webapp.py 50 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415
  1. #!/usr/bin/env python
  2. # SPDX-License-Identifier: AGPL-3.0-or-later
  3. """WebbApp
  4. """
  5. # pylint: disable=use-dict-literal
  6. from __future__ import annotations
  7. import inspect
  8. import json
  9. import os
  10. import sys
  11. import base64
  12. from timeit import default_timer
  13. from html import escape
  14. from io import StringIO
  15. import typing
  16. import urllib
  17. import urllib.parse
  18. from urllib.parse import urlencode, urlparse, unquote
  19. import warnings
  20. import httpx
  21. from pygments import highlight
  22. from pygments.lexers import get_lexer_by_name
  23. from pygments.formatters import HtmlFormatter # pylint: disable=no-name-in-module
  24. from werkzeug.serving import is_running_from_reloader
  25. import flask
  26. from flask import (
  27. Flask,
  28. render_template,
  29. url_for,
  30. make_response,
  31. redirect,
  32. send_from_directory,
  33. )
  34. from flask.wrappers import Response
  35. from flask.json import jsonify
  36. from flask_babel import (
  37. Babel,
  38. gettext,
  39. format_decimal,
  40. )
  41. import searx
  42. from searx.extended_types import sxng_request
  43. from searx import (
  44. logger,
  45. get_setting,
  46. settings,
  47. )
  48. from searx import infopage
  49. from searx import limiter
  50. from searx.botdetection import link_token
  51. from searx.data import ENGINE_DESCRIPTIONS
  52. from searx.result_types import Answer
  53. from searx.settings_defaults import OUTPUT_FORMATS
  54. from searx.settings_loader import DEFAULT_SETTINGS_FILE
  55. from searx.exceptions import SearxParameterException
  56. from searx.engines import (
  57. DEFAULT_CATEGORY,
  58. categories,
  59. engines,
  60. engine_shortcuts,
  61. )
  62. from searx import webutils
  63. from searx.webutils import (
  64. highlight_content,
  65. get_static_files,
  66. get_result_templates,
  67. get_themes,
  68. exception_classname_to_text,
  69. new_hmac,
  70. is_hmac_of,
  71. group_engines_in_tab,
  72. )
  73. from searx.webadapter import (
  74. get_search_query_from_webapp,
  75. get_selected_categories,
  76. parse_lang,
  77. )
  78. from searx.utils import gen_useragent, dict_subset
  79. from searx.version import VERSION_STRING, GIT_URL, GIT_BRANCH
  80. from searx.query import RawTextQuery
  81. from searx.plugins.oa_doi_rewrite import get_doi_resolver
  82. from searx.preferences import (
  83. Preferences,
  84. ClientPref,
  85. ValidationException,
  86. )
  87. import searx.answerers
  88. import searx.plugins
  89. from searx.metrics import get_engines_stats, get_engine_errors, get_reliabilities, histogram, counter, openmetrics
  90. from searx.flaskfix import patch_application
  91. from searx.locales import (
  92. LOCALE_BEST_MATCH,
  93. LOCALE_NAMES,
  94. RTL_LOCALES,
  95. localeselector,
  96. locales_initialize,
  97. match_locale,
  98. )
  99. # renaming names from searx imports ...
  100. from searx.autocomplete import search_autocomplete, backends as autocomplete_backends
  101. from searx import favicons
  102. from searx.redisdb import initialize as redis_initialize
  103. from searx.sxng_locales import sxng_locales
  104. import searx.search
  105. from searx.network import stream as http_stream, set_context_network_name
  106. from searx.search.checker import get_result as checker_get_result
  107. logger = logger.getChild('webapp')
  108. warnings.simplefilter("always")
  109. # about static
  110. logger.debug('static directory is %s', settings['ui']['static_path'])
  111. static_files = get_static_files(settings['ui']['static_path'])
  112. # about templates
  113. logger.debug('templates directory is %s', settings['ui']['templates_path'])
  114. default_theme = settings['ui']['default_theme']
  115. templates_path = settings['ui']['templates_path']
  116. themes = get_themes(templates_path)
  117. result_templates = get_result_templates(templates_path)
  118. STATS_SORT_PARAMETERS = {
  119. 'name': (False, 'name', ''),
  120. 'score': (True, 'score_per_result', 0),
  121. 'result_count': (True, 'result_count', 0),
  122. 'time': (False, 'total', 0),
  123. 'reliability': (False, 'reliability', 100),
  124. }
  125. # Flask app
  126. app = Flask(__name__, static_folder=settings['ui']['static_path'], template_folder=templates_path)
  127. app.jinja_env.trim_blocks = True
  128. app.jinja_env.lstrip_blocks = True
  129. app.jinja_env.add_extension('jinja2.ext.loopcontrols') # pylint: disable=no-member
  130. app.jinja_env.filters['group_engines_in_tab'] = group_engines_in_tab # pylint: disable=no-member
  131. app.secret_key = settings['server']['secret_key']
  132. def get_locale():
  133. locale = localeselector()
  134. logger.debug("%s uses locale `%s`", urllib.parse.quote(sxng_request.url), locale)
  135. return locale
  136. babel = Babel(app, locale_selector=get_locale)
  137. def _get_browser_language(req, lang_list):
  138. client = ClientPref.from_http_request(req)
  139. locale = match_locale(client.locale_tag, lang_list, fallback='en')
  140. return locale
  141. def _get_locale_rfc5646(locale):
