repo.go 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473
  1. package repo
  2. import (
  3. "net/http"
  4. "path"
  5. "github.com/cockroachdb/errors"
  6. api "github.com/gogs/go-gogs-client"
  7. log "unknwon.dev/clog/v2"
  8. "gogs.io/gogs/internal/conf"
  9. "gogs.io/gogs/internal/context"
  10. "gogs.io/gogs/internal/database"
  11. "gogs.io/gogs/internal/form"
  12. "gogs.io/gogs/internal/route/api/v1/convert"
  13. )
  14. func Search(c *context.APIContext) {
  15. opts := &database.SearchRepoOptions{
  16. Keyword: path.Base(c.Query("q")),
  17. OwnerID: c.QueryInt64("uid"),
  18. PageSize: convert.ToCorrectPageSize(c.QueryInt("limit")),
  19. Page: c.QueryInt("page"),
  20. }
  21. // Check visibility.
  22. if c.IsLogged && opts.OwnerID > 0 {
  23. if c.User.ID == opts.OwnerID {
  24. opts.Private = true
  25. } else {
  26. u, err := database.Handle.Users().GetByID(c.Req.Context(), opts.OwnerID)
  27. if err != nil {
  28. c.JSON(http.StatusInternalServerError, map[string]any{
  29. "ok": false,
  30. "error": err.Error(),
  31. })
  32. return
  33. }
  34. if u.IsOrganization() && u.IsOwnedBy(c.User.ID) {
  35. opts.Private = true
  36. }
  37. // FIXME: how about collaborators?
  38. }
  39. }
  40. repos, count, err := database.SearchRepositoryByName(opts)
  41. if err != nil {
  42. c.JSON(http.StatusInternalServerError, map[string]any{
  43. "ok": false,
  44. "error": err.Error(),
  45. })
  46. return
  47. }
  48. if err = database.RepositoryList(repos).LoadAttributes(); err != nil {
  49. c.JSON(http.StatusInternalServerError, map[string]any{
  50. "ok": false,
  51. "error": err.Error(),
  52. })
  53. return
  54. }
  55. results := make([]*api.Repository, len(repos))
  56. for i := range repos {
  57. results[i] = repos[i].APIFormatLegacy(nil)
  58. }
  59. c.SetLinkHeader(int(count), opts.PageSize)
  60. c.JSONSuccess(map[string]any{
  61. "ok": true,
  62. "data": results,
  63. })
  64. }
  65. func listUserRepositories(c *context.APIContext, username string) {
  66. user, err := database.Handle.Users().GetByUsername(c.Req.Context(), username)
  67. if err != nil {
  68. c.NotFoundOrError(err, "get user by name")
  69. return
  70. }
  71. // Only list public repositories if user requests someone else's repository list,
  72. // or an organization isn't a member of.
  73. var ownRepos []*database.Repository
  74. if user.IsOrganization() {
  75. ownRepos, _, err = user.GetUserRepositories(c.User.ID, 1, user.NumRepos)
  76. } else {
  77. ownRepos, err = database.GetUserRepositories(&database.UserRepoOptions{
  78. UserID: user.ID,
  79. Private: c.User.ID == user.ID,
  80. Page: 1,
  81. PageSize: user.NumRepos,
  82. })
  83. }
  84. if err != nil {
  85. c.Error(err, "get user repositories")
  86. return
  87. }
  88. if err = database.RepositoryList(ownRepos).LoadAttributes(); err != nil {
  89. c.Error(err, "load attributes")
  90. return
  91. }
  92. // Early return for querying other user's repositories
  93. if c.User.ID != user.ID {
  94. repos := make([]*api.Repository, len(ownRepos))
  95. for i := range ownRepos {
  96. repos[i] = ownRepos[i].APIFormatLegacy(&api.Permission{Admin: true, Push: true, Pull: true})
  97. }
  98. c.JSONSuccess(&repos)
  99. return
  100. }
  101. accessibleReposWithAccessMode, err := database.Handle.Repositories().GetByCollaboratorIDWithAccessMode(c.Req.Context(), user.ID)
  102. if err != nil {
  103. c.Error(err, "get repositories accesses by collaborator")
  104. return
  105. }
  106. accessibleRepos := make([]*database.Repository, 0, len(accessibleReposWithAccessMode))
