blob: b850be04c581c4ed9a1d93f04498a0b65250982a [file] [log] [blame]
Nils Diewald2fe12e12015-03-06 16:47:06 +00001package Kalamar;
Nils Diewald5d1ffb42014-05-21 17:45:34 +00002use Mojo::Base 'Mojolicious';
Nils Diewalde2c83812014-11-11 21:13:18 +00003use Mojo::ByteStream 'b';
Akronc7656e92018-08-30 13:33:25 +02004use Mojo::URL;
Akronf65ad6c2017-02-01 14:36:38 +01005use Mojo::File;
Akron2c2ddbd2021-03-05 12:10:27 +01006use Mojo::JSON qw/decode_json encode_json/;
Akron0c4cd222019-07-19 16:33:34 +02007use Mojo::Util qw/url_escape deprecated slugify/;
Akron4c33c622018-11-12 13:43:27 +01008use List::Util 'none';
Nils Diewald5d1ffb42014-05-21 17:45:34 +00009
Nils Diewald709f52f2015-05-21 18:32:58 +000010# Minor version - may be patched from package.json
Akron3d68ac32022-01-04 14:40:30 +010011our $VERSION = '0.44';
Akronc7656e92018-08-30 13:33:25 +020012
13# Supported version of Backend API
14our $API_VERSION = '1.0';
Nils Diewald7cad8402014-07-08 17:06:56 +000015
Nils Diewald7148c6f2015-05-04 15:07:53 +000016# TODO: The FAQ-Page has a contact form for new questions
Nils Diewald709f52f2015-05-21 18:32:58 +000017# TODO: Embed query serialization
18# TODO: Embed collection statistics
19# TODO: Implement tab opener for matches and the tutorial
Nils Diewald709f52f2015-05-21 18:32:58 +000020# TODO: Implement a "projects" system
Nils Diewald7148c6f2015-05-04 15:07:53 +000021
Nils Diewald002e8fb2014-06-22 14:27:01 +000022# Start the application and register all routes and plugins
Nils Diewald5d1ffb42014-05-21 17:45:34 +000023sub startup {
24 my $self = shift;
25
Nils Diewalda944fab2015-04-08 21:02:04 +000026 # Set version based on package file
Nils Diewald709f52f2015-05-21 18:32:58 +000027 # This may introduce a SemVer patch number
Akronf65ad6c2017-02-01 14:36:38 +010028 my $pkg_path = $self->home->child('package.json');
29 if (-e $pkg_path->to_abs) {
30 my $pkg = $pkg_path->slurp;
31 $Kalamar::VERSION = decode_json($pkg)->{version};
32 };
Nils Diewalda944fab2015-04-08 21:02:04 +000033
Akron656c5d92015-11-13 21:17:03 +010034 # Lift maximum template cache
35 $self->renderer->cache->max_keys(200);
36
Nils Diewaldab4d3ca2015-04-17 01:48:43 +000037 # Add additional plugin path
38 push(@{$self->plugins->namespaces}, __PACKAGE__ . '::Plugin');
39
Nils Diewaldfccfbcb2015-04-29 20:48:19 +000040 # Set secrets for signed cookies
Akron2c2ddbd2021-03-05 12:10:27 +010041 my $secret_file = $self->home->rel_file('kalamar.secret.json');
42
43 # Support old secrets file
44 # This is deprecated 2021-03-05
45 if (-e (my $old_secret = $self->home->child('kalamar.secret'))) {
Nils Diewalda79b2682015-05-18 18:34:06 +000046
47 # Load file and split lines for multiple secrets
Akron2c2ddbd2021-03-05 12:10:27 +010048 my $secrets = [b($old_secret->slurp)->split("\n")];
Akron3d68ac32022-01-04 14:40:30 +010049
Akron2c2ddbd2021-03-05 12:10:27 +010050 $self->secrets($secrets);
51
Akron3d68ac32022-01-04 14:40:30 +010052 for (@$secrets) {
53 if (length($secrets) > 22) {
54 $self->log->warn(
55 'Unable to automatically switch to Autosecrets, as secret is too long (> 22 chars)'
56 );
57 goto CONF;
58 };
59 }
60
Akron2c2ddbd2021-03-05 12:10:27 +010061 eval {
62 $secret_file->spurt(encode_json(@$secrets));
63 $secret_file->chmod(0600);
64 if (-w $secret_file) {
65 $self->log->warn(
66 "Please delete $old_secret file " .
