You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

429 lines
13 KiB

8 years ago
7 years ago
Add Keybase integration (#10297) * create account_identity_proofs table * add endpoint for keybase to check local proofs * add async task to update validity and liveness of proofs from keybase * first pass keybase proof CRUD * second pass keybase proof creation * clean up proof list and add badges * add avatar url to keybase api * Always highlight the “Identity Proofs” navigation item when interacting with proofs. * Update translations. * Add profile URL. * Reorder proofs. * Add proofs to bio. * Update settings/identity_proofs front-end. * Use `link_to`. * Only encode query params if they exist. URLs without params had a trailing `?`. * Only show live proofs. * change valid to active in proof list and update liveness before displaying * minor fixes * add keybase config at well-known path * extremely naive feature flagging off the identity proof UI * fixes for rubocop * make identity proofs page resilient to potential keybase issues * normalize i18n * tweaks for brakeman * remove two unused translations * cleanup and add more localizations * make keybase_contacts an admin setting * fix ExternalProofService my_domain * use Addressable::URI in identity proofs * use active model serializer for keybase proof config * more cleanup of keybase proof config * rename proof is_valid and is_live to proof_valid and proof_live * cleanup * assorted tweaks for more robust communication with keybase * Clean up * Small fixes * Display verified identity identically to verified links * Clean up unused CSS * Add caching for Keybase avatar URLs * Remove keybase_contacts setting
5 years ago
Add Keybase integration (#10297) * create account_identity_proofs table * add endpoint for keybase to check local proofs * add async task to update validity and liveness of proofs from keybase * first pass keybase proof CRUD * second pass keybase proof creation * clean up proof list and add badges * add avatar url to keybase api * Always highlight the “Identity Proofs” navigation item when interacting with proofs. * Update translations. * Add profile URL. * Reorder proofs. * Add proofs to bio. * Update settings/identity_proofs front-end. * Use `link_to`. * Only encode query params if they exist. URLs without params had a trailing `?`. * Only show live proofs. * change valid to active in proof list and update liveness before displaying * minor fixes * add keybase config at well-known path * extremely naive feature flagging off the identity proof UI * fixes for rubocop * make identity proofs page resilient to potential keybase issues * normalize i18n * tweaks for brakeman * remove two unused translations * cleanup and add more localizations * make keybase_contacts an admin setting * fix ExternalProofService my_domain * use Addressable::URI in identity proofs * use active model serializer for keybase proof config * more cleanup of keybase proof config * rename proof is_valid and is_live to proof_valid and proof_live * cleanup * assorted tweaks for more robust communication with keybase * Clean up * Small fixes * Display verified identity identically to verified links * Clean up unused CSS * Add caching for Keybase avatar URLs * Remove keybase_contacts setting
5 years ago
Add Keybase integration (#10297) * create account_identity_proofs table * add endpoint for keybase to check local proofs * add async task to update validity and liveness of proofs from keybase * first pass keybase proof CRUD * second pass keybase proof creation * clean up proof list and add badges * add avatar url to keybase api * Always highlight the “Identity Proofs” navigation item when interacting with proofs. * Update translations. * Add profile URL. * Reorder proofs. * Add proofs to bio. * Update settings/identity_proofs front-end. * Use `link_to`. * Only encode query params if they exist. URLs without params had a trailing `?`. * Only show live proofs. * change valid to active in proof list and update liveness before displaying * minor fixes * add keybase config at well-known path * extremely naive feature flagging off the identity proof UI * fixes for rubocop * make identity proofs page resilient to potential keybase issues * normalize i18n * tweaks for brakeman * remove two unused translations * cleanup and add more localizations * make keybase_contacts an admin setting * fix ExternalProofService my_domain * use Addressable::URI in identity proofs * use active model serializer for keybase proof config * more cleanup of keybase proof config * rename proof is_valid and is_live to proof_valid and proof_live * cleanup * assorted tweaks for more robust communication with keybase * Clean up * Small fixes * Display verified identity identically to verified links * Clean up unused CSS * Add caching for Keybase avatar URLs * Remove keybase_contacts setting
5 years ago
