2021-07-19 19:22:29 -07:00
|
|
|
package events
|
2020-05-23 17:57:49 -07:00
|
|
|
|
2020-10-13 16:45:52 -07:00
|
|
|
import (
|
|
|
|
"bytes"
|
2021-03-08 23:20:15 -08:00
|
|
|
"regexp"
|
2020-10-13 16:45:52 -07:00
|
|
|
"strings"
|
|
|
|
"time"
|
|
|
|
|
|
|
|
"github.com/microcosm-cc/bluemonday"
|
2021-02-18 23:05:52 -08:00
|
|
|
"github.com/teris-io/shortid"
|
2020-10-13 16:45:52 -07:00
|
|
|
"github.com/yuin/goldmark"
|
|
|
|
"github.com/yuin/goldmark/extension"
|
|
|
|
"github.com/yuin/goldmark/renderer/html"
|
|
|
|
"mvdan.cc/xurls"
|
2021-07-19 19:22:29 -07:00
|
|
|
|
|
|
|
"github.com/owncast/owncast/core/user"
|
|
|
|
log "github.com/sirupsen/logrus"
|
2020-10-13 16:45:52 -07:00
|
|
|
)
|
2020-07-11 19:08:47 -07:00
|
|
|
|
2021-07-19 19:22:29 -07:00
|
|
|
// EventPayload is a generic key/value map for sending out to chat clients.
|
|
|
|
type EventPayload map[string]interface{}
|
|
|
|
|
|
|
|
type OutboundEvent interface {
|
|
|
|
GetBroadcastPayload() EventPayload
|
|
|
|
GetMessageType() EventType
|
|
|
|
}
|
|
|
|
|
|
|
|
// Event is any kind of event. A type is required to be specified.
|
|
|
|
type Event struct {
|
|
|
|
Type EventType `json:"type"`
|
|
|
|
Id string `json:"id"`
|
|
|
|
Timestamp time.Time `json:"timestamp"`
|
|
|
|
}
|
|
|
|
|
|
|
|
type UserEvent struct {
|
|
|
|
User *user.User `json:"user"`
|
|
|
|
HiddenAt *time.Time `json:"hiddenAt,omitempty"`
|
|
|
|
}
|
|
|
|
|
|
|
|
// MessageEvent is an event that has a message body.
|
|
|
|
type MessageEvent struct {
|
|
|
|
OutboundEvent `json:"-"`
|
|
|
|
Body string `json:"body"`
|
|
|
|
RawBody string `json:"-"`
|
|
|
|
}
|
|
|
|
|
|
|
|
type SystemActionEvent struct {
|
|
|
|
Event
|
|
|
|
MessageEvent
|
2020-05-23 17:57:49 -07:00
|
|
|
}
|
|
|
|
|
2021-07-19 19:22:29 -07:00
|
|
|
// SetDefaults will set default properties of all inbound events.
|
|
|
|
func (e *Event) SetDefaults() {
|
|
|
|
e.Id = shortid.MustGenerate()
|
|
|
|
e.Timestamp = time.Now()
|
2020-10-13 16:45:52 -07:00
|
|
|
}
|
|
|
|
|
2021-07-19 19:22:29 -07:00
|
|
|
// SetDefaults will set default properties of all inbound events.
|
|
|
|
func (e *UserMessageEvent) SetDefaults() {
|
|
|
|
e.Id = shortid.MustGenerate()
|
|
|
|
e.Timestamp = time.Now()
|
|
|
|
e.RenderAndSanitizeMessageBody()
|
2021-02-18 23:05:52 -08:00
|
|
|
}
|
|
|
|
|
2020-10-13 16:45:52 -07:00
|
|
|
// RenderAndSanitizeMessageBody will turn markdown into HTML, sanitize raw user-supplied HTML and standardize
|
|
|
|
// the message into something safe and renderable for clients.
|
2021-07-19 19:22:29 -07:00
|
|
|
func (m *MessageEvent) RenderAndSanitizeMessageBody() {
|
2021-02-18 23:05:52 -08:00
|
|
|
m.RawBody = m.Body
|
2020-10-13 16:45:52 -07:00
|
|
|
|
|
|
|
// Set the new, sanitized and rendered message body
|
2021-02-18 23:05:52 -08:00
|
|
|
m.Body = RenderAndSanitize(m.RawBody)
|
2020-10-13 16:45:52 -07:00
|
|
|
}
|
|
|
|
|
2021-02-18 23:05:52 -08:00
|
|
|
// Empty will return if this message's contents is empty.
