You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

433 lines
13 KiB

8 years ago
7 years ago
Add Keybase integration (#10297) * create account_identity_proofs table * add endpoint for keybase to check local proofs * add async task to update validity and liveness of proofs from keybase * first pass keybase proof CRUD * second pass keybase proof creation * clean up proof list and add badges * add avatar url to keybase api * Always highlight the “Identity Proofs” navigation item when interacting with proofs. * Update translations. * Add profile URL. * Reorder proofs. * Add proofs to bio. * Update settings/identity_proofs front-end. * Use `link_to`. * Only encode query params if they exist. URLs without params had a trailing `?`. * Only show live proofs. * change valid to active in proof list and update liveness before displaying * minor fixes * add keybase config at well-known path * extremely naive feature flagging off the identity proof UI * fixes for rubocop * make identity proofs page resilient to potential keybase issues * normalize i18n * tweaks for brakeman * remove two unused translations * cleanup and add more localizations * make keybase_contacts an admin setting * fix ExternalProofService my_domain * use Addressable::URI in identity proofs * use active model serializer for keybase proof config * more cleanup of keybase proof config * rename proof is_valid and is_live to proof_valid and proof_live * cleanup * assorted tweaks for more robust communication with keybase * Clean up * Small fixes * Display verified identity identically to verified links * Clean up unused CSS * Add caching for Keybase avatar URLs * Remove keybase_contacts setting
5 years ago
Add Keybase integration (#10297) * create account_identity_proofs table * add endpoint for keybase to check local proofs * add async task to update validity and liveness of proofs from keybase * first pass keybase proof CRUD * second pass keybase proof creation * clean up proof list and add badges * add avatar url to keybase api * Always highlight the “Identity Proofs” navigation item when interacting with proofs. * Update translations. * Add profile URL. * Reorder proofs. * Add proofs to bio. * Update settings/identity_proofs front-end. * Use `link_to`. * Only encode query params if they exist. URLs without params had a trailing `?`. * Only show live proofs. * change valid to active in proof list and update liveness before displaying * minor fixes * add keybase config at well-known path * extremely naive feature flagging off the identity proof UI * fixes for rubocop * make identity proofs page resilient to potential keybase issues * normalize i18n * tweaks for brakeman * remove two unused translations * cleanup and add more localizations * make keybase_contacts an admin setting * fix ExternalProofService my_domain * use Addressable::URI in identity proofs * use active model serializer for keybase proof config * more cleanup of keybase proof config * rename proof is_valid and is_live to proof_valid and proof_live * cleanup * assorted tweaks for more robust communication with keybase * Clean up * Small fixes * Display verified identity identically to verified links * Clean up unused CSS * Add caching for Keybase avatar URLs * Remove keybase_contacts setting
5 years ago
Add Keybase integration (#10297) * create account_identity_proofs table * add endpoint for keybase to check local proofs * add async task to update validity and liveness of proofs from keybase * first pass keybase proof CRUD * second pass keybase proof creation * clean up proof list and add badges * add avatar url to keybase api * Always highlight the “Identity Proofs” navigation item when interacting with proofs. * Update translations. * Add profile URL. * Reorder proofs. * Add proofs to bio. * Update settings/identity_proofs front-end. * Use `link_to`. * Only encode query params if they exist. URLs without params had a trailing `?`. * Only show live proofs. * change valid to active in proof list and update liveness before displaying * minor fixes * add keybase config at well-known path * extremely naive feature flagging off the identity proof UI * fixes for rubocop * make identity proofs page resilient to potential keybase issues * normalize i18n * tweaks for brakeman * remove two unused translations * cleanup and add more localizations * make keybase_contacts an admin setting * fix ExternalProofService my_domain * use Addressable::URI in identity proofs * use active model serializer for keybase proof config * more cleanup of keybase proof config * rename proof is_valid and is_live to proof_valid and proof_live * cleanup * assorted tweaks for more robust communication with keybase * Clean up * Small fixes * Display verified identity identically to verified links * Clean up unused CSS * Add caching for Keybase avatar URLs * Remove keybase_contacts setting
5 years ago
