webapp.py 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531
  1. #!/usr/bin/env python
  2. '''
  3. searx is free software: you can redistribute it and/or modify
  4. it under the terms of the GNU Affero General Public License as published by
  5. the Free Software Foundation, either version 3 of the License, or
  6. (at your option) any later version.
  7. searx is distributed in the hope that it will be useful,
  8. but WITHOUT ANY WARRANTY; without even the implied warranty of
  9. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  10. GNU Affero General Public License for more details.
  11. You should have received a copy of the GNU Affero General Public License
  12. along with searx. If not, see < http://www.gnu.org/licenses/ >.
  13. (C) 2013- by Adam Tauber, <asciimoo@gmail.com>
  14. '''
  15. from gevent import monkey
  16. monkey.patch_all()
  17. if __name__ == '__main__':
  18. from sys import path
  19. from os.path import realpath, dirname
  20. path.append(realpath(dirname(realpath(__file__))+'/../'))
  21. import json
  22. import cStringIO
  23. import os
  24. from datetime import datetime, timedelta
  25. from itertools import chain
  26. from flask import (
  27. Flask, request, render_template, url_for, Response, make_response,
  28. redirect, send_from_directory
  29. )
  30. from flask.ext.babel import Babel, gettext, format_date
  31. from searx import settings, searx_dir
  32. from searx.engines import (
  33. categories, engines, get_engines_stats, engine_shortcuts
  34. )
  35. from searx.utils import (
  36. UnicodeWriter, highlight_content, html_to_text, get_themes
  37. )
  38. from searx.https_rewrite import https_rules
  39. from searx.languages import language_codes
  40. from searx.search import Search
  41. from searx.autocomplete import backends as autocomplete_backends
  42. from urlparse import urlparse
  43. import re
  44. static_path, templates_path, themes =\
  45. get_themes(settings['themes_path']
  46. if settings.get('themes_path')
  47. else searx_dir)
  48. default_theme = settings['default_theme'] if \
  49. settings.get('default_theme', None) else 'default'
  50. app = Flask(
  51. __name__,
  52. static_folder=static_path,
  53. template_folder=templates_path
  54. )
  55. app.secret_key = settings['server']['secret_key']
  56. babel = Babel(app)
  57. #TODO configurable via settings.yml
  58. favicons = ['wikipedia', 'youtube', 'vimeo', 'soundcloud',
  59. 'twitter', 'stackoverflow', 'github']
  60. cookie_max_age = 60 * 60 * 24 * 365 * 23 # 23 years
  61. @babel.localeselector
  62. def get_locale():
  63. locale = request.accept_languages.best_match(settings['locales'].keys())
  64. if request.cookies.get('locale', '') in settings['locales']:
  65. locale = request.cookies.get('locale', '')
  66. if 'locale' in request.args\
  67. and request.args['locale'] in settings['locales']:
  68. locale = request.args['locale']
  69. if 'locale' in request.form\
  70. and request.form['locale'] in settings['locales']:
  71. locale = request.form['locale']
  72. return locale
  73. def get_base_url():
  74. if settings['server']['base_url']:
  75. hostname = settings['server']['base_url']
  76. else:
  77. scheme = 'http'
  78. if request.is_secure:
  79. scheme = 'https'
  80. hostname = url_for('index', _external=True, _scheme=scheme)
  81. return hostname
  82. def get_current_theme_name(override=None):
  83. """Returns theme name.
