You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

453 lines
14 KiB

8 years ago
7 years ago
Add Keybase integration (#10297) * create account_identity_proofs table * add endpoint for keybase to check local proofs * add async task to update validity and liveness of proofs from keybase * first pass keybase proof CRUD * second pass keybase proof creation * clean up proof list and add badges * add avatar url to keybase api * Always highlight the “Identity Proofs” navigation item when interacting with proofs. * Update translations. * Add profile URL. * Reorder proofs. * Add proofs to bio. * Update settings/identity_proofs front-end. * Use `link_to`. * Only encode query params if they exist. URLs without params had a trailing `?`. * Only show live proofs. * change valid to active in proof list and update liveness before displaying * minor fixes * add keybase config at well-known path * extremely naive feature flagging off the identity proof UI * fixes for rubocop * make identity proofs page resilient to potential keybase issues * normalize i18n * tweaks for brakeman * remove two unused translations * cleanup and add more localizations * make keybase_contacts an admin setting * fix ExternalProofService my_domain * use Addressable::URI in identity proofs * use active model serializer for keybase proof config * more cleanup of keybase proof config * rename proof is_valid and is_live to proof_valid and proof_live * cleanup * assorted tweaks for more robust communication with keybase * Clean up * Small fixes * Display verified identity identically to verified links * Clean up unused CSS * Add caching for Keybase avatar URLs * Remove keybase_contacts setting
5 years ago
Add Keybase integration (#10297) * create account_identity_proofs table * add endpoint for keybase to check local proofs * add async task to update validity and liveness of proofs from keybase * first pass keybase proof CRUD * second pass keybase proof creation * clean up proof list and add badges * add avatar url to keybase api * Always highlight the “Identity Proofs” navigation item when interacting with proofs. * Update translations. * Add profile URL. * Reorder proofs. * Add proofs to bio. * Update settings/identity_proofs front-end. * Use `link_to`. * Only encode query params if they exist. URLs without params had a trailing `?`. * Only show live proofs. * change valid to active in proof list and update liveness before displaying * minor fixes * add keybase config at well-known path * extremely naive feature flagging off the identity proof UI * fixes for rubocop * make identity proofs page resilient to potential keybase issues * normalize i18n * tweaks for brakeman * remove two unused translations * cleanup and add more localizations * make keybase_contacts an admin setting * fix ExternalProofService my_domain * use Addressable::URI in identity proofs * use active model serializer for keybase proof config * more cleanup of keybase proof config * rename proof is_valid and is_live to proof_valid and proof_live * cleanup * assorted tweaks for more robust communication with keybase * Clean up * Small fixes * Display verified identity identically to verified links * Clean up unused CSS * Add caching for Keybase avatar URLs * Remove keybase_contacts setting
5 years ago
Add Keybase integration (#10297) * create account_identity_proofs table * add endpoint for keybase to check local proofs * add async task to update validity and liveness of proofs from keybase * first pass keybase proof CRUD * second pass keybase proof creation * clean up proof list and add badges * add avatar url to keybase api * Always highlight the “Identity Proofs” navigation item when interacting with proofs. * Update translations. * Add profile URL. * Reorder proofs. * Add proofs to bio. * Update settings/identity_proofs front-end. * Use `link_to`. * Only encode query params if they exist. URLs without params had a trailing `?`. * Only show live proofs. * change valid to active in proof list and update liveness before displaying * minor fixes * add keybase config at well-known path * extremely naive feature flagging off the identity proof UI * fixes for rubocop * make identity proofs page resilient to potential keybase issues * normalize i18n * tweaks for brakeman * remove two unused translations * cleanup and add more localizations * make keybase_contacts an admin setting * fix ExternalProofService my_domain * use Addressable::URI in identity proofs * use active model serializer for keybase proof config * more cleanup of keybase proof config * rename proof is_valid and is_live to proof_valid and proof_live * cleanup * assorted tweaks for more robust communication with keybase * Clean up * Small fixes * Display verified identity identically to verified links * Clean up unused CSS * Add caching for Keybase avatar URLs * Remove keybase_contacts setting
5 years ago
