2015-12-04 17:16:42 -05:00
// Copyright 2015 The Gogs Authors. All rights reserved.
2018-11-28 19:26:14 +08:00
// Copyright 2016 The Gitea Authors. All rights reserved.
2022-11-27 13:20:29 -05:00
// SPDX-License-Identifier: MIT
2015-12-04 17:16:42 -05:00
2017-05-02 15:35:59 +02:00
// Package v1 Gitea API.
//
2017-11-12 23:02:25 -08:00
// This documentation describes the Gitea API.
2017-05-02 15:35:59 +02:00
//
2022-08-30 21:15:45 -05:00
// Schemes: http, https
// BasePath: /api/v1
// Version: {{AppVer | JSEscape | Safe}}
// License: MIT http://opensource.org/licenses/MIT
2017-05-02 15:35:59 +02:00
//
2022-08-30 21:15:45 -05:00
// Consumes:
// - application/json
// - text/plain
2017-05-02 15:35:59 +02:00
//
2022-08-30 21:15:45 -05:00
// Produces:
// - application/json
// - text/html
2017-05-02 15:35:59 +02:00
//
2022-08-30 21:15:45 -05:00
// Security:
// - BasicAuth :
// - Token :
// - AccessToken :
// - AuthorizationHeaderToken :
// - SudoParam :
// - SudoHeader :
// - TOTPHeader :
2017-08-21 13:13:47 +02:00
//
2022-08-30 21:15:45 -05:00
// SecurityDefinitions:
// BasicAuth:
// type: basic
// Token:
// type: apiKey
// name: token
// in: query
// AccessToken:
// type: apiKey
// name: access_token
// in: query
// AuthorizationHeaderToken:
// type: apiKey
// name: Authorization
// in: header
// description: API tokens must be prepended with "token" followed by a space.
// SudoParam:
// type: apiKey
// name: sudo
// in: query
// description: Sudo API request as the user provided as the key. Admin privileges are required.
// SudoHeader:
// type: apiKey
// name: Sudo
// in: header
// description: Sudo API request as the user provided as the key. Admin privileges are required.
// TOTPHeader:
// type: apiKey
// name: X-GITEA-OTP
// in: header
// description: Must be used in combination with BasicAuth if two-factor authentication is enabled.
2017-08-21 13:13:47 +02:00
//
2017-05-02 15:35:59 +02:00
// swagger:meta
2015-12-04 17:16:42 -05:00
package v1
import (
2021-11-22 13:05:29 +00:00
"fmt"
2019-12-20 18:07:12 +01:00
"net/http"
2015-12-04 17:16:42 -05:00
"strings"
2023-01-31 09:45:19 +08:00
actions_model "code.gitea.io/gitea/models/actions"
2023-01-17 16:46:03 -05:00
auth_model "code.gitea.io/gitea/models/auth"
2022-03-29 14:29:02 +08:00
"code.gitea.io/gitea/models/organization"
2022-03-30 10:42:47 +02:00
"code.gitea.io/gitea/models/perm"
2022-05-11 18:09:36 +08:00
access_model "code.gitea.io/gitea/models/perm/access"
2021-12-10 09:27:50 +08:00
repo_model "code.gitea.io/gitea/models/repo"
2021-11-10 03:57:58 +08:00
"code.gitea.io/gitea/models/unit"
2021-11-11 15:03:30 +08:00
user_model "code.gitea.io/gitea/models/user"
2016-11-10 17:24:48 +01:00
"code.gitea.io/gitea/modules/context"
2018-09-07 04:31:29 +01:00
"code.gitea.io/gitea/modules/log"
2018-02-14 05:46:00 +01:00
"code.gitea.io/gitea/modules/setting"
2019-05-11 18:21:34 +08:00
api "code.gitea.io/gitea/modules/structs"
2021-01-26 23:36:53 +08:00
"code.gitea.io/gitea/modules/web"
2022-06-19 00:25:12 -05:00
"code.gitea.io/gitea/routers/api/v1/activitypub"
2016-11-10 17:24:48 +01:00
"code.gitea.io/gitea/routers/api/v1/admin"
"code.gitea.io/gitea/routers/api/v1/misc"
2020-01-09 12:56:32 +01:00
"code.gitea.io/gitea/routers/api/v1/notify"
2016-11-10 17:24:48 +01:00
"code.gitea.io/gitea/routers/api/v1/org"
2022-03-30 10:42:47 +02:00
"code.gitea.io/gitea/routers/api/v1/packages"
2016-11-10 17:24:48 +01:00
"code.gitea.io/gitea/routers/api/v1/repo"
2020-06-22 20:21:31 +02:00
"code.gitea.io/gitea/routers/api/v1/settings"
2016-11-10 17:24:48 +01:00
"code.gitea.io/gitea/routers/api/v1/user"
2023-09-12 08:15:16 +02:00
"code.gitea.io/gitea/routers/common"
2021-06-10 01:53:16 +08:00
"code.gitea.io/gitea/services/auth"
2022-03-26 10:04:22 +01:00
context_service "code.gitea.io/gitea/services/context"
2021-04-06 20:44:05 +01:00
"code.gitea.io/gitea/services/forms"
2017-11-12 23:02:25 -08:00
2021-11-17 20:34:35 +08:00
_ "code.gitea.io/gitea/routers/api/v1/swagger" // for swagger generation
2021-01-26 23:36:53 +08:00
"gitea.com/go-chi/binding"
"github.com/go-chi/cors"
2015-12-04 17:16:42 -05:00
)
2021-01-26 23:36:53 +08:00
func sudo ( ) func ( ctx * context . APIContext ) {
2018-09-07 04:31:29 +01:00
return func ( ctx * context . APIContext ) {
2021-08-11 02:31:13 +02:00
sudo := ctx . FormString ( "sudo" )
2018-10-20 23:25:14 +02:00
if len ( sudo ) == 0 {
2018-09-07 04:31:29 +01:00
sudo = ctx . Req . Header . Get ( "Sudo" )
}
if len ( sudo ) > 0 {
2022-03-22 08:03:22 +01:00
if ctx . IsSigned && ctx . Doer . IsAdmin {
2022-05-20 22:08:52 +08:00
user , err := user_model . GetUserByName ( ctx , sudo )
2018-09-07 04:31:29 +01:00
if err != nil {
2021-11-24 17:49:20 +08:00
if user_model . IsErrUserNotExist ( err ) {
2019-03-18 21:29:43 -05:00
ctx . NotFound ( )
2018-09-07 04:31:29 +01:00
} else {
2019-12-20 18:07:12 +01:00
ctx . Error ( http . StatusInternalServerError , "GetUserByName" , err )
2018-09-07 04:31:29 +01:00
}
return
}
2022-03-22 08:03:22 +01:00
log . Trace ( "Sudo from (%s) to: %s" , ctx . Doer . Name , user . Name )
ctx . Doer = user
2018-09-07 04:31:29 +01:00
} else {
2019-12-20 18:07:12 +01:00
ctx . JSON ( http . StatusForbidden , map [ string ] string {
2018-09-07 04:31:29 +01:00
"message" : "Only administrators allowed to sudo." ,
} )
return
}
}
}
}
2021-01-26 23:36:53 +08:00
func repoAssignment ( ) func ( ctx * context . APIContext ) {
2016-03-13 18:49:16 -04:00
return func ( ctx * context . APIContext ) {
2021-01-26 23:36:53 +08:00
userName := ctx . Params ( "username" )
repoName := ctx . Params ( "reponame" )
2015-12-04 17:16:42 -05:00
var (
2021-11-24 17:49:20 +08:00
owner * user_model . User
2015-12-04 17:16:42 -05:00
err error
)
// Check if the user is the same as the repository owner.
2022-03-22 08:03:22 +01:00
if ctx . IsSigned && ctx . Doer . LowerName == strings . ToLower ( userName ) {
owner = ctx . Doer
2015-12-04 17:16:42 -05:00
} else {
2022-05-20 22:08:52 +08:00
owner , err = user_model . GetUserByName ( ctx , userName )
2015-12-04 17:16:42 -05:00
if err != nil {
2021-11-24 17:49:20 +08:00
if user_model . IsErrUserNotExist ( err ) {
2021-11-11 15:03:30 +08:00
if redirectUserID , err := user_model . LookupUserRedirect ( userName ) ; err == nil {
2023-05-21 09:50:53 +08:00
context . RedirectToUser ( ctx . Base , userName , redirectUserID )
2021-11-11 15:03:30 +08:00
} else if user_model . IsErrUserRedirectNotExist ( err ) {
2021-01-24 10:23:05 -05:00
ctx . NotFound ( "GetUserByName" , err )
} else {
ctx . Error ( http . StatusInternalServerError , "LookupUserRedirect" , err )
}
2015-12-04 17:16:42 -05:00
} else {
2019-12-20 18:07:12 +01:00
ctx . Error ( http . StatusInternalServerError , "GetUserByName" , err )
2015-12-04 17:16:42 -05:00
}
return
}
}
ctx . Repo . Owner = owner
2022-03-26 10:04:22 +01:00
ctx . ContextUser = owner
2015-12-04 17:16:42 -05:00
// Get repository.
2021-12-10 09:27:50 +08:00
repo , err := repo_model . GetRepositoryByName ( owner . ID , repoName )
2015-12-04 17:16:42 -05:00
if err != nil {
2021-12-10 09:27:50 +08:00
if repo_model . IsErrRepoNotExist ( err ) {
2021-12-12 23:48:20 +08:00
redirectRepoID , err := repo_model . LookupRedirect ( owner . ID , repoName )
2017-02-05 09:35:03 -05:00
if err == nil {
2023-05-21 09:50:53 +08:00
context . RedirectToRepo ( ctx . Base , redirectRepoID )
2021-12-12 23:48:20 +08:00
} else if repo_model . IsErrRedirectNotExist ( err ) {
2019-03-18 21:29:43 -05:00
ctx . NotFound ( )
2017-02-05 09:35:03 -05:00
} else {
2019-12-20 18:07:12 +01:00
ctx . Error ( http . StatusInternalServerError , "LookupRepoRedirect" , err )
2017-02-05 09:35:03 -05:00
}
2015-12-04 17:16:42 -05:00
} else {
2019-12-20 18:07:12 +01:00
ctx . Error ( http . StatusInternalServerError , "GetRepositoryByName" , err )
2015-12-04 17:16:42 -05:00
}
return
}
2019-04-26 02:59:10 +08:00
2017-02-02 07:33:56 -05:00
repo . Owner = owner
2018-11-28 19:26:14 +08:00
ctx . Repo . Repository = repo
2015-12-04 17:16:42 -05:00
2023-01-31 09:45:19 +08:00
if ctx . Doer != nil && ctx . Doer . ID == user_model . ActionsUserID {
taskID := ctx . Data [ "ActionsTaskID" ] . ( int64 )
task , err := actions_model . GetTaskByID ( ctx , taskID )
if err != nil {
ctx . Error ( http . StatusInternalServerError , "actions_model.GetTaskByID" , err )
return
}
if task . RepoID != repo . ID {
ctx . NotFound ( )
return
}
if task . IsForkPullRequest {
ctx . Repo . Permission . AccessMode = perm . AccessModeRead
} else {
ctx . Repo . Permission . AccessMode = perm . AccessModeWrite
}
if err := ctx . Repo . Repository . LoadUnits ( ctx ) ; err != nil {
ctx . Error ( http . StatusInternalServerError , "LoadUnits" , err )
return
}
ctx . Repo . Permission . Units = ctx . Repo . Repository . Units
ctx . Repo . Permission . UnitsMode = make ( map [ unit . Type ] perm . AccessMode )
for _ , u := range ctx . Repo . Repository . Units {
ctx . Repo . Permission . UnitsMode [ u . Type ] = ctx . Repo . Permission . AccessMode
}
} else {
ctx . Repo . Permission , err = access_model . GetUserRepoPermission ( ctx , repo , ctx . Doer )
if err != nil {
ctx . Error ( http . StatusInternalServerError , "GetUserRepoPermission" , err )
return
}
2015-12-04 17:16:42 -05:00
}
2016-03-13 23:20:22 -04:00
if ! ctx . Repo . HasAccess ( ) {
2019-03-18 21:29:43 -05:00
ctx . NotFound ( )
2015-12-04 17:16:42 -05:00
return
}
}
}
2022-03-30 10:42:47 +02:00
func reqPackageAccess ( accessMode perm . AccessMode ) func ( ctx * context . APIContext ) {
return func ( ctx * context . APIContext ) {
if ctx . Package . AccessMode < accessMode && ! ctx . IsUserSiteAdmin ( ) {
ctx . Error ( http . StatusForbidden , "reqPackageAccess" , "user should have specific permission or be a site admin" )
return
}
}
}
2023-06-04 14:57:16 -04:00
// if a token is being used for auth, we check that it contains the required scope
// if a token is not being used, reqToken will enforce other sign in methods
func tokenRequiresScopes ( requiredScopeCategories ... auth_model . AccessTokenScopeCategory ) func ( ctx * context . APIContext ) {
return func ( ctx * context . APIContext ) {
// no scope required
if len ( requiredScopeCategories ) == 0 {
return
}
// Need OAuth2 token to be present.
scope , scopeExists := ctx . Data [ "ApiTokenScope" ] . ( auth_model . AccessTokenScope )
if ctx . Data [ "IsApiToken" ] != true || ! scopeExists {
return
}
ctx . Data [ "ApiTokenScopePublicRepoOnly" ] = false
ctx . Data [ "ApiTokenScopePublicOrgOnly" ] = false
// use the http method to determine the access level
requiredScopeLevel := auth_model . Read
if ctx . Req . Method == "POST" || ctx . Req . Method == "PUT" || ctx . Req . Method == "PATCH" || ctx . Req . Method == "DELETE" {
requiredScopeLevel = auth_model . Write
}
// get the required scope for the given access level and category
requiredScopes := auth_model . GetRequiredScopes ( requiredScopeLevel , requiredScopeCategories ... )
// check if scope only applies to public resources
publicOnly , err := scope . PublicOnly ( )
if err != nil {
ctx . Error ( http . StatusForbidden , "tokenRequiresScope" , "parsing public resource scope failed: " + err . Error ( ) )
return
}
// this context is used by the middleware in the specific route
ctx . Data [ "ApiTokenScopePublicRepoOnly" ] = publicOnly && auth_model . ContainsCategory ( requiredScopeCategories , auth_model . AccessTokenScopeCategoryRepository )
ctx . Data [ "ApiTokenScopePublicOrgOnly" ] = publicOnly && auth_model . ContainsCategory ( requiredScopeCategories , auth_model . AccessTokenScopeCategoryOrganization )
allow , err := scope . HasScope ( requiredScopes ... )
if err != nil {
ctx . Error ( http . StatusForbidden , "tokenRequiresScope" , "checking scope failed: " + err . Error ( ) )
return
}
if allow {
return
}
ctx . Error ( http . StatusForbidden , "tokenRequiresScope" , fmt . Sprintf ( "token does not have at least one of required scope(s): %v" , requiredScopes ) )
}
}
2015-12-04 17:16:42 -05:00
// Contexter middleware already checks token for user sign in process.