  84. Checks in this order:
  85. 1. override
  86. 2. cookies
  87. 3. settings"""
  88. if override and override in themes:
  89. return override
  90. theme_name = request.cookies.get('theme', default_theme)
  91. if theme_name not in themes:
  92. theme_name = default_theme
  93. return theme_name
  94. def url_for_theme(endpoint, override_theme=None, **values):
  95. if endpoint == 'static' and values.get('filename', None):
  96. theme_name = get_current_theme_name(override=override_theme)
  97. values['filename'] = "{}/{}".format(theme_name, values['filename'])
  98. return url_for(endpoint, **values)
  99. def render(template_name, override_theme=None, **kwargs):
  100. blocked_engines = request.cookies.get('blocked_engines', '').split(',')
  101. autocomplete = request.cookies.get('autocomplete')
  102. if autocomplete not in autocomplete_backends:
  103. autocomplete = None
  104. nonblocked_categories = (engines[e].categories
  105. for e in engines
  106. if e not in blocked_engines)
  107. nonblocked_categories = set(chain.from_iterable(nonblocked_categories))
  108. if not 'categories' in kwargs:
  109. kwargs['categories'] = ['general']
  110. kwargs['categories'].extend(x for x in
  111. sorted(categories.keys())
  112. if x != 'general'
  113. and x in nonblocked_categories)
  114. if not 'selected_categories' in kwargs:
  115. kwargs['selected_categories'] = []
  116. cookie_categories = request.cookies.get('categories', '').split(',')
  117. for ccateg in cookie_categories:
  118. if ccateg in categories:
  119. kwargs['selected_categories'].append(ccateg)
  120. if not kwargs['selected_categories']:
  121. kwargs['selected_categories'] = ['general']
  122. if not 'autocomplete' in kwargs:
  123. kwargs['autocomplete'] = autocomplete
  124. kwargs['method'] = request.cookies.get('method', 'POST')
  125. # override url_for function in templates
  126. kwargs['url_for'] = url_for_theme
  127. kwargs['theme'] = get_current_theme_name(override=override_theme)
  128. return render_template(
  129. '{}/{}'.format(kwargs['theme'], template_name), **kwargs)
  130. @app.route('/search', methods=['GET', 'POST'])
  131. @app.route('/', methods=['GET', 'POST'])
  132. def index():
  133. """Render index page.
  134. Supported outputs: html, json, csv, rss.
  135. """
  136. if not request.args and not request.form:
  137. return render(
  138. 'index.html',
  139. )
  140. try:
  141. search = Search(request)
  142. except:
  143. return render(
  144. 'index.html',
  145. )
  146. search.results, search.suggestions = search.search(request)
  147. for result in search.results:
  148. if not search.paging and engines[result['engine']].paging:
  149. search.paging = True
  150. # check if HTTPS rewrite is required
  151. if settings['server']['https_rewrite']\
  152. and result['parsed_url'].scheme == 'http':
  153. skip_https_rewrite = False
  154. # check if HTTPS rewrite is possible
  155. for target, rules, exclusions in https_rules:
  156. # check if target regex match with url
  157. if target.match(result['url']):
  158. # process exclusions
  159. for exclusion in exclusions:
  160. # check if exclusion match with url
  161. if exclusion.match(result['url']):
  162. skip_https_rewrite = True
  163. break
  164. # skip https rewrite if required
  165. if skip_https_rewrite:
  166. break
  167. # process rules
  168. for rule in rules:
  169. try:
  170. # TODO, precompile rule
  171. p = re.compile(rule[0])
  172. # rewrite url if possible
  173. new_result_url = p.sub(rule[1], result['url'])
  174. except:
  175. break
  176. # parse new url
  177. new_parsed_url = urlparse(new_result_url)
  178. # continiue if nothing was rewritten
  179. if result['url'] == new_result_url:
  180. continue
  181. # get domainname from result
  182. # TODO, does only work correct with TLD's like asdf.com, not for asdf.com.de
  183. # TODO, using publicsuffix instead of this rewrite rule
  184. old_result_domainname = '.'.join(result['parsed_url'].hostname.split('.')[-2:])
  185. new_result_domainname = '.'.join(new_parsed_url.hostname.split('.')[-2:])
  186. # check if rewritten hostname is the same, to protect against wrong or malicious rewrite rules
  187. if old_result_domainname == new_result_domainname:
  188. # set new url
  189. result['url'] = new_result_url
