and proof_live * cleanup * assorted tweaks for more robust communication with keybase * Clean up * Small fixes * Display verified identity identically to verified links * Clean up unused CSS * Add caching for Keybase avatar URLs * Remove keybase_contacts setting
5 years ago
Account domain blocks (#2381) * Add <ostatus:conversation /> tag to Atom input/output Only uses ref attribute (not href) because href would be the alternate link that's always included also. Creates new conversation for every non-reply status. Carries over conversation for every reply. Keeps remote URIs verbatim, generates local URIs on the fly like the rest of them. * Conversation muting - prevents notifications that reference a conversation (including replies, favourites, reblogs) from being created. API endpoints /api/v1/statuses/:id/mute and /api/v1/statuses/:id/unmute Currently no way to tell when a status/conversation is muted, so the web UI only has a "disable notifications" button, doesn't work as a toggle * Display "Dismiss notifications" on all statuses in notifications column, not just own * Add "muted" as a boolean attribute on statuses JSON For now always false on contained reblogs, since it's only relevant for statuses returned from the notifications endpoint, which are not nested Remove "Disable notifications" from detailed status view, since it's only relevant in the notifications column * Up max class length * Remove pending test for conversation mute * Add tests, clean up * Rename to "mute conversation" and "unmute conversation" * Raise validation error when trying to mute/unmute status without conversation * Adding account domain blocks that filter notifications and public timelines * Add tests for domain blocks in notifications, public timelines Filter reblogs of blocked domains from home * Add API for listing and creating account domain blocks * API for creating/deleting domain blocks, tests for Status#ancestors and Status#descendants, filter domain blocks from them * Filter domains in streaming API * Update account_domain_block_spec.rb
7 years ago
Web Push Notifications (#3243) * feat: Register push subscription * feat: Notify when mentioned * feat: Boost, favourite, reply, follow, follow request * feat: Notification interaction * feat: Handle change of public key * feat: Unsubscribe if things go wrong * feat: Do not send normal notifications if push is enabled * feat: Focus client if open * refactor: Move push logic to WebPushSubscription * feat: Better title and body * feat: Localize messages * chore: Fix lint errors * feat: Settings * refactor: Lazy load * fix: Check if push settings exist * feat: Device-based preferences * refactor: Simplify logic * refactor: Pull request feedback * refactor: Pull request feedback * refactor: Create /api/web/push_subscriptions endpoint * feat: Spec PushSubscriptionController * refactor: WebPushSubscription => Web::PushSubscription * feat: Spec Web::PushSubscription * feat: Display first media attachment * feat: Support direction * fix: Stuff broken while rebasing * refactor: Integration with session activations * refactor: Cleanup * refactor: Simplify implementation * feat: Set VAPID keys via environment * chore: Comments * fix: Crash when no alerts * fix: Set VAPID keys in testing environment * fix: Follow link * feat: Notification actions * fix: Delete previous subscription * chore: Temporary logs * refactor: Move migration to a later date * fix: Fetch the correct session activation and misc bugs * refactor: Move migration to a later date * fix: Remove follow request (no notifications) * feat: Send administrator contact to push service * feat: Set time-to-live * fix: Do not show sensitive images * fix: Reducer crash in error handling * feat: Add badge * chore: Fix lint error * fix: Checkbox label overlap * fix: Check for payload support * fix: Rename action "type" (crash in latest Chrome) * feat: Action to expand notification * fix: Lint errors * fix: Unescape notification body * fix: Do not allow boosting if the status is hidden * feat: Add VAPID keys to the production sample environment * fix: Strip HTML tags from status * refactor: Better error messages * refactor: Handle browser not implementing the VAPID protocol (Samsung Internet) * fix: Error when target_status is nil * fix: Handle lack of image * fix: Delete reference to invalid subscriptions * feat: Better error handling * fix: Unescape HTML characters after tags are striped * refactor: Simpify code * fix: Modify to work with #4091 * Sort strings alphabetically * i18n: Updated Polish translation it annoys me that it's not fully localized :P * refactor: Use current_session in PushSubscriptionController * fix: Rebase mistake * fix: Set cacheName to mastodon * refactor: Pull request feedback * refactor: Remove logging statements * chore(yarn): Fix conflicts with master * chore(yarn): Copy latest from master * chore(yarn): Readd offline-plugin * refactor: Use save! and update! * refactor: Send notifications async * fix: Allow retry when push fails * fix: Save track for failed pushes * fix: Minify sw.js * fix: Remove account_id from fabricator
6 years ago
8 years ago
  1. # frozen_string_literal: true
  2. require 'sidekiq/web'
  3. require 'sidekiq-scheduler/web'
  4. Sidekiq::Web.set :session_secret, Rails.application.secrets[:secret_key_base]
  5. Rails.application.routes.draw do
  6. root 'home#index'
  7. mount LetterOpenerWeb::Engine, at: 'letter_opener' if Rails.env.development?
