memo.go 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511
  1. package server
  2. import (
  3. "encoding/json"
  4. "fmt"
  5. "net/http"
  6. "strconv"
  7. "strings"
  8. "time"
  9. "github.com/pkg/errors"
  10. "github.com/usememos/memos/api"
  11. "github.com/usememos/memos/common"
  12. metric "github.com/usememos/memos/plugin/metrics"
  13. "github.com/labstack/echo/v4"
  14. )
  15. func (s *Server) registerMemoRoutes(g *echo.Group) {
  16. g.POST("/memo", func(c echo.Context) error {
  17. ctx := c.Request().Context()
  18. userID, ok := c.Get(getUserIDContextKey()).(int)
  19. if !ok {
  20. return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
  21. }
  22. memoCreate := &api.MemoCreate{}
  23. if err := json.NewDecoder(c.Request().Body).Decode(memoCreate); err != nil {
  24. return echo.NewHTTPError(http.StatusBadRequest, "Malformatted post memo request").SetInternal(err)
  25. }
  26. if memoCreate.Visibility == "" {
  27. userMemoVisibilitySetting, err := s.Store.FindUserSetting(ctx, &api.UserSettingFind{
  28. UserID: userID,
  29. Key: api.UserSettingMemoVisibilityKey,
  30. })
  31. if err != nil {
  32. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to find user setting").SetInternal(err)
  33. }
  34. if userMemoVisibilitySetting != nil {
  35. memoVisibility := api.Private
  36. err := json.Unmarshal([]byte(userMemoVisibilitySetting.Value), &memoVisibility)
  37. if err != nil {
  38. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to unmarshal user setting value").SetInternal(err)
  39. }
  40. memoCreate.Visibility = memoVisibility
  41. } else {
  42. // Private is the default memo visibility.
  43. memoCreate.Visibility = api.Private
  44. }
  45. }
  46. // Find system settings
  47. disablePublicMemosSystemSetting, err := s.Store.FindSystemSetting(ctx, &api.SystemSettingFind{
  48. Name: api.SystemSettingDisablePublicMemosName,
  49. })
  50. if err != nil && common.ErrorCode(err) != common.NotFound {
  51. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to find system setting").SetInternal(err)
  52. }
  53. if disablePublicMemosSystemSetting != nil {
  54. disablePublicMemos := false
  55. err = json.Unmarshal([]byte(disablePublicMemosSystemSetting.Value), &disablePublicMemos)
  56. if err != nil {
  57. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to unmarshal system setting").SetInternal(err)
  58. }
  59. if disablePublicMemos {
  60. memoCreate.Visibility = api.Private
  61. }
  62. }
  63. if len(memoCreate.Content) > api.MaxContentLength {
  64. return echo.NewHTTPError(http.StatusBadRequest, "Content size overflow, up to 1MB").SetInternal(err)
  65. }
  66. memoCreate.CreatorID = userID
  67. memo, err := s.Store.CreateMemo(ctx, memoCreate)
  68. if err != nil {
  69. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to create memo").SetInternal(err)
  70. }
  71. if err := s.createMemoCreateActivity(c, memo); err != nil {
  72. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to create activity").SetInternal(err)
  73. }
  74. for _, resourceID := range memoCreate.ResourceIDList {
  75. if _, err := s.Store.UpsertMemoResource(ctx, &api.MemoResourceUpsert{
  76. MemoID: memo.ID,
  77. ResourceID: resourceID,
  78. }); err != nil {
  79. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to upsert memo resource").SetInternal(err)
  80. }
  81. }
  82. memo, err = s.Store.ComposeMemo(ctx, memo)
  83. if err != nil {
  84. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to compose memo").SetInternal(err)
  85. }
  86. return c.JSON(http.StatusOK, composeResponse(memo))
  87. })
  88. g.PATCH("/memo/:memoId", func(c echo.Context) error {
  89. ctx := c.Request().Context()
  90. userID, ok := c.Get(getUserIDContextKey()).(int)
  91. if !ok {
  92. return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
  93. }
