You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

436 lines
13 KiB

8 years ago
7 years ago
Add Keybase integration (#10297) * create account_identity_proofs table * add endpoint for keybase to check local proofs * add async task to update validity and liveness of proofs from keybase * first pass keybase proof CRUD * second pass keybase proof creation * clean up proof list and add badges * add avatar url to keybase api * Always highlight the “Identity Proofs” navigation item when interacting with proofs. * Update translations. * Add profile URL. * Reorder proofs. * Add proofs to bio. * Update settings/identity_proofs front-end. * Use `link_to`. * Only encode query params if they exist. URLs without params had a trailing `?`. * Only show live proofs. * change valid to active in proof list and update liveness before displaying * minor fixes * add keybase config at well-known path * extremely naive feature flagging off the identity proof UI * fixes for rubocop * make identity proofs page resilient to potential keybase issues * normalize i18n * tweaks for brakeman * remove two unused translations * cleanup and add more localizations * make keybase_contacts an admin setting * fix ExternalProofService my_domain * use Addressable::URI in identity proofs * use active model serializer for keybase proof config * more cleanup of keybase proof config * rename proof is_valid and is_live to proof_valid and proof_live * cleanup * assorted tweaks for more robust communication with keybase * Clean up * Small fixes * Display verified identity identically to verified links * Clean up unused CSS * Add caching for Keybase avatar URLs * Remove keybase_contacts setting
5 years ago
Add Keybase integration (#10297) * create account_identity_proofs table * add endpoint for keybase to check local proofs * add async task to update validity and liveness of proofs from keybase * first pass keybase proof CRUD * second pass keybase proof creation * clean up proof list and add badges * add avatar url to keybase api * Always highlight the “Identity Proofs” navigation item when interacting with proofs. * Update translations. * Add profile URL. * Reorder proofs. * Add proofs to bio. * Update settings/identity_proofs front-end. * Use `link_to`. * Only encode query params if they exist. URLs without params had a trailing `?`. * Only show live proofs. * change valid to active in proof list and update liveness before displaying * minor fixes * add keybase config at well-known path * extremely naive feature flagging off the identity proof UI * fixes for rubocop * make identity proofs page resilient to potential keybase issues * normalize i18n * tweaks for brakeman * remove two unused translations * cleanup and add more localizations * make keybase_contacts an admin setting * fix ExternalProofService my_domain * use Addressable::URI in identity proofs * use active model serializer for keybase proof config * more cleanup of keybase proof config * rename proof is_valid and is_live to proof_valid and proof_live * cleanup * assorted tweaks for more robust communication with keybase * Clean up * Small fixes * Display verified identity identically to verified links * Clean up unused CSS * Add caching for Keybase avatar URLs * Remove keybase_contacts setting
5 years ago
Add Keybase integration (#10297) * create account_identity_proofs table * add endpoint for keybase to check local proofs * add async task to update validity and liveness of proofs from keybase * first pass keybase proof CRUD * second pass keybase proof creation * clean up proof list and add badges * add avatar url to keybase api * Always highlight the “Identity Proofs” navigation item when interacting with proofs. * Update translations. * Add profile URL. * Reorder proofs. * Add proofs to bio. * Update settings/identity_proofs front-end. * Use `link_to`. * Only encode query params if they exist. URLs without params had a trailing `?`. * Only show live proofs. * change valid to active in proof list and update liveness before displaying * minor fixes * add keybase config at well-known path * extremely naive feature flagging off the identity proof UI * fixes for rubocop * make identity proofs page resilient to potential keybase issues * normalize i18n * tweaks for brakeman * remove two unused translations * cleanup and add more localizations * make keybase_contacts an admin setting * fix ExternalProofService my_domain * use Addressable::URI in identity proofs * use active model serializer for keybase proof config * more cleanup of keybase proof config * rename proof is_valid and is_live to proof_valid and proof_live * cleanup * assorted tweaks for more robust communication with keybase * Clean up * Small fixes * Display verified identity identically to verified links * Clean up unused CSS * Add caching for Keybase avatar URLs * Remove keybase_contacts setting
5 years ago
