Remove Revision::getRevisionText from ApiQueryDeletedrevs
[lhc/web/wiklou.git] / includes / api / ApiQueryLogEvents.php
1 <?php
2 /**
3 * Copyright © 2006 Yuri Astrakhan "<Firstname><Lastname>@gmail.com"
4 *
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License as published by
7 * the Free Software Foundation; either version 2 of the License, or
8 * (at your option) any later version.
9 *
10 * This program is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 * GNU General Public License for more details.
14 *
15 * You should have received a copy of the GNU General Public License along
16 * with this program; if not, write to the Free Software Foundation, Inc.,
17 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
18 * http://www.gnu.org/copyleft/gpl.html
19 *
20 * @file
21 */
22
23 use MediaWiki\MediaWikiServices;
24 use MediaWiki\Storage\NameTableAccessException;
25
26 /**
27 * Query action to List the log events, with optional filtering by various parameters.
28 *
29 * @ingroup API
30 */
31 class ApiQueryLogEvents extends ApiQueryBase {
32
33 private $commentStore;
34
35 public function __construct( ApiQuery $query, $moduleName ) {
36 parent::__construct( $query, $moduleName, 'le' );
37 }
38
39 private $fld_ids = false, $fld_title = false, $fld_type = false,
40 $fld_user = false, $fld_userid = false,
41 $fld_timestamp = false, $fld_comment = false, $fld_parsedcomment = false,
42 $fld_details = false, $fld_tags = false;
43
44 public function execute() {
45 $params = $this->extractRequestParams();
46 $db = $this->getDB();
47 $this->commentStore = CommentStore::getStore();
48 $this->requireMaxOneParameter( $params, 'title', 'prefix', 'namespace' );
49
50 $prop = array_flip( $params['prop'] );
51
52 $this->fld_ids = isset( $prop['ids'] );
53 $this->fld_title = isset( $prop['title'] );
54 $this->fld_type = isset( $prop['type'] );
55 $this->fld_user = isset( $prop['user'] );
56 $this->fld_userid = isset( $prop['userid'] );
57 $this->fld_timestamp = isset( $prop['timestamp'] );
58 $this->fld_comment = isset( $prop['comment'] );
59 $this->fld_parsedcomment = isset( $prop['parsedcomment'] );
60 $this->fld_details = isset( $prop['details'] );
61 $this->fld_tags = isset( $prop['tags'] );
62
63 $hideLogs = LogEventsList::getExcludeClause( $db, 'user', $this->getUser() );
64 if ( $hideLogs !== false ) {
65 $this->addWhere( $hideLogs );
66 }
67
68 $actorMigration = ActorMigration::newMigration();
69 $actorQuery = $actorMigration->getJoin( 'log_user' );
70 $this->addTables( 'logging' );
71 $this->addTables( $actorQuery['tables'] );
72 $this->addTables( [ 'user', 'page' ] );
73 $this->addJoinConds( $actorQuery['joins'] );
74 $this->addJoinConds( [
75 'user' => [ 'LEFT JOIN',
76 'user_id=' . $actorQuery['fields']['log_user'] ],
77 'page' => [ 'LEFT JOIN',
78 [ 'log_namespace=page_namespace',
79 'log_title=page_title' ] ] ] );
80
81 $this->addFields( [
82 'log_id',
83 'log_type',
84 'log_action',
85 'log_timestamp',
86 'log_deleted',
87 ] );
88
89 $this->addFieldsIf( 'page_id', $this->fld_ids );
90 // log_page is the page_id saved at log time, whereas page_id is from a
91 // join at query time. This leads to different results in various
92 // scenarios, e.g. deletion, recreation.
