]> BookStack Code Mirror - bookstack/blob - routes/web.php
Quick run through of applying new test entity helper class
[bookstack] / routes / web.php
1 <?php
2
3 use BookStack\Http\Controllers\Api;
4 use BookStack\Http\Controllers\AttachmentController;
5 use BookStack\Http\Controllers\AuditLogController;
6 use BookStack\Http\Controllers\Auth;
7 use BookStack\Http\Controllers\BookController;
8 use BookStack\Http\Controllers\BookExportController;
9 use BookStack\Http\Controllers\BookshelfController;
10 use BookStack\Http\Controllers\BookSortController;
11 use BookStack\Http\Controllers\ChapterController;
12 use BookStack\Http\Controllers\ChapterExportController;
13 use BookStack\Http\Controllers\CommentController;
14 use BookStack\Http\Controllers\FavouriteController;
15 use BookStack\Http\Controllers\HomeController;
16 use BookStack\Http\Controllers\Images;
17 use BookStack\Http\Controllers\MaintenanceController;
18 use BookStack\Http\Controllers\PageController;
19 use BookStack\Http\Controllers\PageExportController;
20 use BookStack\Http\Controllers\PageRevisionController;
21 use BookStack\Http\Controllers\PageTemplateController;
22 use BookStack\Http\Controllers\RecycleBinController;
23 use BookStack\Http\Controllers\ReferenceController;
24 use BookStack\Http\Controllers\RoleController;
25 use BookStack\Http\Controllers\SearchController;
26 use BookStack\Http\Controllers\SettingController;
27 use BookStack\Http\Controllers\StatusController;
28 use BookStack\Http\Controllers\TagController;
29 use BookStack\Http\Controllers\UserApiTokenController;
30 use BookStack\Http\Controllers\UserController;
31 use BookStack\Http\Controllers\UserProfileController;
32 use BookStack\Http\Controllers\UserSearchController;
33 use BookStack\Http\Controllers\WebhookController;
34 use BookStack\Http\Middleware\VerifyCsrfToken;
35 use Illuminate\Session\Middleware\StartSession;
36 use Illuminate\Support\Facades\Route;
37 use Illuminate\View\Middleware\ShareErrorsFromSession;
38
39 Route::get('/status', [StatusController::class, 'show']);
40 Route::get('/robots.txt', [HomeController::class, 'robots']);
41
42 // Authenticated routes...
43 Route::middleware('auth')->group(function () {
44
45     // Secure images routing
46     Route::get('/uploads/images/{path}', [Images\ImageController::class, 'showImage'])
47         ->where('path', '.*$');
48
49     // API docs routes
50     Route::redirect('/api', '/api/docs');
51     Route::get('/api/docs', [Api\ApiDocsController::class, 'display']);
52
53     Route::get('/pages/recently-updated', [PageController::class, 'showRecentlyUpdated']);
54
55     // Shelves
56     Route::get('/create-shelf', [BookshelfController::class, 'create']);
57     Route::get('/shelves/', [BookshelfController::class, 'index']);
58     Route::post('/shelves/', [BookshelfController::class, 'store']);
59     Route::get('/shelves/{slug}/edit', [BookshelfController::class, 'edit']);
60     Route::get('/shelves/{slug}/delete', [BookshelfController::class, 'showDelete']);
61     Route::get('/shelves/{slug}', [BookshelfController::class, 'show']);
62     Route::put('/shelves/{slug}', [BookshelfController::class, 'update']);
63     Route::delete('/shelves/{slug}', [BookshelfController::class, 'destroy']);
64     Route::get('/shelves/{slug}/permissions', [BookshelfController::class, 'showPermissions']);
65     Route::put('/shelves/{slug}/permissions', [BookshelfController::class, 'permissions']);
66     Route::post('/shelves/{slug}/copy-permissions', [BookshelfController::class, 'copyPermissions']);
67     Route::get('/shelves/{slug}/references', [ReferenceController::class, 'shelf']);
68
69     // Book Creation
70     Route::get('/shelves/{shelfSlug}/create-book', [BookController::class, 'create']);
71     Route::post('/shelves/{shelfSlug}/create-book', [BookController::class, 'store']);
