You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

732 lines
22 KiB

8 years ago
7 years ago
Add Keybase integration (#10297) * create account_identity_proofs table * add endpoint for keybase to check local proofs * add async task to update validity and liveness of proofs from keybase * first pass keybase proof CRUD * second pass keybase proof creation * clean up proof list and add badges * add avatar url to keybase api * Always highlight the “Identity Proofs” navigation item when interacting with proofs. * Update translations. * Add profile URL. * Reorder proofs. * Add proofs to bio. * Update settings/identity_proofs front-end. * Use `link_to`. * Only encode query params if they exist. URLs without params had a trailing `?`. * Only show live proofs. * change valid to active in proof list and update liveness before displaying * minor fixes * add keybase config at well-known path * extremely naive feature flagging off the identity proof UI * fixes for rubocop * make identity proofs page resilient to potential keybase issues * normalize i18n * tweaks for brakeman * remove two unused translations * cleanup and add more localizations * make keybase_contacts an admin setting * fix ExternalProofService my_domain * use Addressable::URI in identity proofs * use active model serializer for keybase proof config * more cleanup of keybase proof config * rename proof is_valid and is_live to proof_valid and proof_live * cleanup * assorted tweaks for more robust communication with keybase * Clean up * Small fixes * Display verified identity identically to verified links * Clean up unused CSS * Add caching for Keybase avatar URLs * Remove keybase_contacts setting
5 years ago
Add WebAuthn as an alternative 2FA method (#14466) * feat: add possibility of adding WebAuthn security keys to use as 2FA This adds a basic UI for enabling WebAuthn 2FA. We did a little refactor to the Settings page for editing the 2FA methods – now it will list the methods that are available to the user (TOTP and WebAuthn) and from there they'll be able to add or remove any of them. Also, it's worth mentioning that for enabling WebAuthn it's required to have TOTP enabled, so the first time that you go to the 2FA Settings page, you'll be asked to set it up. This work was inspired by the one donde by Github in their platform, and despite it could be approached in different ways, we decided to go with this one given that we feel that this gives a great UX. Co-authored-by: Facundo Padula <facundo.padula@cedarcode.com> * feat: add request for WebAuthn as second factor at login if enabled This commits adds the feature for using WebAuthn as a second factor for login when enabled. If users have WebAuthn enabled, now a page requesting for the use of a WebAuthn credential for log in will appear, although a link redirecting to the old page for logging in using a two-factor code will also be present. Co-authored-by: Facundo Padula <facundo.padula@cedarcode.com> * feat: add possibility of deleting WebAuthn Credentials Co-authored-by: Facundo Padula <facundo.padula@cedarcode.com> * feat: disable WebAuthn when an Admin disables 2FA for a user Co-authored-by: Facundo Padula <facundo.padula@cedarcode.com> * feat: remove ability to disable TOTP leaving only WebAuthn as 2FA Following examples form other platforms like Github, we decided to make Webauthn 2FA secondary to 2FA with TOTP, so that we removed the possibility of removing TOTP authentication only, leaving users with just WEbAuthn as 2FA. Instead, users will have to click on 'Disable 2FA' in order to remove second factor auth. The reason for WebAuthn being secondary to TOPT is that in that way, users will still be able to log in using their code from their phone's application if they don't have their security keys with them – or maybe even lost them. * We had to change a little the flow for setting up TOTP, given that now it's possible to setting up again if you already had TOTP, in order to let users modify their authenticator app – given that now it's not possible for them to disable TOTP and set it up again with another authenticator app. So, basically, now instead of storing the new `otp_secret` in the user, we store it in the session until the process of set up is finished. This was because, as it was before, when users clicked on 'Edit' in the new two-factor methods lists page, but then went back without finishing the flow, their `otp_secret` had been changed therefore invalidating their previous authenticator app, making them unable to log in again using TOTP. Co-authored-by: Facundo Padula <facundo.padula@cedarcode.com> * refactor: fix eslint errors The PR build was failing given that linting returning some errors. This commit attempts to fix them. * refactor: normalize i18n translations The build was failing given that i18n translations files were not normalized. This commits fixes that. * refactor: avoid having the webauthn gem locked to a specific version * refactor: use symbols for routes without '/' * refactor: avoid sending webauthn disabled email when 2FA is disabled When an admins disable 2FA for users, we were sending two mails to them, one notifying that 2FA was disabled and the other to notify that WebAuthn was disabled. As the second one is redundant since the first email includes it, we can remove it and send just one email to users. * refactor: avoid creating new env variable for webauthn_origin config * refactor: improve flash error messages for webauthn pages Co-authored-by: Facundo Padula <facundo.padula@cedarcode.com>
3 years ago
