DomainBlock (domain, severity, reject-media, public and private comment)
covers the domain and its subdomains. Admins manage them under
/clientapi/admin/domainblocks/{list,insert,delete}; the set is kept in
memory, reloaded on every change and at most five minutes stale.
A suspended domain is refused by FederationHttp.IsAllowed, so nothing is
fetched from it and no job delivers to it, and the inbox drops its
activities with a 202 before fetching any key. Reject-media strips the
attachments of posts from that domain. Silence is recorded for the
timelines and notifications that arrive in P1.2.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
75 lines
2.6 KiB
C#
75 lines
2.6 KiB
C#
using Microsoft.AspNetCore.Authorization;
|
|
using Microsoft.AspNetCore.Mvc;
|
|
using Microsoft.Extensions.Localization;
|
|
|
|
using MongoDB.Entities;
|
|
|
|
using PrivaPub.ClientModels;
|
|
using PrivaPub.ClientModels.Admin;
|
|
using PrivaPub.Federation.Moderation;
|
|
using PrivaPub.Models.Federation;
|
|
using PrivaPub.Resources;
|
|
|
|
namespace PrivaPub.Controllers.ClientToServer
|
|
{
|
|
[ApiController,
|
|
Route("clientapi/admin/domainblocks"),
|
|
Authorize(Policy = Policies.IsAdmin)]
|
|
public class DomainBlockController : ControllerBase
|
|
{
|
|
readonly IDomainBlocks _domainBlocks;
|
|
readonly IStringLocalizer _localizer;
|
|
|
|
public DomainBlockController(IDomainBlocks domainBlocks, IStringLocalizer<GenericRes> localizer)
|
|
{
|
|
_domainBlocks = domainBlocks;
|
|
_localizer = localizer;
|
|
}
|
|
|
|
[HttpGet, Route("/clientapi/admin/domainblocks/list")]
|
|
public async Task<IActionResult> List(CancellationToken token) =>
|
|
Ok((await DB.Default.Find<DomainBlock>().Sort(b => b.Domain, Order.Ascending).ExecuteAsync(token)).Select(ToView).ToList());
|
|
|
|
[HttpPost, Route("/clientapi/admin/domainblocks/insert")]
|
|
public async Task<IActionResult> Insert(DomainBlockForm form, CancellationToken token)
|
|
{
|
|
var domain = DomainBlocks.Normalise(form.Domain);
|
|
if (!ModelState.IsValid || Uri.CheckHostName(domain) != UriHostNameType.Dns)
|
|
return BadRequest(new WebResult().Invalidate(_localizer["Invalid model."]));
|
|
|
|
var block = await DB.Default.UpdateAndGet<DomainBlock>()
|
|
.Match(b => b.Domain == domain)
|
|
.Modify(b => b.Domain, domain)
|
|
.Modify(b => b.Severity, form.Suspend ? DomainBlockSeverity.Suspend : DomainBlockSeverity.Silence)
|
|
.Modify(b => b.RejectMedia, form.RejectMedia)
|
|
.Modify(b => b.PublicComment, form.PublicComment)
|
|
.Modify(b => b.PrivateComment, form.PrivateComment)
|
|
.Modify(b => b.SetOnInsert(x => x.CreatedAt, DateTime.UtcNow))
|
|
.Option(o => o.IsUpsert = true)
|
|
.ExecuteAsync(token);
|
|
await _domainBlocks.Reload(token);
|
|
return Ok(ToView(block));
|
|
}
|
|
|
|
[HttpPost, Route("/clientapi/admin/domainblocks/delete")]
|
|
public async Task<IActionResult> Delete([FromQuery] string domain, CancellationToken token)
|
|
{
|
|
domain = DomainBlocks.Normalise(domain);
|
|
await DB.Default.DeleteAsync<DomainBlock>(b => b.Domain == domain);
|
|
await _domainBlocks.Reload(token);
|
|
return Ok();
|
|
}
|
|
|
|
static ViewDomainBlock ToView(DomainBlock block) => new()
|
|
{
|
|
Id = block.ID,
|
|
Domain = block.Domain,
|
|
Severity = block.Severity.ToString(),
|
|
RejectMedia = block.RejectMedia,
|
|
PublicComment = block.PublicComment,
|
|
PrivateComment = block.PrivateComment,
|
|
CreatedAt = block.CreatedAt
|
|
};
|
|
}
|
|
}
|