72     Route::get('/create-book', [BookController::class, 'create']);
73
74     // Books
75     Route::get('/books/', [BookController::class, 'index']);
76     Route::post('/books/', [BookController::class, 'store']);
77     Route::get('/books/{slug}/edit', [BookController::class, 'edit']);
78     Route::put('/books/{slug}', [BookController::class, 'update']);
79     Route::delete('/books/{id}', [BookController::class, 'destroy']);
80     Route::get('/books/{slug}/sort-item', [BookSortController::class, 'showItem']);
81     Route::get('/books/{slug}', [BookController::class, 'show']);
82     Route::get('/books/{bookSlug}/permissions', [BookController::class, 'showPermissions']);
83     Route::put('/books/{bookSlug}/permissions', [BookController::class, 'permissions']);
84     Route::get('/books/{slug}/delete', [BookController::class, 'showDelete']);
85     Route::get('/books/{bookSlug}/copy', [BookController::class, 'showCopy']);
86     Route::post('/books/{bookSlug}/copy', [BookController::class, 'copy']);
87     Route::post('/books/{bookSlug}/convert-to-shelf', [BookController::class, 'convertToShelf']);
88     Route::get('/books/{bookSlug}/sort', [BookSortController::class, 'show']);
89     Route::put('/books/{bookSlug}/sort', [BookSortController::class, 'update']);
90     Route::get('/books/{slug}/references', [ReferenceController::class, 'book']);
91     Route::get('/books/{bookSlug}/export/html', [BookExportController::class, 'html']);
92     Route::get('/books/{bookSlug}/export/pdf', [BookExportController::class, 'pdf']);
93     Route::get('/books/{bookSlug}/export/markdown', [BookExportController::class, 'markdown']);
94     Route::get('/books/{bookSlug}/export/zip', [BookExportController::class, 'zip']);
95     Route::get('/books/{bookSlug}/export/plaintext', [BookExportController::class, 'plainText']);
96
97     // Pages
98     Route::get('/books/{bookSlug}/create-page', [PageController::class, 'create']);
99     Route::post('/books/{bookSlug}/create-guest-page', [PageController::class, 'createAsGuest']);
100     Route::get('/books/{bookSlug}/draft/{pageId}', [PageController::class, 'editDraft']);
101     Route::post('/books/{bookSlug}/draft/{pageId}', [PageController::class, 'store']);
102     Route::get('/books/{bookSlug}/page/{pageSlug}', [PageController::class, 'show']);
103     Route::get('/books/{bookSlug}/page/{pageSlug}/export/pdf', [PageExportController::class, 'pdf']);
104     Route::get('/books/{bookSlug}/page/{pageSlug}/export/html', [PageExportController::class, 'html']);
105     Route::get('/books/{bookSlug}/page/{pageSlug}/export/markdown', [PageExportController::class, 'markdown']);
106     Route::get('/books/{bookSlug}/page/{pageSlug}/export/plaintext', [PageExportController::class, 'plainText']);
107     Route::get('/books/{bookSlug}/page/{pageSlug}/edit', [PageController::class, 'edit']);
108     Route::get('/books/{bookSlug}/page/{pageSlug}/move', [PageController::class, 'showMove']);
109     Route::put('/books/{bookSlug}/page/{pageSlug}/move', [PageController::class, 'move']);
110     Route::get('/books/{bookSlug}/page/{pageSlug}/copy', [PageController::class, 'showCopy']);
111     Route::post('/books/{bookSlug}/page/{pageSlug}/copy', [PageController::class, 'copy']);
112     Route::get('/books/{bookSlug}/page/{pageSlug}/delete', [PageController::class, 'showDelete']);
113     Route::get('/books/{bookSlug}/draft/{pageId}/delete', [PageController::class, 'showDeleteDraft']);
114     Route::get('/books/{bookSlug}/page/{pageSlug}/permissions', [PageController::class, 'showPermissions']);
115     Route::put('/books/{bookSlug}/page/{pageSlug}/permissions', [PageController::class, 'permissions']);
116     Route::get('/books/{bookSlug}/page/{pageSlug}/references', [ReferenceController::class, 'page']);
117     Route::put('/books/{bookSlug}/page/{pageSlug}', [PageController::class, 'update']);