Add follower synchronization mechanism (#14510) * Add support for followers synchronization on the receiving end Check the `collectionSynchronization` attribute on `Create` and `Announce` activities and synchronize followers from provided collection if possible. * Add tests for followers synchronization on the receiving end * Add support for follower synchronization on the sender's end * Add tests for the sending end * Switch from AS attributes to HTTP header Replace the custom `collectionSynchronization` ActivityStreams attribute by an HTTP header (`X-AS-Collection-Synchronization`) with the same syntax as the `Signature` header and the following fields: - `collectionId` to specify which collection to synchronize - `digest` for the SHA256 hex-digest of the list of followers known on the receiving instance (where “receiving instance” is determined by accounts sharing the same host name for their ActivityPub actor `id`) - `url` of a collection that should be fetched by the instance actor Internally, move away from the webfinger-based `domain` attribute and use account `uri` prefix to group accounts. * Add environment variable to disable followers synchronization Since the whole mechanism relies on some new preconditions that, in some extremely rare cases, might not be met, add an environment variable (DISABLE_FOLLOWERS_SYNCHRONIZATION) to disable the mechanism altogether and avoid followers being incorrectly removed. The current conditions are: 1. all managed accounts' actor `id` and inbox URL have the same URI scheme and netloc. 2. all accounts whose actor `id` or inbox URL share the same URI scheme and netloc as a managed account must be managed by the same Mastodon instance as well. As far as Mastodon is concerned, breaking those preconditions require extensive configuration changes in the reverse proxy and might also cause other issues. Therefore, this environment variable provides a way out for people with highly unusual configurations, and can be safely ignored for the overwhelming majority of Mastodon administrators. * Only set follower synchronization header on non-public statuses This is to avoid unnecessary computations and allow Follow-related activities to be handled by the usual codepath instead of going through the synchronization mechanism (otherwise, any Follow/Undo/Accept activity would trigger the synchronization mechanism even if processing the activity itself would be enough to re-introduce synchronization) * Change how ActivityPub::SynchronizeFollowersService handles follow requests If the remote lists a local follower which we only know has sent a follow request, consider the follow request as accepted instead of sending an Undo. * Integrate review feeback - rename X-AS-Collection-Synchronization to Collection-Synchronization - various minor refactoring and code style changes * Only select required fields when computing followers_hash * Use actor URI rather than webfinger domain in synchronization endpoint * Change hash computation to be a XOR of individual hashes Makes it much easier to be memory-efficient, and avoid sorting discrepancy issues. * Marginally improve followers_hash computation speed * Further improve hash computation performances by using pluck_each
3 years ago
Add WebAuthn as an alternative 2FA method (#14466) * feat: add possibility of adding WebAuthn security keys to use as 2FA This adds a basic UI for enabling WebAuthn 2FA. We did a little refactor to the Settings page for editing the 2FA methods – now it will list the methods that are available to the user (TOTP and WebAuthn) and from there they'll be able to add or remove any of them. Also, it's worth mentioning that for enabling WebAuthn it's required to have TOTP enabled, so the first time that you go to the 2FA Settings page, you'll be asked to set it up. This work was inspired by the one donde by Github in their platform, and despite it could be approached in different ways, we decided to go with this one given that we feel that this gives a great UX. Co-authored-by: Facundo Padula <facundo.padula@cedarcode.com> * feat: add request for WebAuthn as second factor at login if enabled This commits adds the feature for using WebAuthn as a second factor for login when enabled. If users have WebAuthn enabled, now a page requesting for the use of a WebAuthn credential for log in will appear, although a link redirecting to the old page for logging in using a two-factor code will also be present. Co-authored-by: Facundo Padula <facundo.padula@cedarcode.com> * feat: add possibility of deleting WebAuthn Credentials Co-authored-by: Facundo Padula <facundo.padula@cedarcode.com> * feat: disable WebAuthn when an Admin disables 2FA for a user Co-authored-by: Facundo Padula <facundo.padula@cedarcode.com> * feat: remove ability to disable TOTP leaving only WebAuthn as 2FA Following examples form other platforms like Github, we decided to make Webauthn 2FA secondary to 2FA with TOTP, so that we removed the possibility of removing TOTP authentication only, leaving users with just WEbAuthn as 2FA. Instead, users will have to click on 'Disable 2FA' in order to remove second factor auth. The reason for WebAuthn being secondary to TOPT is that in that way, users will still be able to log in using their code from their phone's application if they don't have their security keys with them – or maybe even lost them. * We had to change a little the flow for setting up TOTP, given that now it's possible to setting up again if you already had TOTP, in order to let users modify their authenticator app – given that now it's not possible for them to disable TOTP and set it up again with another authenticator app. So, basically, now instead of storing the new `otp_secret` in the user, we store it in the session until the process of set up is finished. This was because, as it was before, when users clicked on 'Edit' in the new two-factor methods lists page, but then went back without finishing the flow, their `otp_secret` had been changed therefore invalidating their previous authenticator app, making them unable to log in again using TOTP. Co-authored-by: Facundo Padula <facundo.padula@cedarcode.com> * refactor: fix eslint errors The PR build was failing given that linting returning some errors. This commit attempts to fix them. * refactor: normalize i18n translations The build was failing given that i18n translations files were not normalized. This commits fixes that. * refactor: avoid having the webauthn gem locked to a specific version * refactor: use symbols for routes without '/' * refactor: avoid sending webauthn disabled email when 2FA is disabled When an admins disable 2FA for users, we were sending two mails to them, one notifying that 2FA was disabled and the other to notify that WebAuthn was disabled. As the second one is redundant since the first email includes it, we can remove it and send just one email to users. * refactor: avoid creating new env variable for webauthn_origin config * refactor: improve flash error messages for webauthn pages Co-authored-by: Facundo Padula <facundo.padula@cedarcode.com>
