package api import ( "crypto/md5" "database/sql" "fmt" "io" "math" "mime/multipart" "net/http" "os" "path/filepath" "reflect" "sort" "strings" "time" argon2 "github.com/alexedwards/argon2id" "github.com/gabriel-vasile/mimetype" "github.com/gin-gonic/gin" log "github.com/sirupsen/logrus" "golang.org/x/exp/slices" "reichard.io/antholume/api/renderer" "reichard.io/antholume/database" "reichard.io/antholume/metadata" "reichard.io/antholume/ngtemplates/common" "reichard.io/antholume/ngtemplates/pages" "reichard.io/antholume/search" ) type backupType string const ( backupCovers backupType = "COVERS" backupDocuments backupType = "DOCUMENTS" ) type queryParams struct { Page *int64 `form:"page"` Limit *int64 `form:"limit"` Search *string `form:"search"` Document *string `form:"document"` } type searchParams struct { Query *string `form:"query"` Source *search.Source `form:"source"` } type requestDocumentUpload struct { DocumentFile *multipart.FileHeader `form:"document_file"` } type requestDocumentEdit struct { Title *string `form:"title"` Author *string `form:"author"` Description *string `form:"description"` ISBN10 *string `form:"isbn_10"` ISBN13 *string `form:"isbn_13"` RemoveCover *string `form:"remove_cover"` CoverGBID *string `form:"cover_gbid"` CoverFile *multipart.FileHeader `form:"cover_file"` } type requestDocumentIdentify struct { Title *string `form:"title"` Author *string `form:"author"` ISBN *string `form:"isbn"` } type requestSettingsEdit struct { Password *string `form:"password"` NewPassword *string `form:"new_password"` Timezone *string `form:"timezone"` } type requestDocumentAdd struct { ID string `form:"id"` Title *string `form:"title"` Author *string `form:"author"` Source search.Source `form:"source"` } func (api *API) appWebManifest(c *gin.Context) { c.Header("Content-Type", "application/manifest+json") c.FileFromFS("assets/manifest.json", http.FS(api.assets)) } func (api *API) appServiceWorker(c *gin.Context) { c.FileFromFS("assets/sw.js", http.FS(api.assets)) } func (api *API) appFaviconIcon(c *gin.Context) { c.FileFromFS("assets/icons/favicon.ico", http.FS(api.assets)) } func (api *API) appLocalDocuments(c *gin.Context) { c.FileFromFS("assets/local/index.htm", http.FS(api.assets)) } func (api *API) appDocumentReader(c *gin.Context) { c.FileFromFS("assets/reader/index.htm", http.FS(api.assets)) } func (api *API) appGetDocuments(c *gin.Context) { settings, auth := api.getBaseTemplateVarsNew(common.RouteDocuments, c) qParams := bindQueryParams(c, 9) var query *string if qParams.Search != nil && *qParams.Search != "" { search := "%" + *qParams.Search + "%" query = &search } documents, err := api.db.Queries.GetDocumentsWithStats(api.db.Ctx, database.GetDocumentsWithStatsParams{ UserID: auth.UserName, Query: query, Offset: (*qParams.Page - 1) * *qParams.Limit, Limit: *qParams.Limit, }) if err != nil { log.Error("GetDocumentsWithStats DB Error: ", err) appErrorPage(c, http.StatusInternalServerError, fmt.Sprintf("GetDocumentsWithStats DB Error: %v", err)) return } length, err := api.db.Queries.GetDocumentsSize(api.db.Ctx, query) if err != nil { log.Error("GetDocumentsSize DB Error: ", err) appErrorPage(c, http.StatusInternalServerError, fmt.Sprintf("GetDocumentsSize DB Error: %v", err)) return } if err = api.getDocumentsWordCount(documents); err != nil { log.Error("Unable to Get Word Counts: ", err) } totalPages := int64(math.Ceil(float64(length) / float64(*qParams.Limit))) nextPage := *qParams.Page + 1 previousPage := *qParams.Page - 1 r := renderer.New(c.Request.Context(), http.StatusOK, pages.Documents( settings, documents, nextPage, previousPage, totalPages, *qParams.Limit, )) c.Render(http.StatusOK, r) } func (api *API) appGetDocument(c *gin.Context) { templateVars, auth := api.getBaseTemplateVars("document", c) var rDocID requestDocumentID if err := c.ShouldBindUri(&rDocID); err != nil { log.Error("Invalid URI Bind") appErrorPage(c, http.StatusNotFound, "Invalid document") return } document, err := api.db.Queries.GetDocumentWithStats(api.db.Ctx, database.GetDocumentWithStatsParams{ UserID: auth.UserName, DocumentID: rDocID.DocumentID, }) if err != nil { log.Error("GetDocumentWithStats DB Error: ", err) appErrorPage(c, http.StatusInternalServerError, fmt.Sprintf("GetDocumentsWithStats DB Error: %v", err)) return } templateVars["Data"] = document templateVars["TotalTimeLeftSeconds"] = int64((100.0 - document.Percentage) * float64(document.SecondsPerPercent)) c.HTML(http.StatusOK, "page/document", templateVars) } func (api *API) appGetProgress(c *gin.Context) { templateVars, auth := api.getBaseTemplateVars("progress", c) qParams := bindQueryParams(c, 15) progressFilter := database.GetProgressParams{ UserID: auth.UserName, Offset: (*qParams.Page - 1) * *qParams.Limit, Limit: *qParams.Limit, } if qParams.Document != nil { progressFilter.DocFilter = true progressFilter.DocumentID = *qParams.Document } progress, err := api.db.Queries.GetProgress(api.db.Ctx, progressFilter) if err != nil { log.Error("GetProgress DB Error: ", err) appErrorPage(c, http.StatusInternalServerError, fmt.Sprintf("GetActivity DB Error: %v", err)) return } templateVars["Data"] = progress c.HTML(http.StatusOK, "page/progress", templateVars) } func (api *API) appGetActivity(c *gin.Context) { settings, auth := api.getBaseTemplateVarsNew(common.RouteActivity, c) qParams := bindQueryParams(c, 15) activityFilter := database.GetActivityParams{ UserID: auth.UserName, Offset: (*qParams.Page - 1) * *qParams.Limit, Limit: *qParams.Limit, } if qParams.Document != nil { activityFilter.DocFilter = true activityFilter.DocumentID = *qParams.Document } activity, err := api.db.Queries.GetActivity(api.db.Ctx, activityFilter) if err != nil { log.Error("GetActivity DB Error: ", err) appErrorPage(c, http.StatusInternalServerError, fmt.Sprintf("GetActivity DB Error: %v", err)) return } r := renderer.New(c.Request.Context(), http.StatusOK, pages.Activity( settings, activity, )) c.Render(http.StatusOK, r) } func (api *API) appGetHome(c *gin.Context) { settings, auth := api.getBaseTemplateVarsNew(common.RouteHome, c) start := time.Now() graphData, err := api.db.Queries.GetDailyReadStats(api.db.Ctx, auth.UserName) if err != nil { log.Error("GetDailyReadStats DB Error: ", err) appErrorPage(c, http.StatusInternalServerError, fmt.Sprintf("GetDailyReadStats DB Error: %v", err)) return } log.Debug("GetDailyReadStats DB Performance: ", time.Since(start)) start = time.Now() databaseInfo, err := api.db.Queries.GetDatabaseInfo(api.db.Ctx, auth.UserName) if err != nil { log.Error("GetDatabaseInfo DB Error: ", err) appErrorPage(c, http.StatusInternalServerError, fmt.Sprintf("GetDatabaseInfo DB Error: %v", err)) return } log.Debug("GetDatabaseInfo DB Performance: ", time.Since(start)) start = time.Now() streaks, err := api.db.Queries.GetUserStreaks(api.db.Ctx, auth.UserName) if err != nil { log.Error("GetUserStreaks DB Error: ", err) appErrorPage(c, http.StatusInternalServerError, fmt.Sprintf("GetUserStreaks DB Error: %v", err)) return } log.Debug("GetUserStreaks DB Performance: ", time.Since(start)) start = time.Now() userStatistics, err := api.db.Queries.GetUserStatistics(api.db.Ctx) if err != nil { log.Error("GetUserStatistics DB Error: ", err) appErrorPage(c, http.StatusInternalServerError, fmt.Sprintf("GetUserStatistics DB Error: %v", err)) return } log.Debug("GetUserStatistics DB Performance: ", time.Since(start)) r := renderer.New(c.Request.Context(), http.StatusOK, pages.Home( settings, getSVGGraphData(graphData, 800, 70), streaks, arrangeUserStatistics(userStatistics), common.UserMetadata{ DocumentCount: int(databaseInfo.DocumentsSize), ActivityCount: int(databaseInfo.ActivitySize), ProgressCount: int(databaseInfo.ProgressSize), DeviceCount: int(databaseInfo.DevicesSize), }, )) c.Render(http.StatusOK, r) } func (api *API) appGetSettings(c *gin.Context) { templateVars, auth := api.getBaseTemplateVars("settings", c) user, err := api.db.Queries.GetUser(api.db.Ctx, auth.UserName) if err != nil { log.Error("GetUser DB Error: ", err) appErrorPage(c, http.StatusInternalServerError, fmt.Sprintf("GetUser DB Error: %v", err)) return } devices, err := api.db.Queries.GetDevices(api.db.Ctx, auth.UserName) if err != nil { log.Error("GetDevices DB Error: ", err) appErrorPage(c, http.StatusInternalServerError, fmt.Sprintf("GetDevices DB Error: %v", err)) return } templateVars["Data"] = gin.H{ "Timezone": *user.Timezone, "Devices": devices, } c.HTML(http.StatusOK, "page/settings", templateVars) } // Tabs: // - General (Import, Backup & Restore, Version (githash?), Stats?) // - Users // - Metadata func (api *API) appGetSearch(c *gin.Context) { templateVars, _ := api.getBaseTemplateVars("search", c) var sParams searchParams err := c.BindQuery(&sParams) if err != nil { appErrorPage(c, http.StatusInternalServerError, fmt.Sprintf("Invalid Form Bind: %v", err)) return } // Only Handle Query if sParams.Query != nil && sParams.Source != nil { // Search searchResults, err := search.SearchBook(*sParams.Query, *sParams.Source) if err != nil { appErrorPage(c, http.StatusInternalServerError, fmt.Sprintf("Search Error: %v", err)) return } templateVars["Data"] = searchResults templateVars["Source"] = *sParams.Source } else if sParams.Query != nil || sParams.Source != nil { templateVars["SearchErrorMessage"] = "Invalid Query" } c.HTML(http.StatusOK, "page/search", templateVars) } func (api *API) appGetLogin(c *gin.Context) { templateVars, _ := api.getBaseTemplateVars("login", c) templateVars["RegistrationEnabled"] = api.cfg.RegistrationEnabled c.HTML(http.StatusOK, "page/login", templateVars) } func (api *API) appGetRegister(c *gin.Context) { if !api.cfg.RegistrationEnabled { c.Redirect(http.StatusFound, "/login") return } templateVars, _ := api.getBaseTemplateVars("login", c) templateVars["RegistrationEnabled"] = api.cfg.RegistrationEnabled templateVars["Register"] = true c.HTML(http.StatusOK, "page/login", templateVars) } func (api *API) appGetDocumentProgress(c *gin.Context) { var auth authData if data, _ := c.Get("Authorization"); data != nil { auth = data.