2023-06-04 14:57:16 -04:00
func reqToken ( ) func ( ctx * context . APIContext ) {
2018-11-04 01:15:55 +00:00
return func ( ctx * context . APIContext ) {
2023-01-31 09:45:19 +08:00
// If actions token is present
if true == ctx . Data [ "IsActionsToken" ] {
return
}
2023-06-04 14:57:16 -04:00
if true == ctx . Data [ "IsApiToken" ] {
publicRepo , pubRepoExists := ctx . Data [ "ApiTokenScopePublicRepoOnly" ]
publicOrg , pubOrgExists := ctx . Data [ "ApiTokenScopePublicOrgOnly" ]
2023-01-17 16:46:03 -05:00
2023-06-04 14:57:16 -04:00
if pubRepoExists && publicRepo . ( bool ) &&
ctx . Repo . Repository != nil && ctx . Repo . Repository . IsPrivate {
ctx . Error ( http . StatusForbidden , "reqToken" , "token scope is limited to public repos" )
2023-01-17 16:46:03 -05:00
return
}
2023-06-04 14:57:16 -04:00
if pubOrgExists && publicOrg . ( bool ) &&
ctx . Org . Organization != nil && ctx . Org . Organization . Visibility != api . VisibleTypePublic {
ctx . Error ( http . StatusForbidden , "reqToken" , "token scope is limited to public orgs" )
return
2023-01-17 16:46:03 -05:00
}
2018-11-04 01:15:55 +00:00
return
}
2023-06-04 14:57:16 -04:00
2023-05-21 09:50:53 +08:00
if ctx . IsBasicAuth {
2019-04-19 04:59:26 -04:00
ctx . CheckForOTP ( )
return
}
2018-11-04 01:15:55 +00:00
if ctx . IsSigned {
2015-12-04 17:16:42 -05:00
return
}
2020-11-14 17:13:55 +01:00
ctx . Error ( http . StatusUnauthorized , "reqToken" , "token is required" )
2015-12-04 17:16:42 -05:00
}
}
2021-03-11 13:40:54 +00:00
func reqExploreSignIn ( ) func ( ctx * context . APIContext ) {
return func ( ctx * context . APIContext ) {
if setting . Service . Explore . RequireSigninView && ! ctx . IsSigned {
ctx . Error ( http . StatusUnauthorized , "reqExploreSignIn" , "you must be signed in to search for users" )
}
}
}
2023-09-07 16:31:46 +08:00
func reqBasicOrRevProxyAuth ( ) func ( ctx * context . APIContext ) {
2019-04-19 04:59:26 -04:00
return func ( ctx * context . APIContext ) {
2023-09-07 16:31:46 +08:00
if ctx . IsSigned && setting . Service . EnableReverseProxyAuthAPI && ctx . Data [ "AuthedMethod" ] . ( string ) == auth . ReverseProxyMethodName {
return
}
2023-05-21 09:50:53 +08:00
if ! ctx . IsBasicAuth {
2022-12-27 00:34:05 +00:00
ctx . Error ( http . StatusUnauthorized , "reqBasicAuth" , "auth required" )
2015-12-04 17:16:42 -05:00
return
}
2019-04-19 04:59:26 -04:00
ctx . CheckForOTP ( )
2015-12-04 17:16:42 -05:00
}
}
2018-11-28 19:26:14 +08:00
// reqSiteAdmin user should be the site admin
2021-01-26 23:36:53 +08:00
func reqSiteAdmin ( ) func ( ctx * context . APIContext ) {
2020-11-14 17:13:55 +01:00
return func ( ctx * context . APIContext ) {
2019-04-07 22:49:34 +00:00
if ! ctx . IsUserSiteAdmin ( ) {
2020-11-14 17:13:55 +01:00
ctx . Error ( http . StatusForbidden , "reqSiteAdmin" , "user should be the site admin" )
2015-12-04 17:16:42 -05:00
return
}
}
}
2019-04-07 22:49:34 +00:00
// reqOwner user should be the owner of the repo or site admin.
2021-01-26 23:36:53 +08:00
func reqOwner ( ) func ( ctx * context . APIContext ) {
2020-11-14 17:13:55 +01:00
return func ( ctx * context . APIContext ) {
2023-05-09 07:30:14 +08:00
if ! ctx . Repo . IsOwner ( ) && ! ctx . IsUserSiteAdmin ( ) {
2020-11-14 17:13:55 +01:00
ctx . Error ( http . StatusForbidden , "reqOwner" , "user should be the owner of the repo" )
2018-11-28 19:26:14 +08:00
return
}
}
}
2019-04-07 22:49:34 +00:00
// reqAdmin user should be an owner or a collaborator with admin write of a repository, or site admin
2021-01-26 23:36:53 +08:00
func reqAdmin ( ) func ( ctx * context . APIContext ) {
2020-11-14 17:13:55 +01:00
return func ( ctx * context . APIContext ) {
2019-04-07 22:49:34 +00:00
if ! ctx . IsUserRepoAdmin ( ) && ! ctx . IsUserSiteAdmin ( ) {
2020-11-14 17:13:55 +01:00
ctx . Error ( http . StatusForbidden , "reqAdmin" , "user should be an owner or a collaborator with admin write of a repository" )
2018-11-28 19:26:14 +08:00
return
}
}
}
2019-04-07 22:49:34 +00:00
// reqRepoWriter user should have a permission to write to a repo, or be a site admin
2021-11-10 03:57:58 +08:00
func reqRepoWriter ( unitTypes ... unit . Type ) func ( ctx * context . APIContext ) {
2020-11-14 17:13:55 +01:00
return func ( ctx * context . APIContext ) {
2019-04-07 22:49:34 +00:00
if ! ctx . IsUserRepoWriter ( unitTypes ) && ! ctx . IsUserRepoAdmin ( ) && ! ctx . IsUserSiteAdmin ( ) {
2020-11-14 17:13:55 +01:00
ctx . Error ( http . StatusForbidden , "reqRepoWriter" , "user should have a permission to write to a repo" )
2018-11-28 19:26:14 +08:00
return
}
}
}
2022-04-28 17:45:33 +02:00
// reqRepoBranchWriter user should have a permission to write to a branch, or be a site admin
func reqRepoBranchWriter ( ctx * context . APIContext ) {
options , ok := web . GetForm ( ctx ) . ( api . FileOptionInterface )
2023-07-22 22:14:27 +08:00
if ! ok || ( ! ctx . Repo . CanWriteToBranch ( ctx , ctx . Doer , options . Branch ( ) ) && ! ctx . IsUserSiteAdmin ( ) ) {
2022-04-28 17:45:33 +02:00
ctx . Error ( http . StatusForbidden , "reqRepoBranchWriter" , "user should have a permission to write to this branch" )
return
}
}
2019-04-07 22:49:34 +00:00
// reqRepoReader user should have specific read permission or be a repo admin or a site admin
2021-11-10 03:57:58 +08:00
func reqRepoReader ( unitType unit . Type ) func ( ctx * context . APIContext ) {
2020-11-14 17:13:55 +01:00
return func ( ctx * context . APIContext ) {
2023-05-09 07:30:14 +08:00
if ! ctx . Repo . CanRead ( unitType ) && ! ctx . IsUserRepoAdmin ( ) && ! ctx . IsUserSiteAdmin ( ) {
2020-11-14 17:13:55 +01:00
ctx . Error ( http . StatusForbidden , "reqRepoReader" , "user should have specific read permission or be a repo admin or a site admin" )
2016-08-24 16:05:56 -07:00
return
}
}
}
2019-04-07 22:49:34 +00:00
// reqAnyRepoReader user should have any permission to read repository or permissions of site admin
2021-01-26 23:36:53 +08:00
func reqAnyRepoReader ( ) func ( ctx * context . APIContext ) {
2020-11-14 17:13:55 +01:00
return func ( ctx * context . APIContext ) {
2023-05-09 07:30:14 +08:00
if ! ctx . Repo . HasAccess ( ) && ! ctx . IsUserSiteAdmin ( ) {
2020-11-14 17:13:55 +01:00
ctx . Error ( http . StatusForbidden , "reqAnyRepoReader" , "user should have any permission to read repository or permissions of site admin" )
2019-04-07 22:49:34 +00:00
return
2018-11-28 19:26:14 +08:00
}
}
}
2019-04-07 22:49:34 +00:00
// reqOrgOwnership user should be an organization owner, or a site admin
2021-01-26 23:36:53 +08:00
func reqOrgOwnership ( ) func ( ctx * context . APIContext ) {
2017-01-13 21:14:48 -05:00
return func ( ctx * context . APIContext ) {
2023-05-21 09:50:53 +08:00
if ctx . IsUserSiteAdmin ( ) {
2019-04-07 22:49:34 +00:00
return
}
2017-01-13 21:14:48 -05:00
var orgID int64
if ctx . Org . Organization != nil {
orgID = ctx . Org . Organization . ID
} else if ctx . Org . Team != nil {
orgID = ctx . Org . Team . OrgID
} else {
2019-12-20 18:07:12 +01:00
ctx . Error ( http . StatusInternalServerError , "" , "reqOrgOwnership: unprepared context" )
2017-01-13 21:14:48 -05:00
return
}
2022-03-29 14:29:02 +08:00
isOwner , err := organization . IsOrganizationOwner ( ctx , orgID , ctx . Doer . ID )
2019-04-07 22:49:34 +00:00
if err != nil {
2019-12-20 18:07:12 +01:00
ctx . Error ( http . StatusInternalServerError , "IsOrganizationOwner" , err )
2017-12-20 23:43:26 -08:00
return
2019-04-07 22:49:34 +00:00
} else if ! isOwner {
2017-01-26 06:54:04 -05:00
if ctx . Org . Organization != nil {
2019-12-20 18:07:12 +01:00
ctx . Error ( http . StatusForbidden , "" , "Must be an organization owner" )
2017-01-26 06:54:04 -05:00
} else {
2019-03-18 21:29:43 -05:00
ctx . NotFound ( )
2017-01-26 06:54:04 -05:00
}
2017-01-13 21:14:48 -05:00
return
}
}
}
2019-04-24 13:32:35 +08:00
// reqTeamMembership user should be an team member, or a site admin
2021-01-26 23:36:53 +08:00
func reqTeamMembership ( ) func ( ctx * context . APIContext ) {
2019-04-24 13:32:35 +08:00
return func ( ctx * context . APIContext ) {
2023-05-21 09:50:53 +08:00
if ctx . IsUserSiteAdmin ( ) {
2019-04-24 13:32:35 +08:00
return
}
if ctx . Org . Team == nil {
2019-12-20 18:07:12 +01:00
ctx . Error ( http . StatusInternalServerError , "" , "reqTeamMembership: unprepared context" )
2019-04-24 13:32:35 +08:00
return
}
2022-01-20 18:46:10 +01:00
orgID := ctx . Org . Team . OrgID
2022-03-29 14:29:02 +08:00
isOwner , err := organization . IsOrganizationOwner ( ctx , orgID , ctx . Doer . ID )
2019-04-24 13:32:35 +08:00
if err != nil {
2019-12-20 18:07:12 +01:00
ctx . Error ( http . StatusInternalServerError , "IsOrganizationOwner" , err )
2019-04-24 13:32:35 +08:00
return
} else if isOwner {
return
}
2022-03-29 14:29:02 +08:00
if isTeamMember , err := organization . IsTeamMember ( ctx , orgID , ctx . Org . Team . ID , ctx . Doer . ID ) ; err != nil {
2019-12-20 18:07:12 +01:00
ctx . Error ( http . StatusInternalServerError , "IsTeamMember" , err )
2019-04-24 13:32:35 +08:00
return
} else if ! isTeamMember {
2022-03-29 14:29:02 +08:00
isOrgMember , err := organization . IsOrganizationMember ( ctx , orgID , ctx . Doer . ID )
2019-04-24 13:32:35 +08:00
if err != nil {
2019-12-20 18:07:12 +01:00
ctx . Error ( http . StatusInternalServerError , "IsOrganizationMember" , err )
2019-04-24 13:32:35 +08:00
} else if isOrgMember {
2019-12-20 18:07:12 +01:00
ctx . Error ( http . StatusForbidden , "" , "Must be a team member" )
2019-04-24 13:32:35 +08:00
} else {
ctx . NotFound ( )
}
return
}
}
}
2019-04-07 22:49:34 +00:00
// reqOrgMembership user should be an organization member, or a site admin
2021-01-26 23:36:53 +08:00
func reqOrgMembership ( ) func ( ctx * context . APIContext ) {
2017-01-13 21:14:48 -05:00
return func ( ctx * context . APIContext ) {
2023-05-21 09:50:53 +08:00
if ctx . IsUserSiteAdmin ( ) {
2019-04-07 22:49:34 +00:00
return
}
2017-01-13 21:14:48 -05:00
var orgID int64
if ctx . Org . Organization != nil {
orgID = ctx . Org . Organization . ID
} else if ctx . Org . Team != nil {
orgID = ctx . Org . Team . OrgID
} else {
2019-12-20 18:07:12 +01:00
ctx . Error ( http . StatusInternalServerError , "" , "reqOrgMembership: unprepared context" )
2017-01-13 21:14:48 -05:00
return
}
2022-03-29 14:29:02 +08:00
if isMember , err := organization . IsOrganizationMember ( ctx , orgID , ctx . Doer . ID ) ; err != nil {
2019-12-20 18:07:12 +01:00
ctx . Error ( http . StatusInternalServerError , "IsOrganizationMember" , err )
2019-04-07 22:49:34 +00:00
return
} else if ! isMember {
2017-01-26 06:54:04 -05:00
if ctx . Org . Organization != nil {
2019-12-20 18:07:12 +01:00
ctx . Error ( http . StatusForbidden , "" , "Must be an organization member" )
2017-01-26 06:54:04 -05:00
} else {
2019-03-18 21:29:43 -05:00
ctx . NotFound ( )
2017-01-26 06:54:04 -05:00
}
2017-01-13 21:14:48 -05:00
return
}
}
}
2021-01-26 23:36:53 +08:00
func reqGitHook ( ) func ( ctx * context . APIContext ) {
2019-04-17 08:31:08 +03:00
return func ( ctx * context . APIContext ) {
2022-03-22 08:03:22 +01:00
if ! ctx . Doer . CanEditGitHook ( ) {
2019-12-20 18:07:12 +01:00
ctx . Error ( http . StatusForbidden , "" , "must be allowed to edit Git hooks" )
2019-04-17 08:31:08 +03:00
return
}
}
}
2021-02-11 18:34:34 +01:00
// reqWebhooksEnabled requires webhooks to be enabled by admin.