3 years ago
Account domain blocks (#2381) * Add <ostatus:conversation /> tag to Atom input/output Only uses ref attribute (not href) because href would be the alternate link that's always included also. Creates new conversation for every non-reply status. Carries over conversation for every reply. Keeps remote URIs verbatim, generates local URIs on the fly like the rest of them. * Conversation muting - prevents notifications that reference a conversation (including replies, favourites, reblogs) from being created. API endpoints /api/v1/statuses/:id/mute and /api/v1/statuses/:id/unmute Currently no way to tell when a status/conversation is muted, so the web UI only has a "disable notifications" button, doesn't work as a toggle * Display "Dismiss notifications" on all statuses in notifications column, not just own * Add "muted" as a boolean attribute on statuses JSON For now always false on contained reblogs, since it's only relevant for statuses returned from the notifications endpoint, which are not nested Remove "Disable notifications" from detailed status view, since it's only relevant in the notifications column * Up max class length * Remove pending test for conversation mute * Add tests, clean up * Rename to "mute conversation" and "unmute conversation" * Raise validation error when trying to mute/unmute status without conversation * Adding account domain blocks that filter notifications and public timelines * Add tests for domain blocks in notifications, public timelines Filter reblogs of blocked domains from home * Add API for listing and creating account domain blocks * API for creating/deleting domain blocks, tests for Status#ancestors and Status#descendants, filter domain blocks from them * Filter domains in streaming API * Update account_domain_block_spec.rb
7 years ago
Web Push Notifications (#3243) * feat: Register push subscription * feat: Notify when mentioned * feat: Boost, favourite, reply, follow, follow request * feat: Notification interaction * feat: Handle change of public key * feat: Unsubscribe if things go wrong * feat: Do not send normal notifications if push is enabled * feat: Focus client if open * refactor: Move push logic to WebPushSubscription * feat: Better title and body * feat: Localize messages * chore: Fix lint errors * feat: Settings * refactor: Lazy load * fix: Check if push settings exist * feat: Device-based preferences * refactor: Simplify logic * refactor: Pull request feedback * refactor: Pull request feedback * refactor: Create /api/web/push_subscriptions endpoint * feat: Spec PushSubscriptionController * refactor: WebPushSubscription => Web::PushSubscription * feat: Spec Web::PushSubscription * feat: Display first media attachment * feat: Support direction * fix: Stuff broken while rebasing * refactor: Integration with session activations * refactor: Cleanup * refactor: Simplify implementation * feat: Set VAPID keys via environment * chore: Comments * fix: Crash when no alerts * fix: Set VAPID keys in testing environment * fix: Follow link * feat: Notification actions * fix: Delete previous subscription * chore: Temporary logs * refactor: Move migration to a later date * fix: Fetch the correct session activation and misc bugs * refactor: Move migration to a later date * fix: Remove follow request (no notifications) * feat: Send administrator contact to push service * feat: Set time-to-live * fix: Do not show sensitive images * fix: Reducer crash in error handling * feat: Add badge * chore: Fix lint error * fix: Checkbox label overlap * fix: Check for payload support * fix: Rename action "type" (crash in latest Chrome) * feat: Action to expand notification * fix: Lint errors * fix: Unescape notification body * fix: Do not allow boosting if the status is hidden * feat: Add VAPID keys to the production sample environment * fix: Strip HTML tags from status * refactor: Better error messages * refactor: Handle browser not implementing the VAPID protocol (Samsung Internet) * fix: Error when target_status is nil * fix: Handle lack of image * fix: Delete reference to invalid subscriptions * feat: Better error handling * fix: Unescape HTML characters after tags are striped * refactor: Simpify code * fix: Modify to work with #4091 * Sort strings alphabetically * i18n: Updated Polish translation it annoys me that it's not fully localized :P * refactor: Use current_session in PushSubscriptionController * fix: Rebase mistake * fix: Set cacheName to mastodon * refactor: Pull request feedback * refactor: Remove logging statements * chore(yarn): Fix conflicts with master * chore(yarn): Copy latest from master * chore(yarn): Readd offline-plugin * refactor: Use save! and update! * refactor: Send notifications async * fix: Allow retry when push fails * fix: Save track for failed pushes * fix: Minify sw.js * fix: Remove account_id from fabricator
6 years ago
8 years ago
  1. # frozen_string_literal: true
  2. require 'sidekiq_unique_jobs/web'
  3. require 'sidekiq-scheduler/web'
  4. Rails.application.routes.draw do
  5. # Paths of routes on the web app that to not require to be indexed or
  6. # have alternative format representations requiring separate controllers
  7. web_app_paths = %w(
  8. /getting-started
  9. /getting-started-misc
  10. /keyboard-shortcuts
  11. /home
  12. /public
  13. /public/local
  14. /conversations
  15. /lists/(*any)
  16. /notifications
  17. /favourites
  18. /bookmarks
  19. /pinned
  20. /start
  21. /directory
  22. /explore/(*any)
  23. /search
  24. /publish
  25. /follow_requests
  26. /blocks
  27. /domain_blocks
  28. /mutes
  29. /followed_tags
  30. /statuses/(*any)
  31. ).freeze
  32. root 'home#index'
  33. mount LetterOpenerWeb::Engine, at: 'letter_opener' if Rails.env.development?