Account domain blocks (#2381) * Add <ostatus:conversation /> tag to Atom input/output Only uses ref attribute (not href) because href would be the alternate link that's always included also. Creates new conversation for every non-reply status. Carries over conversation for every reply. Keeps remote URIs verbatim, generates local URIs on the fly like the rest of them. * Conversation muting - prevents notifications that reference a conversation (including replies, favourites, reblogs) from being created. API endpoints /api/v1/statuses/:id/mute and /api/v1/statuses/:id/unmute Currently no way to tell when a status/conversation is muted, so the web UI only has a "disable notifications" button, doesn't work as a toggle * Display "Dismiss notifications" on all statuses in notifications column, not just own * Add "muted" as a boolean attribute on statuses JSON For now always false on contained reblogs, since it's only relevant for statuses returned from the notifications endpoint, which are not nested Remove "Disable notifications" from detailed status view, since it's only relevant in the notifications column * Up max class length * Remove pending test for conversation mute * Add tests, clean up * Rename to "mute conversation" and "unmute conversation" * Raise validation error when trying to mute/unmute status without conversation * Adding account domain blocks that filter notifications and public timelines * Add tests for domain blocks in notifications, public timelines Filter reblogs of blocked domains from home * Add API for listing and creating account domain blocks * API for creating/deleting domain blocks, tests for Status#ancestors and Status#descendants, filter domain blocks from them * Filter domains in streaming API * Update account_domain_block_spec.rb
7 years ago
Web Push Notifications (#3243) * feat: Register push subscription * feat: Notify when mentioned * feat: Boost, favourite, reply, follow, follow request * feat: Notification interaction * feat: Handle change of public key * feat: Unsubscribe if things go wrong * feat: Do not send normal notifications if push is enabled * feat: Focus client if open * refactor: Move push logic to WebPushSubscription * feat: Better title and body * feat: Localize messages * chore: Fix lint errors * feat: Settings * refactor: Lazy load * fix: Check if push settings exist * feat: Device-based preferences * refactor: Simplify logic * refactor: Pull request feedback * refactor: Pull request feedback * refactor: Create /api/web/push_subscriptions endpoint * feat: Spec PushSubscriptionController * refactor: WebPushSubscription => Web::PushSubscription * feat: Spec Web::PushSubscription * feat: Display first media attachment * feat: Support direction * fix: Stuff broken while rebasing * refactor: Integration with session activations * refactor: Cleanup * refactor: Simplify implementation * feat: Set VAPID keys via environment * chore: Comments * fix: Crash when no alerts * fix: Set VAPID keys in testing environment * fix: Follow link * feat: Notification actions * fix: Delete previous subscription * chore: Temporary logs * refactor: Move migration to a later date * fix: Fetch the correct session activation and misc bugs * refactor: Move migration to a later date * fix: Remove follow request (no notifications) * feat: Send administrator contact to push service * feat: Set time-to-live * fix: Do not show sensitive images * fix: Reducer crash in error handling * feat: Add badge * chore: Fix lint error * fix: Checkbox label overlap * fix: Check for payload support * fix: Rename action "type" (crash in latest Chrome) * feat: Action to expand notification * fix: Lint errors * fix: Unescape notification body * fix: Do not allow boosting if the status is hidden * feat: Add VAPID keys to the production sample environment * fix: Strip HTML tags from status * refactor: Better error messages * refactor: Handle browser not implementing the VAPID protocol (Samsung Internet) * fix: Error when target_status is nil * fix: Handle lack of image * fix: Delete reference to invalid subscriptions * feat: Better error handling * fix: Unescape HTML characters after tags are striped * refactor: Simpify code * fix: Modify to work with #4091 * Sort strings alphabetically * i18n: Updated Polish translation it annoys me that it's not fully localized :P * refactor: Use current_session in PushSubscriptionController * fix: Rebase mistake * fix: Set cacheName to mastodon * refactor: Pull request feedback * refactor: Remove logging statements * chore(yarn): Fix conflicts with master * chore(yarn): Copy latest from master * chore(yarn): Readd offline-plugin * refactor: Use save! and update! * refactor: Send notifications async * fix: Allow retry when push fails * fix: Save track for failed pushes * fix: Minify sw.js * fix: Remove account_id from fabricator
7 years ago
8 years ago
  1. # frozen_string_literal: true
  2. require 'sidekiq/web'
  3. require 'sidekiq-scheduler/web'
  4. Sidekiq::Web.set :session_secret, Rails.application.secrets[:secret_key_base]
  5. Rails.application.routes.draw do
  6. root 'home#index'
  7. mount LetterOpenerWeb::Engine, at: 'letter_opener' if Rails.env.development?