Account domain blocks (#2381) * Add <ostatus:conversation /> tag to Atom input/output Only uses ref attribute (not href) because href would be the alternate link that's always included also. Creates new conversation for every non-reply status. Carries over conversation for every reply. Keeps remote URIs verbatim, generates local URIs on the fly like the rest of them. * Conversation muting - prevents notifications that reference a conversation (including replies, favourites, reblogs) from being created. API endpoints /api/v1/statuses/:id/mute and /api/v1/statuses/:id/unmute Currently no way to tell when a status/conversation is muted, so the web UI only has a "disable notifications" button, doesn't work as a toggle * Display "Dismiss notifications" on all statuses in notifications column, not just own * Add "muted" as a boolean attribute on statuses JSON For now always false on contained reblogs, since it's only relevant for statuses returned from the notifications endpoint, which are not nested Remove "Disable notifications" from detailed status view, since it's only relevant in the notifications column * Up max class length * Remove pending test for conversation mute * Add tests, clean up * Rename to "mute conversation" and "unmute conversation" * Raise validation error when trying to mute/unmute status without conversation * Adding account domain blocks that filter notifications and public timelines * Add tests for domain blocks in notifications, public timelines Filter reblogs of blocked domains from home * Add API for listing and creating account domain blocks * API for creating/deleting domain blocks, tests for Status#ancestors and Status#descendants, filter domain blocks from them * Filter domains in streaming API * Update account_domain_block_spec.rb
7 years ago
Web Push Notifications (#3243) * feat: Register push subscription * feat: Notify when mentioned * feat: Boost, favourite, reply, follow, follow request * feat: Notification interaction * feat: Handle change of public key * feat: Unsubscribe if things go wrong * feat: Do not send normal notifications if push is enabled * feat: Focus client if open * refactor: Move push logic to WebPushSubscription * feat: Better title and body * feat: Localize messages * chore: Fix lint errors * feat: Settings * refactor: Lazy load * fix: Check if push settings exist * feat: Device-based preferences * refactor: Simplify logic * refactor: Pull request feedback * refactor: Pull request feedback * refactor: Create /api/web/push_subscriptions endpoint * feat: Spec PushSubscriptionController * refactor: WebPushSubscription => Web::PushSubscription * feat: Spec Web::PushSubscription * feat: Display first media attachment * feat: Support direction * fix: Stuff broken while rebasing * refactor: Integration with session activations * refactor: Cleanup * refactor: Simplify implementation * feat: Set VAPID keys via environment * chore: Comments * fix: Crash when no alerts * fix: Set VAPID keys in testing environment * fix: Follow link * feat: Notification actions * fix: Delete previous subscription * chore: Temporary logs * refactor: Move migration to a later date * fix: Fetch the correct session activation and misc bugs * refactor: Move migration to a later date * fix: Remove follow request (no notifications) * feat: Send administrator contact to push service * feat: Set time-to-live * fix: Do not show sensitive images * fix: Reducer crash in error handling * feat: Add badge * chore: Fix lint error * fix: Checkbox label overlap * fix: Check for payload support * fix: Rename action "type" (crash in latest Chrome) * feat: Action to expand notification * fix: Lint errors * fix: Unescape notification body * fix: Do not allow boosting if the status is hidden * feat: Add VAPID keys to the production sample environment * fix: Strip HTML tags from status * refactor: Better error messages * refactor: Handle browser not implementing the VAPID protocol (Samsung Internet) * fix: Error when target_status is nil * fix: Handle lack of image * fix: Delete reference to invalid subscriptions * feat: Better error handling * fix: Unescape HTML characters after tags are striped * refactor: Simpify code * fix: Modify to work with #4091 * Sort strings alphabetically * i18n: Updated Polish translation it annoys me that it's not fully localized :P * refactor: Use current_session in PushSubscriptionController * fix: Rebase mistake * fix: Set cacheName to mastodon * refactor: Pull request feedback * refactor: Remove logging statements * chore(yarn): Fix conflicts with master * chore(yarn): Copy latest from master * chore(yarn): Readd offline-plugin * refactor: Use save! and update! * refactor: Send notifications async * fix: Allow retry when push fails * fix: Save track for failed pushes * fix: Minify sw.js * fix: Remove account_id from fabricator
6 years ago
8 years ago
  1. # frozen_string_literal: true
  2. require 'sidekiq/web'
  3. require 'sidekiq-scheduler/web'
  4. Sidekiq::Web.set :session_secret, Rails.application.secrets[:secret_key_base]
  5. Rails.application.routes.draw do
  6. mount LetterOpenerWeb::Engine, at: 'letter_opener' if Rails.env.development?