Account domain blocks (#2381) * Add <ostatus:conversation /> tag to Atom input/output Only uses ref attribute (not href) because href would be the alternate link that's always included also. Creates new conversation for every non-reply status. Carries over conversation for every reply. Keeps remote URIs verbatim, generates local URIs on the fly like the rest of them. * Conversation muting - prevents notifications that reference a conversation (including replies, favourites, reblogs) from being created. API endpoints /api/v1/statuses/:id/mute and /api/v1/statuses/:id/unmute Currently no way to tell when a status/conversation is muted, so the web UI only has a "disable notifications" button, doesn't work as a toggle * Display "Dismiss notifications" on all statuses in notifications column, not just own * Add "muted" as a boolean attribute on statuses JSON For now always false on contained reblogs, since it's only relevant for statuses returned from the notifications endpoint, which are not nested Remove "Disable notifications" from detailed status view, since it's only relevant in the notifications column * Up max class length * Remove pending test for conversation mute * Add tests, clean up * Rename to "mute conversation" and "unmute conversation" * Raise validation error when trying to mute/unmute status without conversation * Adding account domain blocks that filter notifications and public timelines * Add tests for domain blocks in notifications, public timelines Filter reblogs of blocked domains from home * Add API for listing and creating account domain blocks * API for creating/deleting domain blocks, tests for Status#ancestors and Status#descendants, filter domain blocks from them * Filter domains in streaming API * Update account_domain_block_spec.rb
7 years ago
Web Push Notifications (#3243) * feat: Register push subscription * feat: Notify when mentioned * feat: Boost, favourite, reply, follow, follow request * feat: Notification interaction * feat: Handle change of public key * feat: Unsubscribe if things go wrong * feat: Do not send normal notifications if push is enabled * feat: Focus client if open * refactor: Move push logic to WebPushSubscription * feat: Better title and body * feat: Localize messages * chore: Fix lint errors * feat: Settings * refactor: Lazy load * fix: Check if push settings exist * feat: Device-based preferences * refactor: Simplify logic * refactor: Pull request feedback * refactor: Pull request feedback * refactor: Create /api/web/push_subscriptions endpoint * feat: Spec PushSubscriptionController * refactor: WebPushSubscription => Web::PushSubscription * feat: Spec Web::PushSubscription * feat: Display first media attachment * feat: Support direction * fix: Stuff broken while rebasing * refactor: Integration with session activations * refactor: Cleanup * refactor: Simplify implementation * feat: Set VAPID keys via environment * chore: Comments * fix: Crash when no alerts * fix: Set VAPID keys in testing environment * fix: Follow link * feat: Notification actions * fix: Delete previous subscription * chore: Temporary logs * refactor: Move migration to a later date * fix: Fetch the correct session activation and misc bugs * refactor: Move migration to a later date * fix: Remove follow request (no notifications) * feat: Send administrator contact to push service * feat: Set time-to-live * fix: Do not show sensitive images * fix: Reducer crash in error handling * feat: Add badge * chore: Fix lint error * fix: Checkbox label overlap * fix: Check for payload support * fix: Rename action "type" (crash in latest Chrome) * feat: Action to expand notification * fix: Lint errors * fix: Unescape notification body * fix: Do not allow boosting if the status is hidden * feat: Add VAPID keys to the production sample environment * fix: Strip HTML tags from status * refactor: Better error messages * refactor: Handle browser not implementing the VAPID protocol (Samsung Internet) * fix: Error when target_status is nil * fix: Handle lack of image * fix: Delete reference to invalid subscriptions * feat: Better error handling * fix: Unescape HTML characters after tags are striped * refactor: Simpify code * fix: Modify to work with #4091 * Sort strings alphabetically * i18n: Updated Polish translation it annoys me that it's not fully localized :P * refactor: Use current_session in PushSubscriptionController * fix: Rebase mistake * fix: Set cacheName to mastodon * refactor: Pull request feedback * refactor: Remove logging statements * chore(yarn): Fix conflicts with master * chore(yarn): Copy latest from master * chore(yarn): Readd offline-plugin * refactor: Use save! and update! * refactor: Send notifications async * fix: Allow retry when push fails * fix: Save track for failed pushes * fix: Minify sw.js * fix: Remove account_id from fabricator
6 years ago
8 years ago
  1. # frozen_string_literal: true
  2. require 'sidekiq/web'
  3. require 'sidekiq-scheduler/web'
  4. Sidekiq::Web.set :session_secret, Rails.application.secrets[:secret_key_base]
  5. Rails.application.routes.draw do
  6. mount LetterOpenerWeb::Engine, at: 'letter_opener' if Rails.env.development?