Account domain blocks (#2381) * Add <ostatus:conversation /> tag to Atom input/output Only uses ref attribute (not href) because href would be the alternate link that's always included also. Creates new conversation for every non-reply status. Carries over conversation for every reply. Keeps remote URIs verbatim, generates local URIs on the fly like the rest of them. * Conversation muting - prevents notifications that reference a conversation (including replies, favourites, reblogs) from being created. API endpoints /api/v1/statuses/:id/mute and /api/v1/statuses/:id/unmute Currently no way to tell when a status/conversation is muted, so the web UI only has a "disable notifications" button, doesn't work as a toggle * Display "Dismiss notifications" on all statuses in notifications column, not just own * Add "muted" as a boolean attribute on statuses JSON For now always false on contained reblogs, since it's only relevant for statuses returned from the notifications endpoint, which are not nested Remove "Disable notifications" from detailed status view, since it's only relevant in the notifications column * Up max class length * Remove pending test for conversation mute * Add tests, clean up * Rename to "mute conversation" and "unmute conversation" * Raise validation error when trying to mute/unmute status without conversation * Adding account domain blocks that filter notifications and public timelines * Add tests for domain blocks in notifications, public timelines Filter reblogs of blocked domains from home * Add API for listing and creating account domain blocks * API for creating/deleting domain blocks, tests for Status#ancestors and Status#descendants, filter domain blocks from them * Filter domains in streaming API * Update account_domain_block_spec.rb
7 years ago
Web Push Notifications (#3243) * feat: Register push subscription * feat: Notify when mentioned * feat: Boost, favourite, reply, follow, follow request * feat: Notification interaction * feat: Handle change of public key * feat: Unsubscribe if things go wrong * feat: Do not send normal notifications if push is enabled * feat: Focus client if open * refactor: Move push logic to WebPushSubscription * feat: Better title and body * feat: Localize messages * chore: Fix lint errors * feat: Settings * refactor: Lazy load * fix: Check if push settings exist * feat: Device-based preferences * refactor: Simplify logic * refactor: Pull request feedback * refactor: Pull request feedback * refactor: Create /api/web/push_subscriptions endpoint * feat: Spec PushSubscriptionController * refactor: WebPushSubscription => Web::PushSubscription * feat: Spec Web::PushSubscription * feat: Display first media attachment * feat: Support direction * fix: Stuff broken while rebasing * refactor: Integration with session activations * refactor: Cleanup * refactor: Simplify implementation * feat: Set VAPID keys via environment * chore: Comments * fix: Crash when no alerts * fix: Set VAPID keys in testing environment * fix: Follow link * feat: Notification actions * fix: Delete previous subscription * chore: Temporary logs * refactor: Move migration to a later date * fix: Fetch the correct session activation and misc bugs * refactor: Move migration to a later date * fix: Remove follow request (no notifications) * feat: Send administrator contact to push service * feat: Set time-to-live * fix: Do not show sensitive images * fix: Reducer crash in error handling * feat: Add badge * chore: Fix lint error * fix: Checkbox label overlap * fix: Check for payload support * fix: Rename action "type" (crash in latest Chrome) * feat: Action to expand notification * fix: Lint errors * fix: Unescape notification body * fix: Do not allow boosting if the status is hidden * feat: Add VAPID keys to the production sample environment * fix: Strip HTML tags from status * refactor: Better error messages * refactor: Handle browser not implementing the VAPID protocol (Samsung Internet) * fix: Error when target_status is nil * fix: Handle lack of image * fix: Delete reference to invalid subscriptions * feat: Better error handling * fix: Unescape HTML characters after tags are striped * refactor: Simpify code * fix: Modify to work with #4091 * Sort strings alphabetically * i18n: Updated Polish translation it annoys me that it's not fully localized :P * refactor: Use current_session in PushSubscriptionController * fix: Rebase mistake * fix: Set cacheName to mastodon * refactor: Pull request feedback * refactor: Remove logging statements * chore(yarn): Fix conflicts with master * chore(yarn): Copy latest from master * chore(yarn): Readd offline-plugin * refactor: Use save! and update! * refactor: Send notifications async * fix: Allow retry when push fails * fix: Save track for failed pushes * fix: Minify sw.js * fix: Remove account_id from fabricator
6 years ago
8 years ago
  1. # frozen_string_literal: true
  2. require 'sidekiq/web'
  3. require 'sidekiq-scheduler/web'
  4. Sidekiq::Web.set :session_secret, Rails.application.secrets[:secret_key_base]
  5. Rails.application.routes.draw do
  6. mount LetterOpenerWeb::Engine, at: 'letter_opener' if Rails.env.development?
