| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  | <?php | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-09-11 02:31:09 +08:00
										 |  |  | namespace BookStack\Http\Controllers; | 
					
						
							| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-02-04 08:26:19 +08:00
										 |  |  | use BookStack\Exceptions\NotifyException; | 
					
						
							| 
									
										
										
										
											2020-11-19 07:38:44 +08:00
										 |  |  | use BookStack\Facades\Activity; | 
					
						
							|  |  |  | use BookStack\Interfaces\Loggable; | 
					
						
							| 
									
										
										
										
											2020-12-31 02:25:35 +08:00
										 |  |  | use BookStack\Model; | 
					
						
							| 
									
										
										
										
											2021-11-01 01:58:56 +08:00
										 |  |  | use BookStack\Util\WebSafeMimeSniffer; | 
					
						
							| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  | use Illuminate\Foundation\Bus\DispatchesJobs; | 
					
						
							| 
									
										
										
										
											2018-09-25 23:58:03 +08:00
										 |  |  | use Illuminate\Foundation\Validation\ValidatesRequests; | 
					
						
							| 
									
										
										
										
											2020-11-19 07:38:44 +08:00
										 |  |  | use Illuminate\Http\JsonResponse; | 
					
						
							|  |  |  | use Illuminate\Http\Response; | 
					
						
							| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  | use Illuminate\Routing\Controller as BaseController; | 
					
						
							| 
									
										
										
										
											2022-04-03 01:07:43 +08:00
										 |  |  | use Symfony\Component\HttpFoundation\StreamedResponse; | 
					
						
							| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | abstract class Controller extends BaseController | 
					
						
							|  |  |  | { | 
					
						
							| 
									
										
										
										
											2021-06-26 23:23:15 +08:00
										 |  |  |     use DispatchesJobs; | 
					
						
							|  |  |  |     use ValidatesRequests; | 
					
						
							| 
									
										
										
										
											2015-08-25 04:10:04 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  |     /** | 
					
						
							| 
									
										
										
										
											2019-09-20 07:18:28 +08:00
										 |  |  |      * Check if the current user is signed in. | 
					
						
							| 
									
										
										
										
											2015-08-25 04:10:04 +08:00
										 |  |  |      */ | 
					
						
							| 
									
										
										
										
											2019-09-20 07:18:28 +08:00
										 |  |  |     protected function isSignedIn(): bool | 
					
						
							| 
									
										
										
										
											2015-08-25 04:10:04 +08:00
										 |  |  |     { | 
					
						
							| 
									
										
										
										
											2019-09-20 07:18:28 +08:00
										 |  |  |         return auth()->check(); | 
					
						
							| 
									
										
										
										
											2015-08-29 22:03:42 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-01-01 01:57:34 +08:00
										 |  |  |     /** | 
					
						
							|  |  |  |      * Stops the application and shows a permission error if | 
					
						
							|  |  |  |      * the application is in demo mode. | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2019-09-19 22:12:10 +08:00
										 |  |  |     protected function preventAccessInDemoMode() | 
					
						
							| 
									
										
										
										
											2016-01-01 01:57:34 +08:00
										 |  |  |     { | 
					
						
							| 
									
										
										
										
											2018-01-29 00:58:52 +08:00
										 |  |  |         if (config('app.env') === 'demo') { | 
					
						
							|  |  |  |             $this->showPermissionError(); | 
					
						
							|  |  |  |         } | 
					
						
							| 
									
										
										
										
											2016-01-01 01:57:34 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-12-05 22:41:51 +08:00
										 |  |  |     /** | 
					
						
							|  |  |  |      * Adds the page title into the view. | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2020-11-19 07:38:44 +08:00
										 |  |  |     public function setPageTitle(string $title) | 
					
						
							| 
									
										
										
										
											2015-12-05 22:41:51 +08:00
										 |  |  |     { | 
					
						
							|  |  |  |         view()->share('pageTitle', $title); | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-01-01 01:57:34 +08:00
										 |  |  |     /** | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |      * On a permission error redirect to home and display. | 
					
						
							| 
									
										
										
										
											2016-01-01 01:57:34 +08:00
										 |  |  |      * the error as a notification. | 
					
						
							| 
									
										
										
										
											2022-01-07 21:04:49 +08:00
										 |  |  |      * | 
					
						
							|  |  |  |      * @return never | 
					
						
							| 
									
										
										
										
											2016-01-01 01:57:34 +08:00
										 |  |  |      */ | 
					
						
							|  |  |  |     protected function showPermissionError() | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2022-02-04 08:26:19 +08:00
										 |  |  |         $message = request()->wantsJson() ? trans('errors.permissionJson') : trans('errors.permission'); | 
					
						
							| 
									
										
										