  34. get 'health', to: 'health#show'
  35. authenticate :user, lambda { |u| u.role&.can?(:view_devops) } do
  36. mount Sidekiq::Web, at: 'sidekiq', as: :sidekiq
  37. mount PgHero::Engine, at: 'pghero', as: :pghero
  38. end
  39. use_doorkeeper do
  40. controllers authorizations: 'oauth/authorizations',
  41. authorized_applications: 'oauth/authorized_applications',
  42. tokens: 'oauth/tokens'
  43. end
  44. get '.well-known/host-meta', to: 'well_known/host_meta#show', as: :host_meta, defaults: { format: 'xml' }
  45. get '.well-known/nodeinfo', to: 'well_known/nodeinfo#index', as: :nodeinfo, defaults: { format: 'json' }
  46. get '.well-known/webfinger', to: 'well_known/webfinger#show', as: :webfinger
  47. get '.well-known/change-password', to: redirect('/auth/edit')
  48. get '/nodeinfo/2.0', to: 'well_known/nodeinfo#show', as: :nodeinfo_schema
  49. get 'manifest', to: 'manifests#show', defaults: { format: 'json' }
  50. get 'intent', to: 'intents#show'
  51. get 'custom.css', to: 'custom_css#show', as: :custom_css
  52. resource :instance_actor, path: 'actor', only: [:show] do
  53. resource :inbox, only: [:create], module: :activitypub
  54. resource :outbox, only: [:show], module: :activitypub
  55. end
  56. devise_scope :user do
  57. get '/invite/:invite_code', to: 'auth/registrations#new', as: :public_invite
  58. namespace :auth do
  59. resource :setup, only: [:show, :update], controller: :setup
  60. resource :challenge, only: [:create], controller: :challenges
  61. get 'sessions/security_key_options', to: 'sessions#webauthn_options'
  62. post 'captcha_confirmation', to: 'confirmations#confirm_captcha', as: :captcha_confirmation
  63. end
  64. end
  65. devise_for :users, path: 'auth', format: false, controllers: {
  66. omniauth_callbacks: 'auth/omniauth_callbacks',
  67. sessions: 'auth/sessions',
  68. registrations: 'auth/registrations',
  69. passwords: 'auth/passwords',
  70. confirmations: 'auth/confirmations',
  71. }
  72. get '/users/:username', to: redirect('/@%{username}'), constraints: lambda { |req| req.format.nil? || req.format.html? }
  73. get '/users/:username/statuses/:id', to: redirect('/@%{username}/%{id}'), constraints: lambda { |req| req.format.nil? || req.format.html? }
  74. get '/authorize_follow', to: redirect { |_, request| "/authorize_interaction?#{request.params.to_query}" }
  75. resources :accounts, path: 'users', only: [:show], param: :username do
  76. resources :statuses, only: [:show] do
  77. member do
  78. get :activity
  79. get :embed
  80. end
  81. resources :replies, only: [:index], module: :activitypub
  82. end
  83. resources :followers, only: [:index], controller: :follower_accounts
  84. resources :following, only: [:index], controller: :following_accounts
  85. resource :follow, only: [:create], controller: :account_follow
  86. resource :unfollow, only: [:create], controller: :account_unfollow
  87. resource :outbox, only: [:show], module: :activitypub
  88. resource :inbox, only: [:create], module: :activitypub
  89. resource :claim, only: [:create], module: :activitypub
  90. resources :collections, only: [:show], module: :activitypub
  91. resource :followers_synchronization, only: [:show], module: :activitypub
  92. end
  93. resource :inbox, only: [:create], module: :activitypub
  94. get '/:encoded_at(*path)', to: redirect("/@%{path}"), constraints: { encoded_at: /%40/ }
  95. constraints(username: /[^@\/.]+/) do
  96. get '/@:username', to: 'accounts#show', as: :short_account
  97. get '/@:username/with_replies', to: 'accounts#show', as: :short_account_with_replies
  98. get '/@:username/media', to: 'accounts#show', as: :short_account_media
  99. get '/@:username/tagged/:tag', to: 'accounts#show', as: :short_account_tag
  100. end
  101. constraints(account_username: /[^@\/.]+/) do
  102. get '/@:account_username/following', to: 'following_accounts#index'
  103. get '/@:account_username/followers', to: 'follower_accounts#index'
  104. get '/@:account_username/:id', to: 'statuses#show', as: :short_account_status
  105. get '/@:account_username/:id/embed', to: 'statuses#embed', as: :embed_short_account_status
  106. end
  107. get '/@:username_with_domain/(*any)', to: 'home#index', constraints: { username_with_domain: /([^\/])+?/ }, format: false
  108. get '/settings', to: redirect('/settings/profile')
  109. namespace :settings do
  110. resource :profile, only: [:show, :update] do