  142. """Get locale name for <html lang="...">
  143. Chrom* browsers don't detect the language when there is a subtag (ie a territory).
  144. For example "zh-TW" is detected but not "zh-Hant-TW".
  145. This function returns a locale without the subtag.
  146. """
  147. parts = locale.split('-')
  148. return parts[0].lower() + '-' + parts[-1].upper()
  149. # code-highlighter
  150. @app.template_filter('code_highlighter')
  151. def code_highlighter(codelines, language=None):
  152. if not language:
  153. language = 'text'
  154. try:
  155. # find lexer by programming language
  156. lexer = get_lexer_by_name(language, stripall=True)
  157. except Exception as e: # pylint: disable=broad-except
  158. logger.warning("pygments lexer: %s " % e)
  159. # if lexer is not found, using default one
  160. lexer = get_lexer_by_name('text', stripall=True)
  161. html_code = ''
  162. tmp_code = ''
  163. last_line = None
  164. line_code_start = None
  165. # parse lines
  166. for line, code in codelines:
  167. if not last_line:
  168. line_code_start = line
  169. # new codeblock is detected
  170. if last_line is not None and last_line + 1 != line:
  171. # highlight last codepart
  172. formatter = HtmlFormatter(linenos='inline', linenostart=line_code_start, cssclass="code-highlight")
  173. html_code = html_code + highlight(tmp_code, lexer, formatter)
  174. # reset conditions for next codepart
  175. tmp_code = ''
  176. line_code_start = line
  177. # add codepart
  178. tmp_code += code + '\n'
  179. # update line
  180. last_line = line
  181. # highlight last codepart
  182. formatter = HtmlFormatter(linenos='inline', linenostart=line_code_start, cssclass="code-highlight")
  183. html_code = html_code + highlight(tmp_code, lexer, formatter)
  184. return html_code
  185. def get_result_template(theme_name: str, template_name: str):
  186. themed_path = theme_name + '/result_templates/' + template_name
  187. if themed_path in result_templates:
  188. return themed_path
  189. return 'result_templates/' + template_name
  190. def custom_url_for(endpoint: str, **values):
  191. suffix = ""
  192. if endpoint == 'static' and values.get('filename'):
  193. file_hash = static_files.get(values['filename'])
  194. if not file_hash:
  195. # try file in the current theme
  196. theme_name = sxng_request.preferences.get_value('theme')
  197. filename_with_theme = "themes/{}/{}".format(theme_name, values['filename'])
  198. file_hash = static_files.get(filename_with_theme)
  199. if file_hash:
  200. values['filename'] = filename_with_theme
  201. if get_setting('ui.static_use_hash') and file_hash:
  202. suffix = "?" + file_hash
  203. if endpoint == 'info' and 'locale' not in values:
  204. locale = sxng_request.preferences.get_value('locale')
  205. if infopage.INFO_PAGES.get_page(values['pagename'], locale) is None:
  206. locale = infopage.INFO_PAGES.locale_default
  207. values['locale'] = locale
  208. return url_for(endpoint, **values) + suffix
  209. def image_proxify(url: str):
  210. if not url:
  211. return url
  212. if url.startswith('//'):
  213. url = 'https:' + url
  214. if not sxng_request.preferences.get_value('image_proxy'):
  215. return url
  216. if url.startswith('data:image/'):
  217. # 50 is an arbitrary number to get only the beginning of the image.
  218. partial_base64 = url[len('data:image/') : 50].split(';')
  219. if (
  220. len(partial_base64) == 2
  221. and partial_base64[0] in ['gif', 'png', 'jpeg', 'pjpeg', 'webp', 'tiff', 'bmp']
  222. and partial_base64[1].startswith('base64,')
  223. ):
  224. return url
  225. return None
  226. h = new_hmac(settings['server']['secret_key'], url.encode())
  227. return '{0}?{1}'.format(url_for('image_proxy'), urlencode(dict(url=url.encode(), h=h)))
  228. def get_translations():
  229. return {
  230. # when there is autocompletion
  231. 'no_item_found': gettext('No item found'),
  232. # /preferences: the source of the engine description (wikipedata, wikidata, website)
  233. 'Source': gettext('Source'),
  234. # infinite scroll
  235. 'error_loading_next_page': gettext('Error loading the next page'),
  236. }
  237. def get_enabled_categories(category_names: typing.Iterable[str]):
  238. """The categories in ``category_names```for which there is no active engine
  239. are filtered out and a reduced list is returned."""
  240. enabled_engines = [item[0] for item in sxng_request.preferences.engines.get_enabled()]
  241. enabled_categories = set()
  242. for engine_name in enabled_engines:
  243. enabled_categories.update(engines[engine_name].categories)
  244. return [x for x in category_names if x in enabled_categories]
  245. def get_pretty_url(parsed_url: urllib.parse.ParseResult):
  246. url_formatting_pref = sxng_request.preferences.get_value('url_formatting')
  247. if url_formatting_pref == 'full':
  248. return [parsed_url.geturl()]
  249. if url_formatting_pref == 'host':
  250. return [parsed_url.netloc]
  251. path = parsed_url.path
  252. path = path[:-1] if len(path) > 0 and path[-1] == '/' else path
  253. path = unquote(path.replace("/", " › "))
  254. return [parsed_url.scheme + "://" + parsed_url.netloc, path]
  255. def get_client_settings():
  256. req_pref = sxng_request.preferences
  257. return {
  258. 'autocomplete': req_pref.get_value('autocomplete'),
  259. 'autocomplete_min': get_setting('search.autocomplete_min'),
  260. 'method': req_pref.get_value('method'),
  261. 'infinite_scroll': req_pref.get_value('infinite_scroll'),
  262. 'translations': get_translations(),
  263. 'search_on_category_select': req_pref.get_value('search_on_category_select'),
  264. 'hotkeys': req_pref.get_value('hotkeys'),
  265. 'url_formatting': req_pref.get_value('url_formatting'),
  266. 'theme_static_path': custom_url_for('static', filename='themes/simple'),
  267. 'results_on_new_tab': req_pref.get_value('results_on_new_tab'),
  268. 'favicon_resolver': req_pref.get_value('favicon_resolver'),
  269. 'advanced_search': req_pref.get_value('advanced_search'),
  270. 'query_in_title': req_pref.get_value('query_in_title'),
  271. 'safesearch': str(req_pref.get_value('safesearch')),
  272. 'theme': req_pref.get_value('theme'),
  273. 'doi_resolver': get_doi_resolver(),
  274. }
  275. def render(template_name: str, **kwargs):
  276. # values from the preferences
  277. # pylint: disable=too-many-statements
  278. client_settings = get_client_settings()
  279. kwargs['client_settings'] = str(
  280. base64.b64encode(
  281. bytes(
  282. json.dumps(client_settings),
  283. encoding='utf-8',
  284. )
  285. ),
  286. encoding='utf-8',
  287. )
  288. kwargs['preferences'] = sxng_request.preferences
  289. kwargs.update(client_settings)
  290. # values from the HTTP requests
  291. kwargs['endpoint'] = 'results' if 'q' in kwargs else sxng_request.endpoint
  292. kwargs['cookies'] = sxng_request.cookies
  293. kwargs['errors'] = sxng_request.errors
  294. kwargs['link_token'] = link_token.get_token()
  295. kwargs['categories_as_tabs'] = list(settings['categories_as_tabs'].keys())
  296. kwargs['categories'] = get_enabled_categories(settings['categories_as_tabs'].keys())
  297. kwargs['DEFAULT_CATEGORY'] = DEFAULT_CATEGORY
  298. # i18n
  299. kwargs['sxng_locales'] = [l for l in sxng_locales if l[0] in settings['search']['languages']]
  300. locale = sxng_request.preferences.get_value('locale')
  301. kwargs['locale_rfc5646'] = _get_locale_rfc5646(locale)
  302. if locale in RTL_LOCALES and 'rtl' not in kwargs:
  303. kwargs['rtl'] = True
  304. if 'current_language' not in kwargs:
  305. kwargs['current_language'] = parse_lang(sxng_request.preferences, {}, RawTextQuery('', []))
  306. # values from settings
  307. kwargs['search_formats'] = [x for x in settings['search']['formats'] if x != 'html']
  308. kwargs['instance_name'] = get_setting('general.instance_name')
  309. kwargs['searx_version'] = VERSION_STRING
  310. kwargs['searx_git_url'] = GIT_URL
  311. kwargs['enable_metrics'] = get_setting('general.enable_metrics')
  312. kwargs['get_setting'] = get_setting
  313. kwargs['get_pretty_url'] = get_pretty_url
  314. # values from settings: donation_url
  315. donation_url = get_setting('general.donation_url')
  316. if donation_url is True:
  317. donation_url = custom_url_for('info', pagename='donate')
  318. kwargs['donation_url'] = donation_url
  319. # helpers to create links to other pages
  320. kwargs['url_for'] = custom_url_for # override url_for function in templates
  321. kwargs['image_proxify'] = image_proxify
  322. kwargs['favicon_url'] = favicons.favicon_url
  323. kwargs['cache_url'] = settings['ui']['cache_url']
  324. kwargs['get_result_template'] = get_result_template
  325. kwargs['opensearch_url'] = (
  326. url_for('opensearch')
  327. + '?'
