2015-07-12 15:01:42 -04:00
|
|
|
<?php
|
|
|
|
|
2015-09-10 14:31:09 -04:00
|
|
|
namespace BookStack\Http\Controllers;
|
2015-07-12 15:01:42 -04:00
|
|
|
|
2022-02-03 19:26:19 -05:00
|
|
|
use BookStack\Exceptions\NotifyException;
|
2020-11-18 18:38:44 -05:00
|
|
|
use BookStack\Facades\Activity;
|
|
|
|
use BookStack\Interfaces\Loggable;
|
2020-12-30 13:25:35 -05:00
|
|
|
use BookStack\Model;
|
2021-10-31 13:58:56 -04:00
|
|
|
use BookStack\Util\WebSafeMimeSniffer;
|
2015-07-12 15:01:42 -04:00
|
|
|
use Illuminate\Foundation\Bus\DispatchesJobs;
|
2018-09-25 11:58:03 -04:00
|
|
|
use Illuminate\Foundation\Validation\ValidatesRequests;
|
2020-11-18 18:38:44 -05:00
|
|
|
use Illuminate\Http\JsonResponse;
|
|
|
|
use Illuminate\Http\Response;
|
2015-07-12 15:01:42 -04:00
|
|
|
use Illuminate\Routing\Controller as BaseController;
|
2022-04-02 13:07:43 -04:00
|
|
|
use Symfony\Component\HttpFoundation\StreamedResponse;
|
2015-07-12 15:01:42 -04:00
|
|
|
|
|
|
|
abstract class Controller extends BaseController
|
|
|
|
{
|
2021-06-26 11:23:15 -04:00
|
|
|
use DispatchesJobs;
|
|
|
|
use ValidatesRequests;
|
2015-08-24 16:10:04 -04:00
|
|
|
|
|
|
|
/**
|
2019-09-19 19:18:28 -04:00
|
|
|
* Check if the current user is signed in.
|
2015-08-24 16:10:04 -04:00
|
|
|
*/
|
2019-09-19 19:18:28 -04:00
|
|
|
protected function isSignedIn(): bool
|
2015-08-24 16:10:04 -04:00
|
|
|
{
|
2019-09-19 19:18:28 -04:00
|
|
|
return auth()->check();
|
2015-08-29 10:03:42 -04:00
|
|
|
}
|
|
|
|
|
2015-12-31 12:57:34 -05:00
|
|
|
/**
|
|
|
|
* Stops the application and shows a permission error if
|
|
|
|
* the application is in demo mode.
|
|
|
|
*/
|
2019-09-19 10:12:10 -04:00
|
|
|
protected function preventAccessInDemoMode()
|
2015-12-31 12:57:34 -05:00
|
|
|
{
|
2018-01-28 11:58:52 -05:00
|
|
|
if (config('app.env') === 'demo') {
|
|
|
|
$this->showPermissionError();
|
|
|
|
}
|
2015-12-31 12:57:34 -05:00
|
|
|
}
|
|
|
|
|
2015-12-05 09:41:51 -05:00
|
|
|
/**
|
|
|
|
* Adds the page title into the view.
|
|
|
|
*/
|
2020-11-18 18:38:44 -05:00
|
|
|
public function setPageTitle(string $title)
|
2015-12-05 09:41:51 -05:00
|
|
|
{
|
|
|
|
view()->share('pageTitle', $title);
|
|
|
|
}
|
|
|
|
|
2015-12-31 12:57:34 -05:00
|
|
|
/**
|
2016-02-27 14:24:42 -05:00
|
|
|
* On a permission error redirect to home and display.
|
2015-12-31 12:57:34 -05:00
|
|
|
* the error as a notification.
|
2022-01-07 08:04:49 -05:00
|
|
|
*
|
|
|
|
* @return never
|
2015-12-31 12:57:34 -05:00
|
|
|
*/
|
|
|
|
protected function showPermissionError()
|
|
|
|
{
|
2022-02-03 19:26:19 -05:00
|
|
|
$message = request()->wantsJson() ? trans('errors.permissionJson') : trans('errors.permission');
|
2022-02-08 10:29:58 -05:00
|
|
|
|
2022-02-03 19:26:19 -05:00
|
|
|
throw new NotifyException($message, '/', 403);
|
2015-12-31 12:57:34 -05:00
|
|
|
}
|
|
|
|
|
2015-08-29 10:03:42 -04:00
|
|
|
/**
|
2020-11-18 18:38:44 -05:00
|
|
|
* Checks that the current user has the given permission otherwise throw an exception.
|
2015-08-29 10:03:42 -04:00
|
|
|
*/
|
2020-11-18 18:38:44 -05:00
|
|
|
protected function checkPermission(string $permission): void
|
2015-08-29 10:03:42 -04:00
|
|
|
{
|
2020-11-18 18:38:44 -05:00
|
|
|
if (!user() || !user()->can($permission)) {
|
2015-12-31 12:57:34 -05:00
|
|
|
$this->showPermissionError();
|
2015-08-29 10:03:42 -04:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2016-02-27 14:24:42 -05:00
|
|
|
/**
|
2020-11-18 18:38:44 -05:00
|
|
|
* Check the current user's permissions against an ownable item otherwise throw an exception.