  8. authenticate :user, lambda { |u| u.admin? } do
  9. mount Sidekiq::Web, at: 'sidekiq', as: :sidekiq
  10. mount PgHero::Engine, at: 'pghero', as: :pghero
  11. end
  12. use_doorkeeper do
  13. controllers authorizations: 'oauth/authorizations',
  14. authorized_applications: 'oauth/authorized_applications',
  15. tokens: 'oauth/tokens'
  16. end
  17. get '.well-known/host-meta', to: 'well_known/host_meta#show', as: :host_meta, defaults: { format: 'xml' }
  18. get '.well-known/webfinger', to: 'well_known/webfinger#show', as: :webfinger
  19. get '.well-known/change-password', to: redirect('/auth/edit')
  20. get '.well-known/keybase-proof-config', to: 'well_known/keybase_proof_config#show'
  21. get 'manifest', to: 'manifests#show', defaults: { format: 'json' }
  22. get 'intent', to: 'intents#show'
  23. get 'custom.css', to: 'custom_css#show', as: :custom_css
  24. resource :instance_actor, path: 'actor', only: [:show] do
  25. resource :inbox, only: [:create], module: :activitypub
  26. end
  27. devise_scope :user do
  28. get '/invite/:invite_code', to: 'auth/registrations#new', as: :public_invite
  29. namespace :auth do
  30. resource :setup, only: [:show, :update], controller: :setup
  31. end
  32. end
  33. devise_for :users, path: 'auth', controllers: {
  34. omniauth_callbacks: 'auth/omniauth_callbacks',
  35. sessions: 'auth/sessions',
  36. registrations: 'auth/registrations',
  37. passwords: 'auth/passwords',
  38. confirmations: 'auth/confirmations',
  39. }
  40. get '/users/:username', to: redirect('/@%{username}'), constraints: lambda { |req| req.format.nil? || req.format.html? }
  41. get '/authorize_follow', to: redirect { |_, request| "/authorize_interaction?#{request.params.to_query}" }
  42. resources :accounts, path: 'users', only: [:show], param: :username do
  43. get :remote_follow, to: 'remote_follow#new'
  44. post :remote_follow, to: 'remote_follow#create'
  45. resources :statuses, only: [:show] do
  46. member do
  47. get :activity
  48. get :embed
  49. end
  50. resources :replies, only: [:index], module: :activitypub
  51. end
  52. resources :followers, only: [:index], controller: :follower_accounts
  53. resources :following, only: [:index], controller: :following_accounts
  54. resource :follow, only: [:create], controller: :account_follow
  55. resource :unfollow, only: [:create], controller: :account_unfollow
  56. resource :outbox, only: [:show], module: :activitypub
  57. resource :inbox, only: [:create], module: :activitypub
  58. resources :collections, only: [:show], module: :activitypub
  59. end
  60. resource :inbox, only: [:create], module: :activitypub
  61. get '/@:username', to: 'accounts#show', as: :short_account
  62. get '/@:username/with_replies', to: 'accounts#show', as: :short_account_with_replies
  63. get '/@:username/media', to: 'accounts#show', as: :short_account_media
  64. get '/@:username/tagged/:tag', to: 'accounts#show', as: :short_account_tag
  65. get '/@:account_username/:id', to: 'statuses#show', as: :short_account_status
  66. get '/@:account_username/:id/embed', to: 'statuses#embed', as: :embed_short_account_status
  67. get '/interact/:id', to: 'remote_interaction#new', as: :remote_interaction
  68. post '/interact/:id', to: 'remote_interaction#create'
  69. get '/explore', to: 'directories#index', as: :explore
  70. get '/explore/:id', to: 'directories#show', as: :explore_hashtag
  71. get '/settings', to: redirect('/settings/profile')
  72. namespace :settings do
  73. resource :profile, only: [:show, :update]
  74. get :preferences, to: redirect('/settings/preferences/appearance')
  75. namespace :preferences do
  76. resource :appearance, only: [:show, :update], controller: :appearance
  77. resource :notifications, only: [:show, :update]
  78. resource :other, only: [:show, :update], controller: :other
  79. end
  80. resource :import, only: [:show, :create]
  81. resource :export, only: [:show, :create]
  82. namespace :exports, constraints: { format: :csv } do
  83. resources :follows, only: :index, controller: :following_accounts
  84. resources :blocks, only: :index, controller: :blocked_accounts
  85. resources :mutes, only: :index, controller: :muted_accounts
  86. resources :lists, only: :index, controller: :lists
  87. resources :domain_blocks, only: :index, controller: :blocked_domains
  88. end
  89. resource :two_factor_authentication, only: [:show, :create, :destroy]
  90. namespace :two_factor_authentication do
  91. resources :recovery_codes, only: [:create]