118     Route::delete('/books/{bookSlug}/page/{pageSlug}', [PageController::class, 'destroy']);
119     Route::delete('/books/{bookSlug}/draft/{pageId}', [PageController::class, 'destroyDraft']);
120
121     // Revisions
122     Route::get('/books/{bookSlug}/page/{pageSlug}/revisions', [PageRevisionController::class, 'index']);
123     Route::get('/books/{bookSlug}/page/{pageSlug}/revisions/{revId}', [PageRevisionController::class, 'show']);
124     Route::get('/books/{bookSlug}/page/{pageSlug}/revisions/{revId}/changes', [PageRevisionController::class, 'changes']);
125     Route::put('/books/{bookSlug}/page/{pageSlug}/revisions/{revId}/restore', [PageRevisionController::class, 'restore']);
126     Route::delete('/books/{bookSlug}/page/{pageSlug}/revisions/{revId}/delete', [PageRevisionController::class, 'destroy']);
127
128     // Chapters
129     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/create-page', [PageController::class, 'create']);
130     Route::post('/books/{bookSlug}/chapter/{chapterSlug}/create-guest-page', [PageController::class, 'createAsGuest']);
131     Route::get('/books/{bookSlug}/create-chapter', [ChapterController::class, 'create']);
132     Route::post('/books/{bookSlug}/create-chapter', [ChapterController::class, 'store']);
133     Route::get('/books/{bookSlug}/chapter/{chapterSlug}', [ChapterController::class, 'show']);
134     Route::put('/books/{bookSlug}/chapter/{chapterSlug}', [ChapterController::class, 'update']);
135     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/move', [ChapterController::class, 'showMove']);
136     Route::put('/books/{bookSlug}/chapter/{chapterSlug}/move', [ChapterController::class, 'move']);
137     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/copy', [ChapterController::class, 'showCopy']);
138     Route::post('/books/{bookSlug}/chapter/{chapterSlug}/copy', [ChapterController::class, 'copy']);
139     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/edit', [ChapterController::class, 'edit']);
140     Route::post('/books/{bookSlug}/chapter/{chapterSlug}/convert-to-book', [ChapterController::class, 'convertToBook']);
141     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/permissions', [ChapterController::class, 'showPermissions']);
142     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/export/pdf', [ChapterExportController::class, 'pdf']);
143     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/export/html', [ChapterExportController::class, 'html']);
144     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/export/markdown', [ChapterExportController::class, 'markdown']);
145     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/export/plaintext', [ChapterExportController::class, 'plainText']);
146     Route::put('/books/{bookSlug}/chapter/{chapterSlug}/permissions', [ChapterController::class, 'permissions']);
147     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/references', [ReferenceController::class, 'chapter']);
148     Route::get('/books/{bookSlug}/chapter/{chapterSlug}/delete', [ChapterController::class, 'showDelete']);
149     Route::delete('/books/{bookSlug}/chapter/{chapterSlug}', [ChapterController::class, 'destroy']);
150
151     // User Profile routes
152     Route::get('/user/{slug}', [UserProfileController::class, 'show']);
153
154     // Image routes
155     Route::get('/images/gallery', [Images\GalleryImageController::class, 'list']);
156     Route::post('/images/gallery', [Images\GalleryImageController::class, 'create']);
157     Route::get('/images/drawio', [Images\DrawioImageController::class, 'list']);
158     Route::get('/images/drawio/base64/{id}', [Images\DrawioImageController::class, 'getAsBase64']);
159     Route::post('/images/drawio', [Images\DrawioImageController::class, 'create']);
160     Route::get('/images/edit/{id}', [Images\ImageController::class, 'edit']);
