Pictures!
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

admin.js 6.7KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312
  1. var querystring = require("querystring");
  2. var fs = require("fs");
  3. var pathlib = require("path");
  4. var formidable = require("formidable");
  5. var crypto = require("crypto");
  6. var basepath = "/admin/api/";
  7. var slideshow;
  8. exports.init = function(_slideshow) {
  9. slideshow = _slideshow;
  10. }
  11. var tokens = {};
  12. function pad(str, n) {
  13. if (str.length >= n)
  14. return str;
  15. var missing = str.length;
  16. for (var i = 0; i < n - missing; ++i)
  17. str = "0" + str;
  18. return str;
  19. }
  20. // Used in every method handler to make sure the correct arguments are provided
  21. function hasargs(query, respond, expected) {
  22. var missing = [];
  23. for (var e of expected) {
  24. if (query[e] === undefined)
  25. missing.push(e);
  26. }
  27. if (missing.length > 0) {
  28. respond("Missing arguments: "+missing.join(", "));
  29. return false;
  30. } else {
  31. return true;
  32. }
  33. }
  34. // Method handlers are defined here
  35. var methods = {
  36. // List all slides in the slides directory
  37. list_slides: function(query, conf, req, respond) {
  38. fs.readdir(conf.slides, (err, files) => {
  39. if (err)
  40. return respond(err);
  41. respond(null, files);
  42. });
  43. },
  44. // Get metadata about a slide
  45. slide_meta: function(query, conf, req, respond) {
  46. if (!hasargs(query, respond, [ "slide" ])) return;
  47. var path = pathlib.join(conf.slides, query.slide);
  48. fs.stat(path, (err, stat) => {
  49. if (err || !stat.isDirectory())
  50. return respond(path+" is not a slide.");
  51. fs.readFile(pathlib.join(path, "meta.json"), (err, res) => {
  52. if (err && err.code === "ENOENT")
  53. return respond(null, {});
  54. else if (err)
  55. return respond(err);
  56. try {
  57. respond(null, JSON.parse(res));
  58. } catch (err) {
  59. respond(err);
  60. }
  61. });
  62. });
  63. },
  64. // Get a list of files of a slide
  65. slide_file_list: function(query, conf, req, respond) {
  66. if (!hasargs(query, respond, [ "slide" ])) return;
  67. var dir = pathlib.join(conf.slides, query.slide);
  68. fs.readdir(dir, (err, files) => {
  69. if (err)
  70. return respond(err);
  71. respond(null, { files: files });
  72. });
  73. },
  74. // Get a slide's HTML
  75. slide_content: function(query, conf, req, respond) {
  76. if (!hasargs(query, respond, [ "slide" ])) return;
  77. var path = pathlib.join(conf.slides, query.slide, "index.md");
  78. fs.readFile(path, "utf-8", (err, text) => {
  79. if (err && err.code === "ENOENT")
  80. return respond(null, { text: "" });
  81. else if (err)
  82. return respond(err);
  83. respond(null, { text: text });
  84. });
  85. },
  86. // Update a slide's HTML
  87. slide_content_update: function(query, conf, req, respond) {
  88. if (!hasargs(query, respond, [ "slide", "text" ])) return;
  89. var path = pathlib.join(conf.slides, query.slide, "index.md");
  90. fs.writeFile(path, query.text, err => {
  91. respond(err);
  92. });
  93. },
  94. // Rename a file
  95. slide_file_rename: function(query, conf, req, respond) {
  96. if (!hasargs(query, respond, [ "slide", "from", "to" ])) return;
  97. var op = pathlib.join(conf.slides, query.slide, query.from);
  98. var np = pathlib.join(conf.slides, query.slide, query.to);
  99. fs.rename(op, np, err => respond(err));
  100. },
  101. // Delete a file
  102. slide_file_delete: function(query, conf, req, respond) {
  103. if (!hasargs(query, respond, [ "slide", "file" ])) return;
  104. var path = pathlib.join(conf.slides, query.slide, query.file);
  105. fs.unlink(path, err => respond(err));
  106. },
  107. // Upload a file to a slide
  108. slide_file_upload: function(query, conf, req, respond) {
  109. if (!hasargs(query, respond, [ "slide" ])) return;
  110. var form = new formidable.IncomingForm();
  111. form.uploadDir = pathlib.join(conf.slides, query.slide);
