repo_repo.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497
  1. package v1
  2. import (
  3. "net/http"
  4. "path"
  5. "github.com/cockroachdb/errors"
  6. log "unknwon.dev/clog/v2"
  7. "gogs.io/gogs/internal/conf"
  8. "gogs.io/gogs/internal/context"
  9. "gogs.io/gogs/internal/database"
  10. "gogs.io/gogs/internal/form"
  11. "gogs.io/gogs/internal/route/api/v1/types"
  12. )
  13. func searchRepos(c *context.APIContext) {
  14. opts := &database.SearchRepoOptions{
  15. Keyword: path.Base(c.Query("q")),
  16. OwnerID: c.QueryInt64("uid"),
  17. PageSize: toAllowedPageSize(c.QueryInt("limit")),
  18. Page: c.QueryInt("page"),
  19. }
  20. // Check visibility.
  21. if c.IsLogged && opts.OwnerID > 0 {
  22. if c.User.ID == opts.OwnerID {
  23. opts.Private = true
  24. } else {
  25. u, err := database.Handle.Users().GetByID(c.Req.Context(), opts.OwnerID)
  26. if err != nil {
  27. c.JSON(http.StatusInternalServerError, map[string]any{
  28. "ok": false,
  29. "error": err.Error(),
  30. })
  31. return
  32. }
  33. if u.IsOrganization() && u.IsOwnedBy(c.User.ID) {
  34. opts.Private = true
  35. }
  36. // FIXME: how about collaborators?
  37. }
  38. }
  39. repos, count, err := database.SearchRepositoryByName(opts)
  40. if err != nil {
  41. c.JSON(http.StatusInternalServerError, map[string]any{
  42. "ok": false,
  43. "error": err.Error(),
  44. })
  45. return
  46. }
  47. if err = database.RepositoryList(repos).LoadAttributes(); err != nil {
  48. c.JSON(http.StatusInternalServerError, map[string]any{
  49. "ok": false,
  50. "error": err.Error(),
  51. })
  52. return
  53. }
  54. results := make([]*types.Repository, len(repos))
  55. for i := range repos {
  56. results[i] = toRepository(repos[i], nil)
  57. }
  58. c.SetLinkHeader(int(count), opts.PageSize)
  59. c.JSONSuccess(map[string]any{
  60. "ok": true,
  61. "data": results,
  62. })
  63. }
  64. func listReposOfUser(c *context.APIContext, username string) {
  65. user, err := database.Handle.Users().GetByUsername(c.Req.Context(), username)
  66. if err != nil {
  67. c.NotFoundOrError(err, "get user by name")
  68. return
  69. }
  70. // Only list public repositories if user requests someone else's repository list,
  71. // or an organization isn't a member of.
  72. var ownRepos []*database.Repository
  73. if user.IsOrganization() {
  74. ownRepos, _, err = user.GetUserRepositories(c.User.ID, 1, user.NumRepos)
  75. } else {
  76. ownRepos, err = database.GetUserRepositories(&database.UserRepoOptions{
  77. UserID: user.ID,
  78. Private: c.User.ID == user.ID,
  79. Page: 1,
  80. PageSize: user.NumRepos,
  81. })
  82. }
  83. if err != nil {
  84. c.Error(err, "get user repositories")
  85. return
  86. }
  87. if err = database.RepositoryList(ownRepos).LoadAttributes(); err != nil {
  88. c.Error(err, "load attributes")
  89. return
  90. }
  91. // Early return for querying other user's repositories
  92. if c.User.ID != user.ID {
  93. repos := make([]*types.Repository, len(ownRepos))
  94. for i := range ownRepos {
  95. repos[i] = toRepository(ownRepos[i], &types.RepositoryPermission{Admin: true, Push: true, Pull: true})
  96. }
  97. c.JSONSuccess(&repos)
  98. return
  99. }
  100. accessibleReposWithAccessMode, err := database.Handle.Repositories().GetByCollaboratorIDWithAccessMode(c.Req.Context(), user.ID)
  101. if err != nil {
  102. c.Error(err, "get repositories accesses by collaborator")
  103. return
  104. }
  105. accessibleRepos := make([]*database.Repository, 0, len(accessibleReposWithAccessMode))
  106. for repo := range accessibleReposWithAccessMode {
  107. accessibleRepos = append(accessibleRepos, repo)
  108. }
  109. if err = database.RepositoryList(accessibleRepos).LoadAttributes(); err != nil {
  110. c.Error(err, "load attributes for accessible repositories")
  111. return
  112. }
  113. numOwnRepos := len(ownRepos)
  114. repos := make([]*types.Repository, 0, numOwnRepos+len(accessibleReposWithAccessMode))