  8. health_check_routes
  9. authenticate :user, lambda { |u| u.admin? } do
  10. mount Sidekiq::Web, at: 'sidekiq', as: :sidekiq
  11. mount PgHero::Engine, at: 'pghero', as: :pghero
  12. end
  13. use_doorkeeper do
  14. controllers authorizations: 'oauth/authorizations',
  15. authorized_applications: 'oauth/authorized_applications',
  16. tokens: 'oauth/tokens'
  17. end
  18. get '.well-known/host-meta', to: 'well_known/host_meta#show', as: :host_meta, defaults: { format: 'xml' }
  19. get '.well-known/webfinger', to: 'well_known/webfinger#show', as: :webfinger
  20. get '.well-known/change-password', to: redirect('/auth/edit')
  21. get '.well-known/keybase-proof-config', to: 'well_known/keybase_proof_config#show'
  22. get 'manifest', to: 'manifests#show', defaults: { format: 'json' }
  23. get 'intent', to: 'intents#show'
  24. get 'custom.css', to: 'custom_css#show', as: :custom_css
  25. resource :instance_actor, path: 'actor', only: [:show] do
  26. resource :inbox, only: [:create], module: :activitypub
  27. end
  28. devise_scope :user do
  29. get '/invite/:invite_code', to: 'auth/registrations#new', as: :public_invite
  30. namespace :auth do
  31. resource :setup, only: [:show, :update], controller: :setup
  32. end
  33. end
  34. devise_for :users, path: 'auth', controllers: {
  35. omniauth_callbacks: 'auth/omniauth_callbacks',
  36. sessions: 'auth/sessions',
  37. registrations: 'auth/registrations',
  38. passwords: 'auth/passwords',
  39. confirmations: 'auth/confirmations',
  40. }
  41. get '/users/:username', to: redirect('/@%{username}'), constraints: lambda { |req| req.format.nil? || req.format.html? }
  42. get '/authorize_follow', to: redirect { |_, request| "/authorize_interaction?#{request.params.to_query}" }
  43. resources :accounts, path: 'users', only: [:show], param: :username do
  44. get :remote_follow, to: 'remote_follow#new'
  45. post :remote_follow, to: 'remote_follow#create'
  46. resources :statuses, only: [:show] do
  47. member do
  48. get :activity
  49. get :embed
  50. end
  51. resources :replies, only: [:index], module: :activitypub
  52. end
  53. resources :followers, only: [:index], controller: :follower_accounts
  54. resources :following, only: [:index], controller: :following_accounts
  55. resource :follow, only: [:create], controller: :account_follow
  56. resource :unfollow, only: [:create], controller: :account_unfollow
  57. resource :outbox, only: [:show], module: :activitypub
  58. resource :inbox, only: [:create], module: :activitypub
  59. resources :collections, only: [:show], module: :activitypub
  60. end
  61. resource :inbox, only: [:create], module: :activitypub
  62. get '/@:username', to: 'accounts#show', as: :short_account
  63. get '/@:username/with_replies', to: 'accounts#show', as: :short_account_with_replies
  64. get '/@:username/media', to: 'accounts#show', as: :short_account_media
  65. get '/@:username/tagged/:tag', to: 'accounts#show', as: :short_account_tag
  66. get '/@:account_username/:id', to: 'statuses#show', as: :short_account_status
  67. get '/@:account_username/:id/embed', to: 'statuses#embed', as: :embed_short_account_status
  68. get '/interact/:id', to: 'remote_interaction#new', as: :remote_interaction
  69. post '/interact/:id', to: 'remote_interaction#create'
  70. get '/explore', to: 'directories#index', as: :explore
  71. get '/explore/:id', to: 'directories#show', as: :explore_hashtag
  72. get '/settings', to: redirect('/settings/profile')
  73. namespace :settings do
  74. resource :profile, only: [:show, :update]
  75. get :preferences, to: redirect('/settings/preferences/appearance')
  76. namespace :preferences do
  77. resource :appearance, only: [:show, :update], controller: :appearance
  78. resource :notifications, only: [:show, :update]
  79. resource :other, only: [:show, :update], controller: :other
  80. end
  81. resource :import, only: [:show, :create]
  82. resource :export, only: [:show, :create]
  83. namespace :exports, constraints: { format: :csv } do
  84. resources :follows, only: :index, controller: :following_accounts
  85. resources :blocks, only: :index, controller: :blocked_accounts
  86. resources :mutes, only: :index, controller: :muted_accounts
  87. resources :lists, only: :index, controller: :lists
  88. resources :domain_blocks, only: :index, controller: :blocked_domains
  89. end
  90. resource :two_factor_authentication, only: [:show, :create, :destroy]
  91. namespace :two_factor_authentication do
  92. resources :recovery_codes, only: [:create]
  93. resource :confirmation, only: [:new, :create]