67 "- $secret_file was created instead"
68 );
69 }
70 };
71 if ($@) {
72 $self->log->error("Please make $secret_file accessible");
73 };
Nils Diewald4347ee92015-05-04 20:32:48 +000074 }
Nils Diewald709f52f2015-05-21 18:32:58 +000075
76 # File not found ...
77 # Kalamar needs secrets in a file to be easily deployable
78 # and publishable at the same time.
Nils Diewald4347ee92015-05-04 20:32:48 +000079 else {
Akron2c2ddbd2021-03-05 12:10:27 +010080 $self->plugin(AutoSecrets => {
81 path => $secret_file
82 });
Nils Diewald19402142015-04-30 15:44:52 +000083 };
Nils Diewaldfccfbcb2015-04-29 20:48:19 +000084
Akron3d68ac32022-01-04 14:40:30 +010085 CONF:
Akron2c2ddbd2021-03-05 12:10:27 +010086
Akroncba9f322016-02-29 23:12:45 +010087 # Configuration framework
Akron09a567c2016-04-11 22:49:20 +030088 $self->plugin('Config');
Nils Diewald709f52f2015-05-21 18:32:58 +000089
Akron741b2b12017-04-13 22:15:59 +020090 $self->log->info('Mode is ' . $self->mode);
91
Akron63d963b2019-07-05 15:35:51 +020092 # Get configuration
Akron47787ca2017-05-17 16:00:10 +020093 my $conf = $self->config('Kalamar');
Akron63d963b2019-07-05 15:35:51 +020094 unless ($conf) {
95 $self->config(Kalamar => {});
96 $conf = $self->config('Kalamar');
97 };
98
99 # Check for API endpoint and set the endpoint accordingly
100 if ($conf->{api}) {
101
102 # The api endpoint should be defined as a separated path
103 # and version string
104 $self->log->warn(
105 'Kalamar.api is no longer supported in configurations '.
106 'in favor of Kalamar.api_path'
107 );
108 };
109
Akron0c4cd222019-07-19 16:33:34 +0200110 $self->sessions->cookie_name('kalamar');
111
112 # Require HTTPS
113 if ($conf->{https_only}) {
114
115 # ... for cookie transport
116 $self->sessions->secure(1);
Akron1bee5a42021-01-13 17:44:18 +0100117
Akron26244a72021-04-28 00:17:56 +0200118 # Temporary for session riding
119 $self->sessions->samesite('None');
120
Akron1bee5a42021-01-13 17:44:18 +0100121 # For all pages
122 $self->hook(
123 before_dispatch => sub {
124 shift->res->headers->header('Strict-Transport-Security' => 'max-age=3600; includeSubDomains');
125 }
126 );
Akron0c4cd222019-07-19 16:33:34 +0200127 };
128
129 # Run the app from a subdirectory
Akron63d963b2019-07-05 15:35:51 +0200130 if ($conf->{proxy_prefix}) {
Akron47787ca2017-05-17 16:00:10 +0200131
Akronf3d856c2017-06-21 17:07:40 +0200132 for ($self->sessions) {
Akron1a394722017-06-21 16:25:30 +0200133 $_->cookie_path($conf->{proxy_prefix});
Akron0c4cd222019-07-19 16:33:34 +0200134 $_->cookie_name('kalamar-' . slugify($conf->{proxy_prefix}));
Akron1a394722017-06-21 16:25:30 +0200135 };
136
Akron47787ca2017-05-17 16:00:10 +0200137 # Set prefix in stash
138 $self->defaults(prefix => $conf->{proxy_prefix});
139
140 # Create base path
141 $self->hook(
142 before_dispatch => sub {
143 shift->req->url->base->path($conf->{proxy_prefix} . '/');
144 });
145 };
146
Akron807225b2021-01-13 18:00:13 +0100147 $self->hook(
148 before_dispatch => sub {
Akron5b6d7272021-01-21 11:26:02 +0100149 my $h = shift->res->headers;
150 $h->header('X-Content-Type-Options' => 'nosniff');
Akron52b32d02021-01-21 17:37:19 +0100151 $h->header('X-XSS-Protection' => '1; mode=block');