  328. + urlencode(
  329. {
  330. 'method': sxng_request.preferences.get_value('method'),
  331. 'autocomplete': sxng_request.preferences.get_value('autocomplete'),
  332. }
  333. )
  334. )
  335. kwargs['urlparse'] = urlparse
  336. start_time = default_timer()
  337. result = render_template('{}/{}'.format(kwargs['theme'], template_name), **kwargs)
  338. sxng_request.render_time += default_timer() - start_time # pylint: disable=assigning-non-slot
  339. return result
  340. @app.before_request
  341. def pre_request():
  342. sxng_request.start_time = default_timer() # pylint: disable=assigning-non-slot
  343. sxng_request.render_time = 0 # pylint: disable=assigning-non-slot
  344. sxng_request.timings = [] # pylint: disable=assigning-non-slot
  345. sxng_request.errors = [] # pylint: disable=assigning-non-slot
  346. client_pref = ClientPref.from_http_request(sxng_request)
  347. # pylint: disable=redefined-outer-name
  348. preferences = Preferences(themes, list(categories.keys()), engines, searx.plugins.STORAGE, client_pref)
  349. user_agent = sxng_request.headers.get('User-Agent', '').lower()
  350. if 'webkit' in user_agent and 'android' in user_agent:
  351. preferences.key_value_settings['method'].value = 'GET'
  352. sxng_request.preferences = preferences # pylint: disable=assigning-non-slot
  353. try:
  354. preferences.parse_dict(sxng_request.cookies)
  355. except Exception as e: # pylint: disable=broad-except
  356. logger.exception(e, exc_info=True)
  357. sxng_request.errors.append(gettext('Invalid settings, please edit your preferences'))
  358. # merge GET, POST vars
  359. # HINT request.form is of type werkzeug.datastructures.ImmutableMultiDict
  360. sxng_request.form = dict(sxng_request.form.items()) # type: ignore
  361. for k, v in sxng_request.args.items():
  362. if k not in sxng_request.form:
  363. sxng_request.form[k] = v
  364. if sxng_request.form.get('preferences'):
  365. preferences.parse_encoded_data(sxng_request.form['preferences'])
  366. else:
  367. try:
  368. preferences.parse_dict(sxng_request.form)
  369. except Exception as e: # pylint: disable=broad-except
  370. logger.exception(e, exc_info=True)
  371. sxng_request.errors.append(gettext('Invalid settings'))
  372. # language is defined neither in settings nor in preferences
  373. # use browser headers
  374. if not preferences.get_value("language"):
  375. language = _get_browser_language(sxng_request, settings['search']['languages'])
  376. preferences.parse_dict({"language": language})
  377. logger.debug('set language %s (from browser)', preferences.get_value("language"))
  378. # UI locale is defined neither in settings nor in preferences
  379. # use browser headers
  380. if not preferences.get_value("locale"):
  381. locale = _get_browser_language(sxng_request, LOCALE_NAMES.keys())
  382. preferences.parse_dict({"locale": locale})
  383. logger.debug('set locale %s (from browser)', preferences.get_value("locale"))
  384. # request.user_plugins
  385. sxng_request.user_plugins = [] # pylint: disable=assigning-non-slot
  386. allowed_plugins = preferences.plugins.get_enabled()
  387. disabled_plugins = preferences.plugins.get_disabled()
  388. for plugin in searx.plugins.STORAGE:
  389. if (plugin.id not in disabled_plugins) or plugin.id in allowed_plugins:
  390. sxng_request.user_plugins.append(plugin.id)
  391. @app.after_request
  392. def add_default_headers(response: flask.Response):
  393. # set default http headers
  394. for header, value in settings['server']['default_http_headers'].items():
  395. if header in response.headers:
  396. continue
  397. response.headers[header] = value
  398. return response
  399. @app.after_request
  400. def post_request(response: flask.Response):
  401. total_time = default_timer() - sxng_request.start_time
  402. timings_all = [
  403. 'total;dur=' + str(round(total_time * 1000, 3)),
  404. 'render;dur=' + str(round(sxng_request.render_time * 1000, 3)),
  405. ]
  406. if len(sxng_request.timings) > 0:
  407. timings = sorted(sxng_request.timings, key=lambda t: t.total)
  408. timings_total = [
  409. 'total_' + str(i) + '_' + t.engine + ';dur=' + str(round(t.total * 1000, 3)) for i, t in enumerate(timings)
  410. ]
  411. timings_load = [
  412. 'load_' + str(i) + '_' + t.engine + ';dur=' + str(round(t.load * 1000, 3))
  413. for i, t in enumerate(timings)
  414. if t.load
  415. ]
  416. timings_all = timings_all + timings_total + timings_load
  417. response.headers.add('Server-Timing', ', '.join(timings_all))
  418. return response
  419. def index_error(output_format: str, error_message: str):
  420. if output_format == 'json':
  421. return Response(json.dumps({'error': error_message}), mimetype='application/json')
  422. if output_format == 'csv':
  423. response = Response('', mimetype='application/csv')
  424. cont_disp = 'attachment;Filename=searx.csv'
  425. response.headers.add('Content-Disposition', cont_disp)
  426. return response
  427. if output_format == 'rss':
  428. response_rss = render(
  429. 'opensearch_response_rss.xml',
  430. results=[],
  431. q=sxng_request.form['q'] if 'q' in sxng_request.form else '',
  432. number_of_results=0,
  433. error_message=error_message,
  434. )
  435. return Response(response_rss, mimetype='text/xml')
  436. # html
  437. sxng_request.errors.append(gettext('search error'))
  438. return render(
  439. # fmt: off
  440. 'index.html',
  441. selected_categories=get_selected_categories(sxng_request.preferences, sxng_request.form),
  442. # fmt: on
  443. )
  444. @app.route('/', methods=['GET', 'POST'])
  445. def index():
  446. """Render index page."""