(authData) } var rDoc requestDocumentID if err := c.ShouldBindUri(&rDoc); err != nil { log.Error("Invalid URI Bind") appErrorPage(c, http.StatusNotFound, "Invalid document") return } progress, err := api.db.Queries.GetDocumentProgress(api.db.Ctx, database.GetDocumentProgressParams{ DocumentID: rDoc.DocumentID, UserID: auth.UserName, }) if err != nil && err != sql.ErrNoRows { log.Error("GetDocumentProgress DB Error: ", err) appErrorPage(c, http.StatusInternalServerError, fmt.Sprintf("GetDocumentProgress DB Error: %v", err)) return } document, err := api.db.Queries.GetDocumentWithStats(api.db.Ctx, database.GetDocumentWithStatsParams{ UserID: auth.UserName, DocumentID: rDoc.DocumentID, }) if err != nil { log.Error("GetDocumentWithStats DB Error: ", err) appErrorPage(c, http.StatusInternalServerError, fmt.Sprintf("GetDocumentWithStats DB Error: %v", err)) return } c.JSON(http.StatusOK, gin.H{ "id": document.ID, "title": document.Title, "author": document.Author, "words": document.Words, "progress": progress.Progress, "percentage": document.Percentage, }) } func (api *API) appGetDevices(c *gin.Context) { var auth authData if data, _ := c.Get("Authorization"); data != nil { auth = data.(authData) } devices, err := api.db.Queries.GetDevices(api.db.Ctx, auth.UserName) if err != nil && err != sql.ErrNoRows { log.Error("GetDevices DB Error: ", err) appErrorPage(c, http.StatusInternalServerError, fmt.Sprintf("GetDevices DB Error: %v", err)) return } c.JSON(http.StatusOK, devices) } func (api *API) appUploadNewDocument(c *gin.Context) { var rDocUpload requestDocumentUpload if err := c.ShouldBind(&rDocUpload); err != nil { log.Error("Invalid Form Bind") appErrorPage(c, http.StatusBadRequest, "Invalid or missing form values") return } if rDocUpload.DocumentFile == nil { c.Redirect(http.StatusFound, "./documents") return } // Create Temp File tempFile, err := os.CreateTemp("", "book") if err != nil { log.Warn("Temp File Create Error: ", err) appErrorPage(c, http.StatusInternalServerError, "Unable to create temp file") return } defer os.Remove(tempFile.Name()) defer tempFile.Close() // Save Temp File err = c.SaveUploadedFile(rDocUpload.DocumentFile, tempFile.Name()) if err != nil { log.Error("File Error: ", err) appErrorPage(c, http.StatusInternalServerError, "Unable to save file") return } // Get Metadata metadataInfo, err := metadata.GetMetadata(tempFile.Name()) if err != nil { log.Errorf("unable to acquire metadata: %v", err) appErrorPage(c, http.StatusInternalServerError, "Unable to acquire metadata") return } // Check Already Exists _, err = api.db.Queries.GetDocument(api.db.Ctx, *metadataInfo.PartialMD5) if err == nil { log.Warnf("document already exists: %s", *metadataInfo.PartialMD5) c.Redirect(http.StatusFound, fmt.Sprintf("./documents/%s", *metadataInfo.PartialMD5)) } // Derive & Sanitize File Name fileName := deriveBaseFileName(metadataInfo) basePath := filepath.Join(api.cfg.DataPath, "documents") safePath := filepath.Join(basePath, fileName) // Open Destination File destFile, err := os.Create(safePath) if err != nil { log.Errorf("unable to open destination file: %v", err) appErrorPage(c, http.StatusInternalServerError, "Unable to open destination file") return } defer destFile.Close() // Copy File if _, err = io.Copy(destFile, tempFile); err != nil { log.Errorf("unable to save file: %v", err) appErrorPage(c, http.StatusInternalServerError, "Unable to save file") return } // Upsert Document if _, err = api.db.Queries.UpsertDocument(api.db.Ctx, database.UpsertDocumentParams{ ID: *metadataInfo.PartialMD5, Title: metadataInfo.Title, Author: metadataInfo.Author, Description: metadataInfo.Description, Md5: metadataInfo.MD5, Words: metadataInfo.WordCount, Filepath: &fileName, Basepath: &basePath, }); err != nil { log.Errorf("UpsertDocument DB Error: %v", err) appErrorPage(c, http.StatusInternalServerError, fmt.Sprintf("UpsertDocument DB Error: %v", err)) return } c.Redirect(http.StatusFound, fmt.Sprintf("./documents/%s", *metadataInfo.PartialMD5)) } func (api *API) appEditDocument(c *gin.Context) { var rDocID requestDocumentID if err := c.ShouldBindUri(&rDocID); err != nil { log.Error("Invalid URI Bind") appErrorPage(c, http.StatusNotFound, "Invalid document") return } var rDocEdit requestDocumentEdit if err := c.ShouldBind(&rDocEdit); err != nil { log.Error("Invalid Form Bind") appErrorPage(c, http.StatusBadRequest, "Invalid or missing form values") return } // Validate Something Exists if rDocEdit.Author == nil && rDocEdit.Title == nil && rDocEdit.Description == nil && rDocEdit.ISBN10 == nil && rDocEdit.ISBN13 == nil && rDocEdit.RemoveCover == nil && rDocEdit.CoverGBID == nil && rDocEdit.CoverFile == nil { log.Error("Missing Form Values") appErrorPage(c, http.StatusBadRequest, "Invalid or missing form values") return } // Handle Cover var coverFileName *string if rDocEdit.RemoveCover != nil && *rDocEdit.RemoveCover == "on" { s := "UNKNOWN" coverFileName = &s } else if rDocEdit.CoverFile != nil { // Validate Type & Derive Extension on MIME uploadedFile, err := rDocEdit.CoverFile.Open() if err != nil { log.Error("File Error") appErrorPage(c, http.StatusInternalServerError, "Unable to open file") return } fileMime, err := mimetype.DetectReader(uploadedFile) if err != nil { log.Error("MIME Error") appErrorPage(c, http.StatusInternalServerError, "Unable to detect filetype") return } fileExtension := fileMime.Extension() // Validate Extension if !slices.Contains([]string{".jpg", ".png"}, fileExtension) { log.Error("Invalid FileType: ", fileExtension) appErrorPage(c, http.StatusBadRequest, "Invalid filetype") return } // Generate Storage Path fileName := fmt.Sprintf("%s%s", rDocID.DocumentID, fileExtension) safePath := filepath.Join(api.cfg.DataPath, "covers", fileName) // Save err = c.SaveUploadedFile(rDocEdit.CoverFile, safePath) if err != nil { log.Error("File Error: ", err) appErrorPage(c, http.StatusInternalServerError, "Unable to save file") return } coverFileName = &fileName } else if rDocEdit.CoverGBID != nil { var coverDir string = filepath.Join(api.cfg.DataPath, "covers") fileName, err := metadata.CacheCover(*rDocEdit.CoverGBID, coverDir, rDocID.DocumentID, true) if err == nil { coverFileName = fileName } } // Update Document if _, err := api.db.Queries.UpsertDocument(api.db.Ctx, database.UpsertDocumentParams{ ID: rDocID.DocumentID, Title: api.sanitizeInput(rDocEdit.Title), Author: api.sanitizeInput(rDocEdit.Author), Description: api.sanitizeInput(rDocEdit.Description), Isbn10: api.sanitizeInput(rDocEdit.ISBN10), Isbn13: api.sanitizeInput(rDocEdit.ISBN13), Coverfile: coverFileName, }); err != nil { log.Error("UpsertDocument DB Error: ", err) appErrorPage(c, http.StatusInternalServerError, fmt.Sprintf("UpsertDocument DB Error: %v", err)) return } c.Redirect(http.StatusFound, "./") } func (api *API) appDeleteDocument(c *gin.Context) { var rDocID requestDocumentID if err := c.ShouldBindUri(&rDocID); err != nil { log.Error("Invalid URI Bind") appErrorPage(c, http.StatusNotFound, "Invalid document") return } changed, err := api.db.Queries.DeleteDocument(api.db.Ctx, rDocID.DocumentID) if err != nil { log.Error("DeleteDocument DB Error") appErrorPage(c, http.StatusInternalServerError, fmt.Sprintf("DeleteDocument DB Error: %v", err)) return } if changed == 0 { log.Error("DeleteDocument DB Error") appErrorPage(c, http.StatusNotFound, "Invalid document") return } c.Redirect(http.StatusFound, "../") } func (api *API) appIdentifyDocument(c *gin.Context) { var rDocID requestDocumentID if err := c.ShouldBindUri(&rDocID); err != nil { log.Error("Invalid URI Bind") appErrorPage(c, http.StatusNotFound, "Invalid document") return } var rDocIdentify requestDocumentIdentify if err := c.ShouldBind(&rDocIdentify); err != nil { log.Error("Invalid Form Bind") appErrorPage(c, http.StatusBadRequest, "Invalid or missing form values") return } // Disallow Empty Strings if rDocIdentify.Title != nil && strings.TrimSpace(*rDocIdentify.Title) == "" { rDocIdentify.Title = nil } if rDocIdentify.Author != nil && strings.TrimSpace(*rDocIdentify.Author) == "" { rDocIdentify.Author = nil } if rDocIdentify.ISBN != nil && strings.TrimSpace(*rDocIdentify.ISBN) == "" { rDocIdentify.ISBN = nil } // Validate Values if rDocIdentify.ISBN == nil && rDocIdentify.Title == nil && rDocIdentify.Author == nil { log.Error("Invalid Form") appErrorPage(c, http.StatusBadRequest, "Invalid or missing form values") return } // Get Template Variables templateVars, auth := api.getBaseTemplateVars("document", c) // Get Metadata metadataResults, err := metadata.SearchMetadata(metadata.SOURCE_GBOOK, metadata.MetadataInfo{ Title: rDocIdentify.Title, Author: rDocIdentify.Author, ISBN10: rDocIdentify.ISBN, ISBN13: rDocIdentify.ISBN, }) if err == nil && len(metadataResults) > 0 { firstResult := metadataResults[0] // Store First Metadata Result if _, err = api.db.Queries.AddMetadata(api.db.Ctx, database.AddMetadataParams{ DocumentID: rDocID.DocumentID, Title: firstResult.Title, Author: firstResult.Author, Description: firstResult.Description, Gbid: firstResult.ID, Olid: nil, Isbn10: firstResult.ISBN10, Isbn13: firstResult.ISBN13, }); err != nil { log.Error("AddMetadata DB Error: ", err) } templateVars["Metadata"] = firstResult } else { log.Warn("Metadata Error") templateVars["MetadataError"] = "No Metadata Found" } document, err := api.db.Queries.GetDocumentWithStats(api.db.Ctx, database.GetDocumentWithStatsParams{ UserID: auth.UserName, DocumentID: rDocID.DocumentID, }) if err != nil { log.Error("GetDocumentWithStats DB Error: ", err) appErrorPage(c, http.StatusInternalServerError, fmt.Sprintf("GetDocumentWithStats DB Error: %v", err)) return } templateVars["Data"] = document templateVars["TotalTimeLeftSeconds"] = int64((100.0 - document.Percentage) * float64(document.SecondsPerPercent)) c.HTML(http.StatusOK, "page/document", templateVars) } func (api *API) appSaveNewDocument(c *gin.Context) { var rDocAdd requestDocumentAdd if err := c.ShouldBind(&rDocAdd); err != nil { log.Error("Invalid Form Bind") appErrorPage(c, http.StatusBadRequest, "Invalid or missing form values") return } // Render Initial Template templateVars, _ := api.getBaseTemplateVars("search", c) c.HTML(http.StatusOK, "page/search", templateVars) // Create Streamer stream := api.newStreamer(c, `