2022-08-11 17:42:21 +03:00
|
|
|
const debug = require('@tryghost/debug')('pipeline');
|
2018-10-05 01:50:45 +03:00
|
|
|
const _ = require('lodash');
|
2020-05-22 21:22:20 +03:00
|
|
|
const errors = require('@tryghost/errors');
|
2020-08-11 20:44:21 +03:00
|
|
|
const {sequence} = require('@tryghost/promise');
|
2018-10-05 01:50:45 +03:00
|
|
|
|
2022-08-11 17:29:08 +03:00
|
|
|
const Frame = require('./frame');
|
|
|
|
const serializers = require('./serializers');
|
|
|
|
const validators = require('./validators');
|
|
|
|
|
2018-10-05 01:50:45 +03:00
|
|
|
const STAGES = {
|
|
|
|
validation: {
|
2019-05-06 15:24:12 +03:00
|
|
|
/**
|
|
|
|
* @description Input validation.
|
|
|
|
*
|
|
|
|
* We call the shared validator which runs the request through:
|
|
|
|
*
|
2019-08-01 14:00:13 +03:00
|
|
|
* 1. Shared validator
|
|
|
|
* 2. Custom API validators
|
2019-05-06 15:24:12 +03:00
|
|
|
*
|
|
|
|
* @param {Object} apiUtils - Local utils of target API version.
|
|
|
|
* @param {Object} apiConfig - Docname & Method of ctrl.
|
|
|
|
* @param {Object} apiImpl - Controller configuration.
|
|
|
|
* @param {Object} frame
|
|
|
|
* @return {Promise}
|
|
|
|
*/
|
2018-10-05 01:50:45 +03:00
|
|
|
input(apiUtils, apiConfig, apiImpl, frame) {
|
|
|
|
debug('stages: validation');
|
|
|
|
const tasks = [];
|
|
|
|
|
|
|
|
// CASE: do validation completely yourself
|
|
|
|
if (typeof apiImpl.validation === 'function') {
|
|
|
|
debug('validation function call');
|
|
|
|
return apiImpl.validation(frame);
|
|
|
|
}
|
|
|
|
|
|
|
|
tasks.push(function doValidation() {
|
2022-08-11 17:29:08 +03:00
|
|
|
return validators.handle.input(
|
2018-10-05 01:50:45 +03:00
|
|
|
Object.assign({}, apiConfig, apiImpl.validation),
|
|
|
|
apiUtils.validators.input,
|
|
|
|
frame
|
|
|
|
);
|
|
|
|
});
|
|
|
|
|
|
|
|
return sequence(tasks);
|
|
|
|
}
|
|
|
|
},
|
|
|
|
|
|
|
|
serialisation: {
|
2019-05-06 15:24:12 +03:00
|
|
|
/**
|
|
|
|
* @description Input Serialisation.
|
|
|
|
*
|
|
|
|
* We call the shared serializer which runs the request through:
|
|
|
|
*
|
|
|
|
* 1. Shared serializers
|
|
|
|
* 2. Custom API serializers
|
|
|
|
*
|
|
|
|
* @param {Object} apiUtils - Local utils of target API version.
|
|
|
|
* @param {Object} apiConfig - Docname & Method of ctrl.
|
|
|
|
* @param {Object} apiImpl - Controller configuration.
|
|
|
|
* @param {Object} frame
|
|
|
|
* @return {Promise}
|
|
|
|
*/
|
2018-10-05 01:50:45 +03:00
|
|
|
input(apiUtils, apiConfig, apiImpl, frame) {
|
|
|
|
debug('stages: input serialisation');
|
2022-08-11 17:29:08 +03:00
|
|
|
return serializers.handle.input(
|
2018-10-16 12:51:50 +03:00
|
|
|
Object.assign({data: apiImpl.data}, apiConfig),
|
|
|
|
apiUtils.serializers.input,
|
|
|
|
frame
|
|
|
|
);
|
2018-10-05 01:50:45 +03:00
|
|
|
},
|
2019-05-06 15:24:12 +03:00
|
|
|
|
|
|
|
/**
|
|
|
|
* @description Output Serialisation.
|
|
|
|
*
|
|
|
|
* We call the shared serializer which runs the request through:
|
|
|
|
*
|
|
|
|
* 1. Shared serializers
|
|
|
|
* 2. Custom API serializers
|
|
|
|
*
|
|
|
|
* @param {Object} apiUtils - Local utils of target API version.
|
|
|
|
* @param {Object} apiConfig - Docname & Method of ctrl.
|
|
|
|
* @param {Object} apiImpl - Controller configuration.
|
|
|
|
* @param {Object} frame
|
|
|
|
* @return {Promise}
|
|
|
|
*/
|
2018-10-05 01:50:45 +03:00
|
|
|
output(response, apiUtils, apiConfig, apiImpl, frame) {
|
|
|
|
debug('stages: output serialisation');
|
2022-08-11 17:29:08 +03:00
|
|
|
return serializers.handle.output(response, apiConfig, apiUtils.serializers.output, frame);
|
2018-10-05 01:50:45 +03:00
|
|
|
}
|
|
|
|
},
|
|
|
|
|
2019-05-06 15:24:12 +03:00
|
|
|
/**
|
|
|
|
* @description Permissions stage.
