2021-05-27 16:53:55 +03:00
|
|
|
const _ = require('lodash');
|
|
|
|
const url = require('url');
|
|
|
|
const crypto = require('crypto');
|
|
|
|
const moment = require('moment');
|
|
|
|
const exec = require('child_process').exec;
|
2022-10-30 18:16:10 +03:00
|
|
|
const util = require('util');
|
2021-07-02 17:46:31 +03:00
|
|
|
const tpl = require('@tryghost/tpl');
|
2021-05-27 16:53:55 +03:00
|
|
|
const errors = require('@tryghost/errors');
|
2021-12-07 13:48:01 +03:00
|
|
|
const logging = require('@tryghost/logging');
|
2021-09-22 17:38:09 +03:00
|
|
|
const debug = require('@tryghost/debug')('update-check');
|
2021-05-27 16:53:55 +03:00
|
|
|
|
|
|
|
const internal = {context: {internal: true}};
|
|
|
|
|
2021-07-02 17:46:31 +03:00
|
|
|
const messages = {
|
|
|
|
checkingForUpdatesFailedError: 'Checking for updates failed, your site will continue to function.',
|
|
|
|
checkingForUpdatesFailedHelp: 'If you get this error repeatedly, please seek help from {url}'
|
|
|
|
};
|
|
|
|
|
2021-05-27 16:53:55 +03:00
|
|
|
/**
|
|
|
|
* Update Checker Class
|
|
|
|
*
|
|
|
|
* Makes a request to Ghost.org to request release & custom notifications.
|
|
|
|
* The service is provided in return for users opting in to anonymous usage data collection.
|
|
|
|
*
|
|
|
|
* Blog owners can opt-out of update checks by setting `privacy: { useUpdateCheck: false }` in their config file.
|
|
|
|
*/
|
|
|
|
class UpdateCheckService {
|
2021-06-02 11:36:22 +03:00
|
|
|
/**
|
|
|
|
*
|
|
|
|
* @param {Object} options
|
|
|
|
* @param {Object} options.api - set of Ghost's API methods needed for update check to function
|
|
|
|
* @param {Object} options.api.settings - Settings API methods
|
|
|
|
* @param {Function} options.api.settings.read - method allowing to read Ghost's settings
|
|
|
|
* @param {Function} options.api.settings.edit - method allowing to edit Ghost's settings
|
|
|
|
* @param {Object} options.api.posts - Posts API methods
|
|
|
|
* @param {Function} options.api.posts.browse - method allowing to read Ghost's posts
|
|
|
|
* @param {Object} options.api.users - Users API methods
|
|
|
|
* @param {Function} options.api.users.browse - method allowing to read Ghost's users
|
2021-06-03 12:04:47 +03:00
|
|
|
* @param {Object} options.api.notifications - Notification API methods
|
|
|
|
* @param {Function} options.api.notifications.add - method allowing to add Ghost notifications
|
2021-06-02 13:08:22 +03:00
|
|
|
* @param {Object} options.config
|
|
|
|
* @param {Object} options.config.mail
|
|
|
|
* @param {string} options.config.env
|
|
|
|
* @param {string} options.config.databaseType
|
|
|
|
* @param {string} options.config.checkEndpoint - update check service URL
|
|
|
|
* @param {boolean} [options.config.isPrivacyDisabled]
|
|
|
|
* @param {string[]} [options.config.notificationGroups] - example values ["migration", "something"]
|
|
|
|
* @param {string} options.config.siteUrl - Ghost instance URL
|
|
|
|
* @param {boolean} [options.config.forceUpdate]
|
2021-06-02 14:08:26 +03:00
|
|
|
* @param {string} options.config.ghostVersion - Ghost instance version
|
|
|
|
* @param {Function} options.request - a HTTP request proxy function
|
2021-06-02 14:18:32 +03:00
|
|
|
* @param {Function} options.sendEmail - function handling sending an email
|
2021-06-02 11:36:22 +03:00
|
|
|
*/
|
2021-12-07 13:48:01 +03:00
|
|
|
constructor({api, config, request, sendEmail}) {
|
2021-05-27 16:53:55 +03:00
|
|
|
this.api = api;
|
|
|
|
this.config = config;
|
|
|
|
this.logging = logging;
|
|
|
|
this.request = request;
|
2021-06-02 14:18:32 +03:00
|
|
|
this.sendEmail = sendEmail;
|
2021-05-27 16:53:55 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
nextCheckTimestamp() {
|
|
|
|
const now = Math.round(new Date().getTime() / 1000);
|
|
|
|
return now + (24 * 3600);
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
2021-06-24 16:43:39 +03:00
|
|
|
* @description Centralized error handler for the update check unit.