  115. for _, r := range ownRepos {
  116. repos = append(repos, toRepository(r, &types.RepositoryPermission{Admin: true, Push: true, Pull: true}))
  117. }
  118. for repo, access := range accessibleReposWithAccessMode {
  119. repos = append(repos,
  120. toRepository(repo, &types.RepositoryPermission{
  121. Admin: access >= database.AccessModeAdmin,
  122. Push: access >= database.AccessModeWrite,
  123. Pull: true,
  124. }),
  125. )
  126. }
  127. c.JSONSuccess(&repos)
  128. }
  129. func listMyRepos(c *context.APIContext) {
  130. listReposOfUser(c, c.User.Name)
  131. }
  132. func listUserRepositories(c *context.APIContext) {
  133. listReposOfUser(c, c.Params(":username"))
  134. }
  135. func listOrgRepositories(c *context.APIContext) {
  136. listReposOfUser(c, c.Params(":org"))
  137. }
  138. type createRepoRequest struct {
  139. Name string `json:"name" binding:"Required;AlphaDashDot;MaxSize(100)"`
  140. Description string `json:"description" binding:"MaxSize(255)"`
  141. Private bool `json:"private"`
  142. AutoInit bool `json:"auto_init"`
  143. Gitignores string `json:"gitignores"`
  144. License string `json:"license"`
  145. Readme string `json:"readme"`
  146. }
  147. func createUserRepo(c *context.APIContext, owner *database.User, opt createRepoRequest) {
  148. repo, err := database.CreateRepository(c.User, owner, database.CreateRepoOptionsLegacy{
  149. Name: opt.Name,
  150. Description: opt.Description,
  151. Gitignores: opt.Gitignores,
  152. License: opt.License,
  153. Readme: opt.Readme,
  154. IsPrivate: opt.Private,
  155. AutoInit: opt.AutoInit,
  156. })
  157. if err != nil {
  158. if database.IsErrRepoAlreadyExist(err) ||
  159. database.IsErrNameNotAllowed(err) {
  160. c.ErrorStatus(http.StatusUnprocessableEntity, err)
  161. } else {
  162. if repo != nil {
  163. if err = database.DeleteRepository(c.User.ID, repo.ID); err != nil {
  164. log.Error("Failed to delete repository: %v", err)
  165. }
  166. }
  167. c.Error(err, "create repository")
  168. }
  169. return
  170. }
  171. c.JSON(201, toRepository(repo, &types.RepositoryPermission{Admin: true, Push: true, Pull: true}))
  172. }
  173. func createRepo(c *context.APIContext, opt createRepoRequest) {
  174. // Shouldn't reach this condition, but just in case.
  175. if c.User.IsOrganization() {
  176. c.ErrorStatus(http.StatusUnprocessableEntity, errors.New("Not allowed to create repository for organization."))
  177. return
  178. }
  179. createUserRepo(c, c.User, opt)
  180. }
  181. func createOrgRepo(c *context.APIContext, opt createRepoRequest) {
  182. org, err := database.GetOrgByName(c.Params(":org"))
  183. if err != nil {
  184. c.NotFoundOrError(err, "get organization by name")
  185. return
  186. }
  187. if !org.IsOwnedBy(c.User.ID) {
  188. c.ErrorStatus(http.StatusForbidden, errors.New("Given user is not owner of organization."))
  189. return
  190. }
  191. createUserRepo(c, org, opt)
  192. }
  193. func migrate(c *context.APIContext, f form.MigrateRepo) {
  194. ctxUser := c.User
  195. // Not equal means context user is an organization,
  196. // or is another user/organization if current user is admin.
  197. if f.UID != ctxUser.ID {
  198. org, err := database.Handle.Users().GetByID(c.Req.Context(), f.UID)
  199. if err != nil {
  200. if database.IsErrUserNotExist(err) {
  201. c.ErrorStatus(http.StatusUnprocessableEntity, err)
  202. } else {
  203. c.Error(err, "get user by ID")
  204. }
  205. return
  206. } else if !org.IsOrganization() && !c.User.IsAdmin {
  207. c.ErrorStatus(http.StatusForbidden, errors.New("Given user is not an organization."))
  208. return
  209. }
  210. ctxUser = org
  211. }
  212. if c.HasError() {
  213. c.ErrorStatus(http.StatusUnprocessableEntity, errors.New(c.GetErrMsg()))
  214. return
  215. }
  216. if ctxUser.IsOrganization() && !c.User.IsAdmin {
  217. // Check ownership of organization.