  447. # redirect to search if there's a query in the request
  448. if sxng_request.form.get('q'):
  449. query = ('?' + sxng_request.query_string.decode()) if sxng_request.query_string else ''
  450. return redirect(url_for('search') + query, 308)
  451. return render(
  452. # fmt: off
  453. 'index.html',
  454. selected_categories=get_selected_categories(sxng_request.preferences, sxng_request.form),
  455. current_locale = sxng_request.preferences.get_value("locale"),
  456. # fmt: on
  457. )
  458. @app.route('/healthz', methods=['GET'])
  459. def health():
  460. return Response('OK', mimetype='text/plain')
  461. @app.route('/client<token>.css', methods=['GET', 'POST'])
  462. def client_token(token=None):
  463. link_token.ping(sxng_request, token)
  464. return Response('', mimetype='text/css', headers={"Cache-Control": "no-store, max-age=0"})
  465. @app.route('/rss.xsl', methods=['GET', 'POST'])
  466. def rss_xsl():
  467. return render_template(
  468. f"{sxng_request.preferences.get_value('theme')}/rss.xsl",
  469. url_for=custom_url_for,
  470. )
  471. @app.route('/search', methods=['GET', 'POST'])
  472. def search():
  473. """Search query in q and return results.
  474. Supported outputs: html, json, csv, rss.
  475. """
  476. # pylint: disable=too-many-locals, too-many-return-statements, too-many-branches
  477. # pylint: disable=too-many-statements
  478. # output_format
  479. output_format = sxng_request.form.get('format', 'html')
  480. if output_format not in OUTPUT_FORMATS:
  481. output_format = 'html'
  482. if output_format not in settings['search']['formats']:
  483. flask.abort(403)
  484. # check if there is query (not None and not an empty string)
  485. if not sxng_request.form.get('q'):
  486. if output_format == 'html':
  487. return render(
  488. # fmt: off
  489. 'index.html',
  490. selected_categories=get_selected_categories(sxng_request.preferences, sxng_request.form),
  491. # fmt: on
  492. )
  493. return index_error(output_format, 'No query'), 400
  494. # search
  495. search_query = None
  496. raw_text_query = None
  497. result_container = None
  498. try:
  499. search_query, raw_text_query, _, _, selected_locale = get_search_query_from_webapp(
  500. sxng_request.preferences, sxng_request.form
  501. )
  502. search_obj = searx.search.SearchWithPlugins(search_query, sxng_request, sxng_request.user_plugins)
  503. result_container = search_obj.search()
  504. except SearxParameterException as e:
  505. logger.exception('search error: SearxParameterException')
  506. return index_error(output_format, e.message), 400
  507. except Exception as e: # pylint: disable=broad-except
  508. logger.exception(e, exc_info=True)
  509. return index_error(output_format, gettext('search error')), 500
  510. # 1. check if the result is a redirect for an external bang
  511. if result_container.redirect_url:
  512. return redirect(result_container.redirect_url)
  513. # 2. add Server-Timing header for measuring performance characteristics of
  514. # web applications
  515. sxng_request.timings = result_container.get_timings() # pylint: disable=assigning-non-slot
  516. # 3. formats without a template
  517. if output_format == 'json':
  518. response = webutils.get_json_response(search_query, result_container)
  519. return Response(response, mimetype='application/json')
  520. if output_format == 'csv':
  521. csv = webutils.CSVWriter(StringIO())
  522. webutils.write_csv_response(csv, result_container)
  523. csv.stream.seek(0)
  524. response = Response(csv.stream.read(), mimetype='application/csv')
  525. cont_disp = 'attachment;Filename=searx_-_{0}.csv'.format(search_query.query)
  526. response.headers.add('Content-Disposition', cont_disp)
  527. return response
  528. # 4. formats rendered by a template / RSS & HTML
  529. current_template = None
  530. previous_result = None
  531. results = result_container.get_ordered_results()
  532. if search_query.redirect_to_first_result and results:
  533. return redirect(results[0]['url'], 302)
  534. for result in results:
  535. if output_format == 'html':
  536. if 'content' in result and result['content']:
  537. result['content'] = highlight_content(escape(result['content'][:1024]), search_query.query)
  538. if 'title' in result and result['title']:
  539. result['title'] = highlight_content(escape(result['title'] or ''), search_query.query)
  540. # set result['open_group'] = True when the template changes from the previous result
  541. # set result['close_group'] = True when the template changes on the next result
  542. if current_template != result.template:
  543. result.open_group = True
  544. if previous_result:
  545. previous_result.close_group = True # pylint: disable=unsupported-assignment-operation
  546. current_template = result.template
  547. previous_result = result
  548. if previous_result:
  549. previous_result.close_group = True
  550. # 4.a RSS
  551. if output_format == 'rss':
  552. response_rss = render(
  553. 'opensearch_response_rss.xml',
  554. results=results,
  555. q=sxng_request.form['q'],
  556. number_of_results=result_container.number_of_results,
  557. )
  558. return Response(response_rss, mimetype='text/xml')
  559. # 4.b HTML
  560. # suggestions: use RawTextQuery to get the suggestion URLs with the same bang
  561. suggestion_urls = list(
  562. map(
  563. lambda suggestion: {'url': raw_text_query.changeQuery(suggestion).getFullQuery(), 'title': suggestion},
  564. result_container.suggestions,
  565. )
  566. )
  567. correction_urls = list(
  568. map(
  569. lambda correction: {'url': raw_text_query.changeQuery(correction).getFullQuery(), 'title': correction},
  570. result_container.corrections,
  571. )
  572. )
  573. # engine_timings: get engine response times sorted from slowest to fastest
  574. engine_timings = sorted(result_container.get_timings(), reverse=True, key=lambda e: e.total)
  575. max_response_time = engine_timings[0].total if engine_timings else None
  576. engine_timings_pairs = [(timing.engine, timing.total) for timing in engine_timings]
  577. # search_query.lang contains the user choice (all, auto, en, ...)