|
2021-05-27 16:53:55 +03:00
|
|
|
*
|
|
|
|
* CASES:
|
|
|
|
* - the update check service returns an error
|
|
|
|
* - error during collecting blog stats
|
|
|
|
*
|
|
|
|
* We still need to ensure that we set the "next_update_check" to a new value, otherwise no more
|
|
|
|
* update checks will happen.
|
|
|
|
*
|
|
|
|
* @param err
|
|
|
|
*/
|
|
|
|
updateCheckError(err) {
|
|
|
|
this.api.settings.edit({
|
|
|
|
settings: [{
|
|
|
|
key: 'next_update_check',
|
|
|
|
value: this.nextCheckTimestamp()
|
|
|
|
}]
|
|
|
|
}, internal);
|
|
|
|
|
2021-07-02 17:46:31 +03:00
|
|
|
err.context = tpl(messages.checkingForUpdatesFailedError);
|
|
|
|
err.help = tpl(messages.checkingForUpdatesFailedHelp, {url: 'https://ghost.org/docs/'});
|
2021-05-27 16:53:55 +03:00
|
|
|
|
|
|
|
this.logging.error(err);
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @description Collect stats from your blog.
|
|
|
|
* @returns {Promise}
|
|
|
|
*/
|
2021-05-31 19:57:30 +03:00
|
|
|
async updateCheckData() {
|
2021-05-27 16:53:55 +03:00
|
|
|
let data = {};
|
2021-06-02 13:08:22 +03:00
|
|
|
let mailConfig = this.config.mail;
|
2021-05-27 16:53:55 +03:00
|
|
|
|
2021-06-02 14:08:26 +03:00
|
|
|
data.ghost_version = this.config.ghostVersion;
|
2021-05-27 16:53:55 +03:00
|
|
|
data.node_version = process.versions.node;
|
2021-06-02 13:08:22 +03:00
|
|
|
data.env = this.config.env;
|
|
|
|
data.database_type = this.config.databaseType;
|
2021-05-27 16:53:55 +03:00
|
|
|
data.email_transport = mailConfig &&
|
|
|
|
(mailConfig.options && mailConfig.options.service ?
|
|
|
|
mailConfig.options.service :
|
|
|
|
mailConfig.transport);
|
|
|
|
|
2021-05-31 19:57:30 +03:00
|
|
|
try {
|
|
|
|
const hash = (await this.api.settings.read(_.extend({key: 'db_hash'}, internal))).settings[0];
|
|
|
|
const theme = (await this.api.settings.read(_.extend({key: 'active_theme'}, internal))).settings[0];
|
|
|
|
const posts = await this.api.posts.browse();
|
|
|
|
const users = await this.api.users.browse(internal);
|
2022-10-30 18:16:10 +03:00
|
|
|
const npm = await util.promisify(exec)('npm -v');
|
2021-05-31 19:57:30 +03:00
|
|
|
|
2021-06-02 13:36:53 +03:00
|
|
|
const blogUrl = this.config.siteUrl;
|
2021-05-27 16:53:55 +03:00
|
|
|
const parsedBlogUrl = url.parse(blogUrl);
|
|
|
|
const blogId = parsedBlogUrl.hostname + parsedBlogUrl.pathname.replace(/\//, '') + hash.value;
|
|
|
|
|
|
|
|
data.url = blogUrl;
|
|
|
|
data.blog_id = crypto.createHash('md5').update(blogId).digest('hex');
|
|
|
|
data.theme = theme ? theme.value : '';
|
|
|
|
data.post_count = posts && posts.meta && posts.meta.pagination ? posts.meta.pagination.total : 0;
|
|
|
|
data.user_count = users && users.users && users.users.length ? users.users.length : 0;
|
|
|
|
data.blog_created_at = users && users.users && users.users[0] && users.users[0].created_at ? moment(users.users[0].created_at).unix() : '';
|
2022-10-30 18:16:10 +03:00
|
|
|
data.npm_version = npm.stdout.trim();
|
2021-05-27 16:53:55 +03:00
|
|
|
|
|
|
|
return data;
|
2021-05-31 19:57:30 +03:00
|
|
|
} catch (err) {
|
|
|
|
this.updateCheckError(err);
|
|
|
|
}
|
2021-05-27 16:53:55 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @description Perform request to update check service.
