2018-09-24 19:14:15 +00:00
|
|
|
package api
|
2018-09-24 09:27:46 +00:00
|
|
|
|
|
|
|
import (
|
2018-10-31 06:14:33 +00:00
|
|
|
"net/http"
|
|
|
|
|
2018-09-24 09:27:46 +00:00
|
|
|
"github.com/gin-gonic/gin"
|
|
|
|
"github.com/gin-gonic/gin/binding"
|
2022-03-30 18:36:25 +00:00
|
|
|
|
2020-07-04 10:54:35 +00:00
|
|
|
"github.com/photoprism/photoprism/internal/acl"
|
2022-09-28 07:01:17 +00:00
|
|
|
"github.com/photoprism/photoprism/internal/entity"
|
|
|
|
"github.com/photoprism/photoprism/internal/event"
|
2019-12-05 18:21:35 +00:00
|
|
|
"github.com/photoprism/photoprism/internal/form"
|
2022-10-15 19:54:11 +00:00
|
|
|
"github.com/photoprism/photoprism/internal/get"
|
2022-03-30 18:36:25 +00:00
|
|
|
"github.com/photoprism/photoprism/internal/i18n"
|
2021-09-18 13:32:39 +00:00
|
|
|
"github.com/photoprism/photoprism/internal/search"
|
2018-09-24 09:27:46 +00:00
|
|
|
)
|
|
|
|
|
2021-09-18 13:32:39 +00:00
|
|
|
// SearchPhotos searches the pictures index and returns the result as JSON.
|
2022-09-29 22:42:19 +00:00
|
|
|
// See form.SearchPhotos for supported search params and data types.
|
2021-08-29 14:16:49 +00:00
|
|
|
//
|
2018-11-06 09:43:59 +00:00
|
|
|
// GET /api/v1/photos
|
2021-09-18 13:32:39 +00:00
|
|
|
func SearchPhotos(router *gin.RouterGroup) {
|
2022-03-30 18:36:25 +00:00
|
|
|
// searchPhotos checking authorization and parses the search request.
|
2022-09-28 07:01:17 +00:00
|
|
|
searchForm := func(c *gin.Context) (f form.SearchPhotos, s *entity.Session, err error) {
|
|
|
|
s = AuthAny(c, acl.ResourcePhotos, acl.Permissions{acl.ActionSearch, acl.ActionView, acl.AccessShared})
|
2020-06-25 12:54:04 +00:00
|
|
|
|
2022-09-28 07:01:17 +00:00
|
|
|
// Abort if permission was not granted.
|
|
|
|
if s.Abort(c) {
|
|
|
|
return f, s, i18n.Error(i18n.ErrForbidden)
|
2020-01-22 12:43:07 +00:00
|
|
|
}
|
|
|
|
|
2022-09-28 07:01:17 +00:00
|
|
|
// Abort if request params are invalid.
|
|
|
|
if err = c.MustBindWith(&f, binding.Form); err != nil {
|
2022-09-29 22:42:19 +00:00
|
|
|
event.AuditWarn([]string{ClientIP(c), "session %s", string(acl.ResourcePhotos), "form invalid", "%s"}, s.RefID, err)
|
2020-07-04 10:54:35 +00:00
|
|
|
AbortBadRequest(c)
|
2022-09-28 07:01:17 +00:00
|
|
|
return f, s, err
|
2019-01-15 13:00:42 +00:00
|
|
|
}
|
2018-09-24 09:27:46 +00:00
|
|
|
|
2022-10-15 19:54:11 +00:00
|
|
|
settings := get.Config().Settings()
|
2022-10-04 00:57:15 +00:00
|
|
|
|
2022-09-29 22:42:19 +00:00
|
|
|
// Ignore private flag if feature is disabled.
|
2022-10-04 00:57:15 +00:00
|
|
|
if !settings.Features.Private {
|
2022-08-01 13:57:19 +00:00
|
|
|
f.Public = false
|
2020-06-25 12:54:04 +00:00
|
|
|
}
|
|
|
|
|
2022-10-04 00:57:15 +00:00
|
|
|
// Ignore private flag if feature is disabled.