|
|
|
|
*
|
|
|
|
* We call the target API implementation of permissions.
|
|
|
|
* Permissions implementation can change across API versions.
|
|
|
|
* There is no shared implementation right now.
|
|
|
|
*
|
|
|
|
* @param {Object} apiUtils - Local utils of target API version.
|
|
|
|
* @param {Object} apiConfig - Docname & Method of ctrl.
|
|
|
|
* @param {Object} apiImpl - Controller configuration.
|
|
|
|
* @param {Object} frame
|
|
|
|
* @return {Promise}
|
|
|
|
*/
|
2018-10-05 01:50:45 +03:00
|
|
|
permissions(apiUtils, apiConfig, apiImpl, frame) {
|
|
|
|
debug('stages: permissions');
|
|
|
|
const tasks = [];
|
|
|
|
|
|
|
|
// CASE: it's required to put the permission key to avoid security holes
|
2019-07-05 14:40:43 +03:00
|
|
|
if (!Object.prototype.hasOwnProperty.call(apiImpl, 'permissions')) {
|
2020-05-22 21:22:20 +03:00
|
|
|
return Promise.reject(new errors.IncorrectUsageError());
|
2018-10-05 01:50:45 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
// CASE: handle permissions completely yourself
|
|
|
|
if (typeof apiImpl.permissions === 'function') {
|
|
|
|
debug('permissions function call');
|
|
|
|
return apiImpl.permissions(frame);
|
|
|
|
}
|
|
|
|
|
|
|
|
// CASE: skip stage completely
|
|
|
|
if (apiImpl.permissions === false) {
|
|
|
|
debug('disabled permissions');
|
|
|
|
return Promise.resolve();
|
|
|
|
}
|
|
|
|
|
2018-10-12 20:43:59 +03:00
|
|
|
if (typeof apiImpl.permissions === 'object' && apiImpl.permissions.before) {
|
|
|
|
tasks.push(function beforePermissions() {
|
|
|
|
return apiImpl.permissions.before(frame);
|
|
|
|
});
|
|
|
|
}
|
|
|
|
|
2018-10-05 01:50:45 +03:00
|
|
|
tasks.push(function doPermissions() {
|
|
|
|
return apiUtils.permissions.handle(
|
|
|
|
Object.assign({}, apiConfig, apiImpl.permissions),
|
|
|
|
frame
|
|
|
|
);
|
|
|
|
});
|
|
|
|
|
|
|
|
return sequence(tasks);
|
|
|
|
},
|
|
|
|
|
2019-05-06 15:24:12 +03:00
|
|
|
/**
|
|
|
|
* @description Execute controller & receive model response.
|
|
|
|
*
|
|
|
|
* @param {Object} apiUtils - Local utils of target API version.
|
|
|
|
* @param {Object} apiConfig - Docname & Method of ctrl.
|
|
|
|
* @param {Object} apiImpl - Controller configuration.
|
|
|
|
* @param {Object} frame
|
|
|
|
* @return {Promise}
|
|
|
|
*/
|
2018-10-05 01:50:45 +03:00
|
|
|
query(apiUtils, apiConfig, apiImpl, frame) {
|
|
|
|
debug('stages: query');
|
|
|
|
|
|
|
|
if (!apiImpl.query) {
|
2020-05-22 21:22:20 +03:00
|
|
|
return Promise.reject(new errors.IncorrectUsageError());
|
2018-10-05 01:50:45 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
return apiImpl.query(frame);
|
|
|
|
}
|
|
|
|
};
|
|
|
|
|
2019-05-06 15:24:12 +03:00
|
|
|
/**
|
|
|
|
* @description The pipeline runs the request through all stages (validation, serialisation, permissions).
|
|
|
|
*
|
|
|
|
* The target API version calls the pipeline and wraps the actual ctrl implementation to be able to
|
|
|
|
* run the request through various stages before hitting the controller.
|
|
|
|
*
|
|
|
|
* The stages are executed in the following order:
|
|
|
|
*
|
|
|
|
* 1. Input validation - General & schema validation
|
|
|
|
* 2. Input serialisation - Modification of incoming data e.g. force filters, auto includes, url transformation etc.
|
|
|
|
* 3. Permissions - Runs after validation & serialisation because the body structure must be valid (see unsafeAttrs)
|
|
|
|
* 4. Controller - Execute the controller implementation & receive model response.
|
|
|
|
* 5. Output Serialisation - Output formatting, Deprecations, Extra attributes etc...