161     Route::put('/images/{id}', [Images\ImageController::class, 'update']);
162     Route::delete('/images/{id}', [Images\ImageController::class, 'destroy']);
163
164     // Attachments routes
165     Route::get('/attachments/{id}', [AttachmentController::class, 'get']);
166     Route::post('/attachments/upload', [AttachmentController::class, 'upload']);
167     Route::post('/attachments/upload/{id}', [AttachmentController::class, 'uploadUpdate']);
168     Route::post('/attachments/link', [AttachmentController::class, 'attachLink']);
169     Route::put('/attachments/{id}', [AttachmentController::class, 'update']);
170     Route::get('/attachments/edit/{id}', [AttachmentController::class, 'getUpdateForm']);
171     Route::get('/attachments/get/page/{pageId}', [AttachmentController::class, 'listForPage']);
172     Route::put('/attachments/sort/page/{pageId}', [AttachmentController::class, 'sortForPage']);
173     Route::delete('/attachments/{id}', [AttachmentController::class, 'delete']);
174
175     // AJAX routes
176     Route::put('/ajax/page/{id}/save-draft', [PageController::class, 'saveDraft']);
177     Route::get('/ajax/page/{id}', [PageController::class, 'getPageAjax']);
178     Route::delete('/ajax/page/{id}', [PageController::class, 'ajaxDestroy']);
179
180     // Tag routes
181     Route::get('/tags', [TagController::class, 'index']);
182     Route::get('/ajax/tags/suggest/names', [TagController::class, 'getNameSuggestions']);
183     Route::get('/ajax/tags/suggest/values', [TagController::class, 'getValueSuggestions']);
184
185     Route::get('/ajax/search/entities', [SearchController::class, 'searchEntitiesAjax']);
186
187     // Comments
188     Route::post('/comment/{pageId}', [CommentController::class, 'savePageComment']);
189     Route::put('/comment/{id}', [CommentController::class, 'update']);
190     Route::delete('/comment/{id}', [CommentController::class, 'destroy']);
191
192     // Links
193     Route::get('/link/{id}', [PageController::class, 'redirectFromLink']);
194
195     // Search
196     Route::get('/search', [SearchController::class, 'search']);
197     Route::get('/search/book/{bookId}', [SearchController::class, 'searchBook']);
198     Route::get('/search/chapter/{bookId}', [SearchController::class, 'searchChapter']);
199     Route::get('/search/entity/siblings', [SearchController::class, 'searchSiblings']);
200
201     // User Search
202     Route::get('/search/users/select', [UserSearchController::class, 'forSelect']);
203
204     // Template System
205     Route::get('/templates', [PageTemplateController::class, 'list']);
206     Route::get('/templates/{templateId}', [PageTemplateController::class, 'get']);
207
208     // Favourites
209     Route::get('/favourites', [FavouriteController::class, 'index']);
210     Route::post('/favourites/add', [FavouriteController::class, 'add']);
211     Route::post('/favourites/remove', [FavouriteController::class, 'remove']);
212
213     // Other Pages
214     Route::get('/', [HomeController::class, 'index']);
215     Route::get('/home', [HomeController::class, 'index']);
216
217     // Maintenance
218     Route::get('/settings/maintenance', [MaintenanceController::class, 'index']);
219     Route::delete('/settings/maintenance/cleanup-images', [MaintenanceController::class, 'cleanupImages']);
220     Route::post('/settings/maintenance/send-test-email', [MaintenanceController::class, 'sendTestEmail']);
221     Route::post('/settings/maintenance/regenerate-references', [MaintenanceController::class, 'regenerateReferences']);
222
223     // Recycle Bin
224     Route::get('/settings/recycle-bin', [RecycleBinController::class, 'index']);
225     Route::post('/settings/recycle-bin/empty', [RecycleBinController::class, 'empty']);
226     Route::get('/settings/recycle-bin/{id}/destroy', [RecycleBinController::class, 'showDestroy']);