  107. for repo := range accessibleReposWithAccessMode {
  108. accessibleRepos = append(accessibleRepos, repo)
  109. }
  110. if err = database.RepositoryList(accessibleRepos).LoadAttributes(); err != nil {
  111. c.Error(err, "load attributes for accessible repositories")
  112. return
  113. }
  114. numOwnRepos := len(ownRepos)
  115. repos := make([]*api.Repository, 0, numOwnRepos+len(accessibleReposWithAccessMode))
  116. for _, r := range ownRepos {
  117. repos = append(repos, r.APIFormatLegacy(&api.Permission{Admin: true, Push: true, Pull: true}))
  118. }
  119. for repo, access := range accessibleReposWithAccessMode {
  120. repos = append(repos,
  121. repo.APIFormatLegacy(&api.Permission{
  122. Admin: access >= database.AccessModeAdmin,
  123. Push: access >= database.AccessModeWrite,
  124. Pull: true,
  125. }),
  126. )
  127. }
  128. c.JSONSuccess(&repos)
  129. }
  130. func ListMyRepos(c *context.APIContext) {
  131. listUserRepositories(c, c.User.Name)
  132. }
  133. func ListUserRepositories(c *context.APIContext) {
  134. listUserRepositories(c, c.Params(":username"))
  135. }
  136. func ListOrgRepositories(c *context.APIContext) {
  137. listUserRepositories(c, c.Params(":org"))
  138. }
  139. func CreateUserRepo(c *context.APIContext, owner *database.User, opt api.CreateRepoOption) {
  140. repo, err := database.CreateRepository(c.User, owner, database.CreateRepoOptionsLegacy{
  141. Name: opt.Name,
  142. Description: opt.Description,
  143. Gitignores: opt.Gitignores,
  144. License: opt.License,
  145. Readme: opt.Readme,
  146. IsPrivate: opt.Private,
  147. AutoInit: opt.AutoInit,
  148. })
  149. if err != nil {
  150. if database.IsErrRepoAlreadyExist(err) ||
  151. database.IsErrNameNotAllowed(err) {
  152. c.ErrorStatus(http.StatusUnprocessableEntity, err)
  153. } else {
  154. if repo != nil {
  155. if err = database.DeleteRepository(c.User.ID, repo.ID); err != nil {
  156. log.Error("Failed to delete repository: %v", err)
  157. }
  158. }
  159. c.Error(err, "create repository")
  160. }
  161. return
  162. }
  163. c.JSON(201, repo.APIFormatLegacy(&api.Permission{Admin: true, Push: true, Pull: true}))
  164. }
  165. func Create(c *context.APIContext, opt api.CreateRepoOption) {
  166. // Shouldn't reach this condition, but just in case.
  167. if c.User.IsOrganization() {
  168. c.ErrorStatus(http.StatusUnprocessableEntity, errors.New("Not allowed to create repository for organization."))
  169. return
  170. }
  171. CreateUserRepo(c, c.User, opt)
  172. }
  173. func CreateOrgRepo(c *context.APIContext, opt api.CreateRepoOption) {
  174. org, err := database.GetOrgByName(c.Params(":org"))
  175. if err != nil {
  176. c.NotFoundOrError(err, "get organization by name")
  177. return
  178. }
  179. if !org.IsOwnedBy(c.User.ID) {
  180. c.ErrorStatus(http.StatusForbidden, errors.New("Given user is not owner of organization."))
  181. return
  182. }
  183. CreateUserRepo(c, org, opt)
  184. }
  185. func Migrate(c *context.APIContext, f form.MigrateRepo) {
  186. ctxUser := c.User
  187. // Not equal means context user is an organization,
  188. // or is another user/organization if current user is admin.
  189. if f.UID != ctxUser.ID {
  190. org, err := database.Handle.Users().GetByID(c.Req.Context(), f.UID)
  191. if err != nil {
  192. if database.IsErrUserNotExist(err) {
  193. c.ErrorStatus(http.StatusUnprocessableEntity, err)
  194. } else {
  195. c.Error(err, "get user by ID")
  196. }
  197. return
  198. } else if !org.IsOrganization() && !c.User.IsAdmin {
  199. c.ErrorStatus(http.StatusForbidden, errors.New("Given user is not an organization."))