func reqWebhooksEnabled ( ) func ( ctx * context . APIContext ) {
return func ( ctx * context . APIContext ) {
if setting . DisableWebhooks {
ctx . Error ( http . StatusForbidden , "" , "webhooks disabled by administrator" )
return
}
}
}
2021-01-26 23:36:53 +08:00
func orgAssignment ( args ... bool ) func ( ctx * context . APIContext ) {
2016-03-25 18:04:02 -04:00
var (
2016-04-04 19:41:34 -04:00
assignOrg bool
2016-03-25 18:04:02 -04:00
assignTeam bool
)
if len ( args ) > 0 {
2016-04-04 19:41:34 -04:00
assignOrg = args [ 0 ]
}
if len ( args ) > 1 {
assignTeam = args [ 1 ]
2016-03-25 18:04:02 -04:00
}
return func ( ctx * context . APIContext ) {
2016-04-04 19:41:34 -04:00
ctx . Org = new ( context . APIOrganization )
var err error
if assignOrg {
2023-02-08 07:44:42 +01:00
ctx . Org . Organization , err = organization . GetOrgByName ( ctx , ctx . Params ( ":org" ) )
2016-04-04 19:41:34 -04:00
if err != nil {
2022-03-29 14:29:02 +08:00
if organization . IsErrOrgNotExist ( err ) {
2021-11-11 15:03:30 +08:00
redirectUserID , err := user_model . LookupUserRedirect ( ctx . Params ( ":org" ) )
2021-01-24 10:23:05 -05:00
if err == nil {
2023-05-21 09:50:53 +08:00
context . RedirectToUser ( ctx . Base , ctx . Params ( ":org" ) , redirectUserID )
2021-11-11 15:03:30 +08:00
} else if user_model . IsErrUserRedirectNotExist ( err ) {
2021-01-24 10:23:05 -05:00
ctx . NotFound ( "GetOrgByName" , err )
} else {
ctx . Error ( http . StatusInternalServerError , "LookupUserRedirect" , err )
}
2016-04-04 19:41:34 -04:00
} else {
2019-12-20 18:07:12 +01:00
ctx . Error ( http . StatusInternalServerError , "GetOrgByName" , err )
2016-04-04 19:41:34 -04:00
}
return
2016-03-25 18:04:02 -04:00
}
2022-03-26 10:04:22 +01:00
ctx . ContextUser = ctx . Org . Organization . AsUser ( )
2016-03-25 18:04:02 -04:00
}
if assignTeam {
2022-05-20 22:08:52 +08:00
ctx . Org . Team , err = organization . GetTeamByID ( ctx , ctx . ParamsInt64 ( ":teamid" ) )
2016-03-25 18:04:02 -04:00
if err != nil {
2022-03-29 14:29:02 +08:00
if organization . IsErrTeamNotExist ( err ) {
2019-03-18 21:29:43 -05:00
ctx . NotFound ( )
2016-03-25 18:04:02 -04:00
} else {
2019-12-20 18:07:12 +01:00
ctx . Error ( http . StatusInternalServerError , "GetTeamById" , err )
2016-03-25 18:04:02 -04:00
}
return
}
}
}
}
2016-08-04 17:08:01 -07:00
func mustEnableIssues ( ctx * context . APIContext ) {
2021-11-10 03:57:58 +08:00
if ! ctx . Repo . CanRead ( unit . TypeIssues ) {
2019-04-22 21:40:51 +01:00
if log . IsTrace ( ) {
if ctx . IsSigned {
log . Trace ( "Permission Denied: User %-v cannot read %-v in Repo %-v\n" +
"User in Repo has Permissions: %-+v" ,
2022-03-22 08:03:22 +01:00
ctx . Doer ,
2021-11-10 03:57:58 +08:00
unit . TypeIssues ,
2019-04-22 21:40:51 +01:00
ctx . Repo . Repository ,
ctx . Repo . Permission )
} else {
log . Trace ( "Permission Denied: Anonymous user cannot read %-v in Repo %-v\n" +
"Anonymous user in Repo has Permissions: %-+v" ,
2021-11-10 03:57:58 +08:00
unit . TypeIssues ,
2019-04-22 21:40:51 +01:00
ctx . Repo . Repository ,
ctx . Repo . Permission )
}
}
2019-03-18 21:29:43 -05:00
ctx . NotFound ( )
2016-08-04 16:32:02 -07:00
return
}
}
2019-03-18 21:29:43 -05:00
func mustAllowPulls ( ctx * context . APIContext ) {
2021-11-10 03:57:58 +08:00
if ! ( ctx . Repo . Repository . CanEnablePulls ( ) && ctx . Repo . CanRead ( unit . TypePullRequests ) ) {
2019-04-22 21:40:51 +01:00
if ctx . Repo . Repository . CanEnablePulls ( ) && log . IsTrace ( ) {
if ctx . IsSigned {
log . Trace ( "Permission Denied: User %-v cannot read %-v in Repo %-v\n" +
"User in Repo has Permissions: %-+v" ,
2022-03-22 08:03:22 +01:00
ctx . Doer ,
2021-11-10 03:57:58 +08:00
unit . TypePullRequests ,
2019-04-22 21:40:51 +01:00
ctx . Repo . Repository ,
ctx . Repo . Permission )
} else {
log . Trace ( "Permission Denied: Anonymous user cannot read %-v in Repo %-v\n" +
"Anonymous user in Repo has Permissions: %-+v" ,
2021-11-10 03:57:58 +08:00
unit . TypePullRequests ,
2019-04-22 21:40:51 +01:00
ctx . Repo . Repository ,
ctx . Repo . Permission )
}
}
2019-03-18 21:29:43 -05:00
ctx . NotFound ( )
2016-12-02 12:10:39 +01:00
return
}
}
2019-03-18 21:29:43 -05:00
func mustEnableIssuesOrPulls ( ctx * context . APIContext ) {
2021-11-10 03:57:58 +08:00
if ! ctx . Repo . CanRead ( unit . TypeIssues ) &&
! ( ctx . Repo . Repository . CanEnablePulls ( ) && ctx . Repo . CanRead ( unit . TypePullRequests ) ) {
2019-04-22 21:40:51 +01:00
if ctx . Repo . Repository . CanEnablePulls ( ) && log . IsTrace ( ) {
if ctx . IsSigned {
log . Trace ( "Permission Denied: User %-v cannot read %-v and %-v in Repo %-v\n" +
"User in Repo has Permissions: %-+v" ,
2022-03-22 08:03:22 +01:00
ctx . Doer ,
2021-11-10 03:57:58 +08:00
unit . TypeIssues ,
unit . TypePullRequests ,
2019-04-22 21:40:51 +01:00
ctx . Repo . Repository ,
ctx . Repo . Permission )
} else {
log . Trace ( "Permission Denied: Anonymous user cannot read %-v and %-v in Repo %-v\n" +
"Anonymous user in Repo has Permissions: %-+v" ,
2021-11-10 03:57:58 +08:00
unit . TypeIssues ,
unit . TypePullRequests ,
2019-04-22 21:40:51 +01:00
ctx . Repo . Repository ,
ctx . Repo . Permission )
}
}
2019-03-18 21:29:43 -05:00
ctx . NotFound ( )
2018-09-04 01:20:54 +08:00
return
}
}
2021-10-25 05:43:40 +02:00
func mustEnableWiki ( ctx * context . APIContext ) {
2021-11-10 03:57:58 +08:00
if ! ( ctx . Repo . CanRead ( unit . TypeWiki ) ) {
2021-10-25 05:43:40 +02:00
ctx . NotFound ( )
return
}
}
2019-03-18 21:29:43 -05:00
func mustNotBeArchived ( ctx * context . APIContext ) {
2019-01-30 18:20:40 +01:00
if ctx . Repo . Repository . IsArchived {
2019-03-18 21:29:43 -05:00
ctx . NotFound ( )
2019-01-30 18:20:40 +01:00
return
}
}
2022-12-09 07:35:56 +01:00
func mustEnableAttachments ( ctx * context . APIContext ) {
if ! setting . Attachment . Enabled {
ctx . NotFound ( )
return
}
}
2021-01-26 23:36:53 +08:00
// bind binding an obj to a func(ctx *context.APIContext)
2023-04-21 02:49:06 +08:00
func bind [ T any ] ( _ T ) any {
return func ( ctx * context . APIContext ) {
2022-12-12 16:09:26 +08:00
theObj := new ( T ) // create a new form obj for every request but not use obj directly
2021-01-26 23:36:53 +08:00
errs := binding . Bind ( ctx . Req , theObj )
if len ( errs ) > 0 {
2021-11-22 13:05:29 +00:00
ctx . Error ( http . StatusUnprocessableEntity , "validationError" , fmt . Sprintf ( "%s: %s" , errs [ 0 ] . FieldNames , errs [ 0 ] . Error ( ) ) )
2021-01-26 23:36:53 +08:00
return
}
web . SetForm ( ctx , theObj )
2023-04-21 02:49:06 +08:00
}
2021-01-26 23:36:53 +08:00
}
2015-12-04 17:16:42 -05:00
2022-03-28 12:46:28 +08:00
// The OAuth2 plugin is expected to be executed first, as it must ignore the user id stored
// in the session (if there is a user id stored in session other plugins might return the user
// object for that id).