227     Route::delete('/settings/recycle-bin/{id}', [RecycleBinController::class, 'destroy']);
228     Route::get('/settings/recycle-bin/{id}/restore', [RecycleBinController::class, 'showRestore']);
229     Route::post('/settings/recycle-bin/{id}/restore', [RecycleBinController::class, 'restore']);
230
231     // Audit Log
232     Route::get('/settings/audit', [AuditLogController::class, 'index']);
233
234     // Users
235     Route::get('/settings/users', [UserController::class, 'index']);
236     Route::get('/settings/users/create', [UserController::class, 'create']);
237     Route::get('/settings/users/{id}/delete', [UserController::class, 'delete']);
238     Route::patch('/settings/users/{id}/switch-books-view', [UserController::class, 'switchBooksView']);
239     Route::patch('/settings/users/{id}/switch-shelves-view', [UserController::class, 'switchShelvesView']);
240     Route::patch('/settings/users/{id}/switch-shelf-view', [UserController::class, 'switchShelfView']);
241     Route::patch('/settings/users/{id}/change-sort/{type}', [UserController::class, 'changeSort']);
242     Route::patch('/settings/users/{id}/update-expansion-preference/{key}', [UserController::class, 'updateExpansionPreference']);
243     Route::patch('/settings/users/toggle-dark-mode', [UserController::class, 'toggleDarkMode']);
244     Route::patch('/settings/users/update-code-language-favourite', [UserController::class, 'updateCodeLanguageFavourite']);
245     Route::post('/settings/users/create', [UserController::class, 'store']);
246     Route::get('/settings/users/{id}', [UserController::class, 'edit']);
247     Route::put('/settings/users/{id}', [UserController::class, 'update']);
248     Route::delete('/settings/users/{id}', [UserController::class, 'destroy']);
249
250     // User API Tokens
251     Route::get('/settings/users/{userId}/create-api-token', [UserApiTokenController::class, 'create']);
252     Route::post('/settings/users/{userId}/create-api-token', [UserApiTokenController::class, 'store']);
253     Route::get('/settings/users/{userId}/api-tokens/{tokenId}', [UserApiTokenController::class, 'edit']);
254     Route::put('/settings/users/{userId}/api-tokens/{tokenId}', [UserApiTokenController::class, 'update']);
255     Route::get('/settings/users/{userId}/api-tokens/{tokenId}/delete', [UserApiTokenController::class, 'delete']);
256     Route::delete('/settings/users/{userId}/api-tokens/{tokenId}', [UserApiTokenController::class, 'destroy']);
257
258     // Roles
259     Route::get('/settings/roles', [RoleController::class, 'index']);
260     Route::get('/settings/roles/new', [RoleController::class, 'create']);
261     Route::post('/settings/roles/new', [RoleController::class, 'store']);
262     Route::get('/settings/roles/delete/{id}', [RoleController::class, 'showDelete']);
263     Route::delete('/settings/roles/delete/{id}', [RoleController::class, 'delete']);
264     Route::get('/settings/roles/{id}', [RoleController::class, 'edit']);
265     Route::put('/settings/roles/{id}', [RoleController::class, 'update']);
266
267     // Webhooks
268     Route::get('/settings/webhooks', [WebhookController::class, 'index']);
269     Route::get('/settings/webhooks/create', [WebhookController::class, 'create']);
270     Route::post('/settings/webhooks/create', [WebhookController::class, 'store']);
271     Route::get('/settings/webhooks/{id}', [WebhookController::class, 'edit']);
272     Route::put('/settings/webhooks/{id}', [WebhookController::class, 'update']);
273     Route::get('/settings/webhooks/{id}/delete', [WebhookController::class, 'delete']);
274     Route::delete('/settings/webhooks/{id}', [WebhookController::class, 'destroy']);
275
276     // Settings
277     Route::get('/settings', [SettingController::class, 'index'])->name('settings');
278     Route::get('/settings/{category}', [SettingController::class, 'category'])->name('settings.category');