|
|
|
|
*
|
|
|
|
* With the privacy setting `useUpdateCheck` you can control if you want to expose data/stats from your blog to the
|
|
|
|
* service. Enabled or disabled, you will receive the latest notification available from the service.
|
|
|
|
*
|
|
|
|
* @see https://ghost.org/docs/concepts/config/#privacy
|
|
|
|
* @returns {Promise}
|
|
|
|
*/
|
|
|
|
async updateCheckRequest() {
|
2021-05-31 19:57:30 +03:00
|
|
|
const reqData = await this.updateCheckData();
|
|
|
|
|
|
|
|
let reqObj = {
|
|
|
|
timeout: 1000,
|
|
|
|
headers: {}
|
|
|
|
};
|
|
|
|
|
2021-06-02 13:08:22 +03:00
|
|
|
let checkEndpoint = this.config.checkEndpoint;
|
|
|
|
let checkMethod = this.config.isPrivacyDisabled ? 'GET' : 'POST';
|
2021-05-31 19:57:30 +03:00
|
|
|
|
|
|
|
// CASE: Expose stats and do a check-in
|
|
|
|
if (checkMethod === 'POST') {
|
|
|
|
reqObj.json = true;
|
|
|
|
reqObj.body = reqData;
|
|
|
|
reqObj.headers['Content-Length'] = Buffer.byteLength(JSON.stringify(reqData));
|
|
|
|
reqObj.headers['Content-Type'] = 'application/json';
|
|
|
|
} else {
|
|
|
|
reqObj.json = true;
|
|
|
|
reqObj.query = {
|
|
|
|
ghost_version: reqData.ghost_version
|
|
|
|
};
|
|
|
|
}
|
2021-05-27 16:53:55 +03:00
|
|
|
|
2021-05-31 19:57:30 +03:00
|
|
|
debug('Request Update Check Service', checkEndpoint);
|
2021-05-27 16:53:55 +03:00
|
|
|
|
2021-05-31 19:57:30 +03:00
|
|
|
try {
|
|
|
|
const response = await this.request(checkEndpoint, reqObj);
|
|
|
|
return response.body;
|
|
|
|
} catch (err) {
|
|
|
|
// CASE: no notifications available, ignore
|
|
|
|
if (err.statusCode === 404) {
|
|
|
|
return {
|
|
|
|
next_check: this.nextCheckTimestamp(),
|
|
|
|
notifications: []
|
|
|
|
};
|
|
|
|
}
|
|
|
|
|
|
|
|
// CASE: service returns JSON error, deserialize into JS error
|
|
|
|
if (err.response && err.response.body && typeof err.response.body === 'object') {
|
|
|
|
throw errors.utils.deserialize(err.response.body);
|
|
|
|
} else {
|
|
|
|
throw err;
|
|
|
|
}
|
|
|
|
}
|
2021-05-27 16:53:55 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @description This function handles the response from the update check service.
|
|
|
|
*
|
|
|
|
* The helper does three things:
|
|
|
|
*
|
|
|
|
* 1. Updates the time in the settings table to know when we can execute the next update check request.
|
|
|
|
* 2. Iterates over the received notifications and filters them out based on your notification groups.
|
|
|
|
* 3. Calls a custom helper to generate a Ghost notification for the database.