  94. memoID, err := strconv.Atoi(c.Param("memoId"))
  95. if err != nil {
  96. return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("ID is not a number: %s", c.Param("memoId"))).SetInternal(err)
  97. }
  98. memo, err := s.Store.FindMemo(ctx, &api.MemoFind{
  99. ID: &memoID,
  100. })
  101. if err != nil {
  102. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to find memo").SetInternal(err)
  103. }
  104. if memo.CreatorID != userID {
  105. return echo.NewHTTPError(http.StatusUnauthorized, "Unauthorized")
  106. }
  107. currentTs := time.Now().Unix()
  108. memoPatch := &api.MemoPatch{
  109. ID: memoID,
  110. UpdatedTs: &currentTs,
  111. }
  112. if err := json.NewDecoder(c.Request().Body).Decode(memoPatch); err != nil {
  113. return echo.NewHTTPError(http.StatusBadRequest, "Malformatted patch memo request").SetInternal(err)
  114. }
  115. if memoPatch.Content != nil && len(*memoPatch.Content) > api.MaxContentLength {
  116. return echo.NewHTTPError(http.StatusBadRequest, "Content size overflow, up to 1MB").SetInternal(err)
  117. }
  118. memo, err = s.Store.PatchMemo(ctx, memoPatch)
  119. if err != nil {
  120. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to patch memo").SetInternal(err)
  121. }
  122. for _, resourceID := range memoPatch.ResourceIDList {
  123. if _, err := s.Store.UpsertMemoResource(ctx, &api.MemoResourceUpsert{
  124. MemoID: memo.ID,
  125. ResourceID: resourceID,
  126. }); err != nil {
  127. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to upsert memo resource").SetInternal(err)
  128. }
  129. }
  130. memo, err = s.Store.ComposeMemo(ctx, memo)
  131. if err != nil {
  132. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to compose memo").SetInternal(err)
  133. }
  134. return c.JSON(http.StatusOK, composeResponse(memo))
  135. })
  136. g.GET("/memo", func(c echo.Context) error {
  137. ctx := c.Request().Context()
  138. memoFind := &api.MemoFind{}
  139. if userID, err := strconv.Atoi(c.QueryParam("creatorId")); err == nil {
  140. memoFind.CreatorID = &userID
  141. }
  142. currentUserID, ok := c.Get(getUserIDContextKey()).(int)
  143. if !ok {
  144. if memoFind.CreatorID == nil {
  145. return echo.NewHTTPError(http.StatusBadRequest, "Missing user id to find memo")
  146. }
  147. memoFind.VisibilityList = []api.Visibility{api.Public}
  148. } else {
  149. if memoFind.CreatorID == nil {
  150. memoFind.CreatorID = &currentUserID
  151. } else {
  152. memoFind.VisibilityList = []api.Visibility{api.Public, api.Protected}
  153. }
  154. }
  155. rowStatus := api.RowStatus(c.QueryParam("rowStatus"))
  156. if rowStatus != "" {
  157. memoFind.RowStatus = &rowStatus
  158. }
  159. pinnedStr := c.QueryParam("pinned")
  160. if pinnedStr != "" {
  161. pinned := pinnedStr == "true"
  162. memoFind.Pinned = &pinned
  163. }
  164. tag := c.QueryParam("tag")
  165. if tag != "" {
  166. contentSearch := "#" + tag
  167. memoFind.ContentSearch = &contentSearch
  168. }
  169. visibilityListStr := c.QueryParam("visibility")
  170. if visibilityListStr != "" {
  171. visibilityList := []api.Visibility{}
  172. for _, visibility := range strings.Split(visibilityListStr, ",") {
  173. visibilityList = append(visibilityList, api.Visibility(visibility))
  174. }
  175. memoFind.VisibilityList = visibilityList
  176. }
  177. if limit, err := strconv.Atoi(c.QueryParam("limit")); err == nil {
  178. memoFind.Limit = &limit
  179. }
  180. if offset, err := strconv.Atoi(c.QueryParam("offset")); err == nil {
  181. memoFind.Offset = &offset
  182. }
  183. list, err := s.Store.FindMemoList(ctx, memoFind)
  184. if err != nil {
  185. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to fetch memo list").SetInternal(err)
  186. }
  187. return c.JSON(http.StatusOK, composeResponse(list))
  188. })
  189. g.GET("/memo/:memoId", func(c echo.Context) error {