  7. authenticate :user, lambda { |u| u.admin? } do
  8. mount Sidekiq::Web, at: 'sidekiq', as: :sidekiq
  9. mount PgHero::Engine, at: 'pghero', as: :pghero
  10. end
  11. use_doorkeeper do
  12. controllers authorizations: 'oauth/authorizations',
  13. authorized_applications: 'oauth/authorized_applications',
  14. tokens: 'oauth/tokens'
  15. end
  16. get '.well-known/host-meta', to: 'well_known/host_meta#show', as: :host_meta, defaults: { format: 'xml' }
  17. get '.well-known/webfinger', to: 'well_known/webfinger#show', as: :webfinger
  18. get '.well-known/change-password', to: redirect('/auth/edit')
  19. get '.well-known/keybase-proof-config', to: 'well_known/keybase_proof_config#show'
  20. get 'manifest', to: 'manifests#show', defaults: { format: 'json' }
  21. get 'intent', to: 'intents#show'
  22. get 'custom.css', to: 'custom_css#show', as: :custom_css
  23. resource :instance_actor, path: 'actor', only: [:show] do
  24. resource :inbox, only: [:create], module: :activitypub
  25. end
  26. devise_scope :user do
  27. get '/invite/:invite_code', to: 'auth/registrations#new', as: :public_invite
  28. match '/auth/finish_signup' => 'auth/confirmations#finish_signup', via: [:get, :patch], as: :finish_signup
  29. end
  30. devise_for :users, path: 'auth', controllers: {
  31. omniauth_callbacks: 'auth/omniauth_callbacks',
  32. sessions: 'auth/sessions',
  33. registrations: 'auth/registrations',
  34. passwords: 'auth/passwords',
  35. confirmations: 'auth/confirmations',
  36. }
  37. get '/users/:username', to: redirect('/@%{username}'), constraints: lambda { |req| req.format.nil? || req.format.html? }
  38. get '/authorize_follow', to: redirect { |_, request| "/authorize_interaction?#{request.params.to_query}" }
  39. resources :accounts, path: 'users', only: [:show], param: :username do
  40. get :remote_follow, to: 'remote_follow#new'
  41. post :remote_follow, to: 'remote_follow#create'
  42. resources :statuses, only: [:show] do
  43. member do
  44. get :activity
  45. get :embed
  46. end
  47. resources :replies, only: [:index], module: :activitypub
  48. end
  49. resources :followers, only: [:index], controller: :follower_accounts
  50. resources :following, only: [:index], controller: :following_accounts
  51. resource :follow, only: [:create], controller: :account_follow
  52. resource :unfollow, only: [:create], controller: :account_unfollow
  53. resource :outbox, only: [:show], module: :activitypub
  54. resource :inbox, only: [:create], module: :activitypub
  55. resources :collections, only: [:show], module: :activitypub
  56. end
  57. resource :inbox, only: [:create], module: :activitypub
  58. get '/@:username', to: 'accounts#show', as: :short_account
  59. get '/@:username/with_replies', to: 'accounts#show', as: :short_account_with_replies
  60. get '/@:username/media', to: 'accounts#show', as: :short_account_media
  61. get '/@:username/tagged/:tag', to: 'accounts#show', as: :short_account_tag
  62. get '/@:account_username/:id', to: 'statuses#show', as: :short_account_status
  63. get '/@:account_username/:id/embed', to: 'statuses#embed', as: :embed_short_account_status
  64. get '/interact/:id', to: 'remote_interaction#new', as: :remote_interaction
  65. post '/interact/:id', to: 'remote_interaction#create'
  66. get '/explore', to: 'directories#index', as: :explore
  67. get '/explore/:id', to: 'directories#show', as: :explore_hashtag
  68. get '/settings', to: redirect('/settings/profile')
  69. namespace :settings do
  70. resource :profile, only: [:show, :update]
  71. get :preferences, to: redirect('/settings/preferences/appearance')
  72. namespace :preferences do
  73. resource :appearance, only: [:show, :update], controller: :appearance
  74. resource :notifications, only: [:show, :update]
  75. resource :other, only: [:show, :update], controller: :other
  76. end
  77. resource :import, only: [:show, :create]
  78. resource :export, only: [:show, :create]
  79. namespace :exports, constraints: { format: :csv } do
  80. resources :follows, only: :index, controller: :following_accounts
  81. resources :blocks, only: :index, controller: :blocked_accounts
  82. resources :mutes, only: :index, controller: :muted_accounts
  83. resources :lists, only: :index, controller: :lists
  84. resources :domain_blocks, only: :index, controller: :blocked_domains
  85. end
  86. resource :two_factor_authentication, only: [:show, :create, :destroy]