  111. resources :pictures, only: :destroy
  112. end
  113. get :preferences, to: redirect('/settings/preferences/appearance')
  114. namespace :preferences do
  115. resource :appearance, only: [:show, :update], controller: :appearance
  116. resource :notifications, only: [:show, :update]
  117. resource :other, only: [:show, :update], controller: :other
  118. end
  119. resource :import, only: [:show, :create]
  120. resource :export, only: [:show, :create]
  121. namespace :exports, constraints: { format: :csv } do
  122. resources :follows, only: :index, controller: :following_accounts
  123. resources :blocks, only: :index, controller: :blocked_accounts
  124. resources :mutes, only: :index, controller: :muted_accounts
  125. resources :lists, only: :index, controller: :lists
  126. resources :domain_blocks, only: :index, controller: :blocked_domains
  127. resources :bookmarks, only: :index, controller: :bookmarks
  128. end
  129. resources :two_factor_authentication_methods, only: [:index] do
  130. collection do
  131. post :disable
  132. end
  133. end
  134. resource :otp_authentication, only: [:show, :create], controller: 'two_factor_authentication/otp_authentication'
  135. resources :webauthn_credentials, only: [:index, :new, :create, :destroy],
  136. path: 'security_keys',
  137. controller: 'two_factor_authentication/webauthn_credentials' do
  138. collection do
  139. get :options
  140. end
  141. end
  142. namespace :two_factor_authentication do
  143. resources :recovery_codes, only: [:create]
  144. resource :confirmation, only: [:new, :create]
  145. end
  146. resources :applications, except: [:edit] do
  147. member do
  148. post :regenerate
  149. end
  150. end
  151. resources :flavours, only: [:index, :show, :update], param: :flavour
  152. resource :delete, only: [:show, :destroy]
  153. resource :migration, only: [:show, :create]
  154. namespace :migration do
  155. resource :redirect, only: [:new, :create, :destroy]
  156. end
  157. resources :aliases, only: [:index, :create, :destroy]
  158. resources :sessions, only: [:destroy]
  159. resources :featured_tags, only: [:index, :create, :destroy]
  160. resources :login_activities, only: [:index]
  161. end
  162. namespace :disputes do
  163. resources :strikes, only: [:show, :index] do
  164. resource :appeal, only: [:create]
  165. end
  166. end
  167. resources :media, only: [:show] do
  168. get :player
  169. end
  170. resources :tags, only: [:show]
  171. resources :emojis, only: [:show]
  172. resources :invites, only: [:index, :create, :destroy]
  173. resources :filters, except: [:show] do
  174. resources :statuses, only: [:index], controller: 'filters/statuses' do
  175. collection do
  176. post :batch
  177. end
  178. end
  179. end
  180. resource :relationships, only: [:show, :update]
  181. resource :statuses_cleanup, controller: :statuses_cleanup, only: [:show, :update]
  182. get '/media_proxy/:id/(*any)', to: 'media_proxy#show', as: :media_proxy, format: false
  183. get '/backups/:id/download', to: 'backups#download', as: :download_backup, format: false
  184. resource :authorize_interaction, only: [:show, :create]
  185. resource :share, only: [:show, :create]
  186. namespace :admin do
  187. get '/dashboard', to: 'dashboard#index'
  188. resources :domain_allows, only: [:new, :create, :show, :destroy]
  189. resources :domain_blocks, only: [:new, :create, :destroy, :update, :edit] do
  190. collection do
  191. post :batch
  192. end
  193. end
  194. resources :export_domain_allows, only: [:new] do
  195. collection do
  196. get :export, constraints: { format: :csv }
  197. post :import
  198. end
  199. end
  200. resources :export_domain_blocks, only: [:new] do
  201. collection do
  202. get :export, constraints: { format: :csv }
  203. post :import
  204. end
  205. end
  206. resources :email_domain_blocks, only: [:index, :new, :create] do
  207. collection do
  208. post :batch
  209. end
  210. end
  211. resources :action_logs, only: [:index]
  212. resources :warning_presets, except: [:new]
  213. resources :announcements, except: [:show] do
  214. member do
  215. post :publish
  216. post :unpublish
  217. end
  218. end
  219. get '/settings', to: redirect('/admin/settings/branding')
  220. get '/settings/edit', to: redirect('/admin/settings/branding')
  221. namespace :settings do
  222. resource :branding, only: [:show, :update], controller: 'branding'