|
|
|
|
*
|
2022-08-21 18:31:41 +03:00
|
|
|
* @param {Object} apiController
|
2019-05-06 15:24:12 +03:00
|
|
|
* @param {Object} apiUtils - Local utils (validation & serialisation) from target API version
|
2021-08-13 09:08:50 +03:00
|
|
|
* @param {String} [apiType] - Content or Admin API access
|
2022-08-21 18:31:41 +03:00
|
|
|
* @return {Object}
|
2019-05-06 15:24:12 +03:00
|
|
|
*/
|
2019-02-25 21:52:45 +03:00
|
|
|
const pipeline = (apiController, apiUtils, apiType) => {
|
2018-10-05 01:50:45 +03:00
|
|
|
const keys = Object.keys(apiController);
|
2022-08-21 18:31:41 +03:00
|
|
|
const docName = apiController.docName;
|
2018-10-05 01:50:45 +03:00
|
|
|
|
|
|
|
// CASE: api controllers are objects with configuration.
|
|
|
|
// We have to ensure that we expose a functional interface e.g. `api.posts.add` has to be available.
|
2022-08-21 18:31:41 +03:00
|
|
|
return keys.reduce((obj, method) => {
|
|
|
|
const apiImpl = _.cloneDeep(apiController)[method];
|
2018-10-05 01:50:45 +03:00
|
|
|
|
2022-08-21 18:31:41 +03:00
|
|
|
obj[method] = function wrapper() {
|
2018-10-05 01:50:45 +03:00
|
|
|
const apiConfig = {docName, method};
|
2020-04-29 18:44:27 +03:00
|
|
|
let options;
|
|
|
|
let data;
|
|
|
|
let frame;
|
2018-10-05 01:50:45 +03:00
|
|
|
|
|
|
|
if (arguments.length === 2) {
|
|
|
|
data = arguments[0];
|
|
|
|
options = arguments[1];
|
|
|
|
} else if (arguments.length === 1) {
|
|
|
|
options = arguments[0] || {};
|
|
|
|
} else {
|
|
|
|
options = {};
|
|
|
|
}
|
|
|
|
|
|
|
|
// CASE: http helper already creates it's own frame.
|
2022-08-11 17:29:08 +03:00
|
|
|
if (!(options instanceof Frame)) {
|
2019-10-15 17:07:38 +03:00
|
|
|
debug(`Internal API request for ${docName}.${method}`);
|
2022-08-11 17:29:08 +03:00
|
|
|
frame = new Frame({
|
2018-10-05 01:50:45 +03:00
|
|
|
body: data,
|
2018-10-17 14:45:46 +03:00
|
|
|
options: _.omit(options, 'context'),
|
|
|
|
context: options.context || {}
|
2018-10-05 01:50:45 +03:00
|
|
|
});
|
|
|
|
|
|
|
|
frame.configure({
|
|
|
|
options: apiImpl.options,
|
|
|
|
data: apiImpl.data
|
|
|
|
});
|
|
|
|
} else {
|
|
|
|
frame = options;
|
|
|
|
}
|
|
|
|
|
|
|
|
// CASE: api controller *can* be a single function, but it's not recommended to disable the framework.
|
|
|
|
if (typeof apiImpl === 'function') {
|
|
|
|
debug('ctrl function call');
|
|
|
|
return apiImpl(frame);
|
|
|
|
}
|
|
|
|
|
2019-02-25 21:52:45 +03:00
|
|
|
frame.apiType = apiType;
|
2019-02-25 21:11:16 +03:00
|
|
|
frame.docName = docName;
|
|
|
|
frame.method = method;
|
|
|
|
|
2018-10-05 01:50:45 +03:00
|
|
|
return Promise.resolve()
|
|
|
|
.then(() => {
|
|
|
|
return STAGES.validation.input(apiUtils, apiConfig, apiImpl, frame);
|
|
|
|
})
|
|
|
|
.then(() => {
|
|
|
|
return STAGES.serialisation.input(apiUtils, apiConfig, apiImpl, frame);
|
|
|
|
})
|
|
|
|
.then(() => {
|
|
|
|
return STAGES.permissions(apiUtils, apiConfig, apiImpl, frame);
|
|
|
|
})
|
|
|
|
.then(() => {
|
|
|
|
return STAGES.query(apiUtils, apiConfig, apiImpl, frame);
|
|
|
|
})
|
|
|
|
.then((response) => {
|
|
|
|
return STAGES.serialisation.output(response, apiUtils, apiConfig, apiImpl, frame);
|
|
|
|
})
|
|
|
|
.then(() => {
|
|
|
|
return frame.response;
|
|
|
|
});
|
|
|
|
};
|
|
|
|
|
2022-08-21 18:31:41 +03:00
|
|
|
Object.assign(obj[method], apiImpl);
|
2018-10-05 01:50:45 +03:00
|
|
|
return obj;
|
|
|
|
}, {});
|
|
|
|
};
|
|
|
|
|
|
|
|
module.exports = pipeline;
|
|
|
|
module.exports.STAGES = STAGES;
|