The roster sync tickles at most ONCE per stream per run, not once per member: a tickle is content-free, so five people joining in one sweep is five identical notifications and one piece of information. Suppressed on a Team's FIRST roster, the same condition the activity feed uses and the half where it matters more — importing a 155-member guild would otherwise wake every one of their phones. Forum notifications fire from the CONTROLLER, not from the forum model. That file takes an already-resolved access decision and reads no membership table by design; the fan-out reads both to compute its recipients, so calling it from inside would make the forum model transitively depend on exactly what its header says it must not touch. The model returns a `notify` key the controller destructures out before the response, so the API's answer to "did my post save" is unchanged. `pageUrlTemplate` joins the team provider — the one thing phase 6 found that the design of record had not anticipated. Phase 3 left core with no Team page and therefore no way to LINK to one, so a notification email could name a Team and not take you to it. It is data rather than a callback: a function would put a module hook on the mail path to produce a string that never varies. Relative paths only, and protocol-relative is refused with absolute. The unsubscribe endpoint is the only write in the public tier and the only route with no `siteMode` — the reader is in their mail client, and the mail went out before the site went into maintenance. POST always answers 200, valid token or forged: distinguishing them would be an oracle for which (user, Team) pairs exist. GET redirects and acts on nothing, so a mail client's link scanner cannot mute Teams nobody asked to leave. Co-Authored-By: Claude <noreply@anthropic.com>
125 lines
4.9 KiB
JavaScript
125 lines
4.9 KiB
JavaScript
// Self-service push-notification management for the logged-in user (any role).
|
|
// Mounted under /auth/me behind requireAuth, so req.user is the fresh DB row.
|
|
// Devices (endpoints) and stream subscriptions live here; the fan-out that
|
|
// actually delivers is utils/pushDispatch. See docs/android/PLAN.md §11.
|
|
|
|
const pushDevices = require('../../../model/pushDevices/pushDevices.model')
|
|
const notificationSubs = require('../../../model/notificationSubs/notificationSubs.model')
|
|
const registries = require('../../../modules/registries')
|
|
const teamPrefs = require('../../../model/teams/teamNotify.model')
|
|
const { isAllowedEndpoint } = require('../../../utils/pushDispatch')
|
|
|
|
const log = require('../../../utils/logger')('notifications')
|
|
|
|
// POST /auth/me/devices — register (or refresh) a push endpoint for this user.
|
|
async function registerDevice(req, res) {
|
|
const { transport = 'unifiedpush', endpoint, platform } = req.body
|
|
// SSRF guard: the endpoint is a URL the server will later POST to. Reject
|
|
// anything that isn't an allowed HTTPS relay origin before storing it.
|
|
if (!isAllowedEndpoint(endpoint)) {
|
|
return res.status(400).json({ message: 'Endpoint is not an allowed push URL' })
|
|
}
|
|
try {
|
|
const device = await pushDevices.register({ userId: req.user.id, transport, endpoint, platform })
|
|
return res.status(201).json(device)
|
|
} catch (err) {
|
|
log.error('registerDevice', err)
|
|
return res.status(500).json({ message: 'Internal Server Error' })
|
|
}
|
|
}
|
|
|
|
// GET /auth/me/devices — this user's registered devices.
|
|
async function listDevices(req, res) {
|
|
try {
|
|
return res.json(await pushDevices.listForUser(req.user.id))
|
|
} catch (err) {
|
|
log.error('listDevices', err)
|
|
return res.status(500).json({ message: 'Internal Server Error' })
|
|
}
|
|
}
|
|
|
|
// DELETE /auth/me/devices/:id — unregister a device (must belong to the caller).
|
|
async function removeDevice(req, res) {
|
|
try {
|
|
const ok = await pushDevices.remove(Number(req.params.id), req.user.id)
|
|
if (!ok) return res.status(404).json({ message: 'Not found' })
|
|
return res.json({ ok: true })
|
|
} catch (err) {
|
|
log.error('removeDevice', err)
|
|
return res.status(500).json({ message: 'Internal Server Error' })
|
|
}
|
|
}
|
|
|
|
// GET /auth/me/notifications/streams — the subscribable catalog: core's streams
|
|
// plus every installed module's, in registration order. Fixed for the lifetime of
|
|
// a process (registration is boot-time), not a static constant.
|
|
function getStreams(req, res) {
|
|
return res.json({ streams: registries.allStreams() })
|
|
}
|
|
|
|
// GET /auth/me/notifications/subscriptions — the caller's opted-in stream ids.
|
|
async function getSubscriptions(req, res) {
|
|
try {
|
|
return res.json({ streams: await notificationSubs.getForUser(req.user.id) })
|
|
} catch (err) {
|
|
log.error('getSubscriptions', err)
|
|
return res.status(500).json({ message: 'Internal Server Error' })
|
|
}
|
|
}
|
|
|
|
// PUT /auth/me/notifications/subscriptions — replace the caller's stream set.
|
|
// Unknown ids are dropped; the stored (cleaned) set is echoed back.
|
|
async function putSubscriptions(req, res) {
|
|
try {
|
|
const streams = await notificationSubs.setForUser(req.user.id, req.body.streams)
|
|
return res.json({ streams })
|
|
} catch (err) {
|
|
log.error('putSubscriptions', err)
|
|
return res.status(500).json({ message: 'Internal Server Error' })
|
|
}
|
|
}
|
|
|
|
// GET /auth/me/notifications/teams — this user's per-Team preferences, one row
|
|
// per Team they could be notified about whether or not they have ever set one.
|
|
//
|
|
// Not gated on `teams_forums_enabled`: two of the four streams (member joined,
|
|
// leadership changed) have nothing to do with the forum, so a deployment with
|
|
// forums switched off still has preferences worth showing.
|
|
async function getTeamPrefs(req, res) {
|
|
try {
|
|
return res.json({ teams: await teamPrefs.listPrefs(req.user.id) })
|
|
} catch (err) {
|
|
log.error('getTeamPrefs', err)
|
|
return res.status(500).json({ message: 'Internal Server Error' })
|
|
}
|
|
}
|
|
|
|
// PUT /auth/me/notifications/teams — replace the caller's whole preference set.
|
|
//
|
|
// PUT-the-whole-set, matching the subscriptions endpoint beside it, and the
|
|
// `teams` array is REQUIRED even when empty — the Android gotcha in
|
|
// docs/android/PLAN.md §11: a DTO field with a default is dropped by kotlinx when
|
|
// it equals that default, so clearing the last entry would arrive as a body with
|
|
// no array at all and 400. Entries naming a Team the caller is not in are dropped
|
|
// by the model rather than refused here (an ordinary race, not a client bug).
|
|
async function putTeamPrefs(req, res) {
|
|
try {
|
|
const { prefs } = await teamPrefs.replacePrefs(req.user.id, req.body.teams)
|
|
return res.json({ teams: prefs })
|
|
} catch (err) {
|
|
log.error('putTeamPrefs', err)
|
|
return res.status(500).json({ message: 'Internal Server Error' })
|
|
}
|
|
}
|
|
|
|
module.exports = {
|
|
registerDevice,
|
|
listDevices,
|
|
removeDevice,
|
|
getStreams,
|
|
getSubscriptions,
|
|
putSubscriptions,
|
|
getTeamPrefs,
|
|
putTeamPrefs,
|
|
}
|