  94. end
  95. resources :identity_proofs, only: [:index, :show, :new, :create, :update]
  96. resources :applications, except: [:edit] do
  97. member do
  98. post :regenerate
  99. end
  100. end
  101. resource :delete, only: [:show, :destroy]
  102. resource :migration, only: [:show, :update]
  103. resources :sessions, only: [:destroy]
  104. resources :featured_tags, only: [:index, :create, :destroy]
  105. end
  106. resources :media, only: [:show] do
  107. get :player
  108. end
  109. resources :tags, only: [:show]
  110. resources :emojis, only: [:show]
  111. resources :invites, only: [:index, :create, :destroy]
  112. resources :filters, except: [:show]
  113. resource :relationships, only: [:show, :update]
  114. get '/public', to: 'public_timelines#show', as: :public_timeline
  115. get '/media_proxy/:id/(*any)', to: 'media_proxy#show', as: :media_proxy
  116. resource :authorize_interaction, only: [:show, :create]
  117. resource :share, only: [:show, :create]
  118. namespace :admin do
  119. get '/dashboard', to: 'dashboard#index'
  120. resources :domain_allows, only: [:new, :create, :show, :destroy]
  121. resources :domain_blocks, only: [:new, :create, :show, :destroy, :update] do
  122. member do
  123. get :edit
  124. end
  125. end
  126. resources :email_domain_blocks, only: [:index, :new, :create, :destroy]
  127. resources :action_logs, only: [:index]
  128. resources :warning_presets, except: [:new]
  129. resource :settings, only: [:edit, :update]
  130. resources :invites, only: [:index, :create, :destroy] do
  131. collection do
  132. post :deactivate_all
  133. end
  134. end
  135. resources :relays, only: [:index, :new, :create, :destroy] do
  136. member do
  137. post :enable
  138. post :disable
  139. end
  140. end
  141. resources :instances, only: [:index, :show], constraints: { id: /[^\/]+/ }
  142. resources :reports, only: [:index, :show] do
  143. member do
  144. post :assign_to_self
  145. post :unassign
  146. post :reopen
  147. post :resolve
  148. end
  149. resources :reported_statuses, only: [:create]
  150. end
  151. resources :report_notes, only: [:create, :destroy]
  152. resources :accounts, only: [:index, :show] do
  153. member do
  154. post :enable
  155. post :unsilence
  156. post :unsuspend
  157. post :redownload
  158. post :remove_avatar
  159. post :remove_header
  160. post :memorialize
  161. post :approve
  162. post :reject
  163. end
  164. resource :change_email, only: [:show, :update]
  165. resource :reset, only: [:create]
  166. resource :action, only: [:new, :create], controller: 'account_actions'
  167. resources :statuses, only: [:index, :show, :create, :update, :destroy]
  168. resources :followers, only: [:index]
  169. resource :confirmation, only: [:create] do
  170. collection do
  171. post :resend
  172. end
  173. end
  174. resource :role do
  175. member do
  176. post :promote
  177. post :demote
  178. end
  179. end
  180. end
  181. resources :pending_accounts, only: [:index] do
  182. collection do
  183. post :approve_all
  184. post :reject_all
  185. post :batch
  186. end
  187. end
  188. resources :users, only: [] do
  189. resource :two_factor_authentication, only: [:destroy]
  190. end
  191. resources :custom_emojis, only: [:index, :new, :create] do
  192. collection do
  193. post :batch
  194. end
  195. end
  196. resources :account_moderation_notes, only: [:create, :destroy]
  197. resources :tags, only: [:index, :show, :update] do
  198. collection do
  199. post :approve_all
  200. post :reject_all
  201. post :batch
  202. end
  203. end
  204. end
  205. get '/admin', to: redirect('/admin/dashboard', status: 302)
  206. namespace :api do
  207. # OEmbed
  208. get '/oembed', to: 'oembed#show', as: :oembed
  209. # Identity proofs
  210. get :proofs, to: 'proofs#index'
  211. # JSON / REST API
  212. namespace :v1 do
  213. resources :statuses, only: [:create, :show, :destroy] do
  214. scope module: :statuses do
  215. resources :reblogged_by, controller: :reblogged_by_accounts, only: :index
  216. resources :favourited_by, controller: :favourited_by_accounts, only: :index
  217. resource :reblog, only: :create
  218. post :unreblog, to: 'reblogs#destroy'
  219. resource :favourite, only: :create
  220. post :unfavourite, to: 'favourites#destroy'
  221. resource :mute, only: :create
  222. post :unmute, to: 'mutes#destroy'
  223. resource :pin, only: :create
  224. post :unpin, to: 'pins#destroy'
  225. end
  226. member do
  227. get :context
  228. end
  229. end
  230. namespace :timelines do