//
// The Session plugin is expected to be executed second, in order to skip authentication
// for users that have already signed in.
func buildAuthGroup ( ) * auth . Group {
group := auth . NewGroup (
& auth . OAuth2 { } ,
2022-06-05 09:16:14 +02:00
& auth . HTTPSign { } ,
2022-04-08 12:22:10 +08:00
& auth . Basic { } , // FIXME: this should be removed once we don't allow basic auth in API
2022-03-28 12:46:28 +08:00
)
2023-09-07 16:31:46 +08:00
if setting . Service . EnableReverseProxyAuthAPI {
group . Add ( & auth . ReverseProxy { } )
}
2023-09-18 07:32:56 +08:00
if setting . IsWindows && auth_model . IsSSPIEnabled ( ) {
group . Add ( & auth . SSPI { } ) // it MUST be the last, see the comment of SSPI
}
2022-03-28 12:46:28 +08:00
return group
}
2023-09-12 08:15:16 +02:00
func apiAuth ( authMethod auth . Method ) func ( * context . APIContext ) {
return func ( ctx * context . APIContext ) {
ar , err := common . AuthShared ( ctx . Base , nil , authMethod )
if err != nil {
ctx . Error ( http . StatusUnauthorized , "APIAuth" , err )
return
}
ctx . Doer = ar . Doer
ctx . IsSigned = ar . Doer != nil
ctx . IsBasicAuth = ar . IsBasicAuth
}
}
// verifyAuthWithOptions checks authentication according to options
func verifyAuthWithOptions ( options * common . VerifyOptions ) func ( ctx * context . APIContext ) {
return func ( ctx * context . APIContext ) {
// Check prohibit login users.
if ctx . IsSigned {
if ! ctx . Doer . IsActive && setting . Service . RegisterEmailConfirm {
ctx . Data [ "Title" ] = ctx . Tr ( "auth.active_your_account" )
ctx . JSON ( http . StatusForbidden , map [ string ] string {
"message" : "This account is not activated." ,
} )
return
}
if ! ctx . Doer . IsActive || ctx . Doer . ProhibitLogin {
log . Info ( "Failed authentication attempt for %s from %s" , ctx . Doer . Name , ctx . RemoteAddr ( ) )
ctx . Data [ "Title" ] = ctx . Tr ( "auth.prohibit_login" )
ctx . JSON ( http . StatusForbidden , map [ string ] string {
"message" : "This account is prohibited from signing in, please contact your site administrator." ,
} )
return
}
if ctx . Doer . MustChangePassword {
ctx . JSON ( http . StatusForbidden , map [ string ] string {
"message" : "You must change your password. Change it at: " + setting . AppURL + "/user/change_password" ,
} )
return
}
}
// Redirect to dashboard if user tries to visit any non-login page.
if options . SignOutRequired && ctx . IsSigned && ctx . Req . URL . RequestURI ( ) != "/" {
ctx . Redirect ( setting . AppSubURL + "/" )
return
}
if options . SignInRequired {
if ! ctx . IsSigned {
// Restrict API calls with error message.
ctx . JSON ( http . StatusForbidden , map [ string ] string {
"message" : "Only signed in user is allowed to call APIs." ,
} )
return
} else if ! ctx . Doer . IsActive && setting . Service . RegisterEmailConfirm {
ctx . Data [ "Title" ] = ctx . Tr ( "auth.active_your_account" )
ctx . JSON ( http . StatusForbidden , map [ string ] string {
"message" : "This account is not activated." ,
} )
return
}
if ctx . IsSigned && ctx . IsBasicAuth {
if skip , ok := ctx . Data [ "SkipLocalTwoFA" ] ; ok && skip . ( bool ) {
return // Skip 2FA
}
2023-09-15 08:13:19 +02:00
twofa , err := auth_model . GetTwoFactorByUID ( ctx , ctx . Doer . ID )
2023-09-12 08:15:16 +02:00
if err != nil {
if auth_model . IsErrTwoFactorNotEnrolled ( err ) {
return // No 2FA enrollment for this user
}
ctx . InternalServerError ( err )
return
}
otpHeader := ctx . Req . Header . Get ( "X-Gitea-OTP" )
ok , err := twofa . ValidateTOTP ( otpHeader )
if err != nil {
ctx . InternalServerError ( err )
return
}
if ! ok {
ctx . JSON ( http . StatusForbidden , map [ string ] string {
"message" : "Only signed in user is allowed to call APIs." ,
} )
return
}
}
}
if options . AdminRequired {
if ! ctx . Doer . IsAdmin {
ctx . JSON ( http . StatusForbidden , map [ string ] string {
"message" : "You have no permission to request for this." ,
} )
return
}
}
}
}
2021-01-26 23:36:53 +08:00
// Routes registers all v1 APIs routes to web application.
2023-06-18 15:59:09 +08:00
func Routes ( ) * web . Route {
2022-01-20 18:46:10 +01:00
m := web . NewRoute ( )
2021-01-26 23:36:53 +08:00
m . Use ( securityHeaders ( ) )
if setting . CORSConfig . Enabled {
m . Use ( cors . Handler ( cors . Options {
2022-01-20 18:46:10 +01:00
// Scheme: setting.CORSConfig.Scheme, // FIXME: the cors middleware needs scheme option
2021-01-26 23:36:53 +08:00
AllowedOrigins : setting . CORSConfig . AllowDomain ,
2022-01-20 18:46:10 +01:00
// setting.CORSConfig.AllowSubdomain // FIXME: the cors middleware needs allowSubdomain option
2021-01-26 23:36:53 +08:00
AllowedMethods : setting . CORSConfig . Methods ,
AllowCredentials : setting . CORSConfig . AllowCredentials ,
2022-11-11 01:39:27 -05:00
AllowedHeaders : append ( [ ] string { "Authorization" , "X-Gitea-OTP" } , setting . CORSConfig . Headers ... ) ,
2021-01-26 23:36:53 +08:00
MaxAge : int ( setting . CORSConfig . MaxAge . Seconds ( ) ) ,
} ) )
2018-02-14 05:46:00 +01:00
}
2021-01-26 23:36:53 +08:00
m . Use ( context . APIContexter ( ) )
2021-01-28 01:46:35 +08:00
2021-06-10 01:53:16 +08:00
// Get user from session if logged in.
2023-09-12 08:15:16 +02:00
m . Use ( apiAuth ( buildAuthGroup ( ) ) )
2021-06-10 01:53:16 +08:00
2023-09-12 08:15:16 +02:00
m . Use ( verifyAuthWithOptions ( & common . VerifyOptions {
2021-01-26 23:36:53 +08:00
SignInRequired : setting . Service . RequireSignInView ,
} ) )
2017-10-21 16:05:50 +02:00
2021-01-26 23:36:53 +08:00
m . Group ( "" , func ( ) {
2023-01-17 16:46:03 -05:00
// Miscellaneous (no scope required)
2018-07-28 02:19:01 +02:00
if setting . API . EnableSwagger {
2021-01-26 23:36:53 +08:00
m . Get ( "/swagger" , func ( ctx * context . APIContext ) {
2021-10-16 11:34:07 +08:00
ctx . Redirect ( setting . AppSubURL + "/api/swagger" )
2021-01-26 23:36:53 +08:00
} )
2018-02-14 05:46:00 +01:00
}
2023-06-04 14:57:16 -04:00
2021-09-27 19:38:06 -04:00
if setting . Federation . Enabled {
m . Get ( "/nodeinfo" , misc . NodeInfo )
2022-06-19 00:25:12 -05:00
m . Group ( "/activitypub" , func ( ) {
2023-04-04 10:08:23 +08:00
// deprecated, remove in 1.20, use /user-id/{user-id} instead
2022-06-19 00:25:12 -05:00
m . Group ( "/user/{username}" , func ( ) {
m . Get ( "" , activitypub . Person )
m . Post ( "/inbox" , activitypub . ReqHTTPSignature ( ) , activitypub . PersonInbox )
} , context_service . UserAssignmentAPI ( ) )
2023-04-04 10:08:23 +08:00
m . Group ( "/user-id/{user-id}" , func ( ) {
m . Get ( "" , activitypub . Person )
m . Post ( "/inbox" , activitypub . ReqHTTPSignature ( ) , activitypub . PersonInbox )
} , context_service . UserIDAssignmentAPI ( ) )
2023-06-04 14:57:16 -04:00
} , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryActivityPub ) )
2021-09-27 19:38:06 -04:00
}
2015-12-04 17:16:42 -05:00
2023-07-26 10:53:31 +08:00
// Misc (public accessible)
2023-06-04 14:57:16 -04:00
m . Group ( "" , func ( ) {
m . Get ( "/version" , misc . Version )
m . Get ( "/signing-key.gpg" , misc . SigningKey )
m . Post ( "/markup" , reqToken ( ) , bind ( api . MarkupOption { } ) , misc . Markup )
m . Post ( "/markdown" , reqToken ( ) , bind ( api . MarkdownOption { } ) , misc . Markdown )
m . Post ( "/markdown/raw" , reqToken ( ) , misc . MarkdownRaw )
m . Get ( "/gitignore/templates" , misc . ListGitignoresTemplates )
m . Get ( "/gitignore/templates/{name}" , misc . GetGitignoreTemplateInfo )
m . Get ( "/licenses" , misc . ListLicenseTemplates )
m . Get ( "/licenses/{name}" , misc . GetLicenseTemplateInfo )
m . Get ( "/label/templates" , misc . ListLabelTemplates )
m . Get ( "/label/templates/{name}" , misc . GetLabelTemplate )
m . Group ( "/settings" , func ( ) {
m . Get ( "/ui" , settings . GetGeneralUISettings )
m . Get ( "/api" , settings . GetGeneralAPISettings )
m . Get ( "/attachment" , settings . GetGeneralAttachmentSettings )
m . Get ( "/repository" , settings . GetGeneralRepoSettings )
} )
2023-07-26 10:53:31 +08:00
} )
2023-06-04 14:57:16 -04:00
// Notifications (requires 'notifications' scope)
2020-01-09 12:56:32 +01:00
m . Group ( "/notifications" , func ( ) {
m . Combo ( "" ) .
2023-09-05 16:43:34 +02:00
Get ( reqToken ( ) , notify . ListNotifications ) .
2023-06-28 22:26:56 +08:00
Put ( reqToken ( ) , notify . ReadNotifications )
2023-09-05 16:43:34 +02:00
m . Get ( "/new" , reqToken ( ) , notify . NewAvailable )
2021-01-26 23:36:53 +08:00
m . Combo ( "/threads/{id}" ) .
2023-09-05 16:43:34 +02:00
Get ( reqToken ( ) , notify . GetThread ) .
2023-06-28 22:26:56 +08:00
Patch ( reqToken ( ) , notify . ReadThread )
2023-06-04 14:57:16 -04:00
} , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryNotification ) )
2020-01-09 12:56:32 +01:00
2023-06-04 14:57:16 -04:00
// Users (requires user scope)
2015-12-04 17:16:42 -05:00
m . Group ( "/users" , func ( ) {
2021-03-11 13:40:54 +00:00
m . Get ( "/search" , reqExploreSignIn ( ) , user . Search )
2015-12-04 17:16:42 -05:00
2021-01-26 23:36:53 +08:00
m . Group ( "/{username}" , func ( ) {
2021-03-11 13:40:54 +00:00
m . Get ( "" , reqExploreSignIn ( ) , user . GetInfo )
2021-01-26 23:36:53 +08:00
if setting . Service . EnableUserHeatmap {
m . Get ( "/heatmap" , user . GetUserHeatmapData )
}
2015-12-04 17:16:42 -05:00
2023-06-04 14:57:16 -04:00
m . Get ( "/repos" , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryRepository ) , reqExploreSignIn ( ) , user . ListUserRepos )
2015-12-04 17:16:42 -05:00
m . Group ( "/tokens" , func ( ) {
m . Combo ( "" ) . Get ( user . ListAccessTokens ) .
2023-06-04 14:57:16 -04:00
Post ( bind ( api . CreateAccessTokenOption { } ) , reqToken ( ) , user . CreateAccessToken )
m . Combo ( "/{id}" ) . Delete ( reqToken ( ) , user . DeleteAccessToken )
2023-09-07 16:31:46 +08:00
} , reqBasicOrRevProxyAuth ( ) )
2023-04-04 21:35:31 +08:00
m . Get ( "/activities/feeds" , user . ListUserActivityFeeds )
2022-03-26 10:04:22 +01:00
} , context_service . UserAssignmentAPI ( ) )
2023-06-04 14:57:16 -04:00
} , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryUser ) )
2015-12-04 17:16:42 -05:00
2023-06-04 14:57:16 -04:00
// Users (requires user scope)
2015-12-04 17:16:42 -05:00
m . Group ( "/users" , func ( ) {
2021-01-26 23:36:53 +08:00
m . Group ( "/{username}" , func ( ) {
2015-12-05 17:13:13 -05:00
m . Get ( "/keys" , user . ListPublicKeys )
2017-03-16 02:27:35 +01:00
m . Get ( "/gpg_keys" , user . ListGPGKeys )
2015-12-21 04:24:11 -08:00
m . Get ( "/followers" , user . ListFollowers )
m . Group ( "/following" , func ( ) {
m . Get ( "" , user . ListFollowing )
2021-01-26 23:36:53 +08:00
m . Get ( "/{target}" , user . CheckFollowing )
2015-12-21 04:24:11 -08:00
} )
2016-11-14 17:33:58 -05:00
m . Get ( "/starred" , user . GetStarredRepos )
2016-12-23 20:53:11 -05:00
m . Get ( "/subscriptions" , user . GetWatchedRepos )
2022-03-26 10:04:22 +01:00
} , context_service . UserAssignmentAPI ( ) )
2023-06-04 14:57:16 -04:00
} , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryUser ) , reqToken ( ) )
2015-12-04 17:16:42 -05:00
2023-06-04 14:57:16 -04:00
// Users (requires user scope)
2015-12-04 17:16:42 -05:00
m . Group ( "/user" , func ( ) {
2016-08-11 15:29:39 -07:00
m . Get ( "" , user . GetAuthenticatedUser )
2021-06-23 21:58:44 +02:00
m . Group ( "/settings" , func ( ) {
2023-06-04 14:57:16 -04:00
m . Get ( "" , user . GetUserSettings )
m . Patch ( "" , bind ( api . UserSettingsOptions { } ) , user . UpdateUserSettings )
} , reqToken ( ) )
m . Combo ( "/emails" ) .
