DataModule.pm 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509
  1. package Trog::DataModule;
  2. use strict;
  3. use warnings;
  4. use FindBin::libs;
  5. use List::Util;
  6. use File::Copy;
  7. use Mojo::File;
  8. use Plack::MIME;
  9. use Path::Tiny();
  10. use Ref::Util();
  11. use Trog::Log qw{:all};
  12. use Trog::Utils;
  13. use Trog::Auth();
  14. no warnings 'experimental';
  15. use feature qw{signatures};
  16. =head1 QUERY FORMAT
  17. The $query_language and $query_help variables are presented to the user as to how to use the search box in the tCMS header.
  18. =head1 POST STRUCTURE
  19. Posts generally need to have the following:
  20. data: Brief description of content, or the content itself.
  21. content_type: What this content actually is. Used to filter into the appropriate pages.
  22. href: Primary link. This is the subject of a news post, or a link to the item itself. Can be local or remote.
  23. local_href: Backup link. Automatically created link to a static cache of the content.
  24. title: Title of the content. Used as link name for the 'href' attribute.
  25. user: User was banned for this post
  26. id: Internal identifier in datastore for the post.
  27. tags: array ref of appropriate tags.
  28. created: timestamp of creation of this version of the post
  29. version: revision # of this post.
  30. =head1 CONSTRUCTOR
  31. =head2 new(Config::Simple $config)
  32. Try not to do expensive things here.
  33. =cut
  34. sub new ( $class, $config ) {
  35. $config = $config->vars();
  36. return bless( $config, $class );
  37. }
  38. #It is required that subclasses implement this
  39. sub lang ($self) { ... }
  40. sub help ($self) { ... }
  41. sub read ( $self, $query = {} ) { ... }
  42. sub write ($self) { ... }
  43. sub count ($self) { ... }
  44. sub tags ($self) { ... }
  45. =head1 METHODS
  46. =head2 get(%request)
  47. Queries the data model. Should return the following:
  48. id => Filter down to just the post by ID. May be subsequently filtered by ACL, resulting in a 404 (which is good, as it does not disclose info).
  49. version => if id is passed, return the provided post version rather than the most recent one
  50. tags => ARRAYREF of tags, any one of which is required to give a result. If none are passed, no filtering is performed.
  51. acls => ARRAYREF of acl tags, any one of which is required to give result. Filter applies after tags. 'admin' ACL being present skips this filter.
  52. page => Offset multiplier for pagination.
  53. limit => Offset for pagination.
  54. like => Search query, as might be passed in the search bar.
  55. author => filter by post author
  56. If it is more efficient to filter within your data storage engine, you probably should override this method.
  57. As implemented, this takes the data as a given and filters in post.
  58. =cut
  59. sub get ( $self, %request ) {
  60. my $posts = $self->read( \%request );
  61. return @$posts if $request{raw};
  62. my @filtered = $self->filter( \%request, @$posts );
  63. @filtered = $self->_fixup(@filtered);
  64. @filtered = $self->paginate( \%request, @filtered );
  65. return @filtered;
  66. }
  67. sub _fixup ( $self, @filtered ) {
  68. my %user2display;
  69. # urlencode spaces in filenames
  70. @filtered = map {
  71. my $subj = $_;
  72. foreach my $param (qw{href preview video_href audio_href local_href wallpaper}) {
  73. next unless exists $subj->{$param};
  74. #XXX I don't remember what this fixes, but it also breaks things. URI::Escape usage instead is indicated.
  75. $subj->{$param} =~ s/ /%20/g;
  76. }
  77. $user2display{ $subj->{user} } //= Trog::Auth::username2display( $subj->{user} );
  78. $subj->{display_name} = $user2display{ $subj->{user} };
  79. #XXX Add dynamic routing data for posts which don't have them (/posts/$id) and (/users/$user)
  80. my $is_user_page = List::Util::any { $_ eq 'about' } @{ $subj->{tags} };
  81. if ( !exists $subj->{local_href} ) {
  82. $subj->{local_href} = "/posts/$subj->{id}";
  83. #XXX this needs to be correctly populated in the form?