										
											2022-02-08 23:29:58 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-02-04 08:26:19 +08:00
										 |  |  |         throw new NotifyException($message, '/', 403); | 
					
						
							| 
									
										
										
										
											2016-01-01 01:57:34 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2015-08-29 22:03:42 +08:00
										 |  |  |     /** | 
					
						
							| 
									
										
										
										
											2020-11-19 07:38:44 +08:00
										 |  |  |      * Checks that the current user has the given permission otherwise throw an exception. | 
					
						
							| 
									
										
										
										
											2015-08-29 22:03:42 +08:00
										 |  |  |      */ | 
					
						
							| 
									
										
										
										
											2020-11-19 07:38:44 +08:00
										 |  |  |     protected function checkPermission(string $permission): void | 
					
						
							| 
									
										
										
										
											2015-08-29 22:03:42 +08:00
										 |  |  |     { | 
					
						
							| 
									
										
										
										
											2020-11-19 07:38:44 +08:00
										 |  |  |         if (!user() || !user()->can($permission)) { | 
					
						
							| 
									
										
										
										
											2016-01-01 01:57:34 +08:00
										 |  |  |             $this->showPermissionError(); | 
					
						
							| 
									
										
										
										
											2015-08-29 22:03:42 +08:00
										 |  |  |         } | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |     /** | 
					
						
							| 
									
										
										
										
											2020-11-19 07:38:44 +08:00
										 |  |  |      * Check the current user's permissions against an ownable item otherwise throw an exception. | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |      */ | 
					
						
							| 
									
										
										
										
											2020-12-31 02:25:35 +08:00
										 |  |  |     protected function checkOwnablePermission(string $permission, Model $ownable): void | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |     { | 
					
						
							| 
									
										
										
										
											2020-11-19 07:38:44 +08:00
										 |  |  |         if (!userCan($permission, $ownable)) { | 
					
						
							|  |  |  |             $this->showPermissionError(); | 
					
						
							| 
									
										
										
										
											2018-01-29 00:58:52 +08:00
										 |  |  |         } | 
					
						
							| 
									
										
										
										
											2016-02-28 03:24:42 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-01-01 01:57:34 +08:00
										 |  |  |     /** | 
					
						
							| 
									
										
										
										
											2020-11-19 07:38:44 +08:00
										 |  |  |      * Check if a user has a permission or bypass the permission | 
					
						
							|  |  |  |      * check if the given callback resolves true. | 
					
						
							| 
									
										
										
										
											2016-01-01 01:57:34 +08:00
										 |  |  |      */ | 
					
						
							| 
									
										
										
										
											2020-11-19 07:38:44 +08:00
										 |  |  |     protected function checkPermissionOr(string $permission, callable $callback): void | 
					
						
							| 
									
										
										
										
											2015-08-29 22:03:42 +08:00
										 |  |  |     { | 
					
						
							| 
									
										
										
										
											2020-11-19 07:38:44 +08:00
										 |  |  |         if ($callback() !== true) { | 
					
						
							|  |  |  |             $this->checkPermission($permission); | 
					
						
							| 
									
										
										
										
											2018-01-29 00:58:52 +08:00
										 |  |  |         } | 
					
						
							| 
									
										
										
										
											2015-08-25 04:10:04 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-12-08 02:33:32 +08:00
										 |  |  |     /** | 
					
						
							|  |  |  |      * Check if the current user has a permission or bypass if the provided user | 
					
						
							|  |  |  |      * id matches the current user. | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2020-11-19 07:38:44 +08:00
										 |  |  |     protected function checkPermissionOrCurrentUser(string $permission, int $userId): void | 
					
						
							| 
									
										
										
										
											2018-12-08 02:33:32 +08:00
										 |  |  |     { | 
					
						
							| 
									
										
										
										
											2020-11-19 07:38:44 +08:00
										 |  |  |         $this->checkPermissionOr($permission, function () use ($userId) { | 
					
						
							| 
									
										
										
										
											2019-09-20 07:18:28 +08:00
										 |  |  |             return $userId === user()->id; | 
					
						
							| 
									
										
										
										
											2018-12-08 02:33:32 +08:00
										 |  |  |         }); | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-05-07 21:29:43 +08:00
										 |  |  |     /** | 
					
						
							|  |  |  |      * Send back a json error message. | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2021-06-26 23:23:15 +08:00
										 |  |  |     protected function jsonError(string $messageText = '', int $statusCode = 500): JsonResponse | 
					
						
							| 
									
										
										