Get ( user . ListEmails ) .
Post ( bind ( api . CreateEmailOption { } ) , user . AddEmail ) .
Delete ( bind ( api . DeleteEmailOption { } ) , user . DeleteEmail )
2015-12-21 04:24:11 -08:00
2023-09-05 22:02:50 +08:00
// create or update a user's actions secrets
m . Group ( "/actions/secrets" , func ( ) {
m . Combo ( "/{secretname}" ) .
Put ( bind ( api . CreateOrUpdateSecretOption { } ) , user . CreateOrUpdateSecret ) .
Delete ( repo . DeleteSecret )
} )
2015-12-21 04:24:11 -08:00
m . Get ( "/followers" , user . ListMyFollowers )
m . Group ( "/following" , func ( ) {
m . Get ( "" , user . ListMyFollowing )
2022-03-26 10:04:22 +01:00
m . Group ( "/{username}" , func ( ) {
m . Get ( "" , user . CheckMyFollowing )
2023-06-04 14:57:16 -04:00
m . Put ( "" , user . Follow )
m . Delete ( "" , user . Unfollow )
2022-03-26 10:04:22 +01:00
} , context_service . UserAssignmentAPI ( ) )
2015-12-21 04:24:11 -08:00
} )
2023-01-17 16:46:03 -05:00
// (admin:public_key scope)
2015-12-04 17:16:42 -05:00
m . Group ( "/keys" , func ( ) {
2023-06-04 14:57:16 -04:00
m . Combo ( "" ) . Get ( user . ListMyPublicKeys ) .
Post ( bind ( api . CreateKeyOption { } ) , user . CreatePublicKey )
m . Combo ( "/{id}" ) . Get ( user . GetPublicKey ) .
Delete ( user . DeletePublicKey )
2015-12-04 17:16:42 -05:00
} )
2023-01-17 16:46:03 -05:00
// (admin:application scope)
2020-02-29 07:19:32 +01:00
m . Group ( "/applications" , func ( ) {
m . Combo ( "/oauth2" ) .
2023-06-04 14:57:16 -04:00
Get ( user . ListOauth2Applications ) .
Post ( bind ( api . CreateOAuth2ApplicationOptions { } ) , user . CreateOauth2Application )
2021-01-26 23:36:53 +08:00
m . Combo ( "/oauth2/{id}" ) .
2023-06-04 14:57:16 -04:00
Delete ( user . DeleteOauth2Application ) .
Patch ( bind ( api . CreateOAuth2ApplicationOptions { } ) , user . UpdateOauth2Application ) .
Get ( user . GetOauth2Application )
2023-01-17 16:46:03 -05:00
} )
2016-11-14 17:33:58 -05:00
2023-01-17 16:46:03 -05:00
// (admin:gpg_key scope)
2017-03-16 02:27:35 +01:00
m . Group ( "/gpg_keys" , func ( ) {
2023-06-04 14:57:16 -04:00
m . Combo ( "" ) . Get ( user . ListMyGPGKeys ) .
Post ( bind ( api . CreateGPGKeyOption { } ) , user . CreateGPGKey )
m . Combo ( "/{id}" ) . Get ( user . GetGPGKey ) .
Delete ( user . DeleteGPGKey )
2017-03-16 02:27:35 +01:00
} )
2023-06-04 14:57:16 -04:00
m . Get ( "/gpg_key_token" , user . GetVerificationToken )
m . Post ( "/gpg_key_verify" , bind ( api . VerifyGPGKeyOption { } ) , user . VerifyUserGPGKey )
2017-03-16 02:27:35 +01:00
2023-01-17 16:46:03 -05:00
// (repo scope)
2023-06-04 14:57:16 -04:00
m . Combo ( "/repos" , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryRepository ) ) . Get ( user . ListMyRepos ) .
2017-02-24 16:39:49 -05:00
Post ( bind ( api . CreateRepoOption { } ) , repo . Create )
2023-01-17 16:46:03 -05:00
// (repo scope)
2016-11-14 17:33:58 -05:00
m . Group ( "/starred" , func ( ) {
m . Get ( "" , user . GetMyStarredRepos )
2021-01-26 23:36:53 +08:00
m . Group ( "/{username}/{reponame}" , func ( ) {
2016-11-14 17:33:58 -05:00
m . Get ( "" , user . IsStarring )
m . Put ( "" , user . Star )
m . Delete ( "" , user . Unstar )
2016-12-29 08:17:32 -05:00
} , repoAssignment ( ) )
2023-06-04 14:57:16 -04:00
} , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryRepository ) )
m . Get ( "/times" , repo . ListMyTrackedTimes )
m . Get ( "/stopwatches" , repo . GetStopwatches )
m . Get ( "/subscriptions" , user . GetMyWatchedRepos )
m . Get ( "/teams" , org . ListUserTeams )
2023-03-10 15:28:32 +01:00
m . Group ( "/hooks" , func ( ) {
m . Combo ( "" ) . Get ( user . ListHooks ) .
Post ( bind ( api . CreateHookOption { } ) , user . CreateHook )
m . Combo ( "/{id}" ) . Get ( user . GetHook ) .
Patch ( bind ( api . EditHookOption { } ) , user . EditHook ) .
Delete ( user . DeleteHook )
2023-06-04 14:57:16 -04:00
} , reqWebhooksEnabled ( ) )
2023-06-30 01:22:55 +02:00
m . Group ( "/avatar" , func ( ) {
m . Post ( "" , bind ( api . UpdateUserAvatarOption { } ) , user . UpdateAvatar )
m . Delete ( "" , user . DeleteAvatar )
} , reqToken ( ) )
2023-06-04 14:57:16 -04:00
} , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryUser ) , reqToken ( ) )
2015-12-04 17:16:42 -05:00
2023-06-04 14:57:16 -04:00
// Repositories (requires repo scope, org scope)
m . Post ( "/org/{org}/repos" ,
tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryOrganization , auth_model . AccessTokenScopeCategoryRepository ) ,
reqToken ( ) ,
bind ( api . CreateRepoOption { } ) ,
repo . CreateOrgRepoDeprecated )
2020-01-09 17:40:01 +01:00
2023-06-04 14:57:16 -04:00
// requires repo scope
m . Combo ( "/repositories/{id}" , reqToken ( ) , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryRepository ) ) . Get ( repo . GetByID )
2015-12-04 17:16:42 -05:00
2023-06-04 14:57:16 -04:00
// Repos (requires repo scope)
2015-12-04 17:16:42 -05:00
m . Group ( "/repos" , func ( ) {
m . Get ( "/search" , repo . Search )
2023-01-17 16:46:03 -05:00
// (repo scope)
2023-06-04 14:57:16 -04:00
m . Post ( "/migrate" , reqToken ( ) , bind ( api . MigrateRepoOptions { } ) , repo . Migrate )
2015-12-04 17:16:42 -05:00
2021-01-26 23:36:53 +08:00
m . Group ( "/{username}/{reponame}" , func ( ) {
2018-11-28 19:26:14 +08:00
m . Combo ( "" ) . Get ( reqAnyRepoReader ( ) , repo . Get ) .
2023-06-04 14:57:16 -04:00
Delete ( reqToken ( ) , reqOwner ( ) , repo . Delete ) .
Patch ( reqToken ( ) , reqAdmin ( ) , bind ( api . EditRepoOption { } ) , repo . Edit )
m . Post ( "/generate" , reqToken ( ) , reqRepoReader ( unit . TypeCode ) , bind ( api . GenerateRepoOption { } ) , repo . Generate )
2023-01-17 16:46:03 -05:00
m . Group ( "/transfer" , func ( ) {
m . Post ( "" , reqOwner ( ) , bind ( api . TransferRepoOption { } ) , repo . Transfer )
m . Post ( "/accept" , repo . AcceptTransfer )
m . Post ( "/reject" , repo . RejectTransfer )
2023-06-04 14:57:16 -04:00
} , reqToken ( ) )
2023-08-30 04:54:49 +08:00
m . Group ( "/actions/secrets" , func ( ) {
m . Combo ( "/{secretname}" ) .
2023-09-01 21:02:49 +08:00
Put ( reqToken ( ) , reqOwner ( ) , bind ( api . CreateOrUpdateSecretOption { } ) , repo . CreateOrUpdateSecret ) .
Delete ( reqToken ( ) , reqOwner ( ) , repo . DeleteSecret )
2023-08-30 04:54:49 +08:00
} )
2021-02-11 18:34:34 +01:00
m . Group ( "/hooks/git" , func ( ) {
2023-06-04 14:57:16 -04:00
m . Combo ( "" ) . Get ( repo . ListGitHooks )
2021-02-11 18:34:34 +01:00
m . Group ( "/{id}" , func ( ) {
2023-06-04 14:57:16 -04:00
m . Combo ( "" ) . Get ( repo . GetGitHook ) .
Patch ( bind ( api . EditGitHookOption { } ) , repo . EditGitHook ) .
Delete ( repo . DeleteGitHook )
2021-02-11 18:34:34 +01:00
} )
2023-06-04 14:57:16 -04:00
} , reqToken ( ) , reqAdmin ( ) , reqGitHook ( ) , context . ReferencesGitRepo ( true ) )
2016-07-16 19:08:38 -05:00
m . Group ( "/hooks" , func ( ) {
2023-06-04 14:57:16 -04:00
m . Combo ( "" ) . Get ( repo . ListHooks ) .
Post ( bind ( api . CreateHookOption { } ) , repo . CreateHook )
2021-01-26 23:36:53 +08:00
m . Group ( "/{id}" , func ( ) {
2023-06-04 14:57:16 -04:00
m . Combo ( "" ) . Get ( repo . GetHook ) .
Patch ( bind ( api . EditHookOption { } ) , repo . EditHook ) .
Delete ( repo . DeleteHook )
m . Post ( "/tests" , context . ReferencesGitRepo ( ) , context . RepoRefForAPI , repo . TestHook )
2018-04-28 23:21:33 -07:00
} )
2023-06-04 14:57:16 -04:00
} , reqToken ( ) , reqAdmin ( ) , reqWebhooksEnabled ( ) )
2016-12-26 02:37:01 -05:00
m . Group ( "/collaborators" , func ( ) {
2020-04-21 20:52:04 +05:30
m . Get ( "" , reqAnyRepoReader ( ) , repo . ListCollaborators )
2022-04-29 14:24:38 +02:00
m . Group ( "/{collaborator}" , func ( ) {
m . Combo ( "" ) . Get ( reqAnyRepoReader ( ) , repo . IsCollaborator ) .
Put ( reqAdmin ( ) , bind ( api . AddCollaboratorOption { } ) , repo . AddCollaborator ) .
Delete ( reqAdmin ( ) , repo . DeleteCollaborator )
m . Get ( "/permission" , repo . GetRepoPermissions )
2023-01-17 16:46:03 -05:00
} )
2023-06-04 14:57:16 -04:00
} , reqToken ( ) )
m . Get ( "/assignees" , reqToken ( ) , reqAnyRepoReader ( ) , repo . GetAssignees )
m . Get ( "/reviewers" , reqToken ( ) , reqAnyRepoReader ( ) , repo . GetReviewers )
2021-02-01 22:57:12 +01:00
m . Group ( "/teams" , func ( ) {
m . Get ( "" , reqAnyRepoReader ( ) , repo . ListTeams )
m . Combo ( "/{team}" ) . Get ( reqAnyRepoReader ( ) , repo . IsTeam ) .
Put ( reqAdmin ( ) , repo . AddTeam ) .
Delete ( reqAdmin ( ) , repo . DeleteTeam )
2023-06-04 14:57:16 -04:00
} , reqToken ( ) )
2022-04-21 17:17:57 +02:00
m . Get ( "/raw/*" , context . ReferencesGitRepo ( ) , context . RepoRefForAPI , reqRepoReader ( unit . TypeCode ) , repo . GetRawFile )
2022-06-04 15:17:53 +02:00
m . Get ( "/media/*" , context . ReferencesGitRepo ( ) , context . RepoRefForAPI , reqRepoReader ( unit . TypeCode ) , repo . GetRawFileOrLFS )
2021-11-10 03:57:58 +08:00
m . Get ( "/archive/*" , reqRepoReader ( unit . TypeCode ) , repo . GetArchive )
2016-12-30 20:15:45 -05:00
m . Combo ( "/forks" ) . Get ( repo . ListForks ) .