  7. authenticate :user, lambda { |u| u.admin? } do
  8. mount Sidekiq::Web, at: 'sidekiq', as: :sidekiq
  9. mount PgHero::Engine, at: 'pghero', as: :pghero
  10. end
  11. use_doorkeeper do
  12. controllers authorizations: 'oauth/authorizations',
  13. authorized_applications: 'oauth/authorized_applications',
  14. tokens: 'oauth/tokens'
  15. end
  16. get '.well-known/host-meta', to: 'well_known/host_meta#show', as: :host_meta, defaults: { format: 'xml' }
  17. get '.well-known/webfinger', to: 'well_known/webfinger#show', as: :webfinger
  18. get '.well-known/change-password', to: redirect('/auth/edit')
  19. get '.well-known/keybase-proof-config', to: 'well_known/keybase_proof_config#show'
  20. get 'manifest', to: 'manifests#show', defaults: { format: 'json' }
  21. get 'intent', to: 'intents#show'
  22. get 'custom.css', to: 'custom_css#show', as: :custom_css
  23. devise_scope :user do
  24. get '/invite/:invite_code', to: 'auth/registrations#new', as: :public_invite
  25. match '/auth/finish_signup' => 'auth/confirmations#finish_signup', via: [:get, :patch], as: :finish_signup
  26. end
  27. devise_for :users, path: 'auth', controllers: {
  28. omniauth_callbacks: 'auth/omniauth_callbacks',
  29. sessions: 'auth/sessions',
  30. registrations: 'auth/registrations',
  31. passwords: 'auth/passwords',
  32. confirmations: 'auth/confirmations',
  33. }
  34. get '/users/:username', to: redirect('/@%{username}'), constraints: lambda { |req| req.format.nil? || req.format.html? }
  35. get '/authorize_follow', to: redirect { |_, request| "/authorize_interaction?#{request.params.to_query}" }
  36. resources :accounts, path: 'users', only: [:show], param: :username do
  37. resources :stream_entries, path: 'updates', only: [:show] do
  38. member do
  39. get :embed
  40. end
  41. end
  42. get :remote_follow, to: 'remote_follow#new'
  43. post :remote_follow, to: 'remote_follow#create'
  44. resources :statuses, only: [:show] do
  45. member do
  46. get :activity
  47. get :embed
  48. get :replies
  49. end
  50. end
  51. resources :followers, only: [:index], controller: :follower_accounts
  52. resources :following, only: [:index], controller: :following_accounts
  53. resource :follow, only: [:create], controller: :account_follow
  54. resource :unfollow, only: [:create], controller: :account_unfollow
  55. resource :outbox, only: [:show], module: :activitypub
  56. resource :inbox, only: [:create], module: :activitypub
  57. resources :collections, only: [:show], module: :activitypub
  58. end
  59. resource :inbox, only: [:create], module: :activitypub
  60. get '/@:username', to: 'accounts#show', as: :short_account
  61. get '/@:username/with_replies', to: 'accounts#show', as: :short_account_with_replies
  62. get '/@:username/media', to: 'accounts#show', as: :short_account_media
  63. get '/@:username/tagged/:tag', to: 'accounts#show', as: :short_account_tag
  64. get '/@:account_username/:id', to: 'statuses#show', as: :short_account_status
  65. get '/@:account_username/:id/embed', to: 'statuses#embed', as: :embed_short_account_status
  66. get '/interact/:id', to: 'remote_interaction#new', as: :remote_interaction
  67. post '/interact/:id', to: 'remote_interaction#create'
  68. get '/explore', to: 'directories#index', as: :explore
  69. get '/explore/:id', to: 'directories#show', as: :explore_hashtag
  70. get '/settings', to: redirect('/settings/profile')
  71. namespace :settings do
  72. resource :profile, only: [:show, :update]
  73. get :preferences, to: redirect('/settings/preferences/appearance')
  74. namespace :preferences do
  75. resource :appearance, only: [:show, :update], controller: :appearance
  76. resource :notifications, only: [:show, :update]
  77. resource :other, only: [:show, :update], controller: :other
  78. end
  79. resource :import, only: [:show, :create]
  80. resource :export, only: [:show, :create]
  81. namespace :exports, constraints: { format: :csv } do
  82. resources :follows, only: :index, controller: :following_accounts
  83. resources :blocks, only: :index, controller: :blocked_accounts
  84. resources :mutes, only: :index, controller: :muted_accounts
  85. resources :lists, only: :index, controller: :lists
  86. resources :domain_blocks, only: :index, controller: :blocked_domains
  87. end
  88. resource :two_factor_authentication, only: [:show, :create, :destroy]
  89. namespace :two_factor_authentication do
  90. resources :recovery_codes, only: [:create]
  91. resource :confirmation, only: [:new, :create]
  92. end
  93. resources :identity_proofs, only: [:index, :show, :new, :create, :update]