93 $this->addFieldsIf( 'log_page', $this->fld_ids );
94 $this->addFieldsIf( $actorQuery['fields'] + [ 'user_name' ], $this->fld_user );
95 $this->addFieldsIf( $actorQuery['fields'], $this->fld_userid );
96 $this->addFieldsIf(
97 [ 'log_namespace', 'log_title' ],
98 $this->fld_title || $this->fld_parsedcomment
99 );
100 $this->addFieldsIf( 'log_params', $this->fld_details );
101
102 if ( $this->fld_comment || $this->fld_parsedcomment ) {
103 $commentQuery = $this->commentStore->getJoin( 'log_comment' );
104 $this->addTables( $commentQuery['tables'] );
105 $this->addFields( $commentQuery['fields'] );
106 $this->addJoinConds( $commentQuery['joins'] );
107 }
108
109 if ( $this->fld_tags ) {
110 $this->addFields( [ 'ts_tags' => ChangeTags::makeTagSummarySubquery( 'logging' ) ] );
111 }
112
113 if ( !is_null( $params['tag'] ) ) {
114 $this->addTables( 'change_tag' );
115 $this->addJoinConds( [ 'change_tag' => [ 'JOIN',
116 [ 'log_id=ct_log_id' ] ] ] );
117 $changeTagDefStore = MediaWikiServices::getInstance()->getChangeTagDefStore();
118 try {
119 $this->addWhereFld( 'ct_tag_id', $changeTagDefStore->getId( $params['tag'] ) );
120 } catch ( NameTableAccessException $exception ) {
121 // Return nothing.
122 $this->addWhere( '1=0' );
123 }
124 }
125
126 if ( !is_null( $params['action'] ) ) {
127 // Do validation of action param, list of allowed actions can contains wildcards
128 // Allow the param, when the actions is in the list or a wildcard version is listed.
129 $logAction = $params['action'];
130 if ( strpos( $logAction, '/' ) === false ) {
131 // all items in the list have a slash
132 $valid = false;
133 } else {
134 $logActions = array_flip( $this->getAllowedLogActions() );
135 list( $type, $action ) = explode( '/', $logAction, 2 );
136 $valid = isset( $logActions[$logAction] ) || isset( $logActions[$type . '/*'] );
137 }
138
139 if ( !$valid ) {
140 $encParamName = $this->encodeParamName( 'action' );
141 $this->dieWithError(
142 [ 'apierror-unrecognizedvalue', $encParamName, wfEscapeWikiText( $logAction ) ],
143 "unknown_$encParamName"
144 );
145 }
146
147 $this->addWhereFld( 'log_type', $type );
148 $this->addWhereFld( 'log_action', $action );
149 } elseif ( !is_null( $params['type'] ) ) {
150 $this->addWhereFld( 'log_type', $params['type'] );
151 }
152
153 $this->addTimestampWhereRange(
154 'log_timestamp',
155 $params['dir'],
156 $params['start'],
157 $params['end']
158 );
159 // Include in ORDER BY for uniqueness
160 $this->addWhereRange( 'log_id', $params['dir'], null, null );
161
162 if ( !is_null( $params['continue'] ) ) {
163 $cont = explode( '|', $params['continue'] );
164 $this->dieContinueUsageIf( count( $cont ) != 2 );
165 $op = ( $params['dir'] === 'newer' ? '>' : '<' );
166 $continueTimestamp = $db->addQuotes( $db->timestamp( $cont[0] ) );
167 $continueId = (int)$cont[1];
168 $this->dieContinueUsageIf( $continueId != $cont[1] );
169 $this->addWhere( "log_timestamp $op $continueTimestamp OR " .
170 "(log_timestamp = $continueTimestamp AND " .
171 "log_id $op= $continueId)"
172 );
173 }
174
175 $limit = $params['limit'];
176 $this->addOption( 'LIMIT', $limit + 1 );
177
178 $user = $params['user'];
179 if ( !is_null( $user ) ) {
180 // Note the joins in $q are the same as those from ->getJoin() above
181 // so we only need to add 'conds' here.
