"use strict"; var path = require('path'), async = require('async'), fs = require('fs'), nconf = require('nconf'), user = require('../user'), topics = require('../topics'), posts = require('../posts'), categories = require('../categories'), meta = require('../meta'), plugins = require('../plugins'), utils = require('../../public/src/utils'), image = require('../image'), pkg = require('../../package.json'); function deleteTempFiles(files) { for(var i=0; i parseInt(meta.config.maximumFileSize, 10) * 1024) { return callback(new Error('[[error:file-too-big, ' + meta.config.maximumFileSize + ']]')); } var filename = 'upload-' + utils.generateUUID() + path.extname(file.name); require('../file').saveFileToLocal(filename, file.path, function(err, upload) { if(err) { return callback(err); } callback(null, { url: upload.url, name: file.name }); }); } } function getModerators(req, res, next) { categories.getModerators(req.params.cid, function(err, moderators) { res.json({moderators: moderators}); }); } function getTemplatesListing(req, res, next) { var data = []; async.parallel({ views: function(next) { utils.walk(nconf.get('views_dir'), function (err, views) { data = data.concat( views.filter(function(value, index, self) { return self.indexOf(value) === index; }).map(function(el) { return el.replace(nconf.get('views_dir') + '/', ''); })); res.json(data); }); }, extended: function(next) { plugins.fireHook('filter:templates.get_virtual', [], function(err, virtual) { data = data.concat(virtual); }); } }, function(err) { res.json(data); }); } function getRecentPosts(req, res, next) { var uid = (req.user) ? req.user.uid : 0; posts.getRecentPosts(uid, 0, 19, req.params.term, function (err, data) { if(err) { return next(err); } res.json(data); }); } module.exports = function(app, middleware, controllers) { app.namespace('/api', function () { app.get('/config', controllers.api.getConfig); app.get('/user/uid/:uid', middleware.checkGlobalPrivacySettings, controllers.accounts.getUserByUID); app.get('/get_templates_listing', getTemplatesListing); app.get('/categories/:cid/moderators', getModerators); app.get('/recent/posts/:term?', getRecentPosts); app.post('/post/upload', uploadPost); app.post('/topic/thumb/upload', uploadThumb); }); // this should be in the API namespace // also, perhaps pass in :userslug so we can use checkAccountPermissions middleware - in future will allow admins to upload a picture for a user app.post('/user/uploadpicture', middleware.authenticate, middleware.checkGlobalPrivacySettings, /*middleware.checkAccountPermissions,*/ controllers.accounts.uploadPicture); };