  94. resources :applications, except: [:edit] do
  95. member do
  96. post :regenerate
  97. end
  98. end
  99. resource :delete, only: [:show, :destroy]
  100. resource :migration, only: [:show, :update]
  101. resources :sessions, only: [:destroy]
  102. resources :featured_tags, only: [:index, :create, :destroy]
  103. end
  104. resources :media, only: [:show] do
  105. get :player
  106. end
  107. resources :tags, only: [:show]
  108. resources :emojis, only: [:show]
  109. resources :invites, only: [:index, :create, :destroy]
  110. resources :filters, except: [:show]
  111. resource :relationships, only: [:show, :update]
  112. get '/public', to: 'public_timelines#show', as: :public_timeline
  113. get '/media_proxy/:id/(*any)', to: 'media_proxy#show', as: :media_proxy
  114. # Remote follow
  115. resource :remote_unfollow, only: [:create]
  116. resource :authorize_interaction, only: [:show, :create]
  117. resource :share, only: [:show, :create]
  118. namespace :admin do
  119. get '/dashboard', to: 'dashboard#index'
  120. resources :subscriptions, only: [:index]
  121. resources :domain_blocks, only: [:new, :create, :show, :destroy]
  122. resources :email_domain_blocks, only: [:index, :new, :create, :destroy]
  123. resources :action_logs, only: [:index]
  124. resources :warning_presets, except: [:new]
  125. resource :settings, only: [:edit, :update]
  126. resources :invites, only: [:index, :create, :destroy] do
  127. collection do
  128. post :deactivate_all
  129. end
  130. end
  131. resources :relays, only: [:index, :new, :create, :destroy] do
  132. member do
  133. post :enable
  134. post :disable
  135. end
  136. end
  137. resources :instances, only: [:index, :show], constraints: { id: /[^\/]+/ }
  138. resources :reports, only: [:index, :show] do
  139. member do
  140. post :assign_to_self
  141. post :unassign
  142. post :reopen
  143. post :resolve
  144. end
  145. resources :reported_statuses, only: [:create]
  146. end
  147. resources :report_notes, only: [:create, :destroy]
  148. resources :accounts, only: [:index, :show] do
  149. member do
  150. post :subscribe
  151. post :unsubscribe
  152. post :enable
  153. post :unsilence
  154. post :unsuspend
  155. post :redownload
  156. post :remove_avatar
  157. post :remove_header
  158. post :memorialize
  159. post :approve
  160. post :reject
  161. end
  162. resource :change_email, only: [:show, :update]
  163. resource :reset, only: [:create]
  164. resource :action, only: [:new, :create], controller: 'account_actions'
  165. resources :statuses, only: [:index, :show, :create, :update, :destroy]
  166. resources :followers, only: [:index]
  167. resource :confirmation, only: [:create] do
  168. collection do
  169. post :resend
  170. end
  171. end
  172. resource :role do
  173. member do
  174. post :promote
  175. post :demote
  176. end
  177. end
  178. end
  179. resources :pending_accounts, only: [:index] do
  180. collection do
  181. post :approve_all
  182. post :reject_all
  183. post :batch
  184. end
  185. end
  186. resources :users, only: [] do
  187. resource :two_factor_authentication, only: [:destroy]
  188. end
  189. resources :custom_emojis, only: [:index, :new, :create, :update, :destroy] do
  190. member do
  191. post :copy
  192. post :enable
  193. post :disable
  194. end
  195. end
  196. resources :account_moderation_notes, only: [:create, :destroy]
  197. resources :tags, only: [:index] do
  198. member do
  199. post :hide
  200. post :unhide
  201. end
  202. end
  203. end
  204. get '/admin', to: redirect('/admin/dashboard', status: 302)
  205. namespace :api do
  206. # PubSubHubbub outgoing subscriptions
  207. resources :subscriptions, only: [:show]
  208. post '/subscriptions/:id', to: 'subscriptions#update'
  209. # PubSubHubbub incoming subscriptions
  210. post '/push', to: 'push#update', as: :push
  211. # Salmon
  212. post '/salmon/:id', to: 'salmon#update', as: :salmon
  213. # OEmbed
  214. get '/oembed', to: 'oembed#show', as: :oembed
  215. # Identity proofs
  216. get :proofs, to: 'proofs#index'
  217. # JSON / REST API
  218. namespace :v1 do
  219. resources :statuses, only: [:create, :show, :destroy] do
  220. scope module: :statuses do
  221. resources :reblogged_by, controller: :reblogged_by_accounts, only: :index
  222. resources :favourited_by, controller: :favourited_by_accounts, only: :index
  223. resource :reblog, only: :create
  224. post :unreblog, to: 'reblogs#destroy'
  225. resource :favourite, only: :create
  226. post :unfavourite, to: 'favourites#destroy'