|
|
|
|
*
|
|
|
|
* The structure of the response is:
|
|
|
|
*
|
|
|
|
* {
|
|
|
|
* id: 20,
|
|
|
|
* version: 'all4',
|
|
|
|
* messages:
|
|
|
|
* [{
|
|
|
|
* id: 'f8ff6c80-aa61-11e7-a126-6119te37e2b8',
|
|
|
|
* version: '^2',
|
|
|
|
* content: 'Hallouuuu custom',
|
|
|
|
* top: true,
|
|
|
|
* dismissible: true,
|
|
|
|
* type: 'info'
|
|
|
|
* }],
|
|
|
|
* created_at: '2021-10-06T07:00:00.000Z',
|
|
|
|
* custom: 1,
|
|
|
|
* next_check: 1555608722
|
|
|
|
* }
|
|
|
|
*
|
|
|
|
*
|
|
|
|
* Example for grouped custom notifications in config:
|
|
|
|
*
|
|
|
|
* "notificationGroups": ["migration", "something"]
|
|
|
|
*
|
|
|
|
* The group 'all' is a reserved name for general custom notifications, which every self hosted blog can receive.
|
|
|
|
*
|
|
|
|
* @param {Object} response
|
|
|
|
* @return {Promise}
|
|
|
|
*/
|
|
|
|
async updateCheckResponse(response) {
|
|
|
|
let notifications = [];
|
2021-06-02 13:08:22 +03:00
|
|
|
let notificationGroups = (this.config.notificationGroups || []).concat(['all']);
|
2021-05-27 16:53:55 +03:00
|
|
|
|
|
|
|
debug('Notification Groups', notificationGroups);
|
|
|
|
debug('Response Update Check Service', response);
|
|
|
|
|
|
|
|
await this.api.settings.edit({
|
|
|
|
settings: [{
|
|
|
|
key: 'next_update_check',
|
|
|
|
value: response.next_check
|
|
|
|
}]
|
|
|
|
}, internal);
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @NOTE:
|
|
|
|
*
|
|
|
|
* When we refactored notifications in Ghost 1.20, the service did not support returning multiple messages.
|
|
|
|
* But we wanted to already add the support for future functionality.
|
|
|
|
* That's why this helper supports two ways: returning an array of messages or returning an object with
|
|
|
|
* a "notifications" key. The second one is probably the best, because we need to support "next_check"
|
|
|
|
* on the root level of the response.
|
|
|
|
*/
|
|
|
|
if (_.isArray(response)) {
|
|
|
|
notifications = response;
|
|
|
|
} else if ((Object.prototype.hasOwnProperty.call(response, 'notifications') && _.isArray(response.notifications))) {
|
|
|
|
notifications = response.notifications;
|
|
|
|
} else {
|
|
|
|
// CASE: default right now
|
|
|
|
notifications = [response];
|
|
|
|
}
|
|
|
|
|
|
|
|
// CASE: Hook into received notifications and decide whether you are allowed to receive custom group messages.
|
|
|
|
if (notificationGroups.length) {
|
|
|
|
notifications = notifications.filter(function (notification) {
|
|
|
|
// CASE: release notification, keep
|
|
|
|
if (!notification.custom) {
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
// CASE: filter out messages based on your groups
|
|
|
|
return _.includes(notificationGroups.map(function (groupIdentifier) {
|
2021-06-01 15:34:58 +03:00
|
|
|
if (notification && notification.version && notification.version.match(new RegExp(groupIdentifier))) {
|
2021-05-27 16:53:55 +03:00
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
return false;
|
|
|
|
}), true) === true;
|
|
|
|
});
|
|
|
|
}
|
|
|
|
|
2021-06-01 15:34:58 +03:00
|
|
|
for (const notification of notifications) {
|
|
|
|
await this.createCustomNotification(notification);
|
|
|
|
}
|
2021-05-27 16:53:55 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @description Create a Ghost notification and call the API controller.
