3 * Raw page text accessor
5 * Copyright © 2004 Gabriel Wicke <wicke@wikidev.net>
8 * Based on HistoryAction and SpecialExport
10 * This program is free software; you can redistribute it and/or modify
11 * it under the terms of the GNU General Public License as published by
12 * the Free Software Foundation; either version 2 of the License, or
13 * (at your option) any later version.
15 * This program is distributed in the hope that it will be useful,
16 * but WITHOUT ANY WARRANTY; without even the implied warranty of
17 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18 * GNU General Public License for more details.
20 * You should have received a copy of the GNU General Public License along
21 * with this program; if not, write to the Free Software Foundation, Inc.,
22 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
23 * http://www.gnu.org/copyleft/gpl.html
25 * @author Gabriel Wicke <wicke@wikidev.net>
29 use MediaWiki\Logger\LoggerFactory
;
30 use MediaWiki\MediaWikiServices
;
33 * A simple method to retrieve the plain source of an article,
34 * using "action=raw" in the GET request string.
38 class RawAction
extends FormlessAction
{
39 public function getName() {
43 public function requiresWrite() {
47 public function requiresUnblock() {
52 * @suppress SecurityCheck-XSS Non html mime type
56 $this->getOutput()->disable();
57 $request = $this->getRequest();
58 $response = $request->response();
59 $config = $this->context
->getConfig();
61 if ( !$request->checkUrlExtension() ) {
65 if ( $this->getOutput()->checkLastModified( $this->page
->getTouched() ) ) {
66 return null; // Client cache fresh and headers sent, nothing more to do.
69 $contentType = $this->getContentType();
71 $maxage = $request->getInt( 'maxage', $config->get( 'CdnMaxAge' ) );
72 $smaxage = $request->getIntOrNull( 'smaxage' );
73 if ( $smaxage === null ) {
75 $contentType == 'text/css' ||
76 $contentType == 'application/json' ||
77 $contentType == 'text/javascript'
79 // CSS/JSON/JS raw content has its own CDN max age configuration.
80 // Note: Title::getCdnUrls() includes action=raw for css/json/js
81 // pages, so if using the canonical url, this will get HTCP purges.
82 $smaxage = intval( $config->get( 'ForcedRawSMaxage' ) );
84 // No CDN cache for anything else
89 // Set standard Vary headers so cache varies on cookies and such (T125283)
90 $response->header( $this->getOutput()->getVaryHeader() );
91 if ( $config->get( 'UseKeyHeader' ) ) {
92 $response->header( $this->getOutput()->getKeyHeader() );
95 // Output may contain user-specific data;
96 // vary generated content for open sessions on private wikis
97 $privateCache = !User
::isEveryoneAllowed( 'read' ) &&
98 ( $smaxage == 0 || MediaWiki\Session\SessionManager
::getGlobalSession()->isPersistent() );
99 // Don't accidentally cache cookies if user is logged in (T55032)
100 $privateCache = $privateCache ||
$this->getUser()->isLoggedIn();
101 $mode = $privateCache ?
'private' : 'public';
103 'Cache-Control: ' . $mode . ', s-maxage=' . $smaxage . ', max-age=' . $maxage
106 // In the event of user JS, don't allow loading a user JS/CSS/Json
107 // subpage that has no registered user associated with, as
108 // someone could register the account and take control of the
110 $title = $this->getTitle();
111 if ( $title->isUserConfigPage() && $contentType !== 'text/x-wiki' ) {
112 // not using getRootText() as we want this to work
113 // even if subpages are disabled.
114 $rootPage = strtok( $title->getText(), '/' );
115 $userFromTitle = User
::newFromName( $rootPage, 'usable' );
116 if ( !$userFromTitle ||
$userFromTitle->getId() === 0 ) {
117 $elevated = $this->getUser()->isAllowed( 'editinterface' );
118 $elevatedText = $elevated ?
'by elevated ' : '';
119 $log = LoggerFactory
::getInstance( "security" );
121 "Unsafe JS/CSS/Json {$elevatedText}load - {user} loaded {title} with {ctype}",
123 'user' => $this->getUser()->getName(),
124 'title' => $title->getPrefixedDBkey(),
125 'ctype' => $contentType,
126 'elevated' => $elevated
129 $msg = wfMessage( 'unregistered-user-config' );
130 throw new HttpError( 403, $msg );
134 // Don't allow loading non-protected pages as javascript.
