.circleci
.github
app
chewy
controllers
activitypub
admin
api
v1
v2
web
base_controller.rb
oembed_controller.rb
push_controller.rb
salmon_controller.rb
subscriptions_controller.rb
auth
concerns
oauth
settings
well_known
about_controller.rb
account_follow_controller.rb
account_unfollow_controller.rb
accounts_controller.rb
application_controller.rb
authorize_interactions_controller.rb
custom_css_controller.rb
directories_controller.rb
emojis_controller.rb
filters_controller.rb
follower_accounts_controller.rb
following_accounts_controller.rb
home_controller.rb
intents_controller.rb
invites_controller.rb
manifests_controller.rb
media_controller.rb
media_proxy_controller.rb
remote_follow_controller.rb
remote_interaction_controller.rb
remote_unfollows_controller.rb
shares_controller.rb
statuses_controller.rb
stream_entries_controller.rb
tags_controller.rb
helpers
javascript
lib
mailers
models
policies
presenters
serializers
services
validators
views
workers
bin
config
db
dist
lib
log
nanobox
public
spec
streaming
vendor
.buildpacks
.codeclimate.yml
.dockerignore
.editorconfig
.env.nanobox
.env.production.sample
.env.test
.env.vagrant
.eslintignore
.eslintrc.js
.foreman
.gitattributes
.gitignore
.haml-lint.yml
.nanoignore
.nvmrc
.profile
.rspec
.rubocop.yml
.ruby-version
.scss-lint.yml
.slugignore
.yarnclean
AUTHORS.md
Aptfile
CHANGELOG.md
CODE_OF_CONDUCT.md
CONTRIBUTING.md
Capfile
Dockerfile
Gemfile
Gemfile.lock
LICENSE
Procfile
Procfile.dev
README.md
Rakefile
Vagrantfile
app.json
babel.config.js
boxfile.yml
config.ru
docker-compose.yml
jest.config.js
package.json
postcss.config.js
priv-config
scalingo.json
yarn.lock
90 lines
2.4 KiB
Ruby
90 lines
2.4 KiB
Ruby
# frozen_string_literal: true
|
|
|
|
class Api::BaseController < ApplicationController
|
|
DEFAULT_STATUSES_LIMIT = 20
|
|
DEFAULT_ACCOUNTS_LIMIT = 40
|
|
|
|
include RateLimitHeaders
|
|
|
|
skip_before_action :store_current_location
|
|
skip_before_action :check_user_permissions
|
|
|
|
protect_from_forgery with: :null_session
|
|
|
|
rescue_from ActiveRecord::RecordInvalid, Mastodon::ValidationError do |e|
|
|
render json: { error: e.to_s }, status: 422
|
|
end
|
|
|
|
rescue_from ActiveRecord::RecordNotFound do
|
|
render json: { error: 'Record not found' }, status: 404
|
|
end
|
|
|
|
rescue_from HTTP::Error, Mastodon::UnexpectedResponseError do
|
|
render json: { error: 'Remote data could not be fetched' }, status: 503
|
|
end
|
|
|
|
rescue_from OpenSSL::SSL::SSLError do
|
|
render json: { error: 'Remote SSL certificate could not be verified' }, status: 503
|
|
end
|
|
|
|
rescue_from Mastodon::NotPermittedError do
|
|
render json: { error: 'This action is not allowed' }, status: 403
|
|
end
|
|
|
|
def doorkeeper_unauthorized_render_options(error: nil)
|
|
{ json: { error: (error.try(:description) || 'Not authorized') } }
|
|
end
|
|
|
|
def doorkeeper_forbidden_render_options(*)
|
|
{ json: { error: 'This action is outside the authorized scopes' } }
|
|
end
|
|
|
|
protected
|
|
|
|
def set_pagination_headers(next_path = nil, prev_path = nil)
|
|
links = []
|
|
links << [next_path, [%w(rel next)]] if next_path
|
|
links << [prev_path, [%w(rel prev)]] if prev_path
|
|
response.headers['Link'] = LinkHeader.new(links) unless links.empty?
|
|
end
|
|
|
|
def limit_param(default_limit)
|
|
return default_limit unless params[:limit]
|
|
[params[:limit].to_i.abs, default_limit * 2].min
|
|
end
|
|
|
|
def params_slice(*keys)
|
|
params.slice(*keys).permit(*keys)
|
|
end
|
|
|
|
def current_resource_owner
|
|
@current_user ||= User.find(doorkeeper_token.resource_owner_id) if doorkeeper_token
|
|
end
|
|
|
|
def current_user
|
|
current_resource_owner || super
|
|
rescue ActiveRecord::RecordNotFound
|
|
nil
|
|
end
|
|
|
|
def require_user!
|
|
if !current_user
|
|
render json: { error: 'This method requires an authenticated user' }, status: 422
|
|
elsif current_user.disabled?
|
|
render json: { error: 'Your login is currently disabled' }, status: 403
|
|
elsif !current_user.confirmed?
|
|
render json: { error: 'Email confirmation is not completed' }, status: 403
|
|
else
|
|
set_user_activity
|
|
end
|
|
end
|
|
|
|
def render_empty
|
|
render json: {}, status: 200
|
|
end
|
|
|
|
def authorize_if_got_token!(*scopes)
|
|
doorkeeper_authorize!(*scopes) if doorkeeper_token
|
|
end
|
|
end
|