  92. resource :confirmation, only: [:new, :create]
  93. end
  94. resources :identity_proofs, only: [:index, :show, :new, :create, :update]
  95. resources :applications, except: [:edit] do
  96. member do
  97. post :regenerate
  98. end
  99. end
  100. resource :delete, only: [:show, :destroy]
  101. resource :migration, only: [:show, :update]
  102. resources :sessions, only: [:destroy]
  103. resources :featured_tags, only: [:index, :create, :destroy]
  104. end
  105. resources :media, only: [:show] do
  106. get :player
  107. end
  108. resources :tags, only: [:show]
  109. resources :emojis, only: [:show]
  110. resources :invites, only: [:index, :create, :destroy]
  111. resources :filters, except: [:show]
  112. resource :relationships, only: [:show, :update]
  113. get '/public', to: 'public_timelines#show', as: :public_timeline
  114. get '/media_proxy/:id/(*any)', to: 'media_proxy#show', as: :media_proxy
  115. resource :authorize_interaction, only: [:show, :create]
  116. resource :share, only: [:show, :create]
  117. namespace :admin do
  118. get '/dashboard', to: 'dashboard#index'
  119. resources :domain_allows, only: [:new, :create, :show, :destroy]
  120. resources :domain_blocks, only: [:new, :create, :show, :destroy, :update] do
  121. member do
  122. get :edit
  123. end
  124. end
  125. resources :email_domain_blocks, only: [:index, :new, :create, :destroy]
  126. resources :action_logs, only: [:index]
  127. resources :warning_presets, except: [:new]
  128. resource :settings, only: [:edit, :update]
  129. resources :invites, only: [:index, :create, :destroy] do
  130. collection do
  131. post :deactivate_all
  132. end
  133. end
  134. resources :relays, only: [:index, :new, :create, :destroy] do
  135. member do
  136. post :enable
  137. post :disable
  138. end
  139. end
  140. resources :instances, only: [:index, :show], constraints: { id: /[^\/]+/ }
  141. resources :reports, only: [:index, :show] do
  142. member do
  143. post :assign_to_self
  144. post :unassign
  145. post :reopen
  146. post :resolve
  147. end
  148. resources :reported_statuses, only: [:create]
  149. end
  150. resources :report_notes, only: [:create, :destroy]
  151. resources :accounts, only: [:index, :show] do
  152. member do
  153. post :enable
  154. post :unsilence
  155. post :unsuspend
  156. post :redownload
  157. post :remove_avatar
  158. post :remove_header
  159. post :memorialize
  160. post :approve
  161. post :reject
  162. end
  163. resource :change_email, only: [:show, :update]
  164. resource :reset, only: [:create]
  165. resource :action, only: [:new, :create], controller: 'account_actions'
  166. resources :statuses, only: [:index, :show, :create, :update, :destroy]
  167. resources :followers, only: [:index]
  168. resource :confirmation, only: [:create] do
  169. collection do
  170. post :resend
  171. end
  172. end
  173. resource :role do
  174. member do
  175. post :promote
  176. post :demote
  177. end
  178. end
  179. end
  180. resources :pending_accounts, only: [:index] do
  181. collection do
  182. post :approve_all
  183. post :reject_all
  184. post :batch
  185. end
  186. end
  187. resources :users, only: [] do
  188. resource :two_factor_authentication, only: [:destroy]
  189. end
  190. resources :custom_emojis, only: [:index, :new, :create, :update, :destroy] do
  191. member do
  192. post :copy
  193. post :enable
  194. post :disable
  195. end
  196. end
  197. resources :account_moderation_notes, only: [:create, :destroy]
  198. resources :tags, only: [:index, :show, :update]
  199. end
  200. get '/admin', to: redirect('/admin/dashboard', status: 302)
  201. namespace :api do
  202. # OEmbed
  203. get '/oembed', to: 'oembed#show', as: :oembed
  204. # Identity proofs
  205. get :proofs, to: 'proofs#index'
  206. # JSON / REST API
  207. namespace :v1 do
  208. resources :statuses, only: [:create, :show, :destroy] do
  209. scope module: :statuses do
  210. resources :reblogged_by, controller: :reblogged_by_accounts, only: :index
  211. resources :favourited_by, controller: :favourited_by_accounts, only: :index
  212. resource :reblog, only: :create
  213. post :unreblog, to: 'reblogs#destroy'
  214. resource :favourite, only: :create
  215. post :unfavourite, to: 'favourites#destroy'
  216. resource :mute, only: :create
  217. post :unmute, to: 'mutes#destroy'
  218. resource :pin, only: :create
  219. post :unpin, to: 'pins#destroy'
  220. end