182 $q = $actorMigration->getWhere(
183 $db, 'log_user', User::newFromName( $params['user'], false )
184 );
185 $this->addWhere( $q['conds'] );
186
187 // T71222: MariaDB's optimizer, at least 10.1.37 and .38, likes to choose a wildly bad plan for
188 // some reason for this code path. Tell it not to use the wrong index it wants to pick.
189 $this->addOption( 'IGNORE INDEX', [ 'logging' => [ 'times' ] ] );
190 }
191
192 $title = $params['title'];
193 if ( !is_null( $title ) ) {
194 $titleObj = Title::newFromText( $title );
195 if ( is_null( $titleObj ) ) {
196 $this->dieWithError( [ 'apierror-invalidtitle', wfEscapeWikiText( $title ) ] );
197 }
198 $this->addWhereFld( 'log_namespace', $titleObj->getNamespace() );
199 $this->addWhereFld( 'log_title', $titleObj->getDBkey() );
200 }
201
202 if ( $params['namespace'] !== null ) {
203 $this->addWhereFld( 'log_namespace', $params['namespace'] );
204 }
205
206 $prefix = $params['prefix'];
207
208 if ( !is_null( $prefix ) ) {
209 if ( $this->getConfig()->get( 'MiserMode' ) ) {
210 $this->dieWithError( 'apierror-prefixsearchdisabled' );
211 }
212
213 $title = Title::newFromText( $prefix );
214 if ( is_null( $title ) ) {
215 $this->dieWithError( [ 'apierror-invalidtitle', wfEscapeWikiText( $prefix ) ] );
216 }
217 $this->addWhereFld( 'log_namespace', $title->getNamespace() );
218 $this->addWhere( 'log_title ' . $db->buildLike( $title->getDBkey(), $db->anyString() ) );
219 }
220
221 // Paranoia: avoid brute force searches (T19342)
222 if ( $params['namespace'] !== null || !is_null( $title ) || !is_null( $user ) ) {
223 if ( !$this->getPermissionManager()->userHasRight( $this->getUser(), 'deletedhistory' ) ) {
224 $titleBits = LogPage::DELETED_ACTION;
225 $userBits = LogPage::DELETED_USER;
226 } elseif ( !$this->getPermissionManager()
227 ->userHasAnyRight( $this->getUser(), 'suppressrevision', 'viewsuppressed' )
228 ) {
229 $titleBits = LogPage::DELETED_ACTION | LogPage::DELETED_RESTRICTED;
230 $userBits = LogPage::DELETED_USER | LogPage::DELETED_RESTRICTED;
231 } else {
232 $titleBits = 0;
233 $userBits = 0;
234 }
235 if ( ( $params['namespace'] !== null || !is_null( $title ) ) && $titleBits ) {
236 $this->addWhere( $db->bitAnd( 'log_deleted', $titleBits ) . " != $titleBits" );
237 }
238 if ( !is_null( $user ) && $userBits ) {
239 $this->addWhere( $db->bitAnd( 'log_deleted', $userBits ) . " != $userBits" );
240 }
241 }
242
243 // T220999: MySQL/MariaDB (10.1.37) can sometimes irrationally decide that querying `actor` before
244 // `logging` and filesorting is somehow better than querying $limit+1 rows from `logging`.
245 // Tell it not to reorder the query. But not when `letag` was used, as it seems as likely
246 // to be harmed as helped in that case.
247 if ( $params['tag'] === null ) {
248 $this->addOption( 'STRAIGHT_JOIN' );
249 }
250
251 $count = 0;
252 $res = $this->select( __METHOD__ );
253 $result = $this->getResult();
254 foreach ( $res as $row ) {
255 if ( ++$count > $limit ) {
256 // We've reached the one extra which shows that there are
257 // additional pages to be had. Stop here...