|
2016-02-27 14:24:42 -05:00
|
|
|
*/
|
2020-12-30 13:25:35 -05:00
|
|
|
protected function checkOwnablePermission(string $permission, Model $ownable): void
|
2016-02-27 14:24:42 -05:00
|
|
|
{
|
2020-11-18 18:38:44 -05:00
|
|
|
if (!userCan($permission, $ownable)) {
|
|
|
|
$this->showPermissionError();
|
2018-01-28 11:58:52 -05:00
|
|
|
}
|
2016-02-27 14:24:42 -05:00
|
|
|
}
|
|
|
|
|
2015-12-31 12:57:34 -05:00
|
|
|
/**
|
2020-11-18 18:38:44 -05:00
|
|
|
* Check if a user has a permission or bypass the permission
|
|
|
|
* check if the given callback resolves true.
|
2015-12-31 12:57:34 -05:00
|
|
|
*/
|
2020-11-18 18:38:44 -05:00
|
|
|
protected function checkPermissionOr(string $permission, callable $callback): void
|
2015-08-29 10:03:42 -04:00
|
|
|
{
|
2020-11-18 18:38:44 -05:00
|
|
|
if ($callback() !== true) {
|
|
|
|
$this->checkPermission($permission);
|
2018-01-28 11:58:52 -05:00
|
|
|
}
|
2015-08-24 16:10:04 -04:00
|
|
|
}
|
|
|
|
|
2018-12-07 13:33:32 -05:00
|
|
|
/**
|
|
|
|
* Check if the current user has a permission or bypass if the provided user
|
|
|
|
* id matches the current user.
|
|
|
|
*/
|
2020-11-18 18:38:44 -05:00
|
|
|
protected function checkPermissionOrCurrentUser(string $permission, int $userId): void
|
2018-12-07 13:33:32 -05:00
|
|
|
{
|
2020-11-18 18:38:44 -05:00
|
|
|
$this->checkPermissionOr($permission, function () use ($userId) {
|
2019-09-19 19:18:28 -04:00
|
|
|
return $userId === user()->id;
|
2018-12-07 13:33:32 -05:00
|
|
|
});
|
|
|
|
}
|
|
|
|
|
2016-05-07 09:29:43 -04:00
|
|
|
/**
|
|
|
|
* Send back a json error message.
|
|
|
|
*/
|
2021-06-26 11:23:15 -04:00
|
|
|
protected function jsonError(string $messageText = '', int $statusCode = 500): JsonResponse
|
2016-05-07 09:29:43 -04:00
|
|
|
{
|
2019-10-05 07:55:01 -04:00
|
|
|
return response()->json(['message' => $messageText, 'status' => 'error'], $statusCode);
|
2016-05-07 09:29:43 -04:00
|
|
|
}
|
|
|
|
|
2018-09-22 06:34:09 -04:00
|
|
|
/**
|
|
|
|
* Create a response that forces a download in the browser.
|
|
|
|
*/
|
2020-11-18 18:38:44 -05:00
|
|
|
protected function downloadResponse(string $content, string $fileName): Response
|
2018-09-22 06:34:09 -04:00
|
|
|
{
|
|
|
|
return response()->make($content, 200, [
|
2021-10-31 13:58:56 -04:00
|
|
|
'Content-Type' => 'application/octet-stream',
|
2022-04-03 11:22:31 -04:00
|
|
|
'Content-Disposition' => 'attachment; filename="' . str_replace('"', '', $fileName) . '"',
|
2021-10-31 13:58:56 -04:00
|
|
|
'X-Content-Type-Options' => 'nosniff',
|
2018-09-22 06:34:09 -04:00
|
|
|
]);
|
|
|
|
}
|
2019-09-19 10:12:10 -04:00
|
|
|
|
2022-04-02 13:07:43 -04:00
|
|
|
/**
|
|
|
|
* Create a response that forces a download, from a given stream of content.
|
|
|
|
*/
|
|
|
|
protected function streamedDownloadResponse($stream, string $fileName): StreamedResponse
|
|
|
|
{
|
2022-04-24 13:22:40 -04:00
|
|
|
return response()->stream(function () use ($stream) {
|
2022-04-03 11:22:31 -04:00
|
|
|
// End & flush the output buffer otherwise we still seem to use memory.
|
|
|
|
// Ignore in testing since output buffers are used to gather a response.
|
|
|
|
if (!app()->runningUnitTests()) {
|
|
|
|
ob_end_clean();
|
|
|
|
}
|
|
|
|
|
2022-04-02 13:07:43 -04:00
|
|
|
fpassthru($stream);
|
|
|
|
fclose($stream);
|
|
|
|
}, 200, [
|
|
|
|
'Content-Type' => 'application/octet-stream',
|
2022-04-03 11:22:31 -04:00
|
|
|
'Content-Disposition' => 'attachment; filename="' . str_replace('"', '', $fileName) . '"',
|
2022-04-02 13:07:43 -04:00
|
|
|
'X-Content-Type-Options' => 'nosniff',
|
|
|
|
]);
|
|
|
|
}
|
|
|
|
|
2021-06-05 19:51:06 -04:00
|
|
|
/**
|
|
|
|
* Create a file download response that provides the file with a content-type
|
|
|
|
* correct for the file, in a way so the browser can show the content in browser.
