|
| 1 | +<?php |
| 2 | + |
| 3 | +declare(strict_types=1); |
| 4 | +/** |
| 5 | + * @license EUPL-1.2 |
| 6 | + * @copyright Copyright (c) 2026, Conduction B.V. <info@conduction.nl> |
| 7 | + * |
| 8 | + * SPDX-FileCopyrightText: 2026 Conduction B.V. <info@conduction.nl> |
| 9 | + * SPDX-License-Identifier: EUPL-1.2 |
| 10 | + */ |
| 11 | + |
| 12 | + |
| 13 | +namespace OCA\Versioniq\Controller; |
| 14 | + |
| 15 | +use InvalidArgumentException; |
| 16 | +use OCA\Versioniq\Service\Audit\AuditLogger; |
| 17 | +use OCA\Versioniq\Service\Settings\InstanceSettings; |
| 18 | +use OCP\AppFramework\Http; |
| 19 | +use OCP\AppFramework\Http\Attribute\ApiRoute; |
| 20 | +use OCP\AppFramework\Http\Attribute\PasswordConfirmationRequired; |
| 21 | +use OCP\AppFramework\Http\DataResponse; |
| 22 | +use OCP\AppFramework\OCSController; |
| 23 | +use OCP\IGroupManager; |
| 24 | +use OCP\IRequest; |
| 25 | +use OCP\IUserSession; |
| 26 | + |
| 27 | +/** |
| 28 | + * Reads and sets the instance settings that used to be occ-only (#438 item |
| 29 | + * 7): audit retention, artifact cache size, App Store and GitHub base URLs |
| 30 | + * and the advisory feed URL. |
| 31 | + * |
| 32 | + * Admin-only twice over, like ForgeController: no NoAdminRequired attribute, |
| 33 | + * and the explicit isAdmin() guard the unit tests pin. A change is audited, |
| 34 | + * because pointing the App Store or GitHub at another host changes where |
| 35 | + * installs come from. |
| 36 | + * |
| 37 | + * @psalm-suppress UnusedClass |
| 38 | + */ |
| 39 | +class SettingsController extends OCSController { |
| 40 | + public function __construct( |
| 41 | + string $appName, |
| 42 | + IRequest $request, |
| 43 | + private InstanceSettings $settings, |
| 44 | + private AuditLogger $auditLogger, |
| 45 | + private IGroupManager $groupManager, |
| 46 | + private IUserSession $userSession, |
| 47 | + ) { |
| 48 | + parent::__construct($appName, $request); |
| 49 | + } |
| 50 | + |
| 51 | + /** |
| 52 | + * Returns the instance settings with their defaults |
| 53 | + * |
| 54 | + * @return DataResponse<Http::STATUS_OK, array<string, int|string>, array{}>|DataResponse<Http::STATUS_FORBIDDEN, array{message: string}, array{}> |
| 55 | + * |
| 56 | + * 200: The settings, each override ('' when unset) next to its default |
| 57 | + * 403: Caller is not an administrator |
| 58 | + * |
| 59 | + * @spec openspec/specs/audit-trail/spec.md |
| 60 | + * @spec openspec/specs/external-sources/spec.md |
| 61 | + */ |
| 62 | + #[ApiRoute(verb: 'GET', url: '/api/instance-settings')] |
| 63 | + public function instanceSettings(): DataResponse { |
| 64 | + if (!$this->isAdmin()) { |
| 65 | + return new DataResponse(['message' => 'Forbidden'], Http::STATUS_FORBIDDEN); |
| 66 | + } |
| 67 | + |
| 68 | + return new DataResponse($this->settings->read()); |
| 69 | + } |
| 70 | + |
| 71 | + /** |
| 72 | + * Updates the instance settings (password-confirmed); an omitted field is left alone |
| 73 | + * |
| 74 | + * @param string|null $auditRetentionDays Days of history to keep, 30 to 3650 |
| 75 | + * @param string|null $artifactCacheKeep Archives kept per app, 0 to 20 (0 turns the cache off) |