258 $this->setContinueEnumParameter( 'continue', "$row->log_timestamp|$row->log_id" );
259 break;
260 }
261
262 $vals = $this->extractRowInfo( $row );
263 $fit = $result->addValue( [ 'query', $this->getModuleName() ], null, $vals );
264 if ( !$fit ) {
265 $this->setContinueEnumParameter( 'continue', "$row->log_timestamp|$row->log_id" );
266 break;
267 }
268 }
269 $result->addIndexedTagName( [ 'query', $this->getModuleName() ], 'item' );
270 }
271
272 private function extractRowInfo( $row ) {
273 $logEntry = DatabaseLogEntry::newFromRow( $row );
274 $vals = [
275 ApiResult::META_TYPE => 'assoc',
276 ];
277 $anyHidden = false;
278 $user = $this->getUser();
279
280 if ( $this->fld_ids ) {
281 $vals['logid'] = (int)$row->log_id;
282 }
283
284 if ( $this->fld_title || $this->fld_parsedcomment ) {
285 $title = Title::makeTitle( $row->log_namespace, $row->log_title );
286 }
287
288 if ( $this->fld_title || $this->fld_ids || $this->fld_details && $row->log_params !== '' ) {
289 if ( LogEventsList::isDeleted( $row, LogPage::DELETED_ACTION ) ) {
290 $vals['actionhidden'] = true;
291 $anyHidden = true;
292 }
293 if ( LogEventsList::userCan( $row, LogPage::DELETED_ACTION, $user ) ) {
294 if ( $this->fld_title ) {
295 ApiQueryBase::addTitleInfo( $vals, $title );
296 }
297 if ( $this->fld_ids ) {
298 $vals['pageid'] = (int)$row->page_id;
299 $vals['logpage'] = (int)$row->log_page;
300 }
301 if ( $this->fld_details ) {
302 $vals['params'] = LogFormatter::newFromEntry( $logEntry )->formatParametersForApi();
303 }
304 }
305 }
306
307 if ( $this->fld_type ) {
308 $vals['type'] = $row->log_type;
309 $vals['action'] = $row->log_action;
310 }
311
312 if ( $this->fld_user || $this->fld_userid ) {
313 if ( LogEventsList::isDeleted( $row, LogPage::DELETED_USER ) ) {
314 $vals['userhidden'] = true;
315 $anyHidden = true;
316 }
317 if ( LogEventsList::userCan( $row, LogPage::DELETED_USER, $user ) ) {
318 if ( $this->fld_user ) {
319 $vals['user'] = $row->user_name ?? $row->log_user_text;
320 }
321 if ( $this->fld_userid ) {
322 $vals['userid'] = (int)$row->log_user;
323 }
324
325 if ( !$row->log_user ) {
326 $vals['anon'] = true;
327 }
328 }
329 }
330 if ( $this->fld_timestamp ) {
331 $vals['timestamp'] = wfTimestamp( TS_ISO_8601, $row->log_timestamp );
332 }
333
334 if ( $this->fld_comment || $this->fld_parsedcomment ) {
335 if ( LogEventsList::isDeleted( $row, LogPage::DELETED_COMMENT ) ) {
336 $vals['commenthidden'] = true;
337 $anyHidden = true;
338 }
339 if ( LogEventsList::userCan( $row, LogPage::DELETED_COMMENT, $user ) ) {
340 $comment = $this->commentStore->getComment( 'log_comment', $row )->text;
341 if ( $this->fld_comment ) {
342 $vals['comment'] = $comment;
343 }
344
345 if ( $this->fld_parsedcomment ) {
346 $vals['parsedcomment'] = Linker::formatComment( $comment, $title );
347 }
348 }
349 }
350
351 if ( $this->fld_tags ) {
352 if ( $row->ts_tags ) {
353 $tags = explode( ',', $row->ts_tags );
354 ApiResult::setIndexedTagName( $tags, 'tag' );
355 $vals['tags'] = $tags;
356 } else {
357 $vals['tags'] = [];
358 }
359 }
360
361 if ( $anyHidden && LogEventsList::isDeleted( $row, LogPage::DELETED_RESTRICTED ) ) {
362 $vals['suppressed'] = true;
363 }
364
365 return $vals;
366 }
367
368 /**
369 * @return array
370 */
371 private function getAllowedLogActions() {
372 $config = $this->getConfig();
373 return array_keys( array_merge(
374 $config->get( 'LogActions' ),
375 $config->get( 'LogActionsHandlers' )
376 ) );
377 }
378
379 public function getCacheMode( $params ) {
380 if ( $this->userCanSeeRevDel() ) {
381 return 'private';
382 }
383 if ( !is_null( $params['prop'] ) && in_array( 'parsedcomment', $params['prop'] ) ) {
384 // formatComment() calls wfMessage() among other things
385 return 'anon-public-user-private';
386 } elseif ( LogEventsList::getExcludeClause( $this->getDB(), 'user', $this->getUser() )
387 === LogEventsList::getExcludeClause( $this->getDB(), 'public' )
388 ) { // Output can only contain public data.