2023-06-04 14:57:16 -04:00
Post ( reqToken ( ) , reqRepoReader ( unit . TypeCode ) , bind ( api . CreateForkOption { } ) , repo . CreateFork )
2016-01-15 19:24:03 +01:00
m . Group ( "/branches" , func ( ) {
2022-04-21 17:17:57 +02:00
m . Get ( "" , repo . ListBranches )
m . Get ( "/*" , repo . GetBranch )
2023-06-04 14:57:16 -04:00
m . Delete ( "/*" , reqToken ( ) , reqRepoWriter ( unit . TypeCode ) , repo . DeleteBranch )
m . Post ( "" , reqToken ( ) , reqRepoWriter ( unit . TypeCode ) , bind ( api . CreateBranchRepoOption { } ) , repo . CreateBranch )
2022-04-21 17:17:57 +02:00
} , context . ReferencesGitRepo ( ) , reqRepoReader ( unit . TypeCode ) )
2020-02-13 00:19:35 +01:00
m . Group ( "/branch_protections" , func ( ) {
m . Get ( "" , repo . ListBranchProtections )
m . Post ( "" , bind ( api . CreateBranchProtectionOption { } ) , repo . CreateBranchProtection )
2021-01-26 23:36:53 +08:00
m . Group ( "/{name}" , func ( ) {
2020-02-13 00:19:35 +01:00
m . Get ( "" , repo . GetBranchProtection )
m . Patch ( "" , bind ( api . EditBranchProtectionOption { } ) , repo . EditBranchProtection )
m . Delete ( "" , repo . DeleteBranchProtection )
} )
2023-06-04 14:57:16 -04:00
} , reqToken ( ) , reqAdmin ( ) )
2019-02-07 20:00:52 +08:00
m . Group ( "/tags" , func ( ) {
m . Get ( "" , repo . ListTags )
2021-06-23 23:08:47 +02:00
m . Get ( "/*" , repo . GetTag )
2023-06-04 14:57:16 -04:00
m . Post ( "" , reqToken ( ) , reqRepoWriter ( unit . TypeCode ) , bind ( api . CreateTagOption { } ) , repo . CreateTag )
m . Delete ( "/*" , reqToken ( ) , repo . DeleteTag )
2021-11-10 03:57:58 +08:00
} , reqRepoReader ( unit . TypeCode ) , context . ReferencesGitRepo ( true ) )
2015-12-04 17:16:42 -05:00
m . Group ( "/keys" , func ( ) {
m . Combo ( "" ) . Get ( repo . ListDeployKeys ) .
Post ( bind ( api . CreateKeyOption { } ) , repo . CreateDeployKey )
2021-01-26 23:36:53 +08:00
m . Combo ( "/{id}" ) . Get ( repo . GetDeployKey ) .
2015-12-04 17:16:42 -05:00
Delete ( repo . DeleteDeploykey )
2023-06-04 14:57:16 -04:00
} , reqToken ( ) , reqAdmin ( ) )
2017-09-12 08:48:13 +02:00
m . Group ( "/times" , func ( ) {
m . Combo ( "" ) . Get ( repo . ListTrackedTimesByRepository )
2021-01-26 23:36:53 +08:00
m . Combo ( "/{timetrackingusername}" ) . Get ( repo . ListTrackedTimesByUser )
2023-06-04 14:57:16 -04:00
} , mustEnableIssues , reqToken ( ) )
2021-10-25 05:43:40 +02:00
m . Group ( "/wiki" , func ( ) {
m . Combo ( "/page/{pageName}" ) .
Get ( repo . GetWikiPage ) .
2023-06-04 14:57:16 -04:00
Patch ( mustNotBeArchived , reqToken ( ) , reqRepoWriter ( unit . TypeWiki ) , bind ( api . CreateWikiPageOptions { } ) , repo . EditWikiPage ) .
Delete ( mustNotBeArchived , reqToken ( ) , reqRepoWriter ( unit . TypeWiki ) , repo . DeleteWikiPage )
2021-10-25 05:43:40 +02:00
m . Get ( "/revisions/{pageName}" , repo . ListPageRevisions )
2023-06-04 14:57:16 -04:00
m . Post ( "/new" , reqToken ( ) , mustNotBeArchived , reqRepoWriter ( unit . TypeWiki ) , bind ( api . CreateWikiPageOptions { } ) , repo . NewWikiPage )
2021-10-25 05:43:40 +02:00
m . Get ( "/pages" , repo . ListWikiPages )
} , mustEnableWiki )
2023-06-04 14:57:16 -04:00
m . Post ( "/markup" , reqToken ( ) , bind ( api . MarkupOption { } ) , misc . Markup )
m . Post ( "/markdown" , reqToken ( ) , bind ( api . MarkdownOption { } ) , misc . Markdown )
m . Post ( "/markdown/raw" , reqToken ( ) , misc . MarkdownRaw )
2017-01-06 02:05:09 -05:00
m . Get ( "/stargazers" , repo . ListStargazers )
2017-01-06 22:13:02 -05:00
m . Get ( "/subscribers" , repo . ListSubscribers )
2016-12-23 20:53:11 -05:00
m . Group ( "/subscription" , func ( ) {
m . Get ( "" , user . IsWatching )
2023-06-04 14:57:16 -04:00
m . Put ( "" , reqToken ( ) , user . Watch )
m . Delete ( "" , reqToken ( ) , user . Unwatch )
2016-12-29 08:17:32 -05:00
} )
2016-12-31 11:51:22 -05:00
m . Group ( "/releases" , func ( ) {
m . Combo ( "" ) . Get ( repo . ListReleases ) .
2023-06-04 14:57:16 -04:00
Post ( reqToken ( ) , reqRepoWriter ( unit . TypeReleases ) , context . ReferencesGitRepo ( ) , bind ( api . CreateReleaseOption { } ) , repo . CreateRelease )
2023-01-26 17:33:47 +01:00
m . Combo ( "/latest" ) . Get ( repo . GetLatestRelease )
2021-01-26 23:36:53 +08:00
m . Group ( "/{id}" , func ( ) {
2018-03-06 02:22:16 +01:00
m . Combo ( "" ) . Get ( repo . GetRelease ) .
2023-06-04 14:57:16 -04:00
Patch ( reqToken ( ) , reqRepoWriter ( unit . TypeReleases ) , context . ReferencesGitRepo ( ) , bind ( api . EditReleaseOption { } ) , repo . EditRelease ) .
Delete ( reqToken ( ) , reqRepoWriter ( unit . TypeReleases ) , repo . DeleteRelease )
2018-03-06 02:22:16 +01:00
m . Group ( "/assets" , func ( ) {
m . Combo ( "" ) . Get ( repo . ListReleaseAttachments ) .
2023-06-04 14:57:16 -04:00
Post ( reqToken ( ) , reqRepoWriter ( unit . TypeReleases ) , repo . CreateReleaseAttachment )
2023-07-10 17:31:19 +08:00
m . Combo ( "/{attachment_id}" ) . Get ( repo . GetReleaseAttachment ) .
2023-06-04 14:57:16 -04:00
Patch ( reqToken ( ) , reqRepoWriter ( unit . TypeReleases ) , bind ( api . EditAttachmentOptions { } ) , repo . EditReleaseAttachment ) .
Delete ( reqToken ( ) , reqRepoWriter ( unit . TypeReleases ) , repo . DeleteReleaseAttachment )
2018-03-06 02:22:16 +01:00
} )
} )
2020-09-25 21:11:43 +02:00
m . Group ( "/tags" , func ( ) {
2021-01-26 23:36:53 +08:00
m . Combo ( "/{tag}" ) .
2021-02-07 19:32:18 +01:00
Get ( repo . GetReleaseByTag ) .
2023-06-04 14:57:16 -04:00
Delete ( reqToken ( ) , reqRepoWriter ( unit . TypeReleases ) , repo . DeleteReleaseByTag )
2020-09-25 21:11:43 +02:00
} )
2021-11-10 03:57:58 +08:00
} , reqRepoReader ( unit . TypeReleases ) )
2023-06-04 14:57:16 -04:00
m . Post ( "/mirror-sync" , reqToken ( ) , reqRepoWriter ( unit . TypeCode ) , repo . MirrorSync )
m . Post ( "/push_mirrors-sync" , reqAdmin ( ) , reqToken ( ) , repo . PushMirrorSync )
2022-07-30 18:45:59 +02:00
m . Group ( "/push_mirrors" , func ( ) {
m . Combo ( "" ) . Get ( repo . ListPushMirrors ) .
Post ( bind ( api . CreatePushMirrorOption { } ) , repo . AddPushMirror )
m . Combo ( "/{name}" ) .
Delete ( repo . DeletePushMirrorByRemoteName ) .
Get ( repo . GetPushMirrorByName )
2023-06-04 14:57:16 -04:00
} , reqAdmin ( ) , reqToken ( ) )
2022-07-30 18:45:59 +02:00
2022-04-21 17:17:57 +02:00
m . Get ( "/editorconfig/{filename}" , context . ReferencesGitRepo ( ) , context . RepoRefForAPI , reqRepoReader ( unit . TypeCode ) , repo . GetEditorconfig )
2016-12-02 12:10:39 +01:00
m . Group ( "/pulls" , func ( ) {
2021-01-26 23:36:53 +08:00
m . Combo ( "" ) . Get ( repo . ListPullRequests ) .
2023-06-04 14:57:16 -04:00
Post ( reqToken ( ) , mustNotBeArchived , bind ( api . CreatePullRequestOption { } ) , repo . CreatePullRequest )
2023-05-25 15:17:19 +02:00
m . Get ( "/pinned" , repo . ListPinnedPullRequests )
2021-01-26 23:36:53 +08:00
m . Group ( "/{index}" , func ( ) {
2017-07-11 21:23:41 -04:00
m . Combo ( "" ) . Get ( repo . GetPullRequest ) .
2023-06-04 14:57:16 -04:00
Patch ( reqToken ( ) , bind ( api . EditPullRequestOption { } ) , repo . EditPullRequest )
2021-09-22 01:04:53 +02:00
m . Get ( ".{diffType:diff|patch}" , repo . DownloadPullDiffOrPatch )
2023-06-04 14:57:16 -04:00
m . Post ( "/update" , reqToken ( ) , repo . UpdatePullRequest )
2021-07-02 14:19:57 +02:00
m . Get ( "/commits" , repo . GetPullRequestCommits )
2022-09-29 04:27:20 +02:00
m . Get ( "/files" , repo . GetPullRequestFiles )
2017-07-11 21:23:41 -04:00
m . Combo ( "/merge" ) . Get ( repo . IsPullRequestMerged ) .
2023-06-04 14:57:16 -04:00
Post ( reqToken ( ) , mustNotBeArchived , bind ( forms . MergePullRequestForm { } ) , repo . MergePullRequest ) .
Delete ( reqToken ( ) , mustNotBeArchived , repo . CancelScheduledAutoMerge )
2020-05-02 02:20:51 +02:00
m . Group ( "/reviews" , func ( ) {
m . Combo ( "" ) .
Get ( repo . ListPullReviews ) .
2023-06-04 14:57:16 -04:00
Post ( reqToken ( ) , bind ( api . CreatePullReviewOptions { } ) , repo . CreatePullReview )
2021-01-26 23:36:53 +08:00
m . Group ( "/{id}" , func ( ) {
2020-05-02 02:20:51 +02:00
m . Combo ( "" ) .
Get ( repo . GetPullReview ) .
2023-06-04 14:57:16 -04:00
Delete ( reqToken ( ) , repo . DeletePullReview ) .
Post ( reqToken ( ) , bind ( api . SubmitPullReviewOptions { } ) , repo . SubmitPullReview )
2020-05-02 02:20:51 +02:00
m . Combo ( "/comments" ) .
Get ( repo . GetPullReviewComments )
2023-06-04 14:57:16 -04:00
m . Post ( "/dismissals" , reqToken ( ) , bind ( api . DismissPullReviewOptions { } ) , repo . DismissPullReview )
m . Post ( "/undismissals" , reqToken ( ) , repo . UnDismissPullReview )
2020-05-02 02:20:51 +02:00
} )
} )
2023-06-04 14:57:16 -04:00
m . Combo ( "/requested_reviewers" , reqToken ( ) ) .
2023-01-17 16:46:03 -05:00
Delete ( bind ( api . PullReviewRequestOptions { } ) , repo . DeleteReviewRequests ) .
Post ( bind ( api . PullReviewRequestOptions { } ) , repo . CreateReviewRequests )
2016-12-02 12:10:39 +01:00
} )
2022-04-21 17:17:57 +02:00
} , mustAllowPulls , reqRepoReader ( unit . TypeCode ) , context . ReferencesGitRepo ( ) )
2017-04-21 13:32:31 +02:00
m . Group ( "/statuses" , func ( ) {
2021-01-26 23:36:53 +08:00
m . Combo ( "/{sha}" ) . Get ( repo . GetCommitStatuses ) .