  223. resource :registrations, only: [:show, :update], controller: 'registrations'
  224. resource :content_retention, only: [:show, :update], controller: 'content_retention'
  225. resource :about, only: [:show, :update], controller: 'about'
  226. resource :appearance, only: [:show, :update], controller: 'appearance'
  227. resource :discovery, only: [:show, :update], controller: 'discovery'
  228. resource :other, only: [:show, :update], controller: 'other'
  229. end
  230. resources :site_uploads, only: [:destroy]
  231. resources :invites, only: [:index, :create, :destroy] do
  232. collection do
  233. post :deactivate_all
  234. end
  235. end
  236. resources :relays, only: [:index, :new, :create, :destroy] do
  237. member do
  238. post :enable
  239. post :disable
  240. end
  241. end
  242. resources :instances, only: [:index, :show, :destroy], constraints: { id: /[^\/]+/ } do
  243. member do
  244. post :clear_delivery_errors
  245. post :restart_delivery
  246. post :stop_delivery
  247. end
  248. end
  249. resources :rules
  250. resources :webhooks do
  251. member do
  252. post :enable
  253. post :disable
  254. end
  255. resource :secret, only: [], controller: 'webhooks/secrets' do
  256. post :rotate
  257. end
  258. end
  259. resources :reports, only: [:index, :show] do
  260. resources :actions, only: [:create], controller: 'reports/actions' do
  261. collection do
  262. post :preview
  263. end
  264. end
  265. member do
  266. post :assign_to_self
  267. post :unassign
  268. post :reopen
  269. post :resolve
  270. end
  271. end
  272. resources :report_notes, only: [:create, :destroy]
  273. resources :accounts, only: [:index, :show, :destroy] do
  274. member do
  275. post :enable
  276. post :unsensitive
  277. post :unsilence
  278. post :unsuspend
  279. post :redownload
  280. post :remove_avatar
  281. post :remove_header
  282. post :memorialize
  283. post :approve
  284. post :reject
  285. post :unblock_email
  286. end
  287. collection do
  288. post :batch
  289. end
  290. resource :change_email, only: [:show, :update]
  291. resource :reset, only: [:create]
  292. resource :action, only: [:new, :create], controller: 'account_actions'
  293. resources :statuses, only: [:index, :show] do
  294. collection do
  295. post :batch
  296. end
  297. end
  298. resources :relationships, only: [:index]
  299. resource :confirmation, only: [:create] do
  300. collection do
  301. post :resend
  302. end
  303. end
  304. end
  305. resources :users, only: [] do
  306. resource :two_factor_authentication, only: [:destroy], controller: 'users/two_factor_authentications'
  307. resource :role, only: [:show, :update], controller: 'users/roles'
  308. end
  309. resources :custom_emojis, only: [:index, :new, :create] do
  310. collection do
  311. post :batch
  312. end
  313. end
  314. resources :ip_blocks, only: [:index, :new, :create] do
  315. collection do
  316. post :batch
  317. end
  318. end
  319. resources :roles, except: [:show]
  320. resources :account_moderation_notes, only: [:create, :destroy]
  321. resource :follow_recommendations, only: [:show, :update]
  322. resources :tags, only: [:show, :update]
  323. namespace :trends do
  324. resources :links, only: [:index] do
  325. collection do
  326. post :batch
  327. end
  328. end
  329. resources :tags, only: [:index] do
  330. collection do
  331. post :batch
  332. end
  333. end
  334. resources :statuses, only: [:index] do
  335. collection do
  336. post :batch
  337. end
  338. end
  339. namespace :links do
  340. resources :preview_card_providers, only: [:index], path: :publishers do
  341. collection do
  342. post :batch
  343. end
  344. end
  345. end
  346. end
  347. namespace :disputes do
  348. resources :appeals, only: [:index] do
  349. member do
  350. post :approve
  351. post :reject
  352. end
  353. end
  354. end
  355. end
  356. get '/admin', to: redirect('/admin/dashboard', status: 302)
  357. namespace :api, format: false do
  358. # OEmbed
  359. get '/oembed', to: 'oembed#show', as: :oembed
  360. # JSON / REST API
  361. namespace :v1 do
  362. resources :statuses, only: [:create, :show, :update, :destroy] do
  363. scope module: :statuses do
  364. resources :reblogged_by, controller: :reblogged_by_accounts, only: :index
  365. resources :favourited_by, controller: :favourited_by_accounts, only: :index