  87. namespace :two_factor_authentication do
  88. resources :recovery_codes, only: [:create]
  89. resource :confirmation, only: [:new, :create]
  90. end
  91. resources :identity_proofs, only: [:index, :show, :new, :create, :update]
  92. resources :applications, except: [:edit] do
  93. member do
  94. post :regenerate
  95. end
  96. end
  97. resource :delete, only: [:show, :destroy]
  98. resource :migration, only: [:show, :update]
  99. resources :sessions, only: [:destroy]
  100. resources :featured_tags, only: [:index, :create, :destroy]
  101. end
  102. resources :media, only: [:show] do
  103. get :player
  104. end
  105. resources :tags, only: [:show]
  106. resources :emojis, only: [:show]
  107. resources :invites, only: [:index, :create, :destroy]
  108. resources :filters, except: [:show]
  109. resource :relationships, only: [:show, :update]
  110. get '/public', to: 'public_timelines#show', as: :public_timeline
  111. get '/media_proxy/:id/(*any)', to: 'media_proxy#show', as: :media_proxy
  112. resource :authorize_interaction, only: [:show, :create]
  113. resource :share, only: [:show, :create]
  114. namespace :admin do
  115. get '/dashboard', to: 'dashboard#index'
  116. resources :domain_blocks, only: [:new, :create, :show, :destroy]
  117. resources :email_domain_blocks, only: [:index, :new, :create, :destroy]
  118. resources :action_logs, only: [:index]
  119. resources :warning_presets, except: [:new]
  120. resource :settings, only: [:edit, :update]
  121. resources :invites, only: [:index, :create, :destroy] do
  122. collection do
  123. post :deactivate_all
  124. end
  125. end
  126. resources :relays, only: [:index, :new, :create, :destroy] do
  127. member do
  128. post :enable
  129. post :disable
  130. end
  131. end
  132. resources :instances, only: [:index, :show], constraints: { id: /[^\/]+/ }
  133. resources :reports, only: [:index, :show] do
  134. member do
  135. post :assign_to_self
  136. post :unassign
  137. post :reopen
  138. post :resolve
  139. end
  140. resources :reported_statuses, only: [:create]
  141. end
  142. resources :report_notes, only: [:create, :destroy]
  143. resources :accounts, only: [:index, :show] do
  144. member do
  145. post :enable
  146. post :unsilence
  147. post :unsuspend
  148. post :redownload
  149. post :remove_avatar
  150. post :remove_header
  151. post :memorialize
  152. post :approve
  153. post :reject
  154. end
  155. resource :change_email, only: [:show, :update]
  156. resource :reset, only: [:create]
  157. resource :action, only: [:new, :create], controller: 'account_actions'
  158. resources :statuses, only: [:index, :show, :create, :update, :destroy]
  159. resources :followers, only: [:index]
  160. resource :confirmation, only: [:create] do
  161. collection do
  162. post :resend
  163. end
  164. end
  165. resource :role do
  166. member do
  167. post :promote
  168. post :demote
  169. end
  170. end
  171. end
  172. resources :pending_accounts, only: [:index] do
  173. collection do
  174. post :approve_all
  175. post :reject_all
  176. post :batch
  177. end
  178. end
  179. resources :users, only: [] do
  180. resource :two_factor_authentication, only: [:destroy]
  181. end
  182. resources :custom_emojis, only: [:index, :new, :create, :update, :destroy] do
  183. member do
  184. post :copy
  185. post :enable
  186. post :disable
  187. end
  188. end
  189. resources :account_moderation_notes, only: [:create, :destroy]
  190. resources :tags, only: [:index] do
  191. member do
  192. post :hide
  193. post :unhide
  194. end
  195. end
  196. end
  197. get '/admin', to: redirect('/admin/dashboard', status: 302)
  198. namespace :api do
  199. # OEmbed
  200. get '/oembed', to: 'oembed#show', as: :oembed
  201. # Identity proofs
  202. get :proofs, to: 'proofs#index'
  203. # JSON / REST API
  204. namespace :v1 do
  205. resources :statuses, only: [:create, :show, :destroy] do
  206. scope module: :statuses do
  207. resources :reblogged_by, controller: :reblogged_by_accounts, only: :index
  208. resources :favourited_by, controller: :favourited_by_accounts, only: :index
  209. resource :reblog, only: :create
  210. post :unreblog, to: 'reblogs#destroy'
  211. resource :favourite, only: :create
  212. post :unfavourite, to: 'favourites#destroy'
  213. resource :mute, only: :create
  214. post :unmute, to: 'mutes#destroy'