  578. # when the user choice is "auto", search.search_query.lang contains the detected language
  579. # otherwise it is equals to search_query.lang
  580. return render(
  581. # fmt: off
  582. 'results.html',
  583. results = results,
  584. q=sxng_request.form['q'],
  585. selected_categories = search_query.categories,
  586. pageno = search_query.pageno,
  587. time_range = search_query.time_range or '',
  588. number_of_results = format_decimal(result_container.number_of_results),
  589. suggestions = suggestion_urls,
  590. answers = result_container.answers,
  591. corrections = correction_urls,
  592. infoboxes = result_container.infoboxes,
  593. engine_data = result_container.engine_data,
  594. paging = result_container.paging,
  595. unresponsive_engines = webutils.get_translated_errors(
  596. result_container.unresponsive_engines
  597. ),
  598. current_locale = sxng_request.preferences.get_value("locale"),
  599. current_language = selected_locale,
  600. search_language = match_locale(
  601. search_obj.search_query.lang,
  602. settings['search']['languages'],
  603. fallback=sxng_request.preferences.get_value("language")
  604. ),
  605. timeout_limit = sxng_request.form.get('timeout_limit', None),
  606. timings = engine_timings_pairs,
  607. max_response_time = max_response_time
  608. # fmt: on
  609. )
  610. @app.route('/about', methods=['GET'])
  611. def about():
  612. """Redirect to about page"""
  613. # custom_url_for is going to add the locale
  614. return redirect(custom_url_for('info', pagename='about'))
  615. @app.route('/info/<locale>/<pagename>', methods=['GET'])
  616. def info(pagename, locale):
  617. """Render page of online user documentation"""
  618. page = infopage.INFO_PAGES.get_page(pagename, locale)
  619. if page is None:
  620. flask.abort(404)
  621. user_locale = sxng_request.preferences.get_value('locale')
  622. return render(
  623. 'info.html',
  624. all_pages=infopage.INFO_PAGES.iter_pages(user_locale, fallback_to_default=True),
  625. active_page=page,
  626. active_pagename=pagename,
  627. )
  628. @app.route('/autocompleter', methods=['GET', 'POST'])
  629. def autocompleter():
  630. """Return autocompleter results"""
  631. # run autocompleter
  632. results = []
  633. # set blocked engines
  634. disabled_engines = sxng_request.preferences.engines.get_disabled()
  635. # parse query
  636. raw_text_query = RawTextQuery(sxng_request.form.get('q', ''), disabled_engines)
  637. sug_prefix = raw_text_query.getQuery()
  638. for obj in searx.answerers.STORAGE.ask(sug_prefix):
  639. if isinstance(obj, Answer):
  640. results.append(obj.answer)
  641. # normal autocompletion results only appear if no inner results returned
  642. # and there is a query part
  643. if len(raw_text_query.autocomplete_list) == 0 and len(sug_prefix) > 0:
  644. # get SearXNG's locale and autocomplete backend from cookie
  645. sxng_locale = sxng_request.preferences.get_value('language')
  646. backend_name = sxng_request.preferences.get_value('autocomplete')
  647. for result in search_autocomplete(backend_name, sug_prefix, sxng_locale):
  648. # attention: this loop will change raw_text_query object and this is
  649. # the reason why the sug_prefix was stored before (see above)
  650. if result != sug_prefix:
  651. results.append(raw_text_query.changeQuery(result).getFullQuery())
  652. if len(raw_text_query.autocomplete_list) > 0:
  653. for autocomplete_text in raw_text_query.autocomplete_list:
  654. results.append(raw_text_query.get_autocomplete_full_query(autocomplete_text))
  655. if sxng_request.headers.get('X-Requested-With') == 'XMLHttpRequest':
  656. # the suggestion request comes from the searx search form
  657. suggestions = json.dumps(results)
  658. mimetype = 'application/json'
  659. else:
  660. # the suggestion request comes from browser's URL bar
  661. suggestions = json.dumps([sug_prefix, results])
  662. mimetype = 'application/x-suggestions+json'
  663. suggestions = escape(suggestions, False)
  664. return Response(suggestions, mimetype=mimetype)
  665. @app.route('/preferences', methods=['GET', 'POST'])
  666. def preferences():
  667. """Render preferences page && save user preferences"""
  668. # pylint: disable=too-many-locals, too-many-return-statements, too-many-branches
  669. # pylint: disable=too-many-statements
  670. # save preferences using the link the /preferences?preferences=...
  671. if sxng_request.args.get('preferences') or sxng_request.form.get('preferences'):
  672. resp = make_response(redirect(url_for('index', _external=True)))
  673. return sxng_request.preferences.save(resp)
  674. # save preferences
  675. if sxng_request.method == 'POST':
  676. resp = make_response(redirect(url_for('index', _external=True)))
  677. try:
  678. sxng_request.preferences.parse_form(sxng_request.form)
  679. except ValidationException:
  680. sxng_request.errors.append(gettext('Invalid settings, please edit your preferences'))
  681. return resp
  682. return sxng_request.preferences.save(resp)
  683. # render preferences
  684. image_proxy = sxng_request.preferences.get_value('image_proxy') # pylint: disable=redefined-outer-name
  685. disabled_engines = sxng_request.preferences.engines.get_disabled()
  686. allowed_plugins = sxng_request.preferences.plugins.get_enabled()
  687. # stats for preferences page
  688. filtered_engines = dict(filter(lambda kv: sxng_request.preferences.validate_token(kv[1]), engines.items()))
  689. engines_by_category = {}
  690. for c in categories: # pylint: disable=consider-using-dict-items
  691. engines_by_category[c] = [e for e in categories[c] if e.name in filtered_engines]
  692. # sort the engines alphabetically since the order in settings.yml is meaningless.
  693. list.sort(engines_by_category[c], key=lambda e: e.name)
  694. # get first element [0], the engine time,
  695. # and then the second element [1] : the time (the first one is the label)
  696. stats = {} # pylint: disable=redefined-outer-name
  697. max_rate95 = 0
  698. for _, e in filtered_engines.items():
  699. h = histogram('engine', e.name, 'time', 'total')
  700. median = round(h.percentage(50), 1) if h.count > 0 else None
  701. rate80 = round(h.percentage(80), 1) if h.count > 0 else None
  702. rate95 = round(h.percentage(95), 1) if h.count > 0 else None
  703. max_rate95 = max(max_rate95, rate95 or 0)
  704. result_count_sum = histogram('engine', e.name, 'result', 'count').sum
  705. successful_count = counter('engine', e.name, 'search', 'count', 'successful')
  706. result_count = int(result_count_sum / float(successful_count)) if successful_count else 0
  707. stats[e.name] = {
  708. 'time': median,
  709. 'rate80': rate80,
  710. 'rate95': rate95,
  711. 'warn_timeout': e.timeout > settings['outgoing']['request_timeout'],
  712. 'supports_selected_language': e.traits.is_locale_supported(
  713. str(sxng_request.preferences.get_value('language') or 'all')
  714. ),
  715. 'result_count': result_count,
  716. }
  717. # end of stats
  718. # reliabilities
  719. reliabilities = {}
  720. engine_errors = get_engine_errors(filtered_engines)
  721. checker_results = checker_get_result()
  722. checker_results = (
  723. checker_results['engines'] if checker_results['status'] == 'ok' and 'engines' in checker_results else {}
  724. )
  725. for _, e in filtered_engines.items():
  726. checker_result = checker_results.get(e.name, {})
  727. checker_success = checker_result.get('success', True)
  728. errors = engine_errors.get(e.name) or []
  729. if counter('engine', e.name, 'search', 'count', 'sent') == 0:
  730. # no request
  731. reliability = None
  732. elif checker_success and not errors:
  733. reliability = 100
  734. elif 'simple' in checker_result.get('errors', {}):
  735. # the basic (simple) test doesn't work: the engine is broken according to the checker
  736. # even if there is no exception
  737. reliability = 0
  738. else:
  739. # pylint: disable=consider-using-generator
  740. reliability = 100 - sum([error['percentage'] for error in errors if not error.get('secondary')])
  741. reliabilities[e.name] = {
  742. 'reliability': reliability,
  743. 'errors': [],
  744. 'checker': checker_results.get(e.name, {}).get('errors', {}).keys(),
  745. }
  746. # keep the order of the list checker_results[e.name]['errors'] and deduplicate.