| 76 | + * @param string|null $appStoreApiBase App Store API base URL; blank uses the public store |
| 77 | + * @param string|null $githubApiBase GitHub API base URL (https); blank uses api.github.com |
| 78 | + * @param string|null $githubWebBase GitHub web base URL (https); blank uses github.com |
| 79 | + * @param string|null $advisoryFeedUrl Advisory feed URL; blank uses the published Nextcloud feed |
| 80 | + * |
| 81 | + * @return DataResponse<Http::STATUS_OK, array<string, int|string>, array{}>|DataResponse<Http::STATUS_BAD_REQUEST|Http::STATUS_FORBIDDEN, array{message: string}, array{}> |
| 82 | + * |
| 83 | + * 200: The settings after the change |
| 84 | + * 400: A value is out of range or not an acceptable URL; nothing was changed |
| 85 | + * 403: Caller is not an administrator |
| 86 | + * |
| 87 | + * @spec openspec/specs/audit-trail/spec.md |
| 88 | + * @spec openspec/specs/external-sources/spec.md |
| 89 | + */ |
| 90 | + #[PasswordConfirmationRequired(strict: false)] |
| 91 | + #[ApiRoute(verb: 'PUT', url: '/api/instance-settings')] |
| 92 | + public function updateInstanceSettings( |
| 93 | + ?string $auditRetentionDays = null, |
| 94 | + ?string $artifactCacheKeep = null, |
| 95 | + ?string $appStoreApiBase = null, |
| 96 | + ?string $githubApiBase = null, |
| 97 | + ?string $githubWebBase = null, |
| 98 | + ?string $advisoryFeedUrl = null, |
| 99 | + ): DataResponse { |
| 100 | + if (!$this->isAdmin()) { |
| 101 | + return new DataResponse(['message' => 'Forbidden'], Http::STATUS_FORBIDDEN); |
| 102 | + } |
| 103 | + |
| 104 | + $fields = array_filter([ |
| 105 | + 'auditRetentionDays' => $auditRetentionDays, |
| 106 | + 'artifactCacheKeep' => $artifactCacheKeep, |
| 107 | + 'appStoreApiBase' => $appStoreApiBase, |
| 108 | + 'githubApiBase' => $githubApiBase, |
| 109 | + 'githubWebBase' => $githubWebBase, |
| 110 | + 'advisoryFeedUrl' => $advisoryFeedUrl, |
| 111 | + ], static fn (?string $value): bool => $value !== null); |
| 112 | + |
| 113 | + try { |
| 114 | + $applied = $this->settings->update($fields); |
| 115 | + } catch (InvalidArgumentException $error) { |
| 116 | + return new DataResponse(['message' => $error->getMessage()], Http::STATUS_BAD_REQUEST); |
| 117 | + } |
| 118 | + |
| 119 | + $after = $this->settings->read(); |
| 120 | + if ($applied !== []) { |
| 121 | + $this->auditLogger->record( |
| 122 | + $this->userSession->getUser()?->getUID() ?? '', |
| 123 | + 'versioniq', |
| 124 | + AuditLogger::OPERATION_SETTINGS, |
| 125 | + null, |
| 126 | + null, |
| 127 | + null, |
| 128 | + AuditLogger::STATUS_SUCCESS, |
| 129 | + 'Settings changed: ' . implode(', ', array_map( |
| 130 | + static fn (string $field): string => $field . '=' . (string)$after[$field], |
| 131 | + $applied, |
| 132 | + )), |
| 133 | + ); |
| 134 | + } |
| 135 | + |
| 136 | + return new DataResponse($after); |
| 137 | + } |
| 138 | + |
| 139 | + private function isAdmin(): bool { |
| 140 | + $user = $this->userSession->getUser(); |
| 141 | + if ($user === null) { |
| 142 | + return false; |
| 143 | + } |
| 144 | + |
| 145 | + return $this->groupManager->isAdmin($user->getUID()); |
| 146 | + } |
| 147 | +} |
0 commit comments