  200. return
  201. }
  202. ctxUser = org
  203. }
  204. if c.HasError() {
  205. c.ErrorStatus(http.StatusUnprocessableEntity, errors.New(c.GetErrMsg()))
  206. return
  207. }
  208. if ctxUser.IsOrganization() && !c.User.IsAdmin {
  209. // Check ownership of organization.
  210. if !ctxUser.IsOwnedBy(c.User.ID) {
  211. c.ErrorStatus(http.StatusForbidden, errors.New("Given user is not owner of organization."))
  212. return
  213. }
  214. }
  215. remoteAddr, err := f.ParseRemoteAddr(c.User)
  216. if err != nil {
  217. if database.IsErrInvalidCloneAddr(err) {
  218. addrErr := err.(database.ErrInvalidCloneAddr)
  219. switch {
  220. case addrErr.IsURLError:
  221. c.ErrorStatus(http.StatusUnprocessableEntity, err)
  222. case addrErr.IsPermissionDenied:
  223. c.ErrorStatus(http.StatusUnprocessableEntity, errors.New("You are not allowed to import local repositories."))
  224. case addrErr.IsInvalidPath:
  225. c.ErrorStatus(http.StatusUnprocessableEntity, errors.New("Invalid local path, it does not exist or not a directory."))
  226. case addrErr.IsBlockedLocalAddress:
  227. c.ErrorStatus(http.StatusUnprocessableEntity, errors.New("Clone address resolved to a local network address that is implicitly blocked."))
  228. default:
  229. c.Error(err, "unexpected error")
  230. }
  231. } else {
  232. c.Error(err, "parse remote address")
  233. }
  234. return
  235. }
  236. repo, err := database.MigrateRepository(c.User, ctxUser, database.MigrateRepoOptions{
  237. Name: f.RepoName,
  238. Description: f.Description,
  239. IsPrivate: f.Private || conf.Repository.ForcePrivate,
  240. IsMirror: f.Mirror,
  241. RemoteAddr: remoteAddr,
  242. })
  243. if err != nil {
  244. if repo != nil {
  245. if errDelete := database.DeleteRepository(ctxUser.ID, repo.ID); errDelete != nil {
  246. log.Error("DeleteRepository: %v", errDelete)
  247. }
  248. }
  249. if database.IsErrReachLimitOfRepo(err) {
  250. c.ErrorStatus(http.StatusUnprocessableEntity, err)
  251. } else {
  252. c.Error(errors.New(database.HandleMirrorCredentials(err.Error(), true)), "migrate repository")
  253. }
  254. return
  255. }
  256. log.Trace("Repository migrated: %s/%s", ctxUser.Name, f.RepoName)
  257. c.JSON(201, repo.APIFormatLegacy(&api.Permission{Admin: true, Push: true, Pull: true}))
  258. }
  259. // FIXME: inject in the handler chain
  260. func parseOwnerAndRepo(c *context.APIContext) (*database.User, *database.Repository) {
  261. owner, err := database.Handle.Users().GetByUsername(c.Req.Context(), c.Params(":username"))
  262. if err != nil {
  263. if database.IsErrUserNotExist(err) {
  264. c.ErrorStatus(http.StatusUnprocessableEntity, err)
  265. } else {
  266. c.Error(err, "get user by name")
  267. }
  268. return nil, nil
  269. }
  270. repo, err := database.GetRepositoryByName(owner.ID, c.Params(":reponame"))
  271. if err != nil {
  272. c.NotFoundOrError(err, "get repository by name")
  273. return nil, nil
  274. }
  275. return owner, repo
  276. }
  277. func Get(c *context.APIContext) {
  278. _, repo := parseOwnerAndRepo(c)
  279. if c.Written() {
  280. return
  281. }
  282. c.JSONSuccess(repo.APIFormatLegacy(&api.Permission{
  283. Admin: c.Repo.IsAdmin(),
  284. Push: c.Repo.IsWriter(),
  285. Pull: true,
  286. }))
  287. }
  288. func Delete(c *context.APIContext) {
  289. owner, repo := parseOwnerAndRepo(c)
  290. if c.Written() {
  291. return
  292. }
  293. if owner.IsOrganization() && !owner.IsOwnedBy(c.User.ID) {
  294. c.ErrorStatus(http.StatusForbidden, errors.New("Given user is not owner of organization."))