  7. authenticate :user, lambda { |u| u.admin? } do
  8. mount Sidekiq::Web, at: 'sidekiq', as: :sidekiq
  9. mount PgHero::Engine, at: 'pghero', as: :pghero
  10. end
  11. use_doorkeeper do
  12. controllers authorizations: 'oauth/authorizations',
  13. authorized_applications: 'oauth/authorized_applications',
  14. tokens: 'oauth/tokens'
  15. end
  16. get '.well-known/host-meta', to: 'well_known/host_meta#show', as: :host_meta, defaults: { format: 'xml' }
  17. get '.well-known/webfinger', to: 'well_known/webfinger#show', as: :webfinger
  18. get '.well-known/change-password', to: redirect('/auth/edit')
  19. get '.well-known/keybase-proof-config', to: 'well_known/keybase_proof_config#show'
  20. get 'manifest', to: 'manifests#show', defaults: { format: 'json' }
  21. get 'intent', to: 'intents#show'
  22. get 'custom.css', to: 'custom_css#show', as: :custom_css
  23. devise_scope :user do
  24. get '/invite/:invite_code', to: 'auth/registrations#new', as: :public_invite
  25. match '/auth/finish_signup' => 'auth/confirmations#finish_signup', via: [:get, :patch], as: :finish_signup
  26. end
  27. devise_for :users, path: 'auth', controllers: {
  28. omniauth_callbacks: 'auth/omniauth_callbacks',
  29. sessions: 'auth/sessions',
  30. registrations: 'auth/registrations',
  31. passwords: 'auth/passwords',
  32. confirmations: 'auth/confirmations',
  33. }
  34. get '/users/:username', to: redirect('/@%{username}'), constraints: lambda { |req| req.format.nil? || req.format.html? }
  35. get '/authorize_follow', to: redirect { |_, request| "/authorize_interaction?#{request.params.to_query}" }
  36. resources :accounts, path: 'users', only: [:show], param: :username do
  37. get :remote_follow, to: 'remote_follow#new'
  38. post :remote_follow, to: 'remote_follow#create'
  39. resources :statuses, only: [:show] do
  40. member do
  41. get :activity
  42. get :embed
  43. end
  44. resources :replies, only: [:index], module: :activitypub
  45. end
  46. resources :followers, only: [:index], controller: :follower_accounts
  47. resources :following, only: [:index], controller: :following_accounts
  48. resource :follow, only: [:create], controller: :account_follow
  49. resource :unfollow, only: [:create], controller: :account_unfollow
  50. resource :outbox, only: [:show], module: :activitypub
  51. resource :inbox, only: [:create], module: :activitypub
  52. resources :collections, only: [:show], module: :activitypub
  53. end
  54. resource :inbox, only: [:create], module: :activitypub
  55. get '/@:username', to: 'accounts#show', as: :short_account
  56. get '/@:username/with_replies', to: 'accounts#show', as: :short_account_with_replies
  57. get '/@:username/media', to: 'accounts#show', as: :short_account_media
  58. get '/@:username/tagged/:tag', to: 'accounts#show', as: :short_account_tag
  59. get '/@:account_username/:id', to: 'statuses#show', as: :short_account_status
  60. get '/@:account_username/:id/embed', to: 'statuses#embed', as: :embed_short_account_status
  61. get '/interact/:id', to: 'remote_interaction#new', as: :remote_interaction
  62. post '/interact/:id', to: 'remote_interaction#create'
  63. get '/explore', to: 'directories#index', as: :explore
  64. get '/explore/:id', to: 'directories#show', as: :explore_hashtag
  65. get '/settings', to: redirect('/settings/profile')
  66. namespace :settings do
  67. resource :profile, only: [:show, :update]
  68. get :preferences, to: redirect('/settings/preferences/appearance')
  69. namespace :preferences do
  70. resource :appearance, only: [:show, :update], controller: :appearance
  71. resource :notifications, only: [:show, :update]
  72. resource :other, only: [:show, :update], controller: :other
  73. end
  74. resource :import, only: [:show, :create]
  75. resource :export, only: [:show, :create]
  76. namespace :exports, constraints: { format: :csv } do
  77. resources :follows, only: :index, controller: :following_accounts
  78. resources :blocks, only: :index, controller: :blocked_accounts
  79. resources :mutes, only: :index, controller: :muted_accounts
  80. resources :lists, only: :index, controller: :lists
  81. resources :domain_blocks, only: :index, controller: :blocked_domains
  82. end
  83. resource :two_factor_authentication, only: [:show, :create, :destroy]
  84. namespace :two_factor_authentication do