  190. # target has matched, do not search over the other rules
  191. break
  192. if search.request_data.get('format', 'html') == 'html':
  193. if 'content' in result:
  194. result['content'] = highlight_content(result['content'],
  195. search.query.encode('utf-8')) # noqa
  196. result['title'] = highlight_content(result['title'],
  197. search.query.encode('utf-8'))
  198. else:
  199. if 'content' in result:
  200. result['content'] = html_to_text(result['content']).strip()
  201. # removing html content and whitespace duplications
  202. result['title'] = ' '.join(html_to_text(result['title'])
  203. .strip().split())
  204. if len(result['url']) > 74:
  205. url_parts = result['url'][:35], result['url'][-35:]
  206. result['pretty_url'] = u'{0}[...]{1}'.format(*url_parts)
  207. else:
  208. result['pretty_url'] = result['url']
  209. for engine in result['engines']:
  210. if engine in favicons:
  211. result['favicon'] = engine
  212. # TODO, check if timezone is calculated right
  213. if 'publishedDate' in result:
  214. if result['publishedDate'].replace(tzinfo=None)\
  215. >= datetime.now() - timedelta(days=1):
  216. timedifference = datetime.now() - result['publishedDate']\
  217. .replace(tzinfo=None)
  218. minutes = int((timedifference.seconds / 60) % 60)
  219. hours = int(timedifference.seconds / 60 / 60)
  220. if hours == 0:
  221. result['publishedDate'] = gettext(u'{minutes} minute(s) ago').format(minutes=minutes) # noqa
  222. else:
  223. result['publishedDate'] = gettext(u'{hours} hour(s), {minutes} minute(s) ago').format(hours=hours, minutes=minutes) # noqa
  224. else:
  225. result['pubdate'] = result['publishedDate']\
  226. .strftime('%a, %d %b %Y %H:%M:%S %z')
  227. result['publishedDate'] = format_date(result['publishedDate'])
  228. if search.request_data.get('format') == 'json':
  229. return Response(json.dumps({'query': search.query,
  230. 'results': search.results}),
  231. mimetype='application/json')
  232. elif search.request_data.get('format') == 'csv':
  233. csv = UnicodeWriter(cStringIO.StringIO())
  234. keys = ('title', 'url', 'content', 'host', 'engine', 'score')
  235. if search.results:
  236. csv.writerow(keys)
  237. for row in search.results:
  238. row['host'] = row['parsed_url'].netloc
  239. csv.writerow([row.get(key, '') for key in keys])
  240. csv.stream.seek(0)
  241. response = Response(csv.stream.read(), mimetype='application/csv')
  242. cont_disp = 'attachment;Filename=searx_-_{0}.csv'.format(search.query)
  243. response.headers.add('Content-Disposition', cont_disp)
  244. return response
  245. elif search.request_data.get('format') == 'rss':
  246. response_rss = render(
  247. 'opensearch_response_rss.xml',
  248. results=search.results,
  249. q=search.request_data['q'],
  250. number_of_results=len(search.results),
  251. base_url=get_base_url()
  252. )
  253. return Response(response_rss, mimetype='text/xml')
  254. return render(
  255. 'results.html',
  256. results=search.results,
  257. q=search.request_data['q'],
  258. selected_categories=search.categories,
  259. paging=search.paging,
  260. pageno=search.pageno,
  261. base_url=get_base_url(),
  262. suggestions=search.suggestions,
  263. theme=get_current_theme_name()
  264. )
  265. @app.route('/about', methods=['GET'])
  266. def about():
  267. """Render about page"""
  268. return render(
  269. 'about.html',
  270. )
  271. @app.route('/autocompleter', methods=['GET', 'POST'])
  272. def autocompleter():
  273. """Return autocompleter results"""
  274. request_data = {}
  275. if request.method == 'POST':
  276. request_data = request.form
  277. else:
  278. request_data = request.args
  279. # TODO fix XSS-vulnerability
  280. query = request_data.get('q', '').encode('utf-8')
  281. if not query:
  282. return
  283. completer = autocomplete_backends.get(request.cookies.get('autocomplete'))
  284. if not completer:
  285. return
  286. results = completer(query)
  287. if request_data.get('format') == 'x-suggestions':
  288. return Response(json.dumps([query, results]),
  289. mimetype='application/json')
  290. else:
  291. return Response(json.dumps(results),
  292. mimetype='application/json')
  293. @app.route('/preferences', methods=['GET', 'POST'])
  294. def preferences():
  295. """Render preferences page.