2023-06-04 14:57:16 -04:00
Post ( reqToken ( ) , reqRepoWriter ( unit . TypeCode ) , bind ( api . CreateStatusOption { } ) , repo . NewCommitStatus )
2021-11-10 03:57:58 +08:00
} , reqRepoReader ( unit . TypeCode ) )
2019-08-26 16:09:10 +02:00
m . Group ( "/commits" , func ( ) {
2022-04-21 17:17:57 +02:00
m . Get ( "" , context . ReferencesGitRepo ( ) , repo . GetAllCommits )
2021-01-26 23:36:53 +08:00
m . Group ( "/{ref}" , func ( ) {
2019-08-26 16:09:10 +02:00
m . Get ( "/status" , repo . GetCombinedCommitStatusByRef )
m . Get ( "/statuses" , repo . GetCommitStatusesByRef )
2022-04-30 16:32:01 +02:00
} , context . ReferencesGitRepo ( ) )
2021-11-10 03:57:58 +08:00
} , reqRepoReader ( unit . TypeCode ) )
2018-11-27 23:52:20 +02:00
m . Group ( "/git" , func ( ) {
2019-02-03 11:35:17 +08:00
m . Group ( "/commits" , func ( ) {
2022-04-21 17:17:57 +02:00
m . Get ( "/{sha}" , repo . GetSingleCommit )
2021-09-20 18:14:29 +02:00
m . Get ( "/{sha}.{diffType:diff|patch}" , repo . DownloadCommitDiffOrPatch )
2019-02-03 11:35:17 +08:00
} )
2018-11-27 23:52:20 +02:00
m . Get ( "/refs" , repo . GetGitAllRefs )
m . Get ( "/refs/*" , repo . GetGitRefs )
2022-04-21 17:17:57 +02:00
m . Get ( "/trees/{sha}" , repo . GetTree )
m . Get ( "/blobs/{sha}" , repo . GetBlob )
m . Get ( "/tags/{sha}" , repo . GetAnnotatedTag )
2021-08-11 06:31:40 +05:30
m . Get ( "/notes/{sha}" , repo . GetNote )
2023-01-15 14:33:25 +00:00
} , context . ReferencesGitRepo ( true ) , reqRepoReader ( unit . TypeCode ) )
2023-06-04 14:57:16 -04:00
m . Post ( "/diffpatch" , reqRepoWriter ( unit . TypeCode ) , reqToken ( ) , bind ( api . ApplyDiffPatchFileOptions { } ) , repo . ApplyDiffPatch )
2019-04-17 10:06:35 -06:00
m . Group ( "/contents" , func ( ) {
2019-06-29 16:51:10 -04:00
m . Get ( "" , repo . GetContentsList )
2023-06-04 14:57:16 -04:00
m . Post ( "" , reqToken ( ) , bind ( api . ChangeFilesOptions { } ) , reqRepoBranchWriter , repo . ChangeFiles )
2019-06-29 16:51:10 -04:00
m . Get ( "/*" , repo . GetContents )
2019-04-17 10:06:35 -06:00
m . Group ( "/*" , func ( ) {
2022-04-28 17:45:33 +02:00
m . Post ( "" , bind ( api . CreateFileOptions { } ) , reqRepoBranchWriter , repo . CreateFile )
m . Put ( "" , bind ( api . UpdateFileOptions { } ) , reqRepoBranchWriter , repo . UpdateFile )
m . Delete ( "" , bind ( api . DeleteFileOptions { } ) , reqRepoBranchWriter , repo . DeleteFile )
2023-06-04 14:57:16 -04:00
} , reqToken ( ) )
2021-11-10 03:57:58 +08:00
} , reqRepoReader ( unit . TypeCode ) )
2019-10-16 14:42:42 +01:00
m . Get ( "/signing-key.gpg" , misc . SigningKey )
2019-09-03 17:46:24 +02:00
m . Group ( "/topics" , func ( ) {
m . Combo ( "" ) . Get ( repo . ListTopics ) .
2023-06-04 14:57:16 -04:00
Put ( reqToken ( ) , reqAdmin ( ) , bind ( api . RepoTopicOptions { } ) , repo . UpdateTopics )
2021-01-26 23:36:53 +08:00
m . Group ( "/{topic}" , func ( ) {
2023-06-04 14:57:16 -04:00
m . Combo ( "" ) . Put ( reqToken ( ) , repo . AddTopic ) .
Delete ( reqToken ( ) , repo . DeleteTopic )
2019-09-03 17:46:24 +02:00
} , reqAdmin ( ) )
} , reqAnyRepoReader ( ) )
2022-04-21 17:17:57 +02:00
m . Get ( "/issue_templates" , context . ReferencesGitRepo ( ) , repo . GetIssueTemplates )
2023-03-28 20:22:07 +02:00
m . Get ( "/issue_config" , context . ReferencesGitRepo ( ) , repo . GetIssueConfig )
m . Get ( "/issue_config/validate" , context . ReferencesGitRepo ( ) , repo . ValidateIssueConfig )
2021-11-10 03:57:58 +08:00
m . Get ( "/languages" , reqRepoReader ( unit . TypeCode ) , repo . GetLanguages )
2023-04-04 21:35:31 +08:00
m . Get ( "/activities/feeds" , repo . ListRepoActivityFeeds )
2023-05-25 15:17:19 +02:00
m . Get ( "/new_pin_allowed" , repo . AreNewIssuePinsAllowed )
2023-06-30 01:22:55 +02:00
m . Group ( "/avatar" , func ( ) {
m . Post ( "" , bind ( api . UpdateRepoAvatarOption { } ) , repo . UpdateAvatar )
m . Delete ( "" , repo . DeleteAvatar )
} , reqAdmin ( ) , reqToken ( ) )
2016-08-04 17:08:01 -07:00
} , repoAssignment ( ) )
2023-06-04 14:57:16 -04:00
} , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryRepository ) )
// Notifications (requires notifications scope)
m . Group ( "/repos" , func ( ) {
m . Group ( "/{username}/{reponame}" , func ( ) {
m . Combo ( "/notifications" , reqToken ( ) ) .
Get ( notify . ListRepoNotifications ) .
Put ( notify . ReadRepoNotifications )
} , repoAssignment ( ) )
} , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryNotification ) )
// Issue (requires issue scope)
m . Group ( "/repos" , func ( ) {
m . Get ( "/issues/search" , repo . SearchIssues )
m . Group ( "/{username}/{reponame}" , func ( ) {
m . Group ( "/issues" , func ( ) {
m . Combo ( "" ) . Get ( repo . ListIssues ) .
Post ( reqToken ( ) , mustNotBeArchived , bind ( api . CreateIssueOption { } ) , repo . CreateIssue )
m . Get ( "/pinned" , repo . ListPinnedIssues )
m . Group ( "/comments" , func ( ) {
m . Get ( "" , repo . ListRepoIssueComments )
m . Group ( "/{id}" , func ( ) {
m . Combo ( "" ) .
Get ( repo . GetIssueComment ) .
Patch ( mustNotBeArchived , reqToken ( ) , bind ( api . EditIssueCommentOption { } ) , repo . EditIssueComment ) .
Delete ( reqToken ( ) , repo . DeleteIssueComment )
m . Combo ( "/reactions" ) .
Get ( repo . GetIssueCommentReactions ) .
Post ( reqToken ( ) , bind ( api . EditReactionOption { } ) , repo . PostIssueCommentReaction ) .
Delete ( reqToken ( ) , bind ( api . EditReactionOption { } ) , repo . DeleteIssueCommentReaction )
m . Group ( "/assets" , func ( ) {
m . Combo ( "" ) .
Get ( repo . ListIssueCommentAttachments ) .
Post ( reqToken ( ) , mustNotBeArchived , repo . CreateIssueCommentAttachment )
2023-07-10 17:31:19 +08:00
m . Combo ( "/{attachment_id}" ) .
2023-06-04 14:57:16 -04:00
Get ( repo . GetIssueCommentAttachment ) .
Patch ( reqToken ( ) , mustNotBeArchived , bind ( api . EditAttachmentOptions { } ) , repo . EditIssueCommentAttachment ) .
Delete ( reqToken ( ) , mustNotBeArchived , repo . DeleteIssueCommentAttachment )
} , mustEnableAttachments )
} )
} )
m . Group ( "/{index}" , func ( ) {
m . Combo ( "" ) . Get ( repo . GetIssue ) .
Patch ( reqToken ( ) , bind ( api . EditIssueOption { } ) , repo . EditIssue ) .
Delete ( reqToken ( ) , reqAdmin ( ) , context . ReferencesGitRepo ( ) , repo . DeleteIssue )
m . Group ( "/comments" , func ( ) {
m . Combo ( "" ) . Get ( repo . ListIssueComments ) .
Post ( reqToken ( ) , mustNotBeArchived , bind ( api . CreateIssueCommentOption { } ) , repo . CreateIssueComment )
m . Combo ( "/{id}" , reqToken ( ) ) . Patch ( bind ( api . EditIssueCommentOption { } ) , repo . EditIssueCommentDeprecated ) .
Delete ( repo . DeleteIssueCommentDeprecated )
} )
m . Get ( "/timeline" , repo . ListIssueCommentsAndTimeline )
m . Group ( "/labels" , func ( ) {
m . Combo ( "" ) . Get ( repo . ListIssueLabels ) .
Post ( reqToken ( ) , bind ( api . IssueLabelsOption { } ) , repo . AddIssueLabels ) .
Put ( reqToken ( ) , bind ( api . IssueLabelsOption { } ) , repo . ReplaceIssueLabels ) .
Delete ( reqToken ( ) , repo . ClearIssueLabels )
m . Delete ( "/{id}" , reqToken ( ) , repo . DeleteIssueLabel )
} )
m . Group ( "/times" , func ( ) {
m . Combo ( "" ) .
Get ( repo . ListTrackedTimes ) .
Post ( bind ( api . AddTimeOption { } ) , repo . AddTime ) .
Delete ( repo . ResetIssueTime )
m . Delete ( "/{id}" , repo . DeleteTime )
} , reqToken ( ) )
m . Combo ( "/deadline" ) . Post ( reqToken ( ) , bind ( api . EditDeadlineOption { } ) , repo . UpdateIssueDeadline )
m . Group ( "/stopwatch" , func ( ) {
m . Post ( "/start" , repo . StartIssueStopwatch )
m . Post ( "/stop" , repo . StopIssueStopwatch )
m . Delete ( "/delete" , repo . DeleteIssueStopwatch )
} , reqToken ( ) )
m . Group ( "/subscriptions" , func ( ) {
m . Get ( "" , repo . GetIssueSubscribers )
m . Get ( "/check" , reqToken ( ) , repo . CheckIssueSubscription )
m . Put ( "/{user}" , reqToken ( ) , repo . AddIssueSubscription )
m . Delete ( "/{user}" , reqToken ( ) , repo . DelIssueSubscription )
} )
m . Combo ( "/reactions" ) .
Get ( repo . GetIssueReactions ) .
Post ( reqToken ( ) , bind ( api . EditReactionOption { } ) , repo . PostIssueReaction ) .
Delete ( reqToken ( ) , bind ( api . EditReactionOption { } ) , repo . DeleteIssueReaction )
m . Group ( "/assets" , func ( ) {
m . Combo ( "" ) .
Get ( repo . ListIssueAttachments ) .
Post ( reqToken ( ) , mustNotBeArchived , repo . CreateIssueAttachment )
2023-07-10 17:31:19 +08:00
m . Combo ( "/{attachment_id}" ) .
2023-06-04 14:57:16 -04:00
Get ( repo . GetIssueAttachment ) .
Patch ( reqToken ( ) , mustNotBeArchived , bind ( api . EditAttachmentOptions { } ) , repo . EditIssueAttachment ) .
Delete ( reqToken ( ) , mustNotBeArchived , repo . DeleteIssueAttachment )
} , mustEnableAttachments )
m . Combo ( "/dependencies" ) .
Get ( repo . GetIssueDependencies ) .
Post ( reqToken ( ) , mustNotBeArchived , bind ( api . IssueMeta { } ) , repo . CreateIssueDependency ) .
Delete ( reqToken ( ) , mustNotBeArchived , bind ( api . IssueMeta { } ) , repo . RemoveIssueDependency )
m . Combo ( "/blocks" ) .
Get ( repo . GetIssueBlocks ) .
Post ( reqToken ( ) , bind ( api . IssueMeta { } ) , repo . CreateIssueBlocking ) .
Delete ( reqToken ( ) , bind ( api . IssueMeta { } ) , repo . RemoveIssueBlocking )
m . Group ( "/pin" , func ( ) {
m . Combo ( "" ) .
Post ( reqToken ( ) , reqAdmin ( ) , repo . PinIssue ) .
Delete ( reqToken ( ) , reqAdmin ( ) , repo . UnpinIssue )
m . Patch ( "/{position}" , reqToken ( ) , reqAdmin ( ) , repo . MoveIssuePin )
} )
} )
} , mustEnableIssuesOrPulls )
m . Group ( "/labels" , func ( ) {
m . Combo ( "" ) . Get ( repo . ListLabels ) .
Post ( reqToken ( ) , reqRepoWriter ( unit . TypeIssues , unit . TypePullRequests ) , bind ( api . CreateLabelOption { } ) , repo . CreateLabel )
m . Combo ( "/{id}" ) . Get ( repo . GetLabel ) .
Patch ( reqToken ( ) , reqRepoWriter ( unit . TypeIssues , unit . TypePullRequests ) , bind ( api . EditLabelOption { } ) , repo . EditLabel ) .
Delete ( reqToken ( ) , reqRepoWriter ( unit . TypeIssues , unit . TypePullRequests ) , repo . DeleteLabel )
} )
m . Group ( "/milestones" , func ( ) {
m . Combo ( "" ) . Get ( repo . ListMilestones ) .
Post ( reqToken ( ) , reqRepoWriter ( unit . TypeIssues , unit . TypePullRequests ) , bind ( api . CreateMilestoneOption { } ) , repo . CreateMilestone )
m . Combo ( "/{id}" ) . Get ( repo . GetMilestone ) .
Patch ( reqToken ( ) , reqRepoWriter ( unit . TypeIssues , unit . TypePullRequests ) , bind ( api . EditMilestoneOption { } ) , repo . EditMilestone ) .