  747. # the first element has the highest percentage rate.
  748. reliabilities_errors = []
  749. for error in errors:
  750. error_user_text = None
  751. if error.get('secondary') or 'exception_classname' not in error:
  752. continue
  753. error_user_text = exception_classname_to_text.get(error.get('exception_classname'))
  754. if not error:
  755. error_user_text = exception_classname_to_text[None]
  756. if error_user_text not in reliabilities_errors:
  757. reliabilities_errors.append(error_user_text)
  758. reliabilities[e.name]['errors'] = reliabilities_errors
  759. # supports
  760. supports = {}
  761. for _, e in filtered_engines.items():
  762. supports_selected_language = e.traits.is_locale_supported(
  763. str(sxng_request.preferences.get_value('language') or 'all')
  764. )
  765. safesearch = e.safesearch
  766. time_range_support = e.time_range_support
  767. for checker_test_name in checker_results.get(e.name, {}).get('errors', {}):
  768. if supports_selected_language and checker_test_name.startswith('lang_'):
  769. supports_selected_language = '?'
  770. elif safesearch and checker_test_name == 'safesearch':
  771. safesearch = '?'
  772. elif time_range_support and checker_test_name == 'time_range':
  773. time_range_support = '?'
  774. supports[e.name] = {
  775. 'supports_selected_language': supports_selected_language,
  776. 'safesearch': safesearch,
  777. 'time_range_support': time_range_support,
  778. }
  779. return render(
  780. # fmt: off
  781. 'preferences.html',
  782. preferences = True,
  783. selected_categories = get_selected_categories(sxng_request.preferences, sxng_request.form),
  784. locales = LOCALE_NAMES,
  785. current_locale = sxng_request.preferences.get_value("locale"),
  786. image_proxy = image_proxy,
  787. engines_by_category = engines_by_category,
  788. stats = stats,
  789. max_rate95 = max_rate95,
  790. reliabilities = reliabilities,
  791. supports = supports,
  792. answer_storage = searx.answerers.STORAGE.info,
  793. disabled_engines = disabled_engines,
  794. autocomplete_backends = autocomplete_backends,
  795. favicon_resolver_names = favicons.proxy.CFG.resolver_map.keys(),
  796. shortcuts = {y: x for x, y in engine_shortcuts.items()},
  797. themes = themes,
  798. plugins_storage = searx.plugins.STORAGE.info,
  799. current_doi_resolver = get_doi_resolver(),
  800. allowed_plugins = allowed_plugins,
  801. preferences_url_params = sxng_request.preferences.get_as_url_params(),
  802. locked_preferences = get_setting("preferences.lock", []),
  803. doi_resolvers = get_setting("doi_resolvers", {}),
  804. # fmt: on
  805. )
  806. app.add_url_rule('/favicon_proxy', methods=['GET'], endpoint="favicon_proxy", view_func=favicons.favicon_proxy)
  807. @app.route('/image_proxy', methods=['GET'])
  808. def image_proxy():
  809. # pylint: disable=too-many-return-statements, too-many-branches
  810. url = sxng_request.args.get('url')
  811. if not url:
  812. return '', 400
  813. if not is_hmac_of(settings['server']['secret_key'], url.encode(), sxng_request.args.get('h', '')):
  814. return '', 400
  815. maximum_size = 5 * 1024 * 1024
  816. forward_resp = False
  817. resp = None
  818. try:
  819. request_headers = {
  820. 'User-Agent': gen_useragent(),
  821. 'Accept': 'image/webp,*/*',
  822. 'Accept-Encoding': 'gzip, deflate',
  823. 'Sec-GPC': '1',
  824. 'DNT': '1',
  825. }
  826. set_context_network_name('image_proxy')
  827. resp, stream = http_stream(method='GET', url=url, headers=request_headers, allow_redirects=True)
  828. content_length = resp.headers.get('Content-Length')
  829. if content_length and content_length.isdigit() and int(content_length) > maximum_size:
  830. return 'Max size', 400
  831. if resp.status_code != 200:
  832. logger.debug('image-proxy: wrong response code: %i', resp.status_code)
  833. if resp.status_code >= 400:
  834. return '', resp.status_code
  835. return '', 400
  836. if not resp.headers.get('Content-Type', '').startswith('image/') and not resp.headers.get(
  837. 'Content-Type', ''
  838. ).startswith('binary/octet-stream'):
  839. logger.debug('image-proxy: wrong content-type: %s', resp.headers.get('Content-Type', ''))
  840. return '', 400
  841. forward_resp = True
  842. except httpx.HTTPError:
  843. logger.exception('HTTP error')
  844. return '', 400
  845. finally:
  846. if resp and not forward_resp:
  847. # the code is about to return an HTTP 400 error to the browser
  848. # we make sure to close the response between searxng and the HTTP server
  849. try:
  850. resp.close()
  851. except httpx.HTTPError:
  852. logger.exception('HTTP error on closing')
  853. def close_stream():
  854. nonlocal resp, stream
  855. try:
  856. if resp:
  857. resp.close()
  858. del resp
  859. del stream
  860. except httpx.HTTPError as e:
  861. logger.debug('Exception while closing response', e)
  862. try:
  863. headers = dict_subset(resp.headers, {'Content-Type', 'Content-Encoding', 'Content-Length', 'Length'})
  864. response = Response(stream, mimetype=resp.headers['Content-Type'], headers=headers, direct_passthrough=True)
  865. response.call_on_close(close_stream)
  866. return response
  867. except httpx.HTTPError:
  868. close_stream()
  869. return '', 400
  870. @app.route('/engine_descriptions.json', methods=['GET'])
  871. def engine_descriptions():
  872. sxng_ui_lang_tag = get_locale().replace("_", "-")
  873. sxng_ui_lang_tag = LOCALE_BEST_MATCH.get(sxng_ui_lang_tag, sxng_ui_lang_tag)
  874. result = ENGINE_DESCRIPTIONS['en'].copy()
  875. if sxng_ui_lang_tag != 'en':
  876. for engine, description in ENGINE_DESCRIPTIONS.get(sxng_ui_lang_tag, {}).items():
  877. result[engine] = description
  878. for engine, description in result.items():
  879. if len(description) == 2 and description[1] == 'ref':
  880. ref_engine, ref_lang = description[0].split(':')
  881. description = ENGINE_DESCRIPTIONS[ref_lang][ref_engine]
  882. if isinstance(description, str):
  883. description = [description, 'wikipedia']
  884. result[engine] = description
  885. # overwrite by about:description (from settings)
  886. for engine_name, engine_mod in engines.items():
  887. descr = getattr(engine_mod, 'about', {}).get('description', None)
  888. if descr is not None:
  889. result[engine_name] = [descr, "SearXNG config"]
  890. return jsonify(result)
  891. @app.route('/stats', methods=['GET'])
  892. def stats():
  893. """Render engine statistics page."""