135 // In future we may further restrict this to only CONTENT_MODEL_JAVASCRIPT
136 // in NS_MEDIAWIKI or NS_USER, as well as including other config types,
137 // but for now be more permissive. Allowing protected pages outside of
138 // NS_USER and NS_MEDIAWIKI in particular should be considered a temporary
141 $contentType === 'text/javascript' &&
142 !$title->isUserJsConfigPage() &&
143 !$title->inNamespace( NS_MEDIAWIKI
) &&
144 !in_array( 'sysop', $title->getRestrictions( 'edit' ) ) &&
145 !in_array( 'editprotected', $title->getRestrictions( 'edit' ) )
148 $log = LoggerFactory
::getInstance( "security" );
149 $log->info( "Blocked loading unprotected JS {title} for {user}",
151 'user' => $this->getUser()->getName(),
152 'title' => $title->getPrefixedDBkey(),
155 throw new HttpError( 403, wfMessage( 'unprotected-js' ) );
158 $response->header( 'Content-type: ' . $contentType . '; charset=UTF-8' );
160 $text = $this->getRawText();
162 // Don't return a 404 response for CSS or JavaScript;
163 // 404s aren't generally cached and it would create
164 // extra hits when user CSS/JS are on and the user doesn't
166 if ( $text === false && $contentType == 'text/x-wiki' ) {
167 $response->statusHeader( 404 );
170 // Avoid PHP 7.1 warning of passing $this by reference
172 if ( !Hooks
::run( 'RawPageViewBeforeOutput', [ &$rawAction, &$text ] ) ) {
173 wfDebug( __METHOD__
. ": RawPageViewBeforeOutput hook broke raw page output.\n" );
182 * Get the text that should be returned, or false if the page or revision
185 * @return string|bool
187 public function getRawText() {
189 $title = $this->getTitle();
190 $request = $this->getRequest();
192 // Get it from the DB
193 $rev = Revision
::newFromTitle( $title, $this->getOldId() );
195 $lastmod = wfTimestamp( TS_RFC2822
, $rev->getTimestamp() );
196 $request->response()->header( "Last-modified: $lastmod" );
198 // Public-only due to cache headers
199 $content = $rev->getContent();
201 if ( $content === null ) {
202 // revision not found (or suppressed)
204 } elseif ( !$content instanceof TextContent
) {
206 wfHttpError( 415, "Unsupported Media Type", "The requested page uses the content model `"
207 . $content->getModel() . "` which is not supported via this interface." );
211 $section = $request->getIntOrNull( 'section' );
212 if ( $section !== null ) {
213 $content = $content->getSection( $section );
216 if ( $content === null ||
$content === false ) {
217 // section not found (or section not supported, e.g. for JS, JSON, and CSS)
220 $text = $content->getText();
225 if ( $text !== false && $text !== '' && $request->getRawVal( 'templates' ) === 'expand' ) {
226 $text = MediaWikiServices
::getInstance()->getParser()->preprocess(
229 ParserOptions
::newFromContext( $this->getContext() )
237 * Get the ID of the revision that should used to get the text.
241 public function getOldId() {
242 $oldid = $this->getRequest()->getInt( 'oldid' );
243 switch ( $this->getRequest()->getText( 'direction' ) ) {
245 # output next revision, or nothing if there isn't one
248 $nextid = $this->getTitle()->getNextRevisionID( $oldid );
250 $oldid = $nextid ?
: -1;
253 # output previous revision, or nothing if there isn't one
255 # get the current revision so we can get the penultimate one
256 $oldid = $this->page
->getLatest();
258 $previd = $this->getTitle()->getPreviousRevisionID( $oldid );
259 $oldid = $previd ?
: -1;
270 * Get the content type to use for the response
274 public function getContentType() {
275 // Use getRawVal instead of getVal because we only
276 // need to match against known strings, there is no
277 // storing of localised content or other user input.
278 $ctype = $this->getRequest()->getRawVal( 'ctype' );
280 if ( $ctype == '' ) {
281 // Legacy compatibilty
282 $gen = $this->getRequest()->getRawVal( 'gen' );
283 if ( $gen == 'js' ) {
284 $ctype = 'text/javascript';
285 } elseif ( $gen == 'css' ) {
294 // FIXME: Should we still allow Zope editing? External editing feature was dropped
295 'application/x-zope-edit',
298 if ( $ctype == '' ||
!in_array( $ctype, $allowedCTypes ) ) {
299 $ctype = 'text/x-wiki';