  215. resource :pin, only: :create
  216. post :unpin, to: 'pins#destroy'
  217. end
  218. member do
  219. get :context
  220. end
  221. end
  222. namespace :timelines do
  223. resource :home, only: :show, controller: :home
  224. resource :public, only: :show, controller: :public
  225. resources :tag, only: :show
  226. resources :list, only: :show
  227. end
  228. resources :streaming, only: [:index]
  229. resources :custom_emojis, only: [:index]
  230. resources :suggestions, only: [:index, :destroy]
  231. resources :scheduled_statuses, only: [:index, :show, :update, :destroy]
  232. resources :preferences, only: [:index]
  233. resources :conversations, only: [:index, :destroy] do
  234. member do
  235. post :read
  236. end
  237. end
  238. get '/search', to: 'search#index', as: :search
  239. resources :media, only: [:create, :update]
  240. resources :blocks, only: [:index]
  241. resources :mutes, only: [:index]
  242. resources :favourites, only: [:index]
  243. resources :reports, only: [:create]
  244. resources :filters, only: [:index, :create, :show, :update, :destroy]
  245. resources :endorsements, only: [:index]
  246. namespace :apps do
  247. get :verify_credentials, to: 'credentials#show'
  248. end
  249. resources :apps, only: [:create]
  250. resource :instance, only: [:show] do
  251. resources :peers, only: [:index], controller: 'instances/peers'
  252. resource :activity, only: [:show], controller: 'instances/activity'
  253. end
  254. resource :domain_blocks, only: [:show, :create, :destroy]
  255. resources :follow_requests, only: [:index] do
  256. member do
  257. post :authorize
  258. post :reject
  259. end
  260. end
  261. resources :notifications, only: [:index, :show] do
  262. collection do
  263. post :clear
  264. end
  265. member do
  266. post :dismiss
  267. end
  268. end
  269. namespace :accounts do
  270. get :verify_credentials, to: 'credentials#show'
  271. patch :update_credentials, to: 'credentials#update'
  272. resource :search, only: :show, controller: :search
  273. resources :relationships, only: :index
  274. end
  275. resources :accounts, only: [:create, :show] do
  276. resources :statuses, only: :index, controller: 'accounts/statuses'
  277. resources :followers, only: :index, controller: 'accounts/follower_accounts'
  278. resources :following, only: :index, controller: 'accounts/following_accounts'
  279. resources :lists, only: :index, controller: 'accounts/lists'
  280. resources :identity_proofs, only: :index, controller: 'accounts/identity_proofs'
  281. member do
  282. post :follow
  283. post :unfollow
  284. post :block
  285. post :unblock
  286. post :mute
  287. post :unmute
  288. end
  289. resource :pin, only: :create, controller: 'accounts/pins'
  290. post :unpin, to: 'accounts/pins#destroy'
  291. end
  292. resources :lists, only: [:index, :create, :show, :update, :destroy] do
  293. resource :accounts, only: [:show, :create, :destroy], controller: 'lists/accounts'
  294. end
  295. resources :polls, only: [:create, :show] do
  296. resources :votes, only: :create, controller: 'polls/votes'
  297. end
  298. namespace :push do
  299. resource :subscription, only: [:create, :show, :update, :destroy]
  300. end
  301. namespace :admin do
  302. resources :accounts, only: [:index, :show] do
  303. member do
  304. post :enable
  305. post :unsilence
  306. post :unsuspend
  307. post :approve
  308. post :reject
  309. end
  310. resource :action, only: [:create], controller: 'account_actions'
  311. end
  312. resources :reports, only: [:index, :show] do
  313. member do
  314. post :assign_to_self
  315. post :unassign
  316. post :reopen
  317. post :resolve
  318. end
  319. end
  320. end
  321. end
  322. namespace :v2 do
  323. get '/search', to: 'search#index', as: :search
  324. end
  325. namespace :web do
  326. resource :settings, only: [:update]
  327. resource :embed, only: [:create]
  328. resources :push_subscriptions, only: [:create] do
  329. member do
  330. put :update
  331. end
  332. end
  333. end
  334. end
  335. get '/web/(*any)', to: 'home#index', as: :web
  336. get '/about', to: 'about#show'
  337. get '/about/more', to: 'about#more'
  338. get '/terms', to: 'about#terms'
  339. root 'home#index'
  340. match '*unmatched_route',
  341. via: :all,
  342. to: 'application#raise_not_found',
  343. format: false
  344. end