  190. ctx := c.Request().Context()
  191. memoID, err := strconv.Atoi(c.Param("memoId"))
  192. if err != nil {
  193. return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("ID is not a number: %s", c.Param("memoId"))).SetInternal(err)
  194. }
  195. memoFind := &api.MemoFind{
  196. ID: &memoID,
  197. }
  198. memo, err := s.Store.FindMemo(ctx, memoFind)
  199. if err != nil {
  200. if common.ErrorCode(err) == common.NotFound {
  201. return echo.NewHTTPError(http.StatusNotFound, fmt.Sprintf("Memo ID not found: %d", memoID)).SetInternal(err)
  202. }
  203. return echo.NewHTTPError(http.StatusInternalServerError, fmt.Sprintf("Failed to find memo by ID: %v", memoID)).SetInternal(err)
  204. }
  205. userID, ok := c.Get(getUserIDContextKey()).(int)
  206. if memo.Visibility == api.Private {
  207. if !ok || memo.CreatorID != userID {
  208. return echo.NewHTTPError(http.StatusForbidden, "this memo is private only")
  209. }
  210. } else if memo.Visibility == api.Protected {
  211. if !ok {
  212. return echo.NewHTTPError(http.StatusForbidden, "this memo is protected, missing user in session")
  213. }
  214. }
  215. return c.JSON(http.StatusOK, composeResponse(memo))
  216. })
  217. g.POST("/memo/:memoId/organizer", func(c echo.Context) error {
  218. ctx := c.Request().Context()
  219. memoID, err := strconv.Atoi(c.Param("memoId"))
  220. if err != nil {
  221. return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("ID is not a number: %s", c.Param("memoId"))).SetInternal(err)
  222. }
  223. userID, ok := c.Get(getUserIDContextKey()).(int)
  224. if !ok {
  225. return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
  226. }
  227. memoOrganizerUpsert := &api.MemoOrganizerUpsert{}
  228. if err := json.NewDecoder(c.Request().Body).Decode(memoOrganizerUpsert); err != nil {
  229. return echo.NewHTTPError(http.StatusBadRequest, "Malformatted post memo organizer request").SetInternal(err)
  230. }
  231. memoOrganizerUpsert.MemoID = memoID
  232. memoOrganizerUpsert.UserID = userID
  233. err = s.Store.UpsertMemoOrganizer(ctx, memoOrganizerUpsert)
  234. if err != nil {
  235. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to upsert memo organizer").SetInternal(err)
  236. }
  237. memo, err := s.Store.FindMemo(ctx, &api.MemoFind{
  238. ID: &memoID,
  239. })
  240. if err != nil {
  241. if common.ErrorCode(err) == common.NotFound {
  242. return echo.NewHTTPError(http.StatusNotFound, fmt.Sprintf("Memo ID not found: %d", memoID)).SetInternal(err)
  243. }
  244. return echo.NewHTTPError(http.StatusInternalServerError, fmt.Sprintf("Failed to find memo by ID: %v", memoID)).SetInternal(err)
  245. }
  246. return c.JSON(http.StatusOK, composeResponse(memo))
  247. })
  248. g.POST("/memo/:memoId/resource", func(c echo.Context) error {
  249. ctx := c.Request().Context()
  250. memoID, err := strconv.Atoi(c.Param("memoId"))
  251. if err != nil {
  252. return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("ID is not a number: %s", c.Param("memoId"))).SetInternal(err)
  253. }
  254. userID, ok := c.Get(getUserIDContextKey()).(int)
  255. if !ok {
  256. return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
  257. }
  258. memoResourceUpsert := &api.MemoResourceUpsert{}
  259. if err := json.NewDecoder(c.Request().Body).Decode(memoResourceUpsert); err != nil {
  260. return echo.NewHTTPError(http.StatusBadRequest, "Malformatted post memo resource request").SetInternal(err)
  261. }
  262. resourceFind := &api.ResourceFind{
  263. ID: &memoResourceUpsert.ResourceID,
  264. }
  265. resource, err := s.Store.FindResource(ctx, resourceFind)
  266. if err != nil {
  267. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to fetch resource").SetInternal(err)
  268. }
  269. if resource == nil {