  295. return
  296. }
  297. if err := database.DeleteRepository(owner.ID, repo.ID); err != nil {
  298. c.Error(err, "delete repository")
  299. return
  300. }
  301. log.Trace("Repository deleted: %s/%s", owner.Name, repo.Name)
  302. c.NoContent()
  303. }
  304. func ListForks(c *context.APIContext) {
  305. forks, err := c.Repo.Repository.GetForks()
  306. if err != nil {
  307. c.Error(err, "get forks")
  308. return
  309. }
  310. apiForks := make([]*api.Repository, len(forks))
  311. for i := range forks {
  312. if err := forks[i].GetOwner(); err != nil {
  313. c.Error(err, "get owner")
  314. return
  315. }
  316. accessMode := database.Handle.Permissions().AccessMode(
  317. c.Req.Context(),
  318. c.User.ID,
  319. forks[i].ID,
  320. database.AccessModeOptions{
  321. OwnerID: forks[i].OwnerID,
  322. Private: forks[i].IsPrivate,
  323. },
  324. )
  325. apiForks[i] = forks[i].APIFormatLegacy(
  326. &api.Permission{
  327. Admin: accessMode >= database.AccessModeAdmin,
  328. Push: accessMode >= database.AccessModeWrite,
  329. Pull: true,
  330. },
  331. )
  332. }
  333. c.JSONSuccess(&apiForks)
  334. }
  335. func IssueTracker(c *context.APIContext, form api.EditIssueTrackerOption) {
  336. _, repo := parseOwnerAndRepo(c)
  337. if c.Written() {
  338. return
  339. }
  340. if form.EnableIssues != nil {
  341. repo.EnableIssues = *form.EnableIssues
  342. }
  343. if form.EnableExternalTracker != nil {
  344. repo.EnableExternalTracker = *form.EnableExternalTracker
  345. }
  346. if form.ExternalTrackerURL != nil {
  347. repo.ExternalTrackerURL = *form.ExternalTrackerURL
  348. }
  349. if form.TrackerURLFormat != nil {
  350. repo.ExternalTrackerFormat = *form.TrackerURLFormat
  351. }
  352. if form.TrackerIssueStyle != nil {
  353. repo.ExternalTrackerStyle = *form.TrackerIssueStyle
  354. }
  355. if err := database.UpdateRepository(repo, false); err != nil {
  356. c.Error(err, "update repository")
  357. return
  358. }
  359. c.NoContent()
  360. }
  361. func Wiki(c *context.APIContext, form api.EditWikiOption) {
  362. _, repo := parseOwnerAndRepo(c)
  363. if c.Written() {
  364. return
  365. }
  366. if form.AllowPublicWiki != nil {
  367. repo.AllowPublicWiki = *form.AllowPublicWiki
  368. }
  369. if form.EnableExternalWiki != nil {
  370. repo.EnableExternalWiki = *form.EnableExternalWiki
  371. }
  372. if form.EnableWiki != nil {
  373. repo.EnableWiki = *form.EnableWiki
  374. }
  375. if form.ExternalWikiURL != nil {
  376. repo.ExternalWikiURL = *form.ExternalWikiURL
  377. }
  378. if err := database.UpdateRepository(repo, false); err != nil {
  379. c.Error(err, "update repository")
  380. return
  381. }
  382. c.NoContent()
  383. }
  384. func MirrorSync(c *context.APIContext) {
  385. _, repo := parseOwnerAndRepo(c)
  386. if c.Written() {
  387. return
  388. } else if !repo.IsMirror {
  389. c.NotFound()
  390. return
  391. }
  392. go database.MirrorQueue.Add(repo.ID)
  393. c.Status(http.StatusAccepted)
  394. }
  395. func Releases(c *context.APIContext) {
  396. _, repo := parseOwnerAndRepo(c)
  397. releases, err := database.GetReleasesByRepoID(repo.ID)
  398. if err != nil {
  399. c.Error(err, "get releases by repository ID")
  400. return
  401. }
  402. apiReleases := make([]*api.Release, 0, len(releases))
  403. for _, r := range releases {
  404. publisher, err := database.Handle.Users().GetByID(c.Req.Context(), r.PublisherID)
  405. if err != nil {
  406. c.Error(err, "get release publisher")
  407. return
  408. }
  409. r.Publisher = publisher
  410. }
  411. for _, r := range releases {
  412. apiReleases = append(apiReleases, r.APIFormat())
  413. }
  414. c.JSONSuccess(&apiReleases)
  415. }