Pictures!
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

admin.js 7.8KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363
  1. var querystring = require("querystring");
  2. var fs = require("fs");
  3. var pathlib = require("path");
  4. var formidable = require("formidable");
  5. var crypto = require("crypto");
  6. var basepath = "/admin/api/";
  7. var slideshow;
  8. exports.init = function(_slideshow) {
  9. slideshow = _slideshow;
  10. }
  11. var tokens = {};
  12. function pad(str, n) {
  13. if (str.length >= n)
  14. return str;
  15. var missing = str.length;
  16. for (var i = 0; i < n - missing; ++i)
  17. str = "0" + str;
  18. return str;
  19. }
  20. // Used in every method handler to make sure the correct arguments are provided
  21. function hasargs(query, respond, expected) {
  22. var missing = [];
  23. for (var e of expected) {
  24. if (query[e] === undefined)
  25. missing.push(e);
  26. }
  27. if (missing.length > 0) {
  28. respond("Missing arguments: "+missing.join(", "));
  29. return false;
  30. } else {
  31. return true;
  32. }
  33. }
  34. // Method handlers are defined here
  35. var methods = {
  36. // List all slides in the slides directory
  37. list_slides: function(query, conf, req, respond) {
  38. fs.readdir(conf.slides, (err, files) => {
  39. if (err)
  40. return respond(err);
  41. respond(null, files);
  42. });
  43. },
  44. // Get metadata about a slide
  45. slide_meta: function(query, conf, req, respond) {
  46. if (!hasargs(query, respond, [ "slide" ])) return;
  47. var path = pathlib.join(conf.slides, query.slide);
  48. fs.stat(path, (err, stat) => {
  49. if (err || !stat.isDirectory())
  50. return respond(path+" is not a slide.");
  51. fs.readFile(pathlib.join(path, "meta.json"), (err, res) => {
  52. if (err && err.code === "ENOENT")
  53. return respond(null, {});
  54. else if (err)
  55. return respond(err);
  56. try {
  57. respond(null, JSON.parse(res));
  58. } catch (err) {
  59. respond(err);
  60. }
  61. });
  62. });
  63. },
  64. // Get a list of files of a slide
  65. slide_file_list: function(query, conf, req, respond) {
  66. if (!hasargs(query, respond, [ "slide" ])) return;
  67. var dir = pathlib.join(conf.slides, query.slide);
  68. fs.readdir(dir, (err, files) => {
  69. if (err)
  70. return respond(err);
  71. respond(null, { files: files });
  72. });
  73. },
  74. // Get a slide's HTML
  75. slide_content: function(query, conf, req, respond) {
  76. if (!hasargs(query, respond, [ "slide" ])) return;
  77. var path = pathlib.join(conf.slides, query.slide, "index.md");
  78. fs.readFile(path, "utf-8", (err, text) => {
  79. if (err && err.code === "ENOENT")
  80. return respond(null, { text: "" });
  81. else if (err)
  82. return respond(err);
  83. respond(null, { text: text });
  84. });
  85. },
  86. // Update a slide's HTML
  87. slide_content_update: function(query, conf, req, respond) {
  88. if (!hasargs(query, respond, [ "slide", "text" ])) return;
  89. var path = pathlib.join(conf.slides, query.slide, "index.md");
  90. fs.writeFile(path, query.text, err => {
  91. respond(err);
  92. });
  93. },
  94. // Rename a file
  95. slide_file_rename: function(query, conf, req, respond) {
  96. if (!hasargs(query, respond, [ "slide", "from", "to" ])) return;
  97. var op = pathlib.join(conf.slides, query.slide, query.from);
  98. var np = pathlib.join(conf.slides, query.slide, query.to);
  99. fs.rename(op, np, err => respond(err));
  100. },
  101. // Delete a file
  102. slide_file_delete: function(query, conf, req, respond) {
  103. if (!hasargs(query, respond, [ "slide", "file" ])) return;
  104. var path = pathlib.join(conf.slides, query.slide, query.file);
  105. fs.unlink(path, err => respond(err));
  106. },
  107. // Upload a file to a slide
  108. slide_file_upload: function(query, conf, req, respond) {
  109. if (!hasargs(query, respond, [ "slide" ])) return;
  110. var form = new formidable.IncomingForm();
  111. form.uploadDir = pathlib.join(conf.slides, query.slide);
  112. form.keepExtensions = true;
  113. form.on("fileBegin", (name, file) => {
  114. file.path = pathlib.join(form.uploadDir, file.name);
  115. });
  116. form.parse(req, (err, fields, files) => {
  117. if (err)
  118. return respond(err);
  119. });
  120. form.on("error", err => {
  121. respond(err);
  122. });
  123. form.on("end", () => {
  124. respond();
  125. });
  126. },
  127. // Set a meta property for slide
  128. // Synchronous fs stuff, we don't want races
  129. slide_set_meta: function(query, conf, req, respond) {
  130. if (!hasargs(query, respond, [ "slide", "key", "val" ])) return;
  131. var metafile = pathlib.join(conf.slides, query.slide, "meta.json");