389 return 'public';
390 } else {
391 return 'anon-public-user-private';
392 }
393 }
394
395 public function getAllowedParams( $flags = 0 ) {
396 $config = $this->getConfig();
397 if ( $flags & ApiBase::GET_VALUES_FOR_HELP ) {
398 $logActions = $this->getAllowedLogActions();
399 sort( $logActions );
400 } else {
401 $logActions = null;
402 }
403 $ret = [
404 'prop' => [
405 ApiBase::PARAM_ISMULTI => true,
406 ApiBase::PARAM_DFLT => 'ids|title|type|user|timestamp|comment|details',
407 ApiBase::PARAM_TYPE => [
408 'ids',
409 'title',
410 'type',
411 'user',
412 'userid',
413 'timestamp',
414 'comment',
415 'parsedcomment',
416 'details',
417 'tags'
418 ],
419 ApiBase::PARAM_HELP_MSG_PER_VALUE => [],
420 ],
421 'type' => [
422 ApiBase::PARAM_TYPE => LogPage::validTypes(),
423 ],
424 'action' => [
425 // validation on request is done in execute()
426 ApiBase::PARAM_TYPE => $logActions
427 ],
428 'start' => [
429 ApiBase::PARAM_TYPE => 'timestamp'
430 ],
431 'end' => [
432 ApiBase::PARAM_TYPE => 'timestamp'
433 ],
434 'dir' => [
435 ApiBase::PARAM_DFLT => 'older',
436 ApiBase::PARAM_TYPE => [
437 'newer',
438 'older'
439 ],
440 ApiBase::PARAM_HELP_MSG => 'api-help-param-direction',
441 ],
442 'user' => [
443 ApiBase::PARAM_TYPE => 'user',
444 ],
445 'title' => null,
446 'namespace' => [
447 ApiBase::PARAM_TYPE => 'namespace',
448 ApiBase::PARAM_EXTRA_NAMESPACES => [ NS_MEDIA, NS_SPECIAL ],
449 ],
450 'prefix' => [],
451 'tag' => null,
452 'limit' => [
453 ApiBase::PARAM_DFLT => 10,
454 ApiBase::PARAM_TYPE => 'limit',
455 ApiBase::PARAM_MIN => 1,
456 ApiBase::PARAM_MAX => ApiBase::LIMIT_BIG1,
457 ApiBase::PARAM_MAX2 => ApiBase::LIMIT_BIG2
458 ],
459 'continue' => [
460 ApiBase::PARAM_HELP_MSG => 'api-help-param-continue',
461 ],
462 ];
463
464 if ( $config->get( 'MiserMode' ) ) {
465 $ret['prefix'][ApiBase::PARAM_HELP_MSG] = 'api-help-param-disabled-in-miser-mode';
466 }
467
468 return $ret;
469 }
470
471 protected function getExamplesMessages() {
472 return [
473 'action=query&list=logevents'
474 => 'apihelp-query+logevents-example-simple',
475 ];
476 }
477
478 public function getHelpUrls() {
479 return 'https://www.mediawiki.org/wiki/Special:MyLanguage/API:Logevents';
480 }
481 }