|
|
|
|
if f.Scope == "" &&
|
|
|
|
settings.Features.Review &&
|
|
|
|
acl.Resources.Deny(acl.ResourcePhotos, s.User().AclRole(), acl.ActionManage) {
|
|
|
|
f.Quality = 3
|
|
|
|
}
|
|
|
|
|
2022-09-28 07:01:17 +00:00
|
|
|
return f, s, nil
|
2022-03-30 18:36:25 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// defaultHandler a standard JSON result with all fields.
|
|
|
|
defaultHandler := func(c *gin.Context) {
|
2022-09-28 07:01:17 +00:00
|
|
|
f, s, err := searchForm(c)
|
2022-03-30 18:36:25 +00:00
|
|
|
|
|
|
|
// Abort if authorization or form are invalid.
|
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2022-09-30 17:15:10 +00:00
|
|
|
// Find matching pictures.
|
2022-09-29 22:42:19 +00:00
|
|
|
result, count, err := search.UserPhotos(f, s)
|
2019-12-08 21:45:45 +00:00
|
|
|
|
2022-09-30 17:15:10 +00:00
|
|
|
// Ok?
|
2018-09-24 09:27:46 +00:00
|
|
|
if err != nil {
|
2022-09-29 22:42:19 +00:00
|
|
|
event.AuditWarn([]string{ClientIP(c), "session %s", string(acl.ResourcePhotos), "search", "%s"}, s.RefID, err)
|
2020-07-04 10:54:35 +00:00
|
|
|
AbortBadRequest(c)
|
2019-01-15 13:00:42 +00:00
|
|
|
return
|
2018-09-24 09:27:46 +00:00
|
|
|
}
|
|
|
|
|
2022-03-30 18:36:25 +00:00
|
|
|
// Add response headers.
|
|
|
|
AddCountHeader(c, count)
|
|
|
|
AddLimitHeader(c, f.Count)
|
|
|
|
AddOffsetHeader(c, f.Offset)
|
2022-10-13 20:11:02 +00:00
|
|
|
AddTokenHeaders(c, s)
|
2022-03-30 18:36:25 +00:00
|
|
|
|
2022-09-30 17:15:10 +00:00
|
|
|
// Return as JSON.
|
2022-03-30 18:36:25 +00:00
|
|
|
c.JSON(http.StatusOK, result)
|
|
|
|
}
|
|
|
|
|
|
|
|
// viewHandler returns a photo viewer formatted result.
|
|
|
|
viewHandler := func(c *gin.Context) {
|
2022-09-28 07:01:17 +00:00
|
|
|
f, s, err := searchForm(c)
|
2022-03-30 18:36:25 +00:00
|
|
|
|
|
|
|
// Abort if authorization or form are invalid.
|
|
|
|
if err != nil {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2022-10-15 19:54:11 +00:00
|
|
|
conf := get.Config()
|
2022-08-01 13:57:19 +00:00
|
|
|
|
2022-10-13 20:11:02 +00:00
|
|
|
result, count, err := search.UserPhotosViewerResults(f, s, conf.ContentUri(), conf.ApiUri(), s.PreviewToken, s.DownloadToken)
|
2022-03-30 18:36:25 +00:00
|
|
|
|
|
|
|
if err != nil {
|
2022-09-29 22:42:19 +00:00
|
|
|
event.AuditWarn([]string{ClientIP(c), "session %s", string(acl.ResourcePhotos), "view", "%s"}, s.RefID, err)
|
2022-03-30 18:36:25 +00:00
|
|
|
AbortBadRequest(c)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
// Add response headers.
|
2021-01-08 08:02:30 +00:00
|
|
|
AddCountHeader(c, count)
|
|
|
|
AddLimitHeader(c, f.Count)
|
|
|
|
AddOffsetHeader(c, f.Offset)
|
2022-10-13 20:11:02 +00:00
|
|
|
AddTokenHeaders(c, s)
|
2019-05-16 06:41:16 +00:00
|
|
|
|
2022-09-30 17:15:10 +00:00
|
|
|
// Return as JSON.
|
2018-09-24 09:27:46 +00:00
|
|
|
c.JSON(http.StatusOK, result)
|
2022-03-30 18:36:25 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// Register route handlers.
|
|
|
|
router.GET("/photos", defaultHandler)
|
|
|
|
router.GET("/photos/view", viewHandler)
|
2018-09-27 06:59:53 +00:00
|
|
|
}
|