  132. var meta = {};
  133. try {
  134. meta = JSON.parse(fs.readFileSync(metafile));
  135. } catch (err) {
  136. if (err.code !== "ENOENT")
  137. return respond(err);
  138. }
  139. meta[query.key] = JSON.parse(query.val);
  140. try {
  141. fs.writeFileSync(metafile, JSON.stringify(meta, null, 4)+"\n");
  142. } catch (err) {
  143. respond(err);
  144. }
  145. slideshow.updateSlides();
  146. respond();
  147. },
  148. // Get meta properties
  149. slide_get_meta: function(query, conf, req, respond) {
  150. if (!hasargs(query, respond, [ "slide" ])) return;
  151. var metafile = pathlib.join(conf.slides, query.slide, "meta.json");
  152. fs.readFile(metafile, (err, res) => {
  153. if (err && err.code !== "ENOENT")
  154. return respond(err);
  155. var obj = {};
  156. if (!err) {
  157. obj = JSON.parse(res);
  158. }
  159. respond(null, obj);
  160. });
  161. },
  162. // Create a slide
  163. // Lots of synchronous fs stuff, we don't want races
  164. slide_create: function(query, conf, req, respond) {
  165. var dirs;
  166. try {
  167. dirs = fs.readdirSync(conf.slides);
  168. } catch (err) {
  169. return respond(err);
  170. }
  171. dirs = dirs.sort();
  172. var biggest = dirs[dirs.length - 1];
  173. var newId = pad((parseInt(biggest) + 1).toString(), biggest.length);
  174. var path = pathlib.join(conf.slides, newId);
  175. var meta = JSON.stringify({
  176. disabled: true
  177. }, null, 4) + "\n";
  178. try {
  179. fs.mkdirSync(path);
  180. fs.writeFileSync(pathlib.join(path, "index.md"), "");
  181. fs.writeFileSync(pathlib.join(path, "meta.json"), meta);
  182. } catch (err) {
  183. return respond(err);
  184. }
  185. slideshow.updateSlides();
  186. respond(null, newId);
  187. },
  188. // Delete a slide
  189. // Also synchronous fs stuff
  190. slide_delete: function(query, conf, req, respond) {
  191. if (!hasargs(query, respond, [ "slide" ])) return;
  192. var path = pathlib.join(conf.slides, query.slide);
  193. var files;
  194. try {
  195. files = fs.readdirSync(path);
  196. } catch (err) {
  197. return respond(err);
  198. }
  199. for (var f of files) {
  200. try {
  201. fs.unlinkSync(pathlib.join(path, f));
  202. } catch (err) {
  203. return respond(err);
  204. }
  205. }
  206. try {
  207. fs.rmdirSync(path);
  208. } catch (err) {
  209. return respond(err);
  210. }
  211. respond();
  212. }
  213. }
  214. exports.canServe = function(parts) {
  215. // Temporary, while working on stuff
  216. var name = parts.pathname.replace(basepath, "");
  217. return methods[name] !== undefined || name === "login";
  218. }
  219. var sessTokens = [];
  220. function loginHandler(conf, req, respond) {
  221. var pass = req.headers["session-pass"];
  222. if (!conf.password)
  223. return respond(null, false);
  224. if (!pass)
  225. return respond(null, false);
  226. if (pass !== conf.password)
  227. return respond(null, false);
  228. var token = crypto.randomBytes(16).toString("hex");
  229. var id = sessTokens.length;
  230. sessTokens[id] = token;
  231. // Time out after 30 minutes
  232. setTimeout(() => {
  233. sessTokens[id] = undefined;
  234. }, 30 * 60 * 1000);
  235. respond(null, token);
  236. }
  237. function validateToken(req) {
  238. var cookie = req.headers.cookie;
  239. if (!cookie)
  240. return false;
  241. var token;
  242. for (var c of cookie.split(/;\s*/)) {
  243. var parts = c.split("=");
  244. if (parts[0] === "token") {
  245. token = parts[1];
  246. break;
  247. }
  248. }
  249. if (!token)
  250. return false;
  251. for (var i = 0; i < sessTokens.length; ++i) {
  252. if (sessTokens[i] && sessTokens[i] === token)
  253. return true;
  254. }
  255. return false;
  256. }
  257. exports.serve = function(parts, conf, req, res) {
  258. var name = parts.pathname.replace(basepath, "");
  259. // Better than manually doing res.end(JSON.stringify(obj)) everywhere
  260. function respond(err, obj) {
  261. var result = {
  262. obj: obj,
  263. err: err ? err.toString() : null
  264. };
  265. if (err)
  266. res.writeHead(400);
  267. else
  268. res.writeHead(200);
  269. res.end(JSON.stringify(result));
  270. }
  271. // Special login handler
  272. if (name === "login")
  273. return loginHandler(conf, req, respond);
  274. // Verify token
  275. if (!validateToken(req))
  276. return respond("EINVALTOKEN");
  277. var fn = methods[name];
  278. if (!fn) {
  279. res.writeHead(404);
  280. res.end();
  281. return;
  282. }
  283. var query = querystring.parse(parts.query);
  284. for (var i in query) {
  285. query[i] = decodeURIComponent(query[i]);
  286. }
  287. // Finally, call method handler
  288. fn(query, conf, req, respond);
  289. }