  218. if !ctxUser.IsOwnedBy(c.User.ID) {
  219. c.ErrorStatus(http.StatusForbidden, errors.New("Given user is not owner of organization."))
  220. return
  221. }
  222. }
  223. remoteAddr, err := f.ParseRemoteAddr(c.User)
  224. if err != nil {
  225. if database.IsErrInvalidCloneAddr(err) {
  226. addrErr := err.(database.ErrInvalidCloneAddr)
  227. switch {
  228. case addrErr.IsURLError:
  229. c.ErrorStatus(http.StatusUnprocessableEntity, err)
  230. case addrErr.IsPermissionDenied:
  231. c.ErrorStatus(http.StatusUnprocessableEntity, errors.New("You are not allowed to import local repositories."))
  232. case addrErr.IsInvalidPath:
  233. c.ErrorStatus(http.StatusUnprocessableEntity, errors.New("Invalid local path, it does not exist or not a directory."))
  234. case addrErr.IsBlockedLocalAddress:
  235. c.ErrorStatus(http.StatusUnprocessableEntity, errors.New("Clone address resolved to a local network address that is implicitly blocked."))
  236. default:
  237. c.Error(err, "unexpected error")
  238. }
  239. } else {
  240. c.Error(err, "parse remote address")
  241. }
  242. return
  243. }
  244. repo, err := database.MigrateRepository(c.User, ctxUser, database.MigrateRepoOptions{
  245. Name: f.RepoName,
  246. Description: f.Description,
  247. IsPrivate: f.Private || conf.Repository.ForcePrivate,
  248. IsMirror: f.Mirror,
  249. RemoteAddr: remoteAddr,
  250. })
  251. if err != nil {
  252. if repo != nil {
  253. if errDelete := database.DeleteRepository(ctxUser.ID, repo.ID); errDelete != nil {
  254. log.Error("DeleteRepository: %v", errDelete)
  255. }
  256. }
  257. if database.IsErrReachLimitOfRepo(err) {
  258. c.ErrorStatus(http.StatusUnprocessableEntity, err)
  259. } else {
  260. c.Error(errors.New(database.HandleMirrorCredentials(err.Error(), true)), "migrate repository")
  261. }
  262. return
  263. }
  264. log.Trace("Repository migrated: %s/%s", ctxUser.Name, f.RepoName)
  265. c.JSON(201, toRepository(repo, &types.RepositoryPermission{Admin: true, Push: true, Pull: true}))
  266. }
  267. // FIXME: inject in the handler chain
  268. func parseOwnerAndRepo(c *context.APIContext) (*database.User, *database.Repository) {
  269. owner, err := database.Handle.Users().GetByUsername(c.Req.Context(), c.Params(":username"))
  270. if err != nil {
  271. if database.IsErrUserNotExist(err) {
  272. c.ErrorStatus(http.StatusUnprocessableEntity, err)
  273. } else {
  274. c.Error(err, "get user by name")
  275. }
  276. return nil, nil
  277. }
  278. repo, err := database.GetRepositoryByName(owner.ID, c.Params(":reponame"))
  279. if err != nil {
  280. c.NotFoundOrError(err, "get repository by name")
  281. return nil, nil
  282. }
  283. return owner, repo
  284. }
  285. func getRepo(c *context.APIContext) {
  286. _, repo := parseOwnerAndRepo(c)
  287. if c.Written() {
  288. return
  289. }
  290. c.JSONSuccess(toRepository(repo, &types.RepositoryPermission{
  291. Admin: c.Repo.IsAdmin(),
  292. Push: c.Repo.IsWriter(),
  293. Pull: true,
  294. }))
  295. }
  296. func deleteRepo(c *context.APIContext) {
  297. owner, repo := parseOwnerAndRepo(c)
  298. if c.Written() {
  299. return
  300. }
  301. if owner.IsOrganization() && !owner.IsOwnedBy(c.User.ID) {
  302. c.ErrorStatus(http.StatusForbidden, errors.New("Given user is not owner of organization."))