|
|
|
|
*/
|
|
|
|
protected function inlineDownloadResponse(string $content, string $fileName): Response
|
|
|
|
{
|
2021-11-01 09:26:02 -04:00
|
|
|
$mime = (new WebSafeMimeSniffer())->sniff($content);
|
2021-06-26 11:23:15 -04:00
|
|
|
|
2021-06-05 19:51:06 -04:00
|
|
|
return response()->make($content, 200, [
|
2021-10-31 13:58:56 -04:00
|
|
|
'Content-Type' => $mime,
|
2022-04-03 11:22:31 -04:00
|
|
|
'Content-Disposition' => 'inline; filename="' . str_replace('"', '', $fileName) . '"',
|
2021-10-31 13:58:56 -04:00
|
|
|
'X-Content-Type-Options' => 'nosniff',
|
2021-06-05 19:51:06 -04:00
|
|
|
]);
|
|
|
|
}
|
|
|
|
|
2022-04-02 13:07:43 -04:00
|
|
|
/**
|
|
|
|
* Create a file download response that provides the file with a content-type
|
|
|
|
* correct for the file, in a way so the browser can show the content in browser,
|
|
|
|
* for a given content stream.
|
|
|
|
*/
|
|
|
|
protected function streamedInlineDownloadResponse($stream, string $fileName): StreamedResponse
|
|
|
|
{
|
|
|
|
$sniffContent = fread($stream, 1000);
|
|
|
|
$mime = (new WebSafeMimeSniffer())->sniff($sniffContent);
|
|
|
|
|
2022-04-24 13:22:40 -04:00
|
|
|
return response()->stream(function () use ($sniffContent, $stream) {
|
|
|
|
echo $sniffContent;
|
|
|
|
fpassthru($stream);
|
|
|
|
fclose($stream);
|
2022-04-02 13:07:43 -04:00
|
|
|
}, 200, [
|
|
|
|
'Content-Type' => $mime,
|
2022-04-03 11:22:31 -04:00
|
|
|
'Content-Disposition' => 'inline; filename="' . str_replace('"', '', $fileName) . '"',
|
2022-04-02 13:07:43 -04:00
|
|
|
'X-Content-Type-Options' => 'nosniff',
|
|
|
|
]);
|
|
|
|
}
|
|
|
|
|
2019-09-19 10:12:10 -04:00
|
|
|
/**
|
|
|
|
* Show a positive, successful notification to the user on next view load.
|
|
|
|
*/
|
2020-11-18 18:38:44 -05:00
|
|
|
protected function showSuccessNotification(string $message): void
|
2019-09-19 10:12:10 -04:00
|
|
|
{
|
|
|
|
session()->flash('success', $message);
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Show a warning notification to the user on next view load.
|
|
|
|
*/
|
2020-11-18 18:38:44 -05:00
|
|
|
protected function showWarningNotification(string $message): void
|
2019-09-19 10:12:10 -04:00
|
|
|
{
|
|
|
|
session()->flash('warning', $message);
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Show an error notification to the user on next view load.
|
|
|
|
*/
|
2020-11-18 18:38:44 -05:00
|
|
|
protected function showErrorNotification(string $message): void
|
2019-09-19 10:12:10 -04:00
|
|
|
{
|
|
|
|
session()->flash('error', $message);
|
|
|
|
}
|
2019-10-05 07:55:01 -04:00
|
|
|
|
2020-11-18 18:38:44 -05:00
|
|
|
/**
|
|
|
|
* Log an activity in the system.
|
2021-06-26 11:23:15 -04:00
|
|
|
*
|
2021-11-14 17:03:22 -05:00
|
|
|
* @param string|Loggable $detail
|
2020-11-18 18:38:44 -05:00
|
|
|
*/
|
|
|
|
protected function logActivity(string $type, $detail = ''): void
|
|
|
|
{
|
|
|
|
Activity::add($type, $detail);
|
|
|
|
}
|
|
|
|
|
2019-10-05 07:55:01 -04:00
|
|
|
/**
|
|
|
|
* Get the validation rules for image files.
|
|
|
|
*/
|
2021-11-04 20:26:55 -04:00
|
|
|
protected function getImageValidationRules(): array
|
2019-10-05 07:55:01 -04:00
|
|
|
{
|
2021-11-14 17:03:22 -05:00
|
|
|
return ['image_extension', 'mimes:jpeg,png,gif,webp', 'max:' . (config('app.upload_limit') * 1000)];
|
2019-10-05 07:55:01 -04:00
|
|
|
}
|
2015-07-12 15:01:42 -04:00
|
|
|
}
|