|
|
|
|
*
|
|
|
|
* @param {Object} notification
|
|
|
|
* @return {Promise}
|
|
|
|
*/
|
|
|
|
async createCustomNotification(notification) {
|
2021-06-23 18:14:47 +03:00
|
|
|
if (!notification || !notification.messages || notification.messages.length === 0) {
|
2021-06-23 18:13:11 +03:00
|
|
|
debug(`Skipping notification creation as there are no messages to process`);
|
2021-05-27 16:53:55 +03:00
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
2021-06-23 18:13:11 +03:00
|
|
|
debug(`creating custom notifications for ${notification.messages.length} notifications`);
|
2021-05-27 16:53:55 +03:00
|
|
|
const {users} = await this.api.users.browse(Object.assign({
|
|
|
|
limit: 'all',
|
2021-10-06 23:31:06 +03:00
|
|
|
include: ['roles'],
|
|
|
|
filter: 'status:active'
|
2021-05-27 16:53:55 +03:00
|
|
|
}, internal));
|
|
|
|
|
|
|
|
const adminEmails = users
|
|
|
|
.filter(user => ['Owner', 'Administrator'].includes(user.roles[0].name))
|
|
|
|
.map(user => user.email);
|
|
|
|
|
2021-06-02 13:08:22 +03:00
|
|
|
const siteUrl = this.config.siteUrl;
|
2021-05-27 16:53:55 +03:00
|
|
|
|
|
|
|
for (const message of notification.messages) {
|
|
|
|
const toAdd = {
|
|
|
|
// @NOTE: the update check service returns "0" or "1" (https://github.com/TryGhost/UpdateCheck/issues/43)
|
|
|
|
custom: !!notification.custom,
|
|
|
|
createdAt: moment(notification.created_at).toDate(),
|
|
|
|
status: message.status || 'alert',
|
|
|
|
type: message.type || 'info',
|
|
|
|
id: message.id,
|
|
|
|
dismissible: Object.prototype.hasOwnProperty.call(message, 'dismissible') ? message.dismissible : true,
|
|
|
|
top: !!message.top,
|
|
|
|
message: message.content
|
|
|
|
};
|
|
|
|
|
|
|
|
if (toAdd.type === 'alert') {
|
|
|
|
for (const email of adminEmails) {
|
|
|
|
try {
|
2021-06-02 14:18:32 +03:00
|
|
|
this.sendEmail({
|
2021-05-27 16:53:55 +03:00
|
|
|
to: email,
|
|
|
|
subject: `Action required: Critical alert from Ghost instance ${siteUrl}`,
|
|
|
|
html: toAdd.message,
|
|
|
|
forceTextContent: true
|
|
|
|
});
|
|
|
|
} catch (err) {
|
|
|
|
this.logging.err(err);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
debug('Add Custom Notification', toAdd);
|
|
|
|
await this.api.notifications.add({notifications: [toAdd]}, {context: {internal: true}});
|
|
|
|
}
|
|
|
|
}
|
|
|
|
/**
|
|
|
|
* @description Entry point to trigger the update check unit.
|
|
|
|
*
|
|
|
|
* Based on a settings value, we check if `next_update_check` is less than now to decide whether
|
|
|
|
* we should request the update check service (http://updates.ghost.org) or not.
|
|
|
|
*
|
|
|
|
* @returns {Promise}
|
|
|
|
*/
|
|
|
|
async check() {
|
2021-06-23 17:57:45 +03:00
|
|
|
try {
|
|
|
|
const result = await this.api.settings.read(_.extend({key: 'next_update_check'}, internal));
|
2021-05-27 16:53:55 +03:00
|
|
|
|
2021-06-23 17:57:45 +03:00
|
|
|
const nextUpdateCheck = result.settings[0];
|
2021-05-27 16:53:55 +03:00
|
|
|
|
2021-06-23 17:57:45 +03:00
|
|
|
// CASE: Next update check should happen now?
|
|
|
|
// @NOTE: You can skip this check by adding a config value. This is helpful for developing.
|
|
|
|
if (!this.config.forceUpdate && nextUpdateCheck && nextUpdateCheck.value && nextUpdateCheck.value > moment().unix()) {
|
|
|
|
return;
|
|
|
|
}
|
2021-05-27 16:53:55 +03:00
|
|
|
|
|
|
|
const response = await this.updateCheckRequest();
|
|
|
|
|
2021-05-31 19:57:30 +03:00
|
|
|
return await this.updateCheckResponse(response);
|
2021-05-27 16:53:55 +03:00
|
|
|
} catch (err) {
|
|
|
|
this.updateCheckError(err);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
module.exports = UpdateCheckService;
|