Delete ( reqToken ( ) , reqRepoWriter ( unit . TypeIssues , unit . TypePullRequests ) , repo . DeleteMilestone )
} )
} , repoAssignment ( ) )
} , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryIssue ) )
2015-12-04 17:16:42 -05:00
2022-11-12 18:59:15 +00:00
// NOTE: these are Gitea package management API - see packages.CommonRoutes and packages.DockerContainerRoutes for endpoints that implement package manager APIs
2022-03-30 10:42:47 +02:00
m . Group ( "/packages/{username}" , func ( ) {
m . Group ( "/{type}/{name}/{version}" , func ( ) {
2023-06-04 14:57:16 -04:00
m . Get ( "" , reqToken ( ) , packages . GetPackage )
m . Delete ( "" , reqToken ( ) , reqPackageAccess ( perm . AccessModeWrite ) , packages . DeletePackage )
m . Get ( "/files" , reqToken ( ) , packages . ListPackageFiles )
2022-03-30 10:42:47 +02:00
} )
2023-06-04 14:57:16 -04:00
m . Get ( "/" , reqToken ( ) , packages . ListPackages )
} , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryPackage ) , context_service . UserAssignmentAPI ( ) , context . PackageAssignmentAPI ( ) , reqPackageAccess ( perm . AccessModeRead ) )
2022-03-30 10:42:47 +02:00
2015-12-17 02:28:47 -05:00
// Organizations
2023-06-04 14:57:16 -04:00
m . Get ( "/user/orgs" , reqToken ( ) , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryUser , auth_model . AccessTokenScopeCategoryOrganization ) , org . ListMyOrgs )
2021-10-12 12:47:19 +02:00
m . Group ( "/users/{username}/orgs" , func ( ) {
2023-06-04 14:57:16 -04:00
m . Get ( "" , reqToken ( ) , org . ListUserOrgs )
m . Get ( "/{org}/permissions" , reqToken ( ) , org . GetUserOrgsPermissions )
} , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryUser , auth_model . AccessTokenScopeCategoryOrganization ) , context_service . UserAssignmentAPI ( ) )
m . Post ( "/orgs" , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryOrganization ) , reqToken ( ) , bind ( api . CreateOrgOption { } ) , org . Create )
m . Get ( "/orgs" , org . GetAll , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryOrganization ) )
2021-01-26 23:36:53 +08:00
m . Group ( "/orgs/{org}" , func ( ) {
2023-04-21 11:39:03 -04:00
m . Combo ( "" ) . Get ( org . Get ) .
2023-06-04 14:57:16 -04:00
Patch ( reqToken ( ) , reqOrgOwnership ( ) , bind ( api . EditOrgOption { } ) , org . Edit ) .
Delete ( reqToken ( ) , reqOrgOwnership ( ) , org . Delete )
2023-04-21 11:39:03 -04:00
m . Combo ( "/repos" ) . Get ( user . ListOrgRepos ) .
2023-06-04 14:57:16 -04:00
Post ( reqToken ( ) , bind ( api . CreateRepoOption { } ) , repo . CreateOrgRepo )
2017-01-19 19:31:46 -07:00
m . Group ( "/members" , func ( ) {
2023-06-04 14:57:16 -04:00
m . Get ( "" , reqToken ( ) , org . ListMembers )
m . Combo ( "/{username}" ) . Get ( reqToken ( ) , org . IsMember ) .
Delete ( reqToken ( ) , reqOrgOwnership ( ) , org . DeleteMember )
2017-01-19 19:31:46 -07:00
} )
2023-08-15 20:32:43 +08:00
m . Group ( "/actions/secrets" , func ( ) {
m . Get ( "" , reqToken ( ) , reqOrgOwnership ( ) , org . ListActionsSecrets )
2023-08-24 10:07:00 +08:00
m . Combo ( "/{secretname}" ) .
2023-08-30 04:54:49 +08:00
Put ( reqToken ( ) , reqOrgOwnership ( ) , bind ( api . CreateOrUpdateSecretOption { } ) , org . CreateOrUpdateSecret ) .
2023-09-01 21:02:49 +08:00
Delete ( reqToken ( ) , reqOrgOwnership ( ) , org . DeleteSecret )
2023-08-15 20:32:43 +08:00
} )
2017-01-19 19:31:46 -07:00
m . Group ( "/public_members" , func ( ) {
2023-04-21 11:39:03 -04:00
m . Get ( "" , org . ListPublicMembers )
m . Combo ( "/{username}" ) . Get ( org . IsPublicMember ) .
2023-06-04 14:57:16 -04:00
Put ( reqToken ( ) , reqOrgMembership ( ) , org . PublicizeMember ) .
Delete ( reqToken ( ) , reqOrgMembership ( ) , org . ConcealMember )
2017-01-19 19:31:46 -07:00
} )
2019-10-01 07:32:28 +02:00
m . Group ( "/teams" , func ( ) {
2023-06-04 14:57:16 -04:00
m . Get ( "" , reqToken ( ) , org . ListTeams )
m . Post ( "" , reqToken ( ) , reqOrgOwnership ( ) , bind ( api . CreateTeamOption { } ) , org . CreateTeam )
m . Get ( "/search" , reqToken ( ) , org . SearchTeam )
2023-01-17 16:46:03 -05:00
} , reqOrgMembership ( ) )
2020-04-01 00:14:46 -04:00
m . Group ( "/labels" , func ( ) {
2023-04-21 11:39:03 -04:00
m . Get ( "" , org . ListLabels )
2023-06-04 14:57:16 -04:00
m . Post ( "" , reqToken ( ) , reqOrgOwnership ( ) , bind ( api . CreateLabelOption { } ) , org . CreateLabel )
m . Combo ( "/{id}" ) . Get ( reqToken ( ) , org . GetLabel ) .
Patch ( reqToken ( ) , reqOrgOwnership ( ) , bind ( api . EditLabelOption { } ) , org . EditLabel ) .
Delete ( reqToken ( ) , reqOrgOwnership ( ) , org . DeleteLabel )
2020-04-01 00:14:46 -04:00
} )
2016-12-06 23:36:28 -05:00
m . Group ( "/hooks" , func ( ) {
m . Combo ( "" ) . Get ( org . ListHooks ) .
Post ( bind ( api . CreateHookOption { } ) , org . CreateHook )
2021-01-26 23:36:53 +08:00
m . Combo ( "/{id}" ) . Get ( org . GetHook ) .
2019-07-03 13:31:29 +08:00
Patch ( bind ( api . EditHookOption { } ) , org . EditHook ) .
Delete ( org . DeleteHook )
2023-06-04 14:57:16 -04:00
} , reqToken ( ) , reqOrgOwnership ( ) , reqWebhooksEnabled ( ) )
2023-06-30 01:22:55 +02:00
m . Group ( "/avatar" , func ( ) {
m . Post ( "" , bind ( api . UpdateUserAvatarOption { } ) , org . UpdateAvatar )
m . Delete ( "" , org . DeleteAvatar )
} , reqToken ( ) , reqOrgOwnership ( ) )
2023-04-04 21:35:31 +08:00
m . Get ( "/activities/feeds" , org . ListOrgActivityFeeds )
2023-06-04 14:57:16 -04:00
} , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryOrganization ) , orgAssignment ( true ) )
2021-01-26 23:36:53 +08:00
m . Group ( "/teams/{teamid}" , func ( ) {
2023-06-04 14:57:16 -04:00
m . Combo ( "" ) . Get ( reqToken ( ) , org . GetTeam ) .
Patch ( reqToken ( ) , reqOrgOwnership ( ) , bind ( api . EditTeamOption { } ) , org . EditTeam ) .
Delete ( reqToken ( ) , reqOrgOwnership ( ) , org . DeleteTeam )
2017-01-19 22:16:10 -07:00
m . Group ( "/members" , func ( ) {
2023-06-04 14:57:16 -04:00
m . Get ( "" , reqToken ( ) , org . GetTeamMembers )
2021-01-26 23:36:53 +08:00
m . Combo ( "/{username}" ) .
2023-06-04 14:57:16 -04:00
Get ( reqToken ( ) , org . GetTeamMember ) .
Put ( reqToken ( ) , reqOrgOwnership ( ) , org . AddTeamMember ) .
Delete ( reqToken ( ) , reqOrgOwnership ( ) , org . RemoveTeamMember )
2017-01-19 22:16:10 -07:00
} )
m . Group ( "/repos" , func ( ) {
2023-06-04 14:57:16 -04:00
m . Get ( "" , reqToken ( ) , org . GetTeamRepos )
2021-01-26 23:36:53 +08:00
m . Combo ( "/{org}/{reponame}" ) .
2023-06-04 14:57:16 -04:00
Put ( reqToken ( ) , org . AddTeamRepository ) .
Delete ( reqToken ( ) , org . RemoveTeamRepository ) .
Get ( reqToken ( ) , org . GetTeamRepo )
2017-01-19 22:16:10 -07:00
} )
2023-04-04 21:35:31 +08:00
m . Get ( "/activities/feeds" , org . ListTeamActivityFeeds )
2023-06-04 14:57:16 -04:00
} , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryOrganization ) , orgAssignment ( false , true ) , reqToken ( ) , reqTeamMembership ( ) )
2015-12-17 02:28:47 -05:00
2015-12-05 17:13:13 -05:00
m . Group ( "/admin" , func ( ) {
2020-08-24 16:48:15 +01:00
m . Group ( "/cron" , func ( ) {
m . Get ( "" , admin . ListCronTasks )
2021-01-26 23:36:53 +08:00
m . Post ( "/{task}" , admin . PostCronTask )
2020-08-24 16:48:15 +01:00
} )
2019-01-24 04:00:19 +05:30
m . Get ( "/orgs" , admin . GetAllOrgs )
2015-12-05 17:13:13 -05:00
m . Group ( "/users" , func ( ) {
2023-03-15 19:53:01 +08:00
m . Get ( "" , admin . SearchUsers )
2015-12-05 17:13:13 -05:00
m . Post ( "" , bind ( api . CreateUserOption { } ) , admin . CreateUser )
2021-01-26 23:36:53 +08:00
m . Group ( "/{username}" , func ( ) {
2015-12-05 17:13:13 -05:00
m . Combo ( "" ) . Patch ( bind ( api . EditUserOption { } ) , admin . EditUser ) .
Delete ( admin . DeleteUser )
2017-12-06 12:27:10 +02:00
m . Group ( "/keys" , func ( ) {
m . Post ( "" , bind ( api . CreateKeyOption { } ) , admin . CreatePublicKey )
2021-01-26 23:36:53 +08:00
m . Delete ( "/{id}" , admin . DeleteUserPublicKey )
2017-12-06 12:27:10 +02:00
} )
2019-01-24 04:00:19 +05:30
m . Get ( "/orgs" , org . ListUserOrgs )
2015-12-17 02:28:47 -05:00
m . Post ( "/orgs" , bind ( api . CreateOrgOption { } ) , admin . CreateOrg )
2015-12-17 22:57:41 -05:00
m . Post ( "/repos" , bind ( api . CreateRepoOption { } ) , admin . CreateRepo )
2023-03-14 03:45:21 -04:00
m . Post ( "/rename" , bind ( api . RenameUserOption { } ) , admin . RenameUser )
2022-03-26 10:04:22 +01:00
} , context_service . UserAssignmentAPI ( ) )
2015-12-05 17:13:13 -05:00
} )
2023-03-14 03:54:40 -04:00
m . Group ( "/emails" , func ( ) {
m . Get ( "" , admin . GetAllEmails )
m . Get ( "/search" , admin . SearchEmail )
} )
2020-09-25 05:09:23 +01:00
m . Group ( "/unadopted" , func ( ) {
m . Get ( "" , admin . ListUnadoptedRepositories )
2021-01-26 23:36:53 +08:00
m . Post ( "/{username}/{reponame}" , admin . AdoptRepository )
m . Delete ( "/{username}/{reponame}" , admin . DeleteUnadoptedRepository )
2020-09-25 05:09:23 +01:00
} )
2023-01-29 02:12:10 +08:00
m . Group ( "/hooks" , func ( ) {
m . Combo ( "" ) . Get ( admin . ListHooks ) .
Post ( bind ( api . CreateHookOption { } ) , admin . CreateHook )
m . Combo ( "/{id}" ) . Get ( admin . GetHook ) .
Patch ( bind ( api . EditHookOption { } ) , admin . EditHook ) .
Delete ( admin . DeleteHook )
} )
2023-06-04 14:57:16 -04:00
} , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryAdmin ) , reqToken ( ) , reqSiteAdmin ( ) )
2018-04-11 10:51:44 +08:00
m . Group ( "/topics" , func ( ) {
m . Get ( "/search" , repo . TopicSearch )
2023-06-04 14:57:16 -04:00
} , tokenRequiresScopes ( auth_model . AccessTokenScopeCategoryRepository ) )
2021-01-26 23:36:53 +08:00
} , sudo ( ) )
return m
2019-05-13 08:38:53 -07:00
}
2021-01-26 23:36:53 +08:00
func securityHeaders ( ) func ( http . Handler ) http . Handler {
return func ( next http . Handler ) http . Handler {
return http . HandlerFunc ( func ( resp http . ResponseWriter , req * http . Request ) {
2019-05-13 08:38:53 -07:00
// CORB: https://www.chromium.org/Home/chromium-security/corb-for-developers
// http://stackoverflow.com/a/3146618/244009
2021-01-26 23:36:53 +08:00
resp . Header ( ) . Set ( "x-content-type-options" , "nosniff" )
next . ServeHTTP ( resp , req )
2019-05-13 08:38:53 -07:00
} )
}
2015-12-04 17:16:42 -05:00
}