  84. if ($is_user_page) {
  85. my $display_name = $user2display{ $subj->{user} };
  86. die "No display name for user!" unless $display_name;
  87. $subj->{local_href} = "/users/$display_name";
  88. }
  89. }
  90. if ( !exists $subj->{callback} ) {
  91. $subj->{callback} = "Trog::Routes::HTML::posts";
  92. $subj->{callback} = "Trog::Routes::HTML::users" if $is_user_page;
  93. }
  94. $subj->{method} = 'GET' unless exists( $subj->{method} );
  95. $subj->{user_class} = Trog::Auth::username2classname($subj->{user});
  96. $subj
  97. } @filtered;
  98. return @filtered;
  99. }
  100. sub filter ( $self, $query, @filtered ) {
  101. $query->{acls} //= [];
  102. $query->{tags} //= [];
  103. $query->{exclude_tags} //= [];
  104. # If an ID is passed, just get that (and all it's prior versions)
  105. if ( $query->{id} ) {
  106. @filtered = grep { $_->{id} eq $query->{id} } @filtered;
  107. @filtered = _dedup_versions( $query->{version}, @filtered );
  108. return @filtered;
  109. }
  110. # XXX aclname and id are essentially serving the same purpose, should unify
  111. if ( $query->{aclname} ) {
  112. @filtered = grep { ( $_->{aclname} || '' ) eq $query->{aclname} } @filtered;
  113. @filtered = _dedup_versions( $query->{version}, @filtered );
  114. return @filtered;
  115. }
  116. @filtered = _dedup_versions( undef, @filtered );
  117. #Filter out posts which are too old
  118. #Coerce older into numeric
  119. if ( $query->{older} ) {
  120. $query->{older} =~ s/[^0-9]//g;
  121. @filtered = grep { $_->{created} < $query->{older} } @filtered;
  122. }
  123. if ( $query->{newer} ) {
  124. $query->{newer} =~ s/[^0-9]//g;
  125. @filtered = grep { $_->{created} > $query->{newer} } @filtered;
  126. }
  127. # Filter posts not matching the passed tag(s), if any
  128. @filtered = grep {
  129. my $tags = $_->{tags};
  130. grep {
  131. my $t = $_;
  132. grep { $t eq $_ } @{ $query->{tags} }
  133. } @$tags
  134. } @filtered if @{ $query->{tags} };
  135. # Filter posts *matching* the passed exclude_tag(s), if any
  136. @filtered = grep {
  137. my $tags = $_->{tags};
  138. !grep {
  139. my $t = $_;
  140. grep { $t eq $_ } @{ $query->{exclude_tags} }
  141. } @$tags
  142. } @filtered if @{ $query->{exclude_tags} };
  143. # Filter posts without the proper ACLs
  144. @filtered = grep {
  145. my $tags = $_->{tags};
  146. grep {
  147. my $t = $_;
  148. grep { $t eq $_ } @{ $query->{acls} }
  149. } @$tags
  150. } @filtered unless grep { $_ eq 'admin' } @{ $query->{acls} };
  151. @filtered = grep { $_->{title} =~ m/\Q$query->{like}\E/i || $_->{data} =~ m/\Q$query->{like}\E/i } @filtered if $query->{like};
  152. @filtered = grep { $_->{user} eq $query->{author} } @filtered if $query->{author};
  153. return @filtered;
  154. }
  155. sub paginate ( $self, $query, @filtered ) {
  156. my $offset = int( $query->{limit} // 25 );
  157. $offset = @filtered < $offset ? @filtered : $offset;
  158. @filtered = splice( @filtered, ( int( $query->{page} ) - 1 ) * $offset, $offset ) if $query->{page} && $query->{limit};
  159. return @filtered;
  160. }
  161. sub _dedup_versions ( $version = -1, @posts ) {
  162. #ASSUMPTION made here - if we pass version this is direct ID query
  163. if ( defined $version ) {
  164. my $version_max = List::Util::max( map { $_->{version} } @posts );
  165. return map {
  166. $_->{version_max} //= $version_max;
  167. $_
  168. } grep { $_->{version} eq $version } @posts;
  169. }
  170. my @uniqids = List::Util::uniq( map { $_->{id} } @posts );
  171. my %posts_deduped;
  172. for my $id (@uniqids) {
  173. my @ofid = sort { $b->{version} <=> $a->{version} } grep { $_->{id} eq $id } @posts;
  174. my $version_max = List::Util::max( map { $_->{version} } @ofid );
  175. $posts_deduped{$id} = $ofid[0];
  176. $posts_deduped{$id}{version_max} = $version_max;
  177. # Show orig creation date, and original author.
  178. # XXX this doesn't show the mtime correctly for whatever reason, so I'm omitting it from the interface
  179. $posts_deduped{$id}{modified} = $ofid[0]{created};
  180. $posts_deduped{$id}{created} = $ofid[-1]{created};
  181. $posts_deduped{$id}{author} = $ofid[-1]{author};
  182. }
  183. my @deduped = @posts_deduped{@uniqids};
  184. return @deduped;
  185. }
  186. =head2 count() = INT $num
  187. Returns the total number of posts.
  188. Used to determine paginator parameters.
  189. =cut
  190. =head2 add(@posts) = BOOL $failed_or_not
  191. Add the provided posts to the datastore.
  192. If any post already exists with the same id, a new post with a version higher than it will be added.
  193. Passes an array of new posts to add to the data store module's write() function.
  194. These will have their parameters filtered to those present in the %schema hash.
  195. You probably won't want to override this.
  196. =cut
  197. my $not_ref = sub {
  198. return !Ref::Util::is_ref(shift);
  199. };
  200. my $valid_cb = sub {
  201. my $subname = shift;
  202. my ($modname) = $subname =~ m/^([\w|:]+)::\w+$/;
  203. # Modules always return 0 if they succeed!