Akron5b6d7272021-01-21 11:26:02 +0100152 $h->header(
153 'Access-Control-Allow-Methods' =>
154 $h->header('Access-Control-Allow-Methods') // 'GET, POST, OPTIONS'
155 );
Akron807225b2021-01-13 18:00:13 +0100156 }
157 );
158
Akron90be03b2020-02-03 16:13:37 +0100159 $conf->{proxy_host} //= 1;
160
161 # Take proxy host
162 if ($conf->{proxy_host}) {
163 $self->hook(
164 before_dispatch => sub {
165 my $c = shift;
166 if (my $host = $c->req->headers->header('X-Forwarded-Host')) {
167 foreach ($c->req->url->base) {
168 $_->host($host);
169 $_->scheme(undef);
170 $_->port(undef);
171 };
172 };
173 }
174 );
175 };
176
Akron8f8deda2021-01-15 12:55:06 +0100177 # API is not yet set - define the default Kustvakt api endpoint
178 $conf->{api_path} //= $ENV{KALAMAR_API} || 'https://korap.ids-mannheim.de/api/';
Akron63d963b2019-07-05 15:35:51 +0200179 $conf->{api_version} //= $API_VERSION;
Akronc7656e92018-08-30 13:33:25 +0200180
Akron4036d542018-02-12 13:17:09 +0100181 # Add development path
Akron0e1ed242018-10-11 13:22:00 +0200182 if ($self->mode eq 'development') {
Akron4036d542018-02-12 13:17:09 +0100183 push @{$self->static->paths}, 'dev';
Akronbe9d5b32017-04-05 20:48:24 +0200184 };
185
Akron23ab0472019-12-17 16:55:55 +0100186 # Set proxy timeouts
187 if ($conf->{proxy_inactivity_timeout}) {
188 $self->ua->inactivity_timeout($conf->{proxy_inactivity_timeout});
189 };
190 if ($conf->{proxy_connect_timeout}) {
191 $self->ua->connect_timeout($conf->{proxy_connect_timeout});
192 };
193
Akron09a567c2016-04-11 22:49:20 +0300194 # Client notifications
Akron0504a182016-04-10 21:13:42 +0200195 $self->plugin(Notifications => {
196 'Kalamar::Plugin::Notifications' => 1,
Akron8ea84292018-10-24 13:41:52 +0200197 JSON => 1,
Akron3c390c42020-03-30 09:06:21 +0200198 HTML => 1
Akron0504a182016-04-10 21:13:42 +0200199 });
200
Akronc4ea2e52021-01-27 18:34:05 +0100201 # Establish content security policy
Akron0a4d36e2021-01-18 17:50:48 +0100202 # This needs to be defined prior to Kalamar::Plugin::Piwik!
Akronc4ea2e52021-01-27 18:34:05 +0100203 $self->plugin(CSP => {
204 'default-src' => 'self',
Akron0a4d36e2021-01-18 17:50:48 +0100205 'style-src' => ['self','unsafe-inline'],
Akron1871f032021-01-29 10:35:53 +0100206 # Hash for korap-overview.svg script
207 'script-src' => ['self','sha256-VGXK99kFz+zmAQ0kxgleFrBWZgybFAPOl3GQtS7FQkI='],
Akron5b6d7272021-01-21 11:26:02 +0100208 'connect-src' => 'self',
Akron0a4d36e2021-01-18 17:50:48 +0100209 'frame-src' => '*',
Akronaef5cf22021-06-21 11:45:54 +0200210 'frame-ancestors' => 'self',
Akron0a4d36e2021-01-18 17:50:48 +0100211 'media-src' => 'none',
212 'object-src' => 'self',
213 'font-src' => 'self',
214 'img-src' => ['self', 'data:'],
Akronb7b91c52021-01-27 17:46:52 +0100215 -with_nonce => 1
Akronc4ea2e52021-01-27 18:34:05 +0100216 });
217
Akron09a567c2016-04-11 22:49:20 +0300218 # Localization framework
219 $self->plugin(Localize => {
Akrondbb448c2018-02-14 17:02:36 +0100220 dict => {
221 Q => {
222 _ => sub { shift->config('Kalamar')->{'examplecorpus'} },
223 }
224 },
Akrona7cfd902017-12-21 19:28:36 +0100225 resources => ['kalamar.dict', 'kalamar.queries.dict']