										
											2016-05-07 21:29:43 +08:00
										 |  |  |     { | 
					
						
							| 
									
										
										
										
											2019-10-05 19:55:01 +08:00
										 |  |  |         return response()->json(['message' => $messageText, 'status' => 'error'], $statusCode); | 
					
						
							| 
									
										
										
										
											2016-05-07 21:29:43 +08:00
										 |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-09-22 18:34:09 +08:00
										 |  |  |     /** | 
					
						
							|  |  |  |      * Create a response that forces a download in the browser. | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2020-11-19 07:38:44 +08:00
										 |  |  |     protected function downloadResponse(string $content, string $fileName): Response | 
					
						
							| 
									
										
										
										
											2018-09-22 18:34:09 +08:00
										 |  |  |     { | 
					
						
							|  |  |  |         return response()->make($content, 200, [ | 
					
						
							| 
									
										
										
										
											2021-11-01 01:58:56 +08:00
										 |  |  |             'Content-Type'           => 'application/octet-stream', | 
					
						
							| 
									
										
										
										
											2022-04-03 23:22:31 +08:00
										 |  |  |             'Content-Disposition'    => 'attachment; filename="' . str_replace('"', '', $fileName) . '"', | 
					
						
							| 
									
										
										
										
											2021-11-01 01:58:56 +08:00
										 |  |  |             'X-Content-Type-Options' => 'nosniff', | 
					
						
							| 
									
										
										
										
											2018-09-22 18:34:09 +08:00
										 |  |  |         ]); | 
					
						
							|  |  |  |     } | 
					
						
							| 
									
										
										
										
											2019-09-19 22:12:10 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-04-03 01:07:43 +08:00
										 |  |  |     /** | 
					
						
							|  |  |  |      * Create a response that forces a download, from a given stream of content. | 
					
						
							|  |  |  |      */ | 
					
						
							|  |  |  |     protected function streamedDownloadResponse($stream, string $fileName): StreamedResponse | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2022-04-25 01:22:40 +08:00
										 |  |  |         return response()->stream(function () use ($stream) { | 
					
						
							| 
									
										
										
										
											2022-04-03 23:22:31 +08:00
										 |  |  |             // End & flush the output buffer otherwise we still seem to use memory.
 | 
					
						
							|  |  |  |             // Ignore in testing since output buffers are used to gather a response.
 | 
					
						
							|  |  |  |             if (!app()->runningUnitTests()) { | 
					
						
							|  |  |  |                 ob_end_clean(); | 
					
						
							|  |  |  |             } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-04-03 01:07:43 +08:00
										 |  |  |             fpassthru($stream); | 
					
						
							|  |  |  |             fclose($stream); | 
					
						
							|  |  |  |         }, 200, [ | 
					
						
							|  |  |  |             'Content-Type'           => 'application/octet-stream', | 
					
						
							| 
									
										
										
										
											2022-04-03 23:22:31 +08:00
										 |  |  |             'Content-Disposition'    => 'attachment; filename="' . str_replace('"', '', $fileName) . '"', | 
					
						
							| 
									
										
										
										
											2022-04-03 01:07:43 +08:00
										 |  |  |             'X-Content-Type-Options' => 'nosniff', | 
					
						
							|  |  |  |         ]); | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-06-06 07:51:06 +08:00
										 |  |  |     /** | 
					
						
							|  |  |  |      * Create a file download response that provides the file with a content-type | 
					
						
							|  |  |  |      * correct for the file, in a way so the browser can show the content in browser. | 
					
						
							|  |  |  |      */ | 
					
						
							|  |  |  |     protected function inlineDownloadResponse(string $content, string $fileName): Response | 
					
						
							|  |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-11-01 21:26:02 +08:00
										 |  |  |         $mime = (new WebSafeMimeSniffer())->sniff($content); | 
					
						
							| 
									
										
										
										
											2021-06-26 23:23:15 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2021-06-06 07:51:06 +08:00
										 |  |  |         return response()->make($content, 200, [ | 
					
						
							| 
									
										
										
										
											2021-11-01 01:58:56 +08:00
										 |  |  |             'Content-Type'           => $mime, | 
					
						
							| 
									
										
										
										
											2022-04-03 23:22:31 +08:00
										 |  |  |             'Content-Disposition'    => 'inline; filename="' . str_replace('"', '', $fileName) . '"', | 
					
						
							| 
									
										
										
										
											2021-11-01 01:58:56 +08:00
										 |  |  |             'X-Content-Type-Options' => 'nosniff', | 
					
						
							| 
									
										
										
