292 lines
No EOL
9.1 KiB
Python
292 lines
No EOL
9.1 KiB
Python
from flask import Flask, request, make_response, render_template
|
|
from flask_basicauth import BasicAuth
|
|
from dotenv import load_dotenv
|
|
from flask_sock import Sock
|
|
from glob import glob
|
|
import database
|
|
import json
|
|
import os
|
|
|
|
load_dotenv()
|
|
app = Flask(__name__)
|
|
sock = Sock(app)
|
|
basic_auth = BasicAuth(app)
|
|
|
|
app.config['BASIC_AUTH_USERNAME'] = os.getenv("AUTH_USERNAME")
|
|
app.config['BASIC_AUTH_PASSWORD'] = os.getenv("AUTH_PASSWORD")
|
|
|
|
def make_resp(data=''):
|
|
response = make_response(data)
|
|
|
|
response.status_code = 200
|
|
response.headers['access-control-allow-origin'] = 'app://obsidian.md'
|
|
response.headers['access-control-allow-headers'] = 'content-type'
|
|
|
|
return response
|
|
|
|
index = json.load(open("index.json", "r", encoding="utf-8"))
|
|
|
|
os.makedirs("data", exist_ok=True)
|
|
|
|
def save_index():
|
|
with open("index.json", "w+") as f:
|
|
json.dump(index, f, indent=4)
|
|
|
|
@sock.route("/")
|
|
def websocket(ws):
|
|
vault_id = None
|
|
device_name = "unknown"
|
|
while True:
|
|
raw = ws.receive()
|
|
data = json.loads(raw)
|
|
|
|
operation = data.get("op")
|
|
|
|
if operation == "init":
|
|
ws.send(json.dumps({"res": "ok", "perFileMax": 2147483647, "userId": 1}))
|
|
ws.send(json.dumps({"op": "ready", "version": 11}))
|
|
|
|
vault_id = data.get("id")
|
|
|
|
hisVault = False
|
|
for vault in database.list_vaults(data.get("token"))['vaults']:
|
|
if vault['id'] == vault_id:
|
|
hisVault = True
|
|
|
|
if not hisVault:
|
|
ws.close()
|
|
|
|
device_name = data.get("device", "unknown")
|
|
for path, data in index["files"].items():
|
|
filesize = os.path.getsize(f"data/{path}")
|
|
ws.send(json.dumps({
|
|
"op": "push",
|
|
"path": path,
|
|
"hash": data['hash'],
|
|
"size": filesize,
|
|
"ctime": data["ctime"],
|
|
"mtime": data["mtime"],
|
|
"folder": False,
|
|
"device": device_name,
|
|
"uid": index["id"].index(path)
|
|
}))
|
|
|
|
for path, data in index["folders"].items():
|
|
ws.send(json.dumps({
|
|
"op": "push",
|
|
"path": path,
|
|
"hash": data['hash'],
|
|
"size": 0,
|
|
"ctime": 0,
|
|
"mtime": 0,
|
|
"folder": True,
|
|
"device": device_name,
|
|
"uid": index["id"].index(path)
|
|
}))
|
|
|
|
if operation == "pull":
|
|
uid = data['uid']
|
|
path = index["id"][uid]
|
|
ws.send(json.dumps({
|
|
"hash": index["files"][path]['hash'],
|
|
"size": os.path.getsize(f"data/{path}"),
|
|
"pieces": 1
|
|
}))
|
|
ws.send(open(f'data/{path}', "rb").read())
|
|
|
|
if operation == "ping":
|
|
ws.send(json.dumps({"op":"pong"}))
|
|
|
|
if operation == "size":
|
|
size = 0
|
|
for file in glob("data/*"):
|
|
size += os.path.getsize(file)
|
|
ws.send(json.dumps({"res":"ok","size":size,"vault_size":0,"limit":1099511627776})) # 1To
|
|
|
|
if operation == "deleted":
|
|
return {"items":[]}
|
|
|
|
if operation == "push":
|
|
path = data.get("path")
|
|
hash = data.get("hash")
|
|
|
|
if data.get("deleted", False):
|
|
index["id"].remove(path)
|
|
del index["files"][path]
|
|
|
|
index["id"].append(path)
|
|
if data.get("folder", False):
|
|
index["folders"][path] = {"hash": hash}
|
|
save_index()
|
|
continue
|
|
else:
|
|
index["files"][path] = {
|
|
"hash": hash,
|
|
"ctime": data.get("ctime"),
|
|
"mtime": data.get("mtime"),
|
|
"device": device_name
|
|
}
|
|
save_index()
|
|
|
|
if data.get("pieces") == 1:
|
|
# Client will give us file content
|
|
ws.send(json.dumps({"res":"next"}))
|
|
file = ws.receive()
|
|
with open(f"data/{path}", "wb+") as f:
|
|
f.write(file)
|
|
|
|
ws.send(raw)
|
|
ws.send(json.dumps({"op":"ok"}))
|
|
|
|
if operation == "usernames": # TODO
|
|
ws.send(json.dumps({"1": "Mathias"}))
|
|
|
|
@app.route("/admin")
|
|
@basic_auth.required
|
|
def admin_panel():
|
|
users = database.db.execute_query("SELECT name, email FROM users;")
|
|
vaults = database.db.execute_query("SELECT name, (SELECT name FROM users WHERE uid=owner) FROM vaults;")
|
|
return render_template("admin.html", users=users, vaults=vaults)
|
|
|
|
@app.route("/")
|
|
def index_page():
|
|
return render_template("index.html")
|
|
|
|
@app.route("/user/info", methods=["POST", "OPTIONS"])
|
|
def user_info():
|
|
if request.method == "OPTIONS": return make_resp()