  227. resource :mute, only: :create
  228. post :unmute, to: 'mutes#destroy'
  229. resource :pin, only: :create
  230. post :unpin, to: 'pins#destroy'
  231. end
  232. member do
  233. get :context
  234. get :card
  235. end
  236. end
  237. namespace :timelines do
  238. resource :direct, only: :show, controller: :direct
  239. resource :home, only: :show, controller: :home
  240. resource :public, only: :show, controller: :public
  241. resources :tag, only: :show
  242. resources :list, only: :show
  243. end
  244. resources :streaming, only: [:index]
  245. resources :custom_emojis, only: [:index]
  246. resources :suggestions, only: [:index, :destroy]
  247. resources :scheduled_statuses, only: [:index, :show, :update, :destroy]
  248. resources :preferences, only: [:index]
  249. resources :conversations, only: [:index, :destroy] do
  250. member do
  251. post :read
  252. end
  253. end
  254. get '/search', to: 'search#index', as: :search
  255. resources :follows, only: [:create]
  256. resources :media, only: [:create, :update]
  257. resources :blocks, only: [:index]
  258. resources :mutes, only: [:index]
  259. resources :favourites, only: [:index]
  260. resources :reports, only: [:create]
  261. resources :filters, only: [:index, :create, :show, :update, :destroy]
  262. resources :endorsements, only: [:index]
  263. namespace :apps do
  264. get :verify_credentials, to: 'credentials#show'
  265. end
  266. resources :apps, only: [:create]
  267. resource :instance, only: [:show] do
  268. resources :peers, only: [:index], controller: 'instances/peers'
  269. resource :activity, only: [:show], controller: 'instances/activity'
  270. end
  271. resource :domain_blocks, only: [:show, :create, :destroy]
  272. resources :follow_requests, only: [:index] do
  273. member do
  274. post :authorize
  275. post :reject
  276. end
  277. end
  278. resources :notifications, only: [:index, :show] do
  279. collection do
  280. post :clear
  281. post :dismiss # Deprecated
  282. end
  283. member do
  284. post :dismiss
  285. end
  286. end
  287. namespace :accounts do
  288. get :verify_credentials, to: 'credentials#show'
  289. patch :update_credentials, to: 'credentials#update'
  290. resource :search, only: :show, controller: :search
  291. resources :relationships, only: :index
  292. end
  293. resources :accounts, only: [:create, :show] do
  294. resources :statuses, only: :index, controller: 'accounts/statuses'
  295. resources :followers, only: :index, controller: 'accounts/follower_accounts'
  296. resources :following, only: :index, controller: 'accounts/following_accounts'
  297. resources :lists, only: :index, controller: 'accounts/lists'
  298. resources :identity_proofs, only: :index, controller: 'accounts/identity_proofs'
  299. member do
  300. post :follow
  301. post :unfollow
  302. post :block
  303. post :unblock
  304. post :mute
  305. post :unmute
  306. end
  307. resource :pin, only: :create, controller: 'accounts/pins'
  308. post :unpin, to: 'accounts/pins#destroy'
  309. end
  310. resources :lists, only: [:index, :create, :show, :update, :destroy] do
  311. resource :accounts, only: [:show, :create, :destroy], controller: 'lists/accounts'
  312. end
  313. resources :polls, only: [:create, :show] do
  314. resources :votes, only: :create, controller: 'polls/votes'
  315. end
  316. namespace :push do
  317. resource :subscription, only: [:create, :show, :update, :destroy]
  318. end
  319. namespace :admin do
  320. resources :accounts, only: [:index, :show] do
  321. member do
  322. post :enable
  323. post :unsilence
  324. post :unsuspend
  325. post :approve
  326. post :reject
  327. end
  328. resource :action, only: [:create], controller: 'account_actions'
  329. end
  330. resources :reports, only: [:index, :show] do
  331. member do
  332. post :assign_to_self
  333. post :unassign
  334. post :reopen
  335. post :resolve
  336. end
  337. end
  338. end
  339. end
  340. namespace :v2 do
  341. get '/search', to: 'search#index', as: :search
  342. end
  343. namespace :web do
  344. resource :settings, only: [:update]
  345. resource :embed, only: [:create]
  346. resources :push_subscriptions, only: [:create] do
  347. member do
  348. put :update
  349. end
  350. end
  351. end
  352. end
  353. get '/web/(*any)', to: 'home#index', as: :web
  354. get '/about', to: 'about#show'
  355. get '/about/more', to: 'about#more'
  356. get '/terms', to: 'about#terms'
  357. root 'home#index'
  358. match '*unmatched_route',
  359. via: :all,
  360. to: 'application#raise_not_found',
  361. format: false
  362. end