  112. form.keepExtensions = true;
  113. form.on("fileBegin", (name, file) => {
  114. file.path = pathlib.join(form.uploadDir, file.name);
  115. });
  116. form.parse(req, (err, fields, files) => {
  117. if (err)
  118. return respond(err);
  119. });
  120. form.on("error", err => {
  121. respond(err);
  122. });
  123. form.on("end", () => {
  124. respond();
  125. });
  126. },
  127. // Create a slide
  128. // Lots of synchronous fs stuff, we don't want races
  129. slide_create: function(query, conf, req, respond) {
  130. var dirs;
  131. try {
  132. dirs = fs.readdirSync(conf.slides);
  133. } catch (err) {
  134. return respond(err);
  135. }
  136. dirs = dirs.sort();
  137. var biggest = dirs[dirs.length - 1];
  138. var newId = pad((parseInt(biggest) + 1).toString(), biggest.length);
  139. var path = pathlib.join(conf.slides, newId);
  140. try {
  141. fs.mkdirSync(path);
  142. fs.writeFileSync(pathlib.join(path, "index.md"), "");
  143. } catch (err) {
  144. return respond(err);
  145. }
  146. slideshow.updateSlides();
  147. respond(null, newId);
  148. },
  149. // Delete a slide
  150. // Also synchronous fs stuff
  151. slide_delete: function(query, conf, req, respond) {
  152. if (!hasargs(query, respond, [ "slide" ])) return;
  153. var path = pathlib.join(conf.slides, query.slide);
  154. var files;
  155. try {
  156. files = fs.readdirSync(path);
  157. } catch (err) {
  158. return respond(err);
  159. }
  160. for (var f of files) {
  161. try {
  162. fs.unlinkSync(pathlib.join(path, f));
  163. } catch (err) {
  164. return respond(err);
  165. }
  166. }
  167. try {
  168. fs.rmdirSync(path);
  169. } catch (err) {
  170. return respond(err);
  171. }
  172. respond();
  173. }
  174. }
  175. exports.canServe = function(parts) {
  176. // Temporary, while working on stuff
  177. var name = parts.pathname.replace(basepath, "");
  178. return methods[name] !== undefined || name === "login";
  179. }
  180. var sessTokens = [];
  181. function loginHandler(conf, req, respond) {
  182. var pass = req.headers["session-pass"];
  183. if (!conf.password)
  184. return respond(null, false);
  185. if (!pass)
  186. return respond(null, false);
  187. if (pass !== conf.password)
  188. return respond(null, false);
  189. var token = crypto.randomBytes(16).toString("hex");
  190. var id = sessTokens.length;
  191. sessTokens[id] = token;
  192. // Time out after 30 minutes
  193. setTimeout(() => {
  194. sessTokens[id] = undefined;
  195. }, 30 * 60 * 1000);
  196. respond(null, token);
  197. }
  198. function validateToken(req) {
  199. var cookie = req.headers.cookie;
  200. if (!cookie)
  201. return false;
  202. var token;
  203. for (var c of cookie.split(/;\s*/)) {
  204. var parts = c.split("=");
  205. if (parts[0] === "token") {
  206. token = parts[1];
  207. break;
  208. }
  209. }
  210. if (!token)
  211. return false;
  212. for (var i = 0; i < sessTokens.length; ++i) {
  213. if (sessTokens[i] && sessTokens[i] === token)
  214. return true;
  215. }
  216. return false;
  217. }
  218. exports.serve = function(parts, conf, req, res) {
  219. var name = parts.pathname.replace(basepath, "");
  220. // Better than manually doing res.end(JSON.stringify(obj)) everywhere
  221. function respond(err, obj) {
  222. var result = {
  223. obj: obj,
  224. err: err ? err.toString() : null
  225. };
  226. if (err)
  227. res.writeHead(400);
  228. else
  229. res.writeHead(200);
  230. res.end(JSON.stringify(result));
  231. }
  232. // Special login handler
  233. if (name === "login")
  234. return loginHandler(conf, req, respond);
  235. // Verify token
  236. if (!validateToken(req))
  237. return respond("EINVALTOKEN");
  238. var fn = methods[name];
  239. if (!fn) {
  240. res.writeHead(404);
  241. res.end();
  242. return;
  243. }
  244. var query = querystring.parse(parts.query);
  245. for (var i in query) {
  246. query[i] = decodeURIComponent(query[i]);
  247. }
  248. // Finally, call method handler
  249. fn(query, conf, req, respond);
  250. }