  231. resource :home, only: :show, controller: :home
  232. resource :public, only: :show, controller: :public
  233. resources :tag, only: :show
  234. resources :list, only: :show
  235. end
  236. resources :streaming, only: [:index]
  237. resources :custom_emojis, only: [:index]
  238. resources :suggestions, only: [:index, :destroy]
  239. resources :scheduled_statuses, only: [:index, :show, :update, :destroy]
  240. resources :preferences, only: [:index]
  241. resources :conversations, only: [:index, :destroy] do
  242. member do
  243. post :read
  244. end
  245. end
  246. resources :media, only: [:create, :update]
  247. resources :blocks, only: [:index]
  248. resources :mutes, only: [:index]
  249. resources :favourites, only: [:index]
  250. resources :reports, only: [:create]
  251. resources :trends, only: [:index]
  252. resources :filters, only: [:index, :create, :show, :update, :destroy]
  253. resources :endorsements, only: [:index]
  254. resources :markers, only: [:index, :create]
  255. namespace :apps do
  256. get :verify_credentials, to: 'credentials#show'
  257. end
  258. resources :apps, only: [:create]
  259. resource :instance, only: [:show] do
  260. resources :peers, only: [:index], controller: 'instances/peers'
  261. resource :activity, only: [:show], controller: 'instances/activity'
  262. end
  263. resource :domain_blocks, only: [:show, :create, :destroy]
  264. resource :directory, only: [:show]
  265. resources :follow_requests, only: [:index] do
  266. member do
  267. post :authorize
  268. post :reject
  269. end
  270. end
  271. resources :notifications, only: [:index, :show] do
  272. collection do
  273. post :clear
  274. end
  275. member do
  276. post :dismiss
  277. end
  278. end
  279. namespace :accounts do
  280. get :verify_credentials, to: 'credentials#show'
  281. patch :update_credentials, to: 'credentials#update'
  282. resource :search, only: :show, controller: :search
  283. resources :relationships, only: :index
  284. end
  285. resources :accounts, only: [:create, :show] do
  286. resources :statuses, only: :index, controller: 'accounts/statuses'
  287. resources :followers, only: :index, controller: 'accounts/follower_accounts'
  288. resources :following, only: :index, controller: 'accounts/following_accounts'
  289. resources :lists, only: :index, controller: 'accounts/lists'
  290. resources :identity_proofs, only: :index, controller: 'accounts/identity_proofs'
  291. member do
  292. post :follow
  293. post :unfollow
  294. post :block
  295. post :unblock
  296. post :mute
  297. post :unmute
  298. end
  299. resource :pin, only: :create, controller: 'accounts/pins'
  300. post :unpin, to: 'accounts/pins#destroy'
  301. end
  302. resources :lists, only: [:index, :create, :show, :update, :destroy] do
  303. resource :accounts, only: [:show, :create, :destroy], controller: 'lists/accounts'
  304. end
  305. namespace :featured_tags do
  306. get :suggestions, to: 'suggestions#index'
  307. end
  308. resources :featured_tags, only: [:index, :create, :destroy]
  309. resources :polls, only: [:create, :show] do
  310. resources :votes, only: :create, controller: 'polls/votes'
  311. end
  312. namespace :push do
  313. resource :subscription, only: [:create, :show, :update, :destroy]
  314. end
  315. namespace :admin do
  316. resources :accounts, only: [:index, :show] do
  317. member do
  318. post :enable
  319. post :unsilence
  320. post :unsuspend
  321. post :approve
  322. post :reject
  323. end
  324. resource :action, only: [:create], controller: 'account_actions'
  325. end
  326. resources :reports, only: [:index, :show] do
  327. member do
  328. post :assign_to_self
  329. post :unassign
  330. post :reopen
  331. post :resolve
  332. end
  333. end
  334. end
  335. end
  336. namespace :v2 do
  337. get '/search', to: 'search#index', as: :search
  338. end
  339. namespace :web do
  340. resource :settings, only: [:update]
  341. resource :embed, only: [:create]
  342. resources :push_subscriptions, only: [:create] do
  343. member do
  344. put :update
  345. end
  346. end
  347. end
  348. end
  349. get '/web/(*any)', to: 'home#index', as: :web
  350. get '/about', to: 'about#show'
  351. get '/about/more', to: 'about#more'
  352. get '/about/blocks', to: 'about#blocks'
  353. get '/terms', to: 'about#terms'
  354. match '/', via: [:post, :put, :patch, :delete], to: 'application#raise_not_found', format: false
  355. match '*unmatched_route', via: :all, to: 'application#raise_not_found', format: false
  356. end