|
|
data = request.json
|
|
|
|
return make_resp(database.get_userinfo(data.get("token")))
|
|
|
|
@app.route("/user/signout", methods=["POST", "OPTIONS"])
|
|
def user_signout():
|
|
if request.method == "OPTIONS": return make_resp()
|
|
return make_resp({})
|
|
|
|
@app.route("/user/signin", methods=["POST", "OPTIONS"])
|
|
def user_signin():
|
|
if request.method == "OPTIONS": return make_resp()
|
|
data = request.json
|
|
|
|
return make_resp(
|
|
database.login(data["email"], data["password"])
|
|
)
|
|
|
|
@app.route("/vault/list", methods=["POST", "OPTIONS"])
|
|
def vault_list():
|
|
if request.method == "OPTIONS": return make_resp()
|
|
data = request.json
|
|
|
|
return make_resp(database.list_vaults(data.get("token")))
|
|
|
|
@app.route("/vault/regions", methods=["POST", "OPTIONS"])
|
|
def vault_regions():
|
|
if request.method == "OPTIONS": return make_resp()
|
|
|
|
return make_resp({
|
|
"regions": [
|
|
{
|
|
"name": "Home",
|
|
"value": "home"
|
|
}
|
|
]
|
|
})
|
|
|
|
@app.route("/vault/create", methods=["POST", "OPTIONS"])
|
|
def vault_create():
|
|
if request.method == "OPTIONS": return make_resp()
|
|
data = request.json
|
|
|
|
if data.get("encryption_version") != 0:
|
|
return {"error": "End2End encryption not supported"}
|
|
|
|
return make_resp(database.create_vault(data.get("name", "my awesome vault"), data.get("token")))
|
|
|
|
@app.route("/subscription/business", methods=["POST", "OPTIONS"])
|
|
def subscription_business():
|
|
if request.method == "OPTIONS": return make_resp()
|
|
return {}
|
|
|
|
@app.route("/subscription/list", methods=["POST", "OPTIONS"])
|
|
def subscription_list():
|
|
if request.method == "OPTIONS": return make_resp()
|
|
return make_resp({"business":None,"publish":None,"sync":{"earlybird":False,"expiry_ts":1747156338125,"plan":"basic_1","renew":""},"syncPlans":[{"code":"basic_1","display":"Standard 1 GB","monthly":500,"perFileMax":6291456,"revisionHistoryDays":31,"storage":1073741824,"vaults":1,"yearly":4800},{"code":"standard_10","display":"Plus 10 GB","monthly":1000,"perFileMax":209715200,"revisionHistoryDays":365,"storage":10737418240,"vaults":10,"yearly":9600},{"code":"standard_100","display":"Plus 100 GB","monthly":2000,"perFileMax":209715200,"revisionHistoryDays":365,"storage":107374182400,"vaults":10,"yearly":19200}]})
|
|
|
|
@app.route("/vault/access", methods=["POST", "OPTIONS"])
|
|
def vault_access():
|
|
if request.method == "OPTIONS": return make_resp()
|
|
data = request.json
|
|
|
|
userinfo = database.get_userinfo(data.get("token"))
|
|
|
|
return make_resp({
|
|
"allowed": True,
|
|
"email": userinfo['email'],
|
|
"encryption_version": 0,
|
|
"name": userinfo['name'],
|
|
"useruid": userinfo['uid']
|
|
})
|
|
|
|
@app.route("/vault/delete", methods=["POST", "OPTIONS"])
|
|
def vault_delete():
|
|
if request.method == "OPTIONS": return make_resp()
|
|
data = request.json
|
|
|
|
return make_resp(database.delete_database(data.get("vault_uid"), data.get("token")))
|
|
|
|
@app.route("/vault/rename", methods=["POST", "OPTIONS"])
|
|
def vault_rename():
|
|
if request.method == "OPTIONS": return make_resp()
|
|
data = request.json
|
|
return make_resp(database.rename_vault(data.get("name"), data.get("vault_uid"), data.get("token")))
|
|
|
|
@app.route("/vault/share/list", methods=["POST", "OPTIONS"])
|
|
def vault_share_list():
|
|
if request.method == "OPTIONS": return make_resp()
|
|
return make_resp(json.dumps({"shares":[]}))
|
|
"""
|
|
POST:{
|
|
"vault_uid": "",
|
|
+token
|
|
}
|
|
RESPONSE:{
|
|
"shares": [
|
|
{
|
|
"accepted": false,
|
|
"code": "",
|
|
"email": "",
|
|
"uid": ""
|
|
}
|
|
]
|
|
}
|
|
"""
|
|
|
|
@app.route("/vault/share/invite", methods=["POST", "OPTIONS"])
|
|
def vault_share_invite():
|
|
if request.method == "OPTIONS": return make_resp()
|
|
return make_resp(json.dumps({}))
|
|
"""
|
|
POST:{
|
|
"email": "",
|
|
"vault_uid": "",
|
|
+token
|
|
}
|
|
RESPONSE:{}
|
|
"""
|
|
|
|
@app.route("/vault/share/remove", methods=["POST", "OPTIONS"])
|
|
def vault_share_remove():
|
|
"""
|
|
POST:{
|
|
"share_uid": "",
|
|
"vault_uid": ""
|
|
+token
|
|
}
|
|
RESPONSE:{}
|
|
"""
|
|
|
|
sock.init_app(app)
|
|
|
|
if __name__ == "__main__":
|
|
app.run(host=os.getenv("HOST"), port=os.getenv("PORT")) |