  270. return echo.NewHTTPError(http.StatusBadRequest, "Resource not found").SetInternal(err)
  271. } else if resource.CreatorID != userID {
  272. return echo.NewHTTPError(http.StatusUnauthorized, "Unauthorized to bind this resource").SetInternal(err)
  273. }
  274. memoResourceUpsert.MemoID = memoID
  275. currentTs := time.Now().Unix()
  276. memoResourceUpsert.UpdatedTs = &currentTs
  277. if _, err := s.Store.UpsertMemoResource(ctx, memoResourceUpsert); err != nil {
  278. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to upsert memo resource").SetInternal(err)
  279. }
  280. return c.JSON(http.StatusOK, composeResponse(resource))
  281. })
  282. g.GET("/memo/:memoId/resource", func(c echo.Context) error {
  283. ctx := c.Request().Context()
  284. memoID, err := strconv.Atoi(c.Param("memoId"))
  285. if err != nil {
  286. return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("ID is not a number: %s", c.Param("memoId"))).SetInternal(err)
  287. }
  288. resourceFind := &api.ResourceFind{
  289. MemoID: &memoID,
  290. }
  291. resourceList, err := s.Store.FindResourceList(ctx, resourceFind)
  292. if err != nil {
  293. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to fetch resource list").SetInternal(err)
  294. }
  295. return c.JSON(http.StatusOK, composeResponse(resourceList))
  296. })
  297. g.GET("/memo/stats", func(c echo.Context) error {
  298. ctx := c.Request().Context()
  299. normalStatus := api.Normal
  300. memoFind := &api.MemoFind{
  301. RowStatus: &normalStatus,
  302. }
  303. if creatorID, err := strconv.Atoi(c.QueryParam("creatorId")); err == nil {
  304. memoFind.CreatorID = &creatorID
  305. }
  306. if memoFind.CreatorID == nil {
  307. return echo.NewHTTPError(http.StatusBadRequest, "Missing user id to find memo")
  308. }
  309. currentUserID, ok := c.Get(getUserIDContextKey()).(int)
  310. if !ok {
  311. memoFind.VisibilityList = []api.Visibility{api.Public}
  312. } else {
  313. if *memoFind.CreatorID != currentUserID {
  314. memoFind.VisibilityList = []api.Visibility{api.Public, api.Protected}
  315. } else {
  316. memoFind.VisibilityList = []api.Visibility{api.Public, api.Protected, api.Private}
  317. }
  318. }
  319. list, err := s.Store.FindMemoList(ctx, memoFind)
  320. if err != nil {
  321. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to fetch memo list").SetInternal(err)
  322. }
  323. createdTsList := []int64{}
  324. for _, memo := range list {
  325. createdTsList = append(createdTsList, memo.CreatedTs)
  326. }
  327. return c.JSON(http.StatusOK, composeResponse(createdTsList))
  328. })
  329. g.GET("/memo/all", func(c echo.Context) error {
  330. ctx := c.Request().Context()
  331. memoFind := &api.MemoFind{}
  332. _, ok := c.Get(getUserIDContextKey()).(int)
  333. if !ok {
  334. memoFind.VisibilityList = []api.Visibility{api.Public}
  335. } else {
  336. memoFind.VisibilityList = []api.Visibility{api.Public, api.Protected}
  337. }
  338. pinnedStr := c.QueryParam("pinned")
  339. if pinnedStr != "" {
  340. pinned := pinnedStr == "true"
  341. memoFind.Pinned = &pinned
  342. }
  343. tag := c.QueryParam("tag")
  344. if tag != "" {
  345. contentSearch := "#" + tag + " "
  346. memoFind.ContentSearch = &contentSearch
  347. }
  348. visibilityListStr := c.QueryParam("visibility")
  349. if visibilityListStr != "" {
  350. visibilityList := []api.Visibility{}
  351. for _, visibility := range strings.Split(visibilityListStr, ",") {
  352. visibilityList = append(visibilityList, api.Visibility(visibility))
  353. }
  354. memoFind.VisibilityList = visibilityList
  355. }
  356. if limit, err := strconv.Atoi(c.QueryParam("limit")); err == nil {
  357. memoFind.Limit = &limit
  358. }
  359. if offset, err := strconv.Atoi(c.QueryParam("offset")); err == nil {
  360. memoFind.Offset = &offset
  361. }
  362. // Only fetch normal status memos.