										
											2021-06-06 07:51:06 +08:00
										 |  |  |         ]); | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-04-03 01:07:43 +08:00
										 |  |  |     /** | 
					
						
							|  |  |  |      * Create a file download response that provides the file with a content-type | 
					
						
							|  |  |  |      * correct for the file, in a way so the browser can show the content in browser, | 
					
						
							|  |  |  |      * for a given content stream. | 
					
						
							|  |  |  |      */ | 
					
						
							|  |  |  |     protected function streamedInlineDownloadResponse($stream, string $fileName): StreamedResponse | 
					
						
							|  |  |  |     { | 
					
						
							|  |  |  |         $sniffContent = fread($stream, 1000); | 
					
						
							|  |  |  |         $mime = (new WebSafeMimeSniffer())->sniff($sniffContent); | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2022-04-25 01:22:40 +08:00
										 |  |  |         return response()->stream(function () use ($sniffContent, $stream) { | 
					
						
							|  |  |  |             echo $sniffContent; | 
					
						
							|  |  |  |             fpassthru($stream); | 
					
						
							|  |  |  |             fclose($stream); | 
					
						
							| 
									
										
										
										
											2022-04-03 01:07:43 +08:00
										 |  |  |         }, 200, [ | 
					
						
							|  |  |  |             'Content-Type'           => $mime, | 
					
						
							| 
									
										
										
										
											2022-04-03 23:22:31 +08:00
										 |  |  |             'Content-Disposition'    => 'inline; filename="' . str_replace('"', '', $fileName) . '"', | 
					
						
							| 
									
										
										
										
											2022-04-03 01:07:43 +08:00
										 |  |  |             'X-Content-Type-Options' => 'nosniff', | 
					
						
							|  |  |  |         ]); | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-09-19 22:12:10 +08:00
										 |  |  |     /** | 
					
						
							|  |  |  |      * Show a positive, successful notification to the user on next view load. | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2020-11-19 07:38:44 +08:00
										 |  |  |     protected function showSuccessNotification(string $message): void | 
					
						
							| 
									
										
										
										
											2019-09-19 22:12:10 +08:00
										 |  |  |     { | 
					
						
							|  |  |  |         session()->flash('success', $message); | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     /** | 
					
						
							|  |  |  |      * Show a warning notification to the user on next view load. | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2020-11-19 07:38:44 +08:00
										 |  |  |     protected function showWarningNotification(string $message): void | 
					
						
							| 
									
										
										
										
											2019-09-19 22:12:10 +08:00
										 |  |  |     { | 
					
						
							|  |  |  |         session()->flash('warning', $message); | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     /** | 
					
						
							|  |  |  |      * Show an error notification to the user on next view load. | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2020-11-19 07:38:44 +08:00
										 |  |  |     protected function showErrorNotification(string $message): void | 
					
						
							| 
									
										
										
										
											2019-09-19 22:12:10 +08:00
										 |  |  |     { | 
					
						
							|  |  |  |         session()->flash('error', $message); | 
					
						
							|  |  |  |     } | 
					
						
							| 
									
										
										
										
											2019-10-05 19:55:01 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-11-19 07:38:44 +08:00
										 |  |  |     /** | 
					
						
							|  |  |  |      * Log an activity in the system. | 
					
						
							| 
									
										
										
										
											2021-06-26 23:23:15 +08:00
										 |  |  |      * | 
					
						
							| 
									
										
										
										
											2021-11-15 06:03:22 +08:00
										 |  |  |      * @param string|Loggable $detail | 
					
						
							| 
									
										
										
										
											2020-11-19 07:38:44 +08:00
										 |  |  |      */ | 
					
						
							|  |  |  |     protected function logActivity(string $type, $detail = ''): void | 
					
						
							|  |  |  |     { | 
					
						
							|  |  |  |         Activity::add($type, $detail); | 
					
						
							|  |  |  |     } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-10-05 19:55:01 +08:00
										 |  |  |     /** | 
					
						
							|  |  |  |      * Get the validation rules for image files. | 
					
						
							|  |  |  |      */ | 
					
						
							| 
									
										
										
										
											2021-11-05 08:26:55 +08:00
										 |  |  |     protected function getImageValidationRules(): array | 
					
						
							| 
									
										
										
										
											2019-10-05 19:55:01 +08:00
										 |  |  |     { | 
					
						
							| 
									
										
										
										
											2021-11-15 06:03:22 +08:00
										 |  |  |         return ['image_extension', 'mimes:jpeg,png,gif,webp', 'max:' . (config('app.upload_limit') * 1000)]; | 
					
						
							| 
									
										
										
										
											2019-10-05 19:55:01 +08:00
										 |  |  |     } | 
					
						
							| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  | } |