  894. sort_order = sxng_request.args.get('sort', default='name', type=str)
  895. selected_engine_name = sxng_request.args.get('engine', default=None, type=str)
  896. filtered_engines = dict(filter(lambda kv: sxng_request.preferences.validate_token(kv[1]), engines.items()))
  897. if selected_engine_name:
  898. if selected_engine_name not in filtered_engines:
  899. selected_engine_name = None
  900. else:
  901. filtered_engines = [selected_engine_name]
  902. checker_results = checker_get_result()
  903. checker_results = (
  904. checker_results['engines'] if checker_results['status'] == 'ok' and 'engines' in checker_results else {}
  905. )
  906. engine_stats = get_engines_stats(filtered_engines)
  907. engine_reliabilities = get_reliabilities(filtered_engines, checker_results)
  908. if sort_order not in STATS_SORT_PARAMETERS:
  909. sort_order = 'name'
  910. reverse, key_name, default_value = STATS_SORT_PARAMETERS[sort_order]
  911. def get_key(engine_stat):
  912. reliability = engine_reliabilities.get(engine_stat['name'], {}).get('reliability', 0)
  913. reliability_order = 0 if reliability else 1
  914. if key_name == 'reliability':
  915. key = reliability
  916. reliability_order = 0
  917. else:
  918. key = engine_stat.get(key_name) or default_value
  919. if reverse:
  920. reliability_order = 1 - reliability_order
  921. return (reliability_order, key, engine_stat['name'])
  922. technical_report = []
  923. for error in engine_reliabilities.get(selected_engine_name, {}).get('errors', []):
  924. technical_report.append(
  925. f"\
  926. Error: {error['exception_classname'] or error['log_message']} \
  927. Parameters: {error['log_parameters']} \
  928. File name: {error['filename'] }:{ error['line_no'] } \
  929. Error Function: {error['function']} \
  930. Code: {error['code']} \
  931. ".replace(
  932. ' ' * 12, ''
  933. ).strip()
  934. )
  935. technical_report = ' '.join(technical_report)
  936. engine_stats['time'] = sorted(engine_stats['time'], reverse=reverse, key=get_key)
  937. return render(
  938. # fmt: off
  939. 'stats.html',
  940. sort_order = sort_order,
  941. engine_stats = engine_stats,
  942. engine_reliabilities = engine_reliabilities,
  943. selected_engine_name = selected_engine_name,
  944. searx_git_branch = GIT_BRANCH,
  945. technical_report = technical_report,
  946. # fmt: on
  947. )
  948. @app.route('/stats/errors', methods=['GET'])
  949. def stats_errors():
  950. filtered_engines = dict(filter(lambda kv: sxng_request.preferences.validate_token(kv[1]), engines.items()))
  951. result = get_engine_errors(filtered_engines)
  952. return jsonify(result)
  953. @app.route('/stats/checker', methods=['GET'])
  954. def stats_checker():
  955. result = checker_get_result()
  956. return jsonify(result)
  957. @app.route('/metrics')
  958. def stats_open_metrics():
  959. password = settings['general'].get("open_metrics")
  960. if not (settings['general'].get("enable_metrics") and password):
  961. return Response('open metrics is disabled', status=404, mimetype='text/plain')
  962. if not sxng_request.authorization or sxng_request.authorization.password != password:
  963. return Response('access forbidden', status=401, mimetype='text/plain')
  964. filtered_engines = dict(filter(lambda kv: sxng_request.preferences.validate_token(kv[1]), engines.items()))
  965. checker_results = checker_get_result()
  966. checker_results = (
  967. checker_results['engines'] if checker_results['status'] == 'ok' and 'engines' in checker_results else {}
  968. )
  969. engine_stats = get_engines_stats(filtered_engines)
  970. engine_reliabilities = get_reliabilities(filtered_engines, checker_results)
  971. metrics_text = openmetrics(engine_stats, engine_reliabilities)
  972. return Response(metrics_text, mimetype='text/plain')
  973. @app.route('/robots.txt', methods=['GET'])
  974. def robots():
  975. return Response(
  976. """User-agent: *
  977. Allow: /info/en/about
  978. Disallow: /stats
  979. Disallow: /image_proxy
  980. Disallow: /preferences
  981. Disallow: /*?*q=*
  982. """,
  983. mimetype='text/plain',
  984. )
  985. @app.route('/opensearch.xml', methods=['GET'])
  986. def opensearch():
  987. method = sxng_request.preferences.get_value('method')
  988. autocomplete = sxng_request.preferences.get_value('autocomplete')
  989. # chrome/chromium only supports HTTP GET....
  990. if sxng_request.headers.get('User-Agent', '').lower().find('webkit') >= 0:
  991. method = 'GET'
  992. if method not in ('POST', 'GET'):
  993. method = 'POST'
  994. ret = render('opensearch.xml', opensearch_method=method, autocomplete=autocomplete)
  995. resp = Response(response=ret, status=200, mimetype="application/opensearchdescription+xml")
  996. return resp
  997. @app.route('/favicon.ico')
  998. def favicon():
  999. theme = sxng_request.preferences.get_value("theme")
  1000. return send_from_directory(
  1001. os.path.join(app.root_path, settings['ui']['static_path'], 'themes', theme, 'img'), # type: ignore
  1002. 'favicon.png',
  1003. mimetype='image/vnd.microsoft.icon',
  1004. )
  1005. @app.route('/clear_cookies')
  1006. def clear_cookies():
  1007. resp = make_response(redirect(url_for('index', _external=True)))
  1008. for cookie_name in sxng_request.cookies:
  1009. resp.delete_cookie(cookie_name)
  1010. return resp
  1011. @app.route('/config')
  1012. def config():
  1013. """Return configuration in JSON format."""