Akron09a567c2016-04-11 22:49:20 +0300226 });
227
228 # Pagination widget
229 $self->plugin('TagHelpers::Pagination' => {
230 prev => '<span><span>&lt;</span></span>',
Akron86e63a92019-02-27 17:35:04 +0100231 next => '<span><span>&gt;</span></span>',
Akrona4b17f72021-11-04 15:37:02 +0100232 ellipsis => '<a class="ellipsis inactive"><span><span>...</span></span></a>',
Akron09a567c2016-04-11 22:49:20 +0300233 separator => '',
234 current => '<span>{current}</span>',
235 page => '<span>{page}</span>'
236 });
237
Akron1011daf2021-03-01 12:34:58 +0100238 # Obfuscate email addresses
239 $self->plugin('TagHelpers::MailToChiffre' => {
240 method_name => 'PArok',
241 pattern_rotate => 673,
242 no_inline => 1
243 });
244
Nils Diewaldab4d3ca2015-04-17 01:48:43 +0000245 # Load plugins
Nils Diewaldfccfbcb2015-04-29 20:48:19 +0000246 foreach (
Akrone8235be2016-06-27 11:02:18 +0200247 'KalamarHelpers', # Specific Helpers for Kalamar
Akronb7b91c52021-01-27 17:46:52 +0100248 'KalamarPages', # Page Helpers for Kalamar
Akron7093b812018-10-19 17:28:21 +0200249 'KalamarErrors', # Specific Errors for Kalamar
250 'KalamarUser', # Specific Helpers for Kalamar Users
Akron429aeda2018-03-19 16:02:29 +0100251 'ClientIP', # Get client IP from X-Forwarded-For
Akron51757cb2018-05-16 13:10:08 +0200252 'ClosedRedirect', # Redirect with OpenRedirect protection
Akronafeca252018-05-23 15:54:28 +0200253 'TagHelpers::ContentBlock', # Flexible content blocks
Nils Diewaldfccfbcb2015-04-29 20:48:19 +0000254 ) {
Nils Diewaldab4d3ca2015-04-17 01:48:43 +0000255 $self->plugin($_);
256 };
257
Akron751e9e42019-03-13 09:54:55 +0100258 my $serializer = 'JSON';
259
260 if (my $chi = $self->config('CHI')) {
261 if ($chi->{default}) {
262 $chi->{default}->{serializer} = $serializer;
263 };
264 if ($chi->{user}) {
265 $chi->{user}->{serializer} = $serializer;
266 };
267 };
268
Akron05c6dd62018-10-11 17:05:06 +0200269 # Global caching mechanism
270 $self->plugin('CHI' => {
271 default => {
272 driver => 'Memory',
Akron751e9e42019-03-13 09:54:55 +0100273 global => 1,
274 serializer => $serializer
Akron05c6dd62018-10-11 17:05:06 +0200275 },
276 user => {
277 driver => 'Memory',
Akron751e9e42019-03-13 09:54:55 +0100278 global => 1,
279 serializer => $serializer
Akron05c6dd62018-10-11 17:05:06 +0200280 }
281 });
Nils Diewald709f52f2015-05-21 18:32:58 +0000282
Nils Diewaldfccfbcb2015-04-29 20:48:19 +0000283 # Configure mail exception
Akron40cc1d82017-05-10 17:58:16 +0200284 if ($self->config('MailException')) {
285 $self->plugin('MailException' => $self->config('MailException'));
286 };
Nils Diewald709f52f2015-05-21 18:32:58 +0000287
Akroncdfd9d52019-07-23 11:35:00 +0200288 # Load further plugins,
289 # that can override core functions,
290 # therefore order may be of importance
Akron4c33c622018-11-12 13:43:27 +0100291 if (exists $conf->{'plugins'}) {
292 foreach (@{$conf->{'plugins'}}) {
293 $self->plugin('Kalamar::Plugin::' . $_);
294 };
295 };
296
Akron864c2932018-11-16 17:18:55 +0100297 # Deprecated Legacy code
Akron864c2932018-11-16 17:18:55 +0100298 if ($self->config('Kalamar')->{auth_support} &&