  221. member do
  222. get :context
  223. end
  224. end
  225. namespace :timelines do
  226. resource :home, only: :show, controller: :home
  227. resource :public, only: :show, controller: :public
  228. resources :tag, only: :show
  229. resources :list, only: :show
  230. end
  231. resources :streaming, only: [:index]
  232. resources :custom_emojis, only: [:index]
  233. resources :suggestions, only: [:index, :destroy]
  234. resources :scheduled_statuses, only: [:index, :show, :update, :destroy]
  235. resources :preferences, only: [:index]
  236. resources :conversations, only: [:index, :destroy] do
  237. member do
  238. post :read
  239. end
  240. end
  241. get '/search', to: 'search#index', as: :search
  242. resources :media, only: [:create, :update]
  243. resources :blocks, only: [:index]
  244. resources :mutes, only: [:index]
  245. resources :favourites, only: [:index]
  246. resources :reports, only: [:create]
  247. resources :trends, only: [:index]
  248. resources :filters, only: [:index, :create, :show, :update, :destroy]
  249. resources :endorsements, only: [:index]
  250. namespace :apps do
  251. get :verify_credentials, to: 'credentials#show'
  252. end
  253. resources :apps, only: [:create]
  254. resource :instance, only: [:show] do
  255. resources :peers, only: [:index], controller: 'instances/peers'
  256. resource :activity, only: [:show], controller: 'instances/activity'
  257. end
  258. resource :domain_blocks, only: [:show, :create, :destroy]
  259. resource :directory, only: [:show]
  260. resources :follow_requests, only: [:index] do
  261. member do
  262. post :authorize
  263. post :reject
  264. end
  265. end
  266. resources :notifications, only: [:index, :show] do
  267. collection do
  268. post :clear
  269. end
  270. member do
  271. post :dismiss
  272. end
  273. end
  274. namespace :accounts do
  275. get :verify_credentials, to: 'credentials#show'
  276. patch :update_credentials, to: 'credentials#update'
  277. resource :search, only: :show, controller: :search
  278. resources :relationships, only: :index
  279. end
  280. resources :accounts, only: [:create, :show] do
  281. resources :statuses, only: :index, controller: 'accounts/statuses'
  282. resources :followers, only: :index, controller: 'accounts/follower_accounts'
  283. resources :following, only: :index, controller: 'accounts/following_accounts'
  284. resources :lists, only: :index, controller: 'accounts/lists'
  285. resources :identity_proofs, only: :index, controller: 'accounts/identity_proofs'
  286. member do
  287. post :follow
  288. post :unfollow
  289. post :block
  290. post :unblock
  291. post :mute
  292. post :unmute
  293. end
  294. resource :pin, only: :create, controller: 'accounts/pins'
  295. post :unpin, to: 'accounts/pins#destroy'
  296. end
  297. resources :lists, only: [:index, :create, :show, :update, :destroy] do
  298. resource :accounts, only: [:show, :create, :destroy], controller: 'lists/accounts'
  299. end
  300. resources :polls, only: [:create, :show] do
  301. resources :votes, only: :create, controller: 'polls/votes'
  302. end
  303. namespace :push do
  304. resource :subscription, only: [:create, :show, :update, :destroy]
  305. end
  306. namespace :admin do
  307. resources :accounts, only: [:index, :show] do
  308. member do
  309. post :enable
  310. post :unsilence
  311. post :unsuspend
  312. post :approve
  313. post :reject
  314. end
  315. resource :action, only: [:create], controller: 'account_actions'
  316. end
  317. resources :reports, only: [:index, :show] do
  318. member do
  319. post :assign_to_self
  320. post :unassign
  321. post :reopen
  322. post :resolve
  323. end
  324. end
  325. end
  326. end
  327. namespace :v2 do
  328. get '/search', to: 'search#index', as: :search
  329. end
  330. namespace :web do
  331. resource :settings, only: [:update]
  332. resource :embed, only: [:create]
  333. resources :push_subscriptions, only: [:create] do
  334. member do
  335. put :update
  336. end
  337. end
  338. end
  339. end
  340. get '/web/(*any)', to: 'home#index', as: :web
  341. get '/about', to: 'about#show'
  342. get '/about/more', to: 'about#more'
  343. get '/about/blocks', to: 'about#blocks'
  344. get '/terms', to: 'about#terms'
  345. match '/', via: [:post, :put, :patch, :delete], to: 'application#raise_not_found', format: false
  346. match '*unmatched_route', via: :all, to: 'application#raise_not_found', format: false
  347. end