  204. eval { require $modname; } and do {
  205. WARN("Post uses a callback whos module ($modname) cannot be found!");
  206. return 0;
  207. };
  208. no strict 'refs';
  209. my $ref = eval '\&' . $subname;
  210. use strict;
  211. return Ref::Util::is_coderef($ref);
  212. };
  213. my $hashref_or_string = sub {
  214. my $subj = shift;
  215. return Ref::Util::is_hashref($subj) || $not_ref->($subj);
  216. };
  217. # TODO more strict validation of strings?
  218. our %schema = (
  219. ## Parameters which must be in every single post
  220. 'title' => $not_ref,
  221. 'callback' => $valid_cb,
  222. 'tags' => \&Ref::Util::is_arrayref,
  223. 'version' => $not_ref,
  224. 'visibility' => $not_ref,
  225. 'aliases' => \&Ref::Util::is_arrayref,
  226. 'tiled' => $not_ref,
  227. # title links here
  228. 'href' => $not_ref,
  229. # Link to post locally
  230. 'local_href' => $not_ref,
  231. # Post body
  232. 'data' => $not_ref,
  233. # How do I edit this post?
  234. 'form' => $not_ref,
  235. # Post is restricted to visibility to these ACLs if not public/unlisted
  236. 'acls' => \&Ref::Util::is_arrayref,
  237. 'id' => $not_ref,
  238. # Author of the post
  239. 'user' => $not_ref,
  240. 'created' => $not_ref,
  241. ## Series specific parameters
  242. 'child_form' => $not_ref,
  243. 'aclname' => $not_ref,
  244. ## User specific parameters
  245. 'user_acls' => \&Ref::Util::is_arrayref,
  246. 'username' => $not_ref,
  247. 'display_name' => $not_ref,
  248. 'contact_email' => $not_ref,
  249. 'wallpaper_file' => $hashref_or_string,
  250. 'wallpaper' => $not_ref,
  251. # user avatar, but does double duty in content posts as preview images on videos, etc
  252. 'preview_file' => $hashref_or_string,
  253. 'preview' => $not_ref,
  254. ## Content specific parameters
  255. 'audio_href' => $not_ref,
  256. 'video_href' => $not_ref,
  257. 'file' => $hashref_or_string,
  258. );
  259. sub add ( $self, @posts ) {
  260. my @to_write;
  261. foreach my $post (@posts) {
  262. # Filter all the irrelevant data
  263. foreach my $key ( keys(%$post) ) {
  264. # We need to have the key in the schema, and it validate.
  265. delete $post->{$key} unless List::Util::any { ( $_ eq $key ) && ( $schema{$key}->( $post->{$key} ) ) } keys(%schema);
  266. }
  267. $post->{id} //= Trog::Utils::uuid();
  268. $post->{aliases} //= [];
  269. $post->{aliases} = [ $post->{aliases} ] unless ref $post->{aliases} eq 'ARRAY';
  270. if ( $post->{aclname} ) {
  271. # Then this is a series
  272. $post->{local_href} //= "/$post->{aclname}";
  273. push( @{ $post->{aliases} }, "/posts/$post->{id}", "/series/$post->{id}" );
  274. }
  275. $post->{callback} //= 'Trog::Routes::HTML::posts';
  276. # If this is a user creation post, add in the /user/ route
  277. if ( $post->{callback} eq 'Trog::Routes::HTML::users' ) {
  278. $post->{local_href} //= "/users/$post->{display_name}";
  279. $post->{title} //= $post->{display_name};
  280. }
  281. $post->{local_href} //= "/posts/$post->{id}";
  282. $post->{method} //= 'GET';
  283. $post->{created} = time();
  284. my @existing_posts = $self->get( id => $post->{id} );
  285. if (@existing_posts) {
  286. my $existing_post = $existing_posts[0];
  287. $post->{version} = $existing_post->{version};
  288. $post->{version}++;
  289. }
  290. $post->{version} //= 0;
  291. $post = _process($post);
  292. push @to_write, $post;
  293. }
  294. $self->write( \@to_write );
  295. #hup the parent to refresh the routing table
  296. Trog::Utils::restart_parent();
  297. # Gorilla cache invalidation
  298. Path::Tiny::path('www/statics')->remove_tree;
  299. return 0;
  300. }
  301. #XXX this level of post-processing seems gross, but may be unavoidable
  302. # Not actually a subprocess, kek