  1014. _engines = []
  1015. for name, engine in engines.items():
  1016. if not sxng_request.preferences.validate_token(engine):
  1017. continue
  1018. _languages = engine.traits.languages.keys()
  1019. _engines.append(
  1020. {
  1021. 'name': name,
  1022. 'categories': engine.categories,
  1023. 'shortcut': engine.shortcut,
  1024. 'enabled': not engine.disabled,
  1025. 'paging': engine.paging,
  1026. 'language_support': engine.language_support,
  1027. 'languages': list(_languages),
  1028. 'regions': list(engine.traits.regions.keys()),
  1029. 'safesearch': engine.safesearch,
  1030. 'time_range_support': engine.time_range_support,
  1031. 'timeout': engine.timeout,
  1032. }
  1033. )
  1034. _plugins = []
  1035. for _ in searx.plugins.STORAGE:
  1036. _plugins.append({'name': _.id, 'enabled': _.active})
  1037. _limiter_cfg = limiter.get_cfg()
  1038. return jsonify(
  1039. {
  1040. 'categories': list(categories.keys()),
  1041. 'engines': _engines,
  1042. 'plugins': _plugins,
  1043. 'instance_name': settings['general']['instance_name'],
  1044. 'locales': LOCALE_NAMES,
  1045. 'default_locale': settings['ui']['default_locale'],
  1046. 'autocomplete': settings['search']['autocomplete'],
  1047. 'safe_search': settings['search']['safe_search'],
  1048. 'default_theme': settings['ui']['default_theme'],
  1049. 'version': VERSION_STRING,
  1050. 'brand': {
  1051. 'PRIVACYPOLICY_URL': get_setting('general.privacypolicy_url'),
  1052. 'CONTACT_URL': get_setting('general.contact_url'),
  1053. 'GIT_URL': GIT_URL,
  1054. 'GIT_BRANCH': GIT_BRANCH,
  1055. 'DOCS_URL': get_setting('brand.docs_url'),
  1056. },
  1057. 'limiter': {
  1058. 'enabled': limiter.is_installed(),
  1059. 'botdetection.ip_limit.link_token': _limiter_cfg.get('botdetection.ip_limit.link_token'),
  1060. 'botdetection.ip_lists.pass_searxng_org': _limiter_cfg.get('botdetection.ip_lists.pass_searxng_org'),
  1061. },
  1062. 'doi_resolvers': list(settings['doi_resolvers'].keys()),
  1063. 'default_doi_resolver': settings['default_doi_resolver'],
  1064. 'public_instance': settings['server']['public_instance'],
  1065. }
  1066. )
  1067. @app.errorhandler(404)
  1068. def page_not_found(_e):
  1069. return render('404.html'), 404
  1070. def run():
  1071. """Runs the application on a local development server.
  1072. This run method is only called when SearXNG is started via ``__main__``::
  1073. python -m searx.webapp
  1074. Do not use :ref:`run() <flask.Flask.run>` in a production setting. It is
  1075. not intended to meet security and performance requirements for a production
  1076. server.
  1077. It is not recommended to use this function for development with automatic
  1078. reloading as this is badly supported. Instead you should be using the flask
  1079. command line script’s run support::
  1080. flask --app searx.webapp run --debug --reload --host 127.0.0.1 --port 8888
  1081. .. _Flask.run: https://flask.palletsprojects.com/en/stable/api/#flask.Flask.run
  1082. """
  1083. host: str = get_setting("server.bind_address") # type: ignore
  1084. port: int = get_setting("server.port") # type: ignore
  1085. if searx.sxng_debug:
  1086. logger.debug("run local development server (DEBUG) on %s:%s", host, port)
  1087. app.run(
  1088. debug=True,
  1089. port=port,
  1090. host=host,
  1091. threaded=True,
  1092. extra_files=[DEFAULT_SETTINGS_FILE],
  1093. )
  1094. else:
  1095. logger.debug("run local development server on %s:%s", host, port)
  1096. app.run(port=port, host=host, threaded=True)
  1097. def is_werkzeug_reload_active() -> bool:
  1098. """Returns ``True`` if server is is launched by :ref:`werkzeug.serving` and
  1099. the ``use_reload`` argument was set to ``True``. If this is the case, it
  1100. should be avoided that the server is initialized twice (:py:obj:`init`,
  1101. :py:obj:`run`).
  1102. .. _werkzeug.serving:
  1103. https://werkzeug.palletsprojects.com/en/stable/serving/#werkzeug.serving.run_simple
  1104. """
  1105. if "uwsgi" in sys.argv:
  1106. # server was launched by uWSGI
  1107. return False
  1108. # https://github.com/searxng/searxng/pull/1656#issuecomment-1214198941
  1109. # https://github.com/searxng/searxng/pull/1616#issuecomment-1206137468
  1110. frames = inspect.stack()
  1111. if len(frames) > 1 and frames[-2].filename.endswith('flask/cli.py'):
  1112. # server was launched by "flask run", is argument "--reload" set?
  1113. if "--reload" in sys.argv or "--debug" in sys.argv:
  1114. return True
  1115. elif frames[0].filename.endswith('searx/webapp.py'):
  1116. # server was launched by "python -m searx.webapp" / see run()
  1117. if searx.sxng_debug:
  1118. return True
  1119. return False
  1120. def init():
  1121. if searx.sxng_debug or app.debug:
  1122. app.debug = True
  1123. searx.sxng_debug = True
  1124. # check secret_key in production
  1125. if not app.debug and get_setting("server.secret_key") == 'ultrasecretkey':
  1126. logger.error("server.secret_key is not changed. Please use something else instead of ultrasecretkey.")
  1127. sys.exit(1)
  1128. # When automatic reloading is activated stop Flask from initialising twice.
  1129. # - https://github.com/pallets/flask/issues/5307#issuecomment-1774646119
  1130. # - https://stackoverflow.com/a/25504196
  1131. reloader_active = is_werkzeug_reload_active()
  1132. werkzeug_run_main = is_running_from_reloader()
  1133. if reloader_active and not werkzeug_run_main:
  1134. logger.info("in reloading mode and not in main loop, cancel the initialization")
  1135. return
  1136. locales_initialize()
  1137. redis_initialize()
  1138. searx.plugins.initialize(app)
  1139. metrics: bool = get_setting("general.enable_metrics") # type: ignore
  1140. searx.search.initialize(enable_checker=True, check_network=True, enable_metrics=metrics)
  1141. limiter.initialize(app, settings)
  1142. favicons.init()
  1143. application = app
  1144. patch_application(app)
  1145. init()
  1146. if __name__ == "__main__":
  1147. run()