  363. normalStatus := api.Normal
  364. memoFind.RowStatus = &normalStatus
  365. list, err := s.Store.FindMemoList(ctx, memoFind)
  366. if err != nil {
  367. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to fetch all memo list").SetInternal(err)
  368. }
  369. return c.JSON(http.StatusOK, composeResponse(list))
  370. })
  371. g.DELETE("/memo/:memoId", func(c echo.Context) error {
  372. ctx := c.Request().Context()
  373. userID, ok := c.Get(getUserIDContextKey()).(int)
  374. if !ok {
  375. return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
  376. }
  377. memoID, err := strconv.Atoi(c.Param("memoId"))
  378. if err != nil {
  379. return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("ID is not a number: %s", c.Param("memoId"))).SetInternal(err)
  380. }
  381. memo, err := s.Store.FindMemo(ctx, &api.MemoFind{
  382. ID: &memoID,
  383. })
  384. if err != nil {
  385. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to find memo").SetInternal(err)
  386. }
  387. if memo.CreatorID != userID {
  388. return echo.NewHTTPError(http.StatusUnauthorized, "Unauthorized")
  389. }
  390. memoDelete := &api.MemoDelete{
  391. ID: memoID,
  392. }
  393. if err := s.Store.DeleteMemo(ctx, memoDelete); err != nil {
  394. if common.ErrorCode(err) == common.NotFound {
  395. return echo.NewHTTPError(http.StatusNotFound, fmt.Sprintf("Memo ID not found: %d", memoID))
  396. }
  397. return echo.NewHTTPError(http.StatusInternalServerError, fmt.Sprintf("Failed to delete memo ID: %v", memoID)).SetInternal(err)
  398. }
  399. return c.JSON(http.StatusOK, true)
  400. })
  401. g.DELETE("/memo/:memoId/resource/:resourceId", func(c echo.Context) error {
  402. ctx := c.Request().Context()
  403. userID, ok := c.Get(getUserIDContextKey()).(int)
  404. if !ok {
  405. return echo.NewHTTPError(http.StatusUnauthorized, "Missing user in session")
  406. }
  407. memoID, err := strconv.Atoi(c.Param("memoId"))
  408. if err != nil {
  409. return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("Memo ID is not a number: %s", c.Param("memoId"))).SetInternal(err)
  410. }
  411. resourceID, err := strconv.Atoi(c.Param("resourceId"))
  412. if err != nil {
  413. return echo.NewHTTPError(http.StatusBadRequest, fmt.Sprintf("Resource ID is not a number: %s", c.Param("resourceId"))).SetInternal(err)
  414. }
  415. memo, err := s.Store.FindMemo(ctx, &api.MemoFind{
  416. ID: &memoID,
  417. })
  418. if err != nil {
  419. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to find memo").SetInternal(err)
  420. }
  421. if memo.CreatorID != userID {
  422. return echo.NewHTTPError(http.StatusUnauthorized, "Unauthorized")
  423. }
  424. memoResourceDelete := &api.MemoResourceDelete{
  425. MemoID: &memoID,
  426. ResourceID: &resourceID,
  427. }
  428. if err := s.Store.DeleteMemoResource(ctx, memoResourceDelete); err != nil {
  429. return echo.NewHTTPError(http.StatusInternalServerError, "Failed to fetch resource list").SetInternal(err)
  430. }
  431. return c.JSON(http.StatusOK, true)
  432. })
  433. }
  434. func (s *Server) createMemoCreateActivity(c echo.Context, memo *api.Memo) error {
  435. ctx := c.Request().Context()
  436. payload := api.ActivityMemoCreatePayload{
  437. Content: memo.Content,
  438. Visibility: memo.Visibility.String(),
  439. }
  440. payloadBytes, err := json.Marshal(payload)
  441. if err != nil {
  442. return errors.Wrap(err, "failed to marshal activity payload")
  443. }
  444. activity, err := s.Store.CreateActivity(ctx, &api.ActivityCreate{
  445. CreatorID: memo.CreatorID,
  446. Type: api.ActivityMemoCreate,
  447. Level: api.ActivityInfo,
  448. Payload: string(payloadBytes),
  449. })
  450. if err != nil || activity == nil {
  451. return errors.Wrap(err, "failed to create activity")
  452. }
  453. s.Collector.Collect(ctx, &metric.Metric{
  454. Name: string(activity.Type),
  455. })
  456. return err
  457. }