  85. resources :recovery_codes, only: [:create]
  86. resource :confirmation, only: [:new, :create]
  87. end
  88. resources :identity_proofs, only: [:index, :show, :new, :create, :update]
  89. resources :applications, except: [:edit] do
  90. member do
  91. post :regenerate
  92. end
  93. end
  94. resource :delete, only: [:show, :destroy]
  95. resource :migration, only: [:show, :update]
  96. resources :sessions, only: [:destroy]
  97. resources :featured_tags, only: [:index, :create, :destroy]
  98. end
  99. resources :media, only: [:show] do
  100. get :player
  101. end
  102. resources :tags, only: [:show]
  103. resources :emojis, only: [:show]
  104. resources :invites, only: [:index, :create, :destroy]
  105. resources :filters, except: [:show]
  106. resource :relationships, only: [:show, :update]
  107. get '/public', to: 'public_timelines#show', as: :public_timeline
  108. get '/media_proxy/:id/(*any)', to: 'media_proxy#show', as: :media_proxy
  109. resource :authorize_interaction, only: [:show, :create]
  110. resource :share, only: [:show, :create]
  111. namespace :admin do
  112. get '/dashboard', to: 'dashboard#index'
  113. resources :domain_blocks, only: [:new, :create, :show, :destroy]
  114. resources :email_domain_blocks, only: [:index, :new, :create, :destroy]
  115. resources :action_logs, only: [:index]
  116. resources :warning_presets, except: [:new]
  117. resource :settings, only: [:edit, :update]
  118. resources :invites, only: [:index, :create, :destroy] do
  119. collection do
  120. post :deactivate_all
  121. end
  122. end
  123. resources :relays, only: [:index, :new, :create, :destroy] do
  124. member do
  125. post :enable
  126. post :disable
  127. end
  128. end
  129. resources :instances, only: [:index, :show], constraints: { id: /[^\/]+/ }
  130. resources :reports, only: [:index, :show] do
  131. member do
  132. post :assign_to_self
  133. post :unassign
  134. post :reopen
  135. post :resolve
  136. end
  137. resources :reported_statuses, only: [:create]
  138. end
  139. resources :report_notes, only: [:create, :destroy]
  140. resources :accounts, only: [:index, :show] do
  141. member do
  142. post :enable
  143. post :unsilence
  144. post :unsuspend
  145. post :redownload
  146. post :remove_avatar
  147. post :remove_header
  148. post :memorialize
  149. post :approve
  150. post :reject
  151. end
  152. resource :change_email, only: [:show, :update]
  153. resource :reset, only: [:create]
  154. resource :action, only: [:new, :create], controller: 'account_actions'
  155. resources :statuses, only: [:index, :show, :create, :update, :destroy]
  156. resources :followers, only: [:index]
  157. resource :confirmation, only: [:create] do
  158. collection do
  159. post :resend
  160. end
  161. end
  162. resource :role do
  163. member do
  164. post :promote
  165. post :demote
  166. end
  167. end
  168. end
  169. resources :pending_accounts, only: [:index] do
  170. collection do
  171. post :approve_all
  172. post :reject_all
  173. post :batch
  174. end
  175. end
  176. resources :users, only: [] do
  177. resource :two_factor_authentication, only: [:destroy]
  178. end
  179. resources :custom_emojis, only: [:index, :new, :create, :update, :destroy] do
  180. member do
  181. post :copy
  182. post :enable
  183. post :disable
  184. end
  185. end
  186. resources :account_moderation_notes, only: [:create, :destroy]
  187. resources :tags, only: [:index] do
  188. member do
  189. post :hide
  190. post :unhide
  191. end
  192. end
  193. end
  194. get '/admin', to: redirect('/admin/dashboard', status: 302)
  195. namespace :api do
  196. # OEmbed
  197. get '/oembed', to: 'oembed#show', as: :oembed
  198. # Identity proofs
  199. get :proofs, to: 'proofs#index'
  200. # JSON / REST API
  201. namespace :v1 do
  202. resources :statuses, only: [:create, :show, :destroy] do
  203. scope module: :statuses do
  204. resources :reblogged_by, controller: :reblogged_by_accounts, only: :index
  205. resources :favourited_by, controller: :favourited_by_accounts, only: :index
  206. resource :reblog, only: :create
  207. post :unreblog, to: 'reblogs#destroy'
  208. resource :favourite, only: :create
  209. post :unfavourite, to: 'favourites#destroy'
  210. resource :mute, only: :create
  211. post :unmute, to: 'mutes#destroy'
  212. resource :pin, only: :create