  366. resource :reblog, only: :create
  367. post :unreblog, to: 'reblogs#destroy'
  368. resource :favourite, only: :create
  369. post :unfavourite, to: 'favourites#destroy'
  370. resource :bookmark, only: :create
  371. post :unbookmark, to: 'bookmarks#destroy'
  372. resource :mute, only: :create
  373. post :unmute, to: 'mutes#destroy'
  374. resource :pin, only: :create
  375. post :unpin, to: 'pins#destroy'
  376. resource :history, only: :show
  377. resource :source, only: :show
  378. post :translate, to: 'translations#create'
  379. end
  380. member do
  381. get :context
  382. end
  383. end
  384. namespace :timelines do
  385. resource :direct, only: :show, controller: :direct
  386. resource :home, only: :show, controller: :home
  387. resource :public, only: :show, controller: :public
  388. resources :tag, only: :show
  389. resources :list, only: :show
  390. end
  391. get '/streaming', to: 'streaming#index'
  392. get '/streaming/(*any)', to: 'streaming#index'
  393. resources :custom_emojis, only: [:index]
  394. resources :suggestions, only: [:index, :destroy]
  395. resources :scheduled_statuses, only: [:index, :show, :update, :destroy]
  396. resources :preferences, only: [:index]
  397. resources :announcements, only: [:index] do
  398. scope module: :announcements do
  399. resources :reactions, only: [:update, :destroy]
  400. end
  401. member do
  402. post :dismiss
  403. end
  404. end
  405. # namespace :crypto do
  406. # resources :deliveries, only: :create
  407. # namespace :keys do
  408. # resource :upload, only: [:create]
  409. # resource :query, only: [:create]
  410. # resource :claim, only: [:create]
  411. # resource :count, only: [:show]
  412. # end
  413. # resources :encrypted_messages, only: [:index] do
  414. # collection do
  415. # post :clear
  416. # end
  417. # end
  418. # end
  419. resources :conversations, only: [:index, :destroy] do
  420. member do
  421. post :read
  422. end
  423. end
  424. resources :media, only: [:create, :update, :show]
  425. resources :blocks, only: [:index]
  426. resources :mutes, only: [:index]
  427. resources :favourites, only: [:index]
  428. resources :bookmarks, only: [:index]
  429. resources :reports, only: [:create]
  430. resources :trends, only: [:index], controller: 'trends/tags'
  431. resources :filters, only: [:index, :create, :show, :update, :destroy]
  432. resources :endorsements, only: [:index]
  433. resources :markers, only: [:index, :create]
  434. namespace :apps do
  435. get :verify_credentials, to: 'credentials#show'
  436. end
  437. resources :apps, only: [:create]
  438. namespace :trends do
  439. resources :links, only: [:index]
  440. resources :tags, only: [:index]
  441. resources :statuses, only: [:index]
  442. end
  443. namespace :emails do
  444. resources :confirmations, only: [:create]
  445. end
  446. resource :instance, only: [:show] do
  447. resources :peers, only: [:index], controller: 'instances/peers'
  448. resources :rules, only: [:index], controller: 'instances/rules'
  449. resources :domain_blocks, only: [:index], controller: 'instances/domain_blocks'
  450. resource :privacy_policy, only: [:show], controller: 'instances/privacy_policies'
  451. resource :extended_description, only: [:show], controller: 'instances/extended_descriptions'
  452. resource :translation_languages, only: [:show], controller: 'instances/translation_languages'
  453. resource :activity, only: [:show], controller: 'instances/activity'
  454. end
  455. resource :domain_blocks, only: [:show, :create, :destroy]
  456. resource :directory, only: [:show]
  457. resources :follow_requests, only: [:index] do
  458. member do
  459. post :authorize
  460. post :reject
  461. end
  462. end
  463. resources :notifications, only: [:index, :show, :destroy] do
  464. collection do
  465. post :clear
  466. delete :destroy_multiple
  467. end
  468. member do
  469. post :dismiss
  470. end
  471. end
  472. namespace :accounts do
  473. get :verify_credentials, to: 'credentials#show'
  474. patch :update_credentials, to: 'credentials#update'
  475. resource :search, only: :show, controller: :search
  476. resource :lookup, only: :show, controller: :lookup
  477. resources :relationships, only: :index
  478. resources :familiar_followers, only: :index
  479. end
  480. resources :accounts, only: [:create, :show] do