  303. return
  304. }
  305. if err := database.DeleteRepository(owner.ID, repo.ID); err != nil {
  306. c.Error(err, "delete repository")
  307. return
  308. }
  309. log.Trace("Repository deleted: %s/%s", owner.Name, repo.Name)
  310. c.NoContent()
  311. }
  312. func listForks(c *context.APIContext) {
  313. forks, err := c.Repo.Repository.GetForks()
  314. if err != nil {
  315. c.Error(err, "get forks")
  316. return
  317. }
  318. apiForks := make([]*types.Repository, len(forks))
  319. for i := range forks {
  320. if err := forks[i].GetOwner(); err != nil {
  321. c.Error(err, "get owner")
  322. return
  323. }
  324. accessMode := database.Handle.Permissions().AccessMode(
  325. c.Req.Context(),
  326. c.User.ID,
  327. forks[i].ID,
  328. database.AccessModeOptions{
  329. OwnerID: forks[i].OwnerID,
  330. Private: forks[i].IsPrivate,
  331. },
  332. )
  333. apiForks[i] = toRepository(forks[i],
  334. &types.RepositoryPermission{
  335. Admin: accessMode >= database.AccessModeAdmin,
  336. Push: accessMode >= database.AccessModeWrite,
  337. Pull: true,
  338. },
  339. )
  340. }
  341. c.JSONSuccess(&apiForks)
  342. }
  343. type editIssueTrackerRequest struct {
  344. EnableIssues *bool `json:"enable_issues"`
  345. EnableExternalTracker *bool `json:"enable_external_tracker"`
  346. ExternalTrackerURL *string `json:"external_tracker_url"`
  347. TrackerURLFormat *string `json:"tracker_url_format"`
  348. TrackerIssueStyle *string `json:"tracker_issue_style"`
  349. }
  350. func issueTracker(c *context.APIContext, form editIssueTrackerRequest) {
  351. _, repo := parseOwnerAndRepo(c)
  352. if c.Written() {
  353. return
  354. }
  355. if form.EnableIssues != nil {
  356. repo.EnableIssues = *form.EnableIssues
  357. }
  358. if form.EnableExternalTracker != nil {
  359. repo.EnableExternalTracker = *form.EnableExternalTracker
  360. }
  361. if form.ExternalTrackerURL != nil {
  362. repo.ExternalTrackerURL = *form.ExternalTrackerURL
  363. }
  364. if form.TrackerURLFormat != nil {
  365. repo.ExternalTrackerFormat = *form.TrackerURLFormat
  366. }
  367. if form.TrackerIssueStyle != nil {
  368. repo.ExternalTrackerStyle = *form.TrackerIssueStyle
  369. }
  370. if err := database.UpdateRepository(repo, false); err != nil {
  371. c.Error(err, "update repository")
  372. return
  373. }
  374. c.NoContent()
  375. }
  376. type editWikiRequest struct {
  377. EnableWiki *bool `json:"enable_wiki"`
  378. AllowPublicWiki *bool `json:"allow_public_wiki"`
  379. EnableExternalWiki *bool `json:"enable_external_wiki"`
  380. ExternalWikiURL *string `json:"external_wiki_url"`
  381. }
  382. func wiki(c *context.APIContext, form editWikiRequest) {
  383. _, repo := parseOwnerAndRepo(c)
  384. if c.Written() {
  385. return
  386. }
  387. if form.AllowPublicWiki != nil {
  388. repo.AllowPublicWiki = *form.AllowPublicWiki
  389. }
  390. if form.EnableExternalWiki != nil {
  391. repo.EnableExternalWiki = *form.EnableExternalWiki
  392. }
  393. if form.EnableWiki != nil {
  394. repo.EnableWiki = *form.EnableWiki
  395. }
  396. if form.ExternalWikiURL != nil {
  397. repo.ExternalWikiURL = *form.ExternalWikiURL
  398. }
  399. if err := database.UpdateRepository(repo, false); err != nil {
  400. c.Error(err, "update repository")
  401. return
  402. }
  403. c.NoContent()
  404. }
  405. func mirrorSync(c *context.APIContext) {
  406. _, repo := parseOwnerAndRepo(c)
  407. if c.Written() {
  408. return
  409. } else if !repo.IsMirror {
  410. c.NotFound()
  411. return
  412. }
  413. go database.MirrorQueue.Add(repo.ID)
  414. c.Status(http.StatusAccepted)
  415. }
  416. func releases(c *context.APIContext) {
  417. _, repo := parseOwnerAndRepo(c)
  418. releases, err := database.GetReleasesByRepoID(repo.ID)
  419. if err != nil {
  420. c.Error(err, "get releases by repository ID")
  421. return
  422. }
  423. apiReleases := make([]*types.RepositoryRelease, 0, len(releases))
  424. for _, r := range releases {
  425. publisher, err := database.Handle.Users().GetByID(c.Req.Context(), r.PublisherID)
  426. if err != nil {
  427. c.Error(err, "get release publisher")
  428. return
  429. }
  430. r.Publisher = publisher
  431. }
  432. for _, r := range releases {
  433. apiReleases = append(apiReleases, toRelease(r))
  434. }
  435. c.JSONSuccess(&apiReleases)
  436. }