299 none { $_ eq 'Auth' } @{$conf->{plugins} // []}) {
300
301 # 2018-11-16
302 deprecated 'auth_support configuration is deprecated in favor of Plugin loading';
303 $self->plugin('Kalamar::Plugin::Auth')
Akron4c33c622018-11-12 13:43:27 +0100304 };
305
Nils Diewaldfccfbcb2015-04-29 20:48:19 +0000306 # Configure documentation navigation
Akrond512ea62019-10-24 15:50:04 +0200307 my $doc_navi = Mojo::File->new($self->home->child('templates','doc','navigation.json'))->slurp;
308 $doc_navi = $doc_navi ? decode_json($doc_navi) : [];
Akron1b1a2712018-12-21 14:59:05 +0100309
Akronf7ec4442019-10-27 20:01:05 +0100310 # TODO:
311 # Use navi->add()
Akron1b1a2712018-12-21 14:59:05 +0100312 if ($conf->{navi_ext}) {
Akrond512ea62019-10-24 15:50:04 +0200313 push @$doc_navi, @{$conf->{navi_ext}};
Akron1b1a2712018-12-21 14:59:05 +0100314 };
315
Akronf7ec4442019-10-27 20:01:05 +0100316 # TODO:
317 # Remove navi entry
Akrond512ea62019-10-24 15:50:04 +0200318 $self->config(doc_navi => $doc_navi);
Nils Diewaldfccfbcb2015-04-29 20:48:19 +0000319
Akronf7ec4442019-10-27 20:01:05 +0100320 $self->navi->set(doc => $doc_navi);
321
Akron63d963b2019-07-05 15:35:51 +0200322 $self->log->info('API expected at ' . $self->korap->api);
Nils Diewald709f52f2015-05-21 18:32:58 +0000323
Akron3cd391e2017-03-29 23:42:54 +0200324 # Establish routes with authentification
Akron7d75ee32017-05-02 13:42:41 +0200325 my $r = $self->routes;
Akron3cd391e2017-03-29 23:42:54 +0200326
Akronafeca252018-05-23 15:54:28 +0200327 # Set footer value
Akronef6d5f12018-05-28 17:54:58 +0200328 $self->content_block(footer => {
Akron3cfa26d2019-10-24 15:17:34 +0200329 inline => '<%= embedded_link_to "doc", "V ' . $Kalamar::VERSION . '", "korap", "kalamar" %>',
Akronafeca252018-05-23 15:54:28 +0200330 position => 100
Akronef6d5f12018-05-28 17:54:58 +0200331 });
Akronafeca252018-05-23 15:54:28 +0200332
Akronb7b91c52021-01-27 17:46:52 +0100333 # Add nonce script
334 $self->content_block(nonce_js => {
335 inline => <<'NONCE_JS'
336 // Remove the no-js class from the body
337 document.body.classList.remove('no-js');
338NONCE_JS
339 });
340
Nils Diewalda79b2682015-05-18 18:34:06 +0000341 # Base query route
Akronfb6d87d2018-10-24 18:10:20 +0200342 $r->get('/')->to('search#query')->name('index');
Nils Diewaldab4d3ca2015-04-17 01:48:43 +0000343
Nils Diewalda79b2682015-05-18 18:34:06 +0000344 # Documentation routes
hebastada903dd2021-07-20 15:58:48 +0200345 $r->get('/doc')->to('documentation#page', page => 'ql')->name('doc_start');
Akron254fe212019-10-24 14:33:28 +0200346 $r->get('/doc/:scope/:page')->to('documentation#page', scope => undef)->name('doc');
Nils Diewaldab4d3ca2015-04-17 01:48:43 +0000347
Akron59992122019-10-29 11:28:45 +0100348 # Settings routes
349 if ($self->navi->exists('settings')) {
350 $r->get('/settings')->to(
351 cb => sub {
Akron88c26b12020-09-07 12:44:18 +0200352 my $c = shift;
353 $c->res->headers->header('X-Robots' => 'noindex');
354 return $c->render('settings');
Akron59992122019-10-29 11:28:45 +0100355 }
356 )->name('settings_start');
357 $r->get('/settings/:scope/:page')->to(
358 scope => undef,
359 page => undef
360 )->name('settings');
361 };