  481. resources :statuses, only: :index, controller: 'accounts/statuses'
  482. resources :followers, only: :index, controller: 'accounts/follower_accounts'
  483. resources :following, only: :index, controller: 'accounts/following_accounts'
  484. resources :lists, only: :index, controller: 'accounts/lists'
  485. resources :identity_proofs, only: :index, controller: 'accounts/identity_proofs'
  486. resources :featured_tags, only: :index, controller: 'accounts/featured_tags'
  487. member do
  488. post :follow
  489. post :unfollow
  490. post :remove_from_followers
  491. post :block
  492. post :unblock
  493. post :mute
  494. post :unmute
  495. end
  496. resource :pin, only: :create, controller: 'accounts/pins'
  497. post :unpin, to: 'accounts/pins#destroy'
  498. resource :note, only: :create, controller: 'accounts/notes'
  499. end
  500. resources :tags, only: [:show] do
  501. member do
  502. post :follow
  503. post :unfollow
  504. end
  505. end
  506. resources :followed_tags, only: [:index]
  507. resources :lists, only: [:index, :create, :show, :update, :destroy] do
  508. resource :accounts, only: [:show, :create, :destroy], controller: 'lists/accounts'
  509. end
  510. namespace :featured_tags do
  511. get :suggestions, to: 'suggestions#index'
  512. end
  513. resources :featured_tags, only: [:index, :create, :destroy]
  514. resources :polls, only: [:create, :show] do
  515. resources :votes, only: :create, controller: 'polls/votes'
  516. end
  517. namespace :push do
  518. resource :subscription, only: [:create, :show, :update, :destroy]
  519. end
  520. namespace :admin do
  521. resources :accounts, only: [:index, :show, :destroy] do
  522. member do
  523. post :enable
  524. post :unsensitive
  525. post :unsilence
  526. post :unsuspend
  527. post :approve
  528. post :reject
  529. end
  530. resource :action, only: [:create], controller: 'account_actions'
  531. end
  532. resources :reports, only: [:index, :update, :show] do
  533. member do
  534. post :assign_to_self
  535. post :unassign
  536. post :reopen
  537. post :resolve
  538. end
  539. end
  540. resources :domain_allows, only: [:index, :show, :create, :destroy]
  541. resources :domain_blocks, only: [:index, :show, :update, :create, :destroy]
  542. resources :email_domain_blocks, only: [:index, :show, :create, :destroy]
  543. resources :ip_blocks, only: [:index, :show, :update, :create, :destroy]
  544. namespace :trends do
  545. resources :tags, only: [:index]
  546. resources :links, only: [:index]
  547. resources :statuses, only: [:index]
  548. end
  549. post :measures, to: 'measures#create'
  550. post :dimensions, to: 'dimensions#create'
  551. post :retention, to: 'retention#create'
  552. resources :canonical_email_blocks, only: [:index, :create, :show, :destroy] do
  553. collection do
  554. post :test
  555. end
  556. end
  557. end
  558. end
  559. namespace :v2 do
  560. get '/search', to: 'search#index', as: :search
  561. resources :media, only: [:create]
  562. resources :suggestions, only: [:index]
  563. resource :instance, only: [:show]
  564. resources :filters, only: [:index, :create, :show, :update, :destroy] do
  565. resources :keywords, only: [:index, :create], controller: 'filters/keywords'
  566. resources :statuses, only: [:index, :create], controller: 'filters/statuses'
  567. end
  568. namespace :filters do
  569. resources :keywords, only: [:show, :update, :destroy]
  570. resources :statuses, only: [:show, :destroy]
  571. end
  572. namespace :admin do
  573. resources :accounts, only: [:index]
  574. end
  575. end
  576. namespace :web do
  577. resource :settings, only: [:update]
  578. resource :embed, only: [:create]
  579. resources :push_subscriptions, only: [:create] do
  580. member do
  581. put :update
  582. end
  583. end
  584. end
  585. end
  586. web_app_paths.each do |path|
  587. get path, to: 'home#index'
  588. end
  589. get '/web/(*any)', to: redirect('/%{any}', status: 302), as: :web, defaults: { any: '' }, format: false
  590. get '/about', to: 'about#show'
  591. get '/about/more', to: redirect('/about')
  592. get '/privacy-policy', to: 'privacy#show', as: :privacy_policy
  593. get '/terms', to: redirect('/privacy-policy')
  594. match '/', via: [:post, :put, :patch, :delete], to: 'application#raise_not_found', format: false
  595. match '*unmatched_route', via: :all, to: 'application#raise_not_found', format: false
  596. end