279     Route::post('/settings/{category}', [SettingController::class, 'update']);
280 });
281
282 // MFA routes
283 Route::middleware('mfa-setup')->group(function () {
284     Route::get('/mfa/setup', [Auth\MfaController::class, 'setup']);
285     Route::get('/mfa/totp/generate', [Auth\MfaTotpController::class, 'generate']);
286     Route::post('/mfa/totp/confirm', [Auth\MfaTotpController::class, 'confirm']);
287     Route::get('/mfa/backup_codes/generate', [Auth\MfaBackupCodesController::class, 'generate']);
288     Route::post('/mfa/backup_codes/confirm', [Auth\MfaBackupCodesController::class, 'confirm']);
289 });
290 Route::middleware('guest')->group(function () {
291     Route::get('/mfa/verify', [Auth\MfaController::class, 'verify']);
292     Route::post('/mfa/totp/verify', [Auth\MfaTotpController::class, 'verify']);
293     Route::post('/mfa/backup_codes/verify', [Auth\MfaBackupCodesController::class, 'verify']);
294 });
295 Route::delete('/mfa/{method}/remove', [Auth\MfaController::class, 'remove'])->middleware('auth');
296
297 // Social auth routes
298 Route::get('/login/service/{socialDriver}', [Auth\SocialController::class, 'login']);
299 Route::get('/login/service/{socialDriver}/callback', [Auth\SocialController::class, 'callback']);
300 Route::post('/login/service/{socialDriver}/detach', [Auth\SocialController::class, 'detach'])->middleware('auth');
301 Route::get('/register/service/{socialDriver}', [Auth\SocialController::class, 'register']);
302
303 // Login/Logout routes
304 Route::get('/login', [Auth\LoginController::class, 'getLogin']);
305 Route::post('/login', [Auth\LoginController::class, 'login']);
306 Route::post('/logout', [Auth\LoginController::class, 'logout']);
307 Route::get('/register', [Auth\RegisterController::class, 'getRegister']);
308 Route::get('/register/confirm', [Auth\ConfirmEmailController::class, 'show']);
309 Route::get('/register/confirm/awaiting', [Auth\ConfirmEmailController::class, 'showAwaiting']);
310 Route::post('/register/confirm/resend', [Auth\ConfirmEmailController::class, 'resend']);
311 Route::get('/register/confirm/{token}', [Auth\ConfirmEmailController::class, 'confirm']);
312 Route::post('/register', [Auth\RegisterController::class, 'postRegister']);
313
314 // SAML routes
315 Route::post('/saml2/login', [Auth\Saml2Controller::class, 'login']);
316 Route::post('/saml2/logout', [Auth\Saml2Controller::class, 'logout']);
317 Route::get('/saml2/metadata', [Auth\Saml2Controller::class, 'metadata']);
318 Route::get('/saml2/sls', [Auth\Saml2Controller::class, 'sls']);
319 Route::post('/saml2/acs', [Auth\Saml2Controller::class, 'startAcs'])->withoutMiddleware([
320     StartSession::class,
321     ShareErrorsFromSession::class,
322     VerifyCsrfToken::class,
323 ]);
324 Route::get('/saml2/acs', [Auth\Saml2Controller::class, 'processAcs']);
325
326 // OIDC routes
327 Route::post('/oidc/login', [Auth\OidcController::class, 'login']);
328 Route::get('/oidc/callback', [Auth\OidcController::class, 'callback']);
329
330 // User invitation routes
331 Route::get('/register/invite/{token}', [Auth\UserInviteController::class, 'showSetPassword']);
332 Route::post('/register/invite/{token}', [Auth\UserInviteController::class, 'setPassword']);
333
334 // Password reset link request routes
335 Route::get('/password/email', [Auth\ForgotPasswordController::class, 'showLinkRequestForm']);
336 Route::post('/password/email', [Auth\ForgotPasswordController::class, 'sendResetLinkEmail']);
337
338 // Password reset routes
339 Route::get('/password/reset/{token}', [Auth\ResetPasswordController::class, 'showResetForm']);
340 Route::post('/password/reset', [Auth\ResetPasswordController::class, 'reset']);
341
342 // Metadata routes
343 Route::view('/help/wysiwyg', 'help.wysiwyg');
344
345 Route::fallback([HomeController::class, 'notFound'])->name('fallback');