  296. Settings that are going to be saved as cookies."""
  297. lang = None
  298. if request.cookies.get('language')\
  299. and request.cookies['language'] in (x[0] for x in language_codes):
  300. lang = request.cookies['language']
  301. blocked_engines = []
  302. if request.method == 'GET':
  303. blocked_engines = request.cookies.get('blocked_engines', '').split(',')
  304. else: # on save
  305. selected_categories = []
  306. locale = None
  307. autocomplete = ''
  308. method = 'POST'
  309. for pd_name, pd in request.form.items():
  310. if pd_name.startswith('category_'):
  311. category = pd_name[9:]
  312. if not category in categories:
  313. continue
  314. selected_categories.append(category)
  315. elif pd_name == 'locale' and pd in settings['locales']:
  316. locale = pd
  317. elif pd_name == 'autocomplete':
  318. autocomplete = pd
  319. elif pd_name == 'language' and (pd == 'all' or
  320. pd in (x[0] for
  321. x in language_codes)):
  322. lang = pd
  323. elif pd_name == 'method':
  324. method = pd
  325. elif pd_name.startswith('engine_'):
  326. engine_name = pd_name.replace('engine_', '', 1)
  327. if engine_name in engines:
  328. blocked_engines.append(engine_name)
  329. elif pd_name == 'theme':
  330. theme = pd if pd in themes else default_theme
  331. resp = make_response(redirect(url_for('index')))
  332. user_blocked_engines = request.cookies.get('blocked_engines', '').split(',') # noqa
  333. if sorted(blocked_engines) != sorted(user_blocked_engines):
  334. resp.set_cookie(
  335. 'blocked_engines', ','.join(blocked_engines),
  336. max_age=cookie_max_age
  337. )
  338. if locale:
  339. resp.set_cookie(
  340. 'locale', locale,
  341. max_age=cookie_max_age
  342. )
  343. if lang:
  344. resp.set_cookie(
  345. 'language', lang,
  346. max_age=cookie_max_age
  347. )
  348. if selected_categories:
  349. # cookie max age: 4 weeks
  350. resp.set_cookie(
  351. 'categories', ','.join(selected_categories),
  352. max_age=cookie_max_age
  353. )
  354. resp.set_cookie(
  355. 'autocomplete', autocomplete,
  356. max_age=cookie_max_age
  357. )
  358. resp.set_cookie('method', method, max_age=cookie_max_age)
  359. resp.set_cookie(
  360. 'theme', theme, max_age=cookie_max_age)
  361. return resp
  362. return render('preferences.html',
  363. locales=settings['locales'],
  364. current_locale=get_locale(),
  365. current_language=lang or 'all',
  366. language_codes=language_codes,
  367. categs=categories.items(),
  368. blocked_engines=blocked_engines,
  369. autocomplete_backends=autocomplete_backends,
  370. shortcuts={y: x for x, y in engine_shortcuts.items()},
  371. themes=themes,
  372. theme=get_current_theme_name())
  373. @app.route('/stats', methods=['GET'])
  374. def stats():
  375. """Render engine statistics page."""
  376. stats = get_engines_stats()
  377. return render(
  378. 'stats.html',
  379. stats=stats,
  380. )
  381. @app.route('/robots.txt', methods=['GET'])
  382. def robots():
  383. return Response("""User-agent: *
  384. Allow: /
  385. Allow: /about
  386. Disallow: /stats
  387. Disallow: /preferences
  388. """, mimetype='text/plain')
  389. @app.route('/opensearch.xml', methods=['GET'])
  390. def opensearch():
  391. method = 'post'
  392. # chrome/chromium only supports HTTP GET....
  393. if request.headers.get('User-Agent', '').lower().find('webkit') >= 0:
  394. method = 'get'
  395. ret = render('opensearch.xml',
  396. opensearch_method=method,
  397. host=get_base_url())
  398. resp = Response(response=ret,
  399. status=200,
  400. mimetype="application/xml")
  401. return resp
  402. @app.route('/favicon.ico')
  403. def favicon():
  404. return send_from_directory(os.path.join(app.root_path,
  405. 'static',
  406. get_current_theme_name(),
  407. 'img'),
  408. 'favicon.png',
  409. mimetype='image/vnd.microsoft.icon')
  410. def run():
  411. app.run(
  412. debug=settings['server']['debug'],
  413. use_debugger=settings['server']['debug'],
  414. port=settings['server']['port']
  415. )
  416. application = app
  417. if __name__ == "__main__":
  418. run()