Akronf7ec4442019-10-27 20:01:05 +0100362
Nils Diewaldc46003b2015-05-07 15:55:35 +0000363 # Contact route
364 $r->get('/contact')->to('documentation#contact');
365 $r->get('/contact')->mail_to_chiffre('documentation#contact');
366
Akron63d963b2019-07-05 15:35:51 +0200367 # API proxy route
Akron8a21b4d2020-04-16 16:17:42 +0200368 $r->any('/api/v#apiv' => [apiv => ['1.0']])->name('proxy')->to('Proxy#pass');
Akron03c3c9d2021-02-15 07:41:27 +0100369 $r->any('/api/v#apiv/*api_path' => [apiv => ['1.0']])->to('Proxy#pass');
Akron63d963b2019-07-05 15:35:51 +0200370
Nils Diewald7148c6f2015-05-04 15:07:53 +0000371 # Match route
Akron80a84b22018-10-24 17:44:24 +0200372 # Corpus route
Akronfb6d87d2018-10-24 18:10:20 +0200373 my $corpus = $r->get('/corpus')->to('search#corpus_info')->name('corpus');
Akron8f9aae52020-12-17 15:52:28 +0100374 my $doc = $r->any('/corpus/:corpus_id/:doc_id');
Akronfb6d87d2018-10-24 18:10:20 +0200375 my $text = $doc->get('/:text_id')->to('search#text_info')->name('text');
376 my $match = $doc->get('/:text_id/:match_id')->to('search#match_info')->name('match');
Nils Diewald996aa552014-12-02 03:26:44 +0000377};
378
379
3801;
381
382
383__END__
Nils Diewalda898dac2015-05-06 21:04:16 +0000384
385=pod
386
Nils Diewaldeb5f3072015-05-20 09:32:42 +0000387=encoding utf8
Nils Diewalda898dac2015-05-06 21:04:16 +0000388
Nils Diewaldeb5f3072015-05-20 09:32:42 +0000389=head1 NAME
390
391Kalamar
Nils Diewalda0defc42015-05-07 23:54:17 +0000392
393
Nils Diewaldeb5f3072015-05-20 09:32:42 +0000394=head1 DESCRIPTION
Nils Diewalda0defc42015-05-07 23:54:17 +0000395
Nils Diewaldeb5f3072015-05-20 09:32:42 +0000396L<Kalamar> is a L<Mojolicious|http://mojolicio.us/> based user interface
Akron87468c22021-02-08 09:30:01 +0100397frontend for the L<KorAP Corpus Analysis Platform|https://korap.ids-mannheim.de/>.
Nils Diewaldeb5f3072015-05-20 09:32:42 +0000398
Akron456abd92015-06-02 15:07:21 +0200399B<See the README for further information!>
Nils Diewaldeb5f3072015-05-20 09:32:42 +0000400
Akron456abd92015-06-02 15:07:21 +0200401=head2 COPYRIGHT AND LICENSE
Nils Diewalda748b0e2015-05-19 22:54:06 +0000402
Akron87468c22021-02-08 09:30:01 +0100403Copyright (C) 2015-2021, L<IDS Mannheim|https://www.ids-mannheim.de/>
404Author: L<Nils Diewald|https://www.nils-diewald.de/>
Nils Diewalda748b0e2015-05-19 22:54:06 +0000405
406Kalamar is developed as part of the L<KorAP|http://korap.ids-mannheim.de/>
407Corpus Analysis Platform at the
Akron87468c22021-02-08 09:30:01 +0100408L<Leibniz Institute for the German Language (IDS)|https://www.ids-mannheim.de/>,
Nils Diewalda748b0e2015-05-19 22:54:06 +0000409member of the
hebasta21b7baf2019-12-16 10:32:43 +0100410L<Leibniz-Gemeinschaft|http://www.leibniz-gemeinschaft.de>
Nils Diewalda748b0e2015-05-19 22:54:06 +0000411and supported by the L<KobRA|http://www.kobra.tu-dortmund.de> project,
412funded by the
413L<Federal Ministry of Education and Research (BMBF)|http://www.bmbf.de/en/>.
414
415Kalamar is free software published under the
Akron87468c22021-02-08 09:30:01 +0100416L<BSD-2 License|https://opensource.org/licenses/BSD-2-Clause>.
Nils Diewalda748b0e2015-05-19 22:54:06 +0000417
418=cut