|
2021-07-19 19:22:29 -07:00
|
|
|
func (m *MessageEvent) Empty() bool {
|
2021-01-31 23:57:50 +01:00
|
|
|
return m.Body == ""
|
|
|
|
}
|
|
|
|
|
2021-07-19 19:22:29 -07:00
|
|
|
// RenderBody will render markdown to html without any sanitization.
|
|
|
|
func (m *MessageEvent) RenderBody() {
|
2021-03-12 00:43:10 -08:00
|
|
|
m.RawBody = m.Body
|
|
|
|
m.Body = RenderMarkdown(m.RawBody)
|
|
|
|
}
|
|
|
|
|
2020-10-13 16:45:52 -07:00
|
|
|
// RenderAndSanitize will turn markdown into HTML, sanitize raw user-supplied HTML and standardize
|
|
|
|
// the message into something safe and renderable for clients.
|
|
|
|
func RenderAndSanitize(raw string) string {
|
2021-03-12 00:43:10 -08:00
|
|
|
rendered := RenderMarkdown(raw)
|
2020-10-13 16:45:52 -07:00
|
|
|
safe := sanitize(rendered)
|
|
|
|
|
|
|
|
// Set the new, sanitized and rendered message body
|
|
|
|
return strings.TrimSpace(safe)
|
|
|
|
}
|
|
|
|
|
2021-03-12 00:43:10 -08:00
|
|
|
func RenderMarkdown(raw string) string {
|
2020-10-13 16:45:52 -07:00
|
|
|
markdown := goldmark.New(
|
|
|
|
goldmark.WithRendererOptions(
|
|
|
|
html.WithUnsafe(),
|
|
|
|
),
|
|
|
|
goldmark.WithExtensions(
|
|
|
|
extension.NewLinkify(
|
|
|
|
extension.WithLinkifyAllowedProtocols([][]byte{
|
|
|
|
[]byte("http:"),
|
|
|
|
[]byte("https:"),
|
|
|
|
}),
|
|
|
|
extension.WithLinkifyURLRegexp(
|
|
|
|
xurls.Strict,
|
|
|
|
),
|
|
|
|
),
|
|
|
|
),
|
|
|
|
)
|
|
|
|
|
|
|
|
trimmed := strings.TrimSpace(raw)
|
|
|
|
var buf bytes.Buffer
|
|
|
|
if err := markdown.Convert([]byte(trimmed), &buf); err != nil {
|
2021-07-19 19:22:29 -07:00
|
|
|
log.Debugln(err)
|
2020-10-13 16:45:52 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
return buf.String()
|
|
|
|
}
|
|
|
|
|
|
|
|
func sanitize(raw string) string {
|
|
|
|
p := bluemonday.StrictPolicy()
|
|
|
|
|
|
|
|
// Require URLs to be parseable by net/url.Parse
|
|
|
|
p.AllowStandardURLs()
|
2021-03-08 23:20:15 -08:00
|
|
|
p.RequireParseableURLs(true)
|
2020-10-13 16:45:52 -07:00
|
|
|
|
|
|
|
// Allow links
|
|
|
|
p.AllowAttrs("href").OnElements("a")
|
|
|
|
|
|
|
|
// Force all URLs to have "noreferrer" in their rel attribute.
|
|
|
|
p.RequireNoReferrerOnLinks(true)
|
|
|
|
|
|
|
|
// Links will get target="_blank" added to them.
|
|
|
|
p.AddTargetBlankToFullyQualifiedLinks(true)
|
|
|
|
|
2021-03-08 23:20:15 -08:00
|
|
|
// Allow breaks
|
|
|
|
p.AllowElements("br", "p")
|
2020-10-13 16:45:52 -07:00
|
|
|
|
2021-03-08 23:20:15 -08:00
|
|
|
// Allow img tags from the the local emoji directory only
|
|
|
|
p.AllowAttrs("src", "alt", "class", "title").Matching(regexp.MustCompile(`(?i)/img/emoji`)).OnElements("img")
|
2020-10-13 16:45:52 -07:00
|
|
|
p.AllowAttrs("class").OnElements("img")
|
|
|
|
|
|
|
|
// Allow bold
|
|
|
|
p.AllowElements("strong")
|
|
|
|
|
|
|
|
// Allow emphasis
|
|
|
|
p.AllowElements("em")
|
|
|
|
|
2021-01-31 23:57:50 +01:00
|
|
|
// Allow code blocks
|
|
|
|
p.AllowElements("code")
|
|
|
|
p.AllowElements("pre")
|
|
|
|
|
2020-10-13 16:45:52 -07:00
|
|
|
return p.Sanitize(raw)
|
2020-06-23 15:11:01 -05:00
|
|
|
}
|