  213. post :unpin, to: 'pins#destroy'
  214. end
  215. member do
  216. get :context
  217. end
  218. end
  219. namespace :timelines do
  220. resource :home, only: :show, controller: :home
  221. resource :public, only: :show, controller: :public
  222. resources :tag, only: :show
  223. resources :list, only: :show
  224. end
  225. resources :streaming, only: [:index]
  226. resources :custom_emojis, only: [:index]
  227. resources :suggestions, only: [:index, :destroy]
  228. resources :scheduled_statuses, only: [:index, :show, :update, :destroy]
  229. resources :preferences, only: [:index]
  230. resources :conversations, only: [:index, :destroy] do
  231. member do
  232. post :read
  233. end
  234. end
  235. get '/search', to: 'search#index', as: :search
  236. resources :media, only: [:create, :update]
  237. resources :blocks, only: [:index]
  238. resources :mutes, only: [:index]
  239. resources :favourites, only: [:index]
  240. resources :reports, only: [:create]
  241. resources :filters, only: [:index, :create, :show, :update, :destroy]
  242. resources :endorsements, only: [:index]
  243. namespace :apps do
  244. get :verify_credentials, to: 'credentials#show'
  245. end
  246. resources :apps, only: [:create]
  247. resource :instance, only: [:show] do
  248. resources :peers, only: [:index], controller: 'instances/peers'
  249. resource :activity, only: [:show], controller: 'instances/activity'
  250. end
  251. resource :domain_blocks, only: [:show, :create, :destroy]
  252. resources :follow_requests, only: [:index] do
  253. member do
  254. post :authorize
  255. post :reject
  256. end
  257. end
  258. resources :notifications, only: [:index, :show] do
  259. collection do
  260. post :clear
  261. end
  262. member do
  263. post :dismiss
  264. end
  265. end
  266. namespace :accounts do
  267. get :verify_credentials, to: 'credentials#show'
  268. patch :update_credentials, to: 'credentials#update'
  269. resource :search, only: :show, controller: :search
  270. resources :relationships, only: :index
  271. end
  272. resources :accounts, only: [:create, :show] do
  273. resources :statuses, only: :index, controller: 'accounts/statuses'
  274. resources :followers, only: :index, controller: 'accounts/follower_accounts'
  275. resources :following, only: :index, controller: 'accounts/following_accounts'
  276. resources :lists, only: :index, controller: 'accounts/lists'
  277. resources :identity_proofs, only: :index, controller: 'accounts/identity_proofs'
  278. member do
  279. post :follow
  280. post :unfollow
  281. post :block
  282. post :unblock
  283. post :mute
  284. post :unmute
  285. end
  286. resource :pin, only: :create, controller: 'accounts/pins'
  287. post :unpin, to: 'accounts/pins#destroy'
  288. end
  289. resources :lists, only: [:index, :create, :show, :update, :destroy] do
  290. resource :accounts, only: [:show, :create, :destroy], controller: 'lists/accounts'
  291. end
  292. resources :polls, only: [:create, :show] do
  293. resources :votes, only: :create, controller: 'polls/votes'
  294. end
  295. namespace :push do
  296. resource :subscription, only: [:create, :show, :update, :destroy]
  297. end
  298. namespace :admin do
  299. resources :accounts, only: [:index, :show] do
  300. member do
  301. post :enable
  302. post :unsilence
  303. post :unsuspend
  304. post :approve
  305. post :reject
  306. end
  307. resource :action, only: [:create], controller: 'account_actions'
  308. end
  309. resources :reports, only: [:index, :show] do
  310. member do
  311. post :assign_to_self
  312. post :unassign
  313. post :reopen
  314. post :resolve
  315. end
  316. end
  317. end
  318. end
  319. namespace :v2 do
  320. get '/search', to: 'search#index', as: :search
  321. end
  322. namespace :web do
  323. resource :settings, only: [:update]
  324. resource :embed, only: [:create]
  325. resources :push_subscriptions, only: [:create] do
  326. member do
  327. put :update
  328. end
  329. end
  330. end
  331. end
  332. get '/web/(*any)', to: 'home#index', as: :web
  333. get '/about', to: 'about#show'
  334. get '/about/more', to: 'about#more'
  335. get '/terms', to: 'about#terms'
  336. root 'home#index'
  337. match '*unmatched_route',
  338. via: :all,
  339. to: 'application#raise_not_found',
  340. format: false
  341. end