  303. sub _process ($post) {
  304. $post->{href} = _handle_upload( $post->{file}, $post->{id} ) if $post->{file};
  305. $post->{preview} = _handle_upload( $post->{preview_file}, $post->{id} ) if $post->{preview_file};
  306. $post->{wallpaper} = _handle_upload( $post->{wallpaper_file}, $post->{id} ) if $post->{wallpaper_file};
  307. $post->{preview} = $post->{href} if $post->{app} && $post->{app} eq 'image';
  308. delete $post->{app};
  309. delete $post->{file};
  310. delete $post->{preview_file};
  311. delete $post->{wallpaper_file};
  312. delete $post->{scheme};
  313. delete $post->{route};
  314. delete $post->{domain};
  315. # Handle acls/tags
  316. $post->{tags} //= [];
  317. $post->{acls} //= [];
  318. @{ $post->{tags} } = grep {
  319. my $subj = $_;
  320. !grep { $_ eq $subj } qw{public private unlisted}
  321. } @{ $post->{tags} };
  322. push( @{ $post->{tags} }, @{ $post->{acls} } ) if $post->{visibility} eq 'private';
  323. delete $post->{acls};
  324. push( @{ $post->{tags} }, $post->{visibility} );
  325. # Add the 'series' tag if we are in a series, restrict to relevant acl
  326. if ( $post->{series} ) {
  327. push( @{ $post->{tags} }, 'series' );
  328. push( @{ $post->{tags} }, $post->{series} );
  329. }
  330. #Filter adding the same acl twice
  331. @{ $post->{tags} } = List::Util::uniq( @{ $post->{tags} } );
  332. @{ $post->{aliases} } = List::Util::uniq( @{ $post->{aliases} } );
  333. # Handle multimedia content types
  334. if ( $post->{href} ) {
  335. my $mf = Mojo::File->new("www/$post->{href}");
  336. my $ext = '.' . $mf->extname();
  337. $post->{content_type} = Plack::MIME->mime_type($ext) if $ext;
  338. }
  339. if ( $post->{video_href} ) {
  340. my $mf = Mojo::File->new("www/$post->{video_href}");
  341. my $ext = '.' . $mf->extname();
  342. $post->{video_content_type} = Plack::MIME->mime_type($ext) if $ext;
  343. }
  344. if ( $post->{audio_href} ) {
  345. my $mf = Mojo::File->new("www/$post->{audio_href}");
  346. my $ext = '.' . $mf->extname();
  347. $post->{audio_content_type} = Plack::MIME->mime_type($ext) if $ext;
  348. }
  349. $post->{content_type} ||= 'text/html';
  350. $post->{is_video} = 1 if $post->{content_type} =~ m/^video\//;
  351. $post->{is_audio} = 1 if $post->{content_type} =~ m/^audio\//;
  352. $post->{is_image} = 1 if $post->{content_type} =~ m/^image\//;
  353. $post->{is_profile} = 1 if grep { $_ eq 'about' } @{ $post->{tags} };
  354. return $post;
  355. }
  356. sub _handle_upload ( $file, $uuid ) {
  357. my $f = $file->{tempname};
  358. my $newname = "$uuid.$file->{filename}";
  359. File::Copy::move( $f, "www/assets/$newname" );
  360. return "/assets/$newname";
  361. }
  362. =head2 delete(@posts)
  363. Delete the following posts.
  364. Will remove all versions of said post.
  365. You should override this, it is a stub here.
  366. =cut
  367. sub delete ($self) { die 'stub' }
  368. =head2 routes() = HASH
  369. Returns the routes to each post.
  370. You should override this for performance reasons, as it's just a wrapper around get() by defualt.
  371. =cut
  372. sub routes ($self) {
  373. my %routes = map { $_->{local_href} => { method => $_->{method}, callback => \&{ $_->{callback} } } } ( $self->get( limit => 0, acls => ['admin'] ) );
  374. return %routes;
  375. }
  376. =head2 aliases() = HASH
  377. Returns the aliases for each post, indexed by aliases.
  378. You should override this for performance reasons, as it's just a wrapper around get() by defualt.
  379. =cut
  380. sub aliases ($self) {
  381. my @posts = $self->get( limit => 0, acls => ['admin'] );
  382. my %aliases;
  383. foreach my $post (@posts) {
  384. @aliases{ @{ $post->{aliases} } } = $post->{local_href};
  385. }
  386. return %aliases;
  387. }
  388. 1;