webapp.py 30 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874
  1. #!/usr/bin/env python
  2. '''
  3. searx is free software: you can redistribute it and/or modify
  4. it under the terms of the GNU Affero General Public License as published by
  5. the Free Software Foundation, either version 3 of the License, or
  6. (at your option) any later version.
  7. searx is distributed in the hope that it will be useful,
  8. but WITHOUT ANY WARRANTY; without even the implied warranty of
  9. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  10. GNU Affero General Public License for more details.
  11. You should have received a copy of the GNU Affero General Public License
  12. along with searx. If not, see < http://www.gnu.org/licenses/ >.
  13. (C) 2013- by Adam Tauber, <asciimoo@gmail.com>
  14. '''
  15. if __name__ == '__main__':
  16. from sys import path
  17. from os.path import realpath, dirname
  18. path.append(realpath(dirname(realpath(__file__)) + '/../'))
  19. import cStringIO
  20. import hashlib
  21. import hmac
  22. import json
  23. import os
  24. import requests
  25. from searx import logger
  26. logger = logger.getChild('webapp')
  27. try:
  28. from pygments import highlight
  29. from pygments.lexers import get_lexer_by_name
  30. from pygments.formatters import HtmlFormatter
  31. except:
  32. logger.critical("cannot import dependency: pygments")
  33. from sys import exit
  34. exit(1)
  35. from cgi import escape
  36. from datetime import datetime, timedelta
  37. from urllib import urlencode
  38. from urlparse import urlparse, urljoin
  39. from werkzeug.contrib.fixers import ProxyFix
  40. from flask import (
  41. Flask, request, render_template, url_for, Response, make_response,
  42. redirect, send_from_directory
  43. )
  44. from flask_babel import Babel, gettext, format_date, format_decimal
  45. from flask.json import jsonify
  46. from searx import settings, searx_dir, searx_debug
  47. from searx.exceptions import SearxException, SearxParameterException
  48. from searx.engines import (
  49. categories, engines, engine_shortcuts, get_engines_stats, initialize_engines
  50. )
  51. from searx.utils import (
  52. UnicodeWriter, highlight_content, html_to_text, get_themes,
  53. get_static_files, get_result_templates, gen_useragent, dict_subset,
  54. prettify_url
  55. )
  56. from searx.version import VERSION_STRING
  57. from searx.languages import language_codes
  58. from searx.search import SearchWithPlugins, get_search_query_from_webapp
  59. from searx.query import RawTextQuery
  60. from searx.autocomplete import searx_bang, backends as autocomplete_backends
  61. from searx.plugins import plugins
  62. from searx.preferences import Preferences, ValidationException
  63. from searx.answerers import answerers
  64. # check if the pyopenssl package is installed.
  65. # It is needed for SSL connection without trouble, see #298
  66. try:
  67. import OpenSSL.SSL # NOQA
  68. except ImportError:
  69. logger.critical("The pyopenssl package has to be installed.\n"
  70. "Some HTTPS connections will fail")
  71. # serve pages with HTTP/1.1
  72. from werkzeug.serving import WSGIRequestHandler
  73. WSGIRequestHandler.protocol_version = "HTTP/{}".format(settings['server'].get('http_protocol_version', '1.0'))
  74. static_path, templates_path, themes =\
  75. get_themes(settings['ui']['themes_path']
  76. if settings['ui']['themes_path']
  77. else searx_dir)
  78. default_theme = settings['ui']['default_theme']
  79. static_files = get_static_files(searx_dir)
  80. result_templates = get_result_templates(searx_dir)
  81. app = Flask(
  82. __name__,
  83. static_folder=static_path,
  84. template_folder=templates_path
  85. )
  86. app.jinja_env.trim_blocks = True
  87. app.jinja_env.lstrip_blocks = True
  88. app.secret_key = settings['server']['secret_key']
  89. if not searx_debug or os.environ.get("WERKZEUG_RUN_MAIN") == "true":
  90. initialize_engines(settings['engines'])
  91. babel = Babel(app)
  92. rtl_locales = ['ar', 'arc', 'bcc', 'bqi', 'ckb', 'dv', 'fa', 'glk', 'he',
  93. 'ku', 'mzn', 'pnb'', ''ps', 'sd', 'ug', 'ur', 'yi']
  94. global_favicons = []
  95. for indice, theme in enumerate(themes):
  96. global_favicons.append([])
  97. theme_img_path = searx_dir + "/static/themes/" + theme + "/img/icons/"
  98. for (dirpath, dirnames, filenames) in os.walk(theme_img_path):
  99. global_favicons[indice].extend(filenames)
  100. # used when translating category names
  101. _category_names = (gettext('files'),
  102. gettext('general'),
  103. gettext('music'),
  104. gettext('social media'),
  105. gettext('images'),
  106. gettext('videos'),
  107. gettext('it'),
  108. gettext('news'),
  109. gettext('map'),
  110. gettext('science'))
  111. outgoing_proxies = settings['outgoing'].get('proxies', None)
  112. @babel.localeselector
  113. def get_locale():
  114. locale = request.accept_languages.best_match(settings['locales'].keys())
  115. if request.preferences.get_value('locale') != '':
  116. locale = request.preferences.get_value('locale')
  117. if 'locale' in request.args\
  118. and request.args['locale'] in settings['locales']:
  119. locale = request.args['locale']
  120. if 'locale' in request.form\
  121. and request.form['locale'] in settings['locales']:
  122. locale = request.form['locale']
  123. return locale
  124. # code-highlighter
  125. @app.template_filter('code_highlighter')
  126. def code_highlighter(codelines, language=None):
  127. if not language:
  128. language = 'text'
  129. try:
  130. # find lexer by programing language
  131. lexer = get_lexer_by_name(language, stripall=True)
  132. except:
  133. # if lexer is not found, using default one
  134. logger.debug('highlighter cannot find lexer for {0}'.format(language))
  135. lexer = get_lexer_by_name('text', stripall=True)
  136. html_code = ''
  137. tmp_code = ''
  138. last_line = None
  139. # parse lines
  140. for line, code in codelines:
  141. if not last_line:
  142. line_code_start = line
  143. # new codeblock is detected
  144. if last_line is not None and\
  145. last_line + 1 != line:
  146. # highlight last codepart
  147. formatter = HtmlFormatter(linenos='inline',
  148. linenostart=line_code_start)
  149. html_code = html_code + highlight(tmp_code, lexer, formatter)
  150. # reset conditions for next codepart
  151. tmp_code = ''
  152. line_code_start = line
  153. # add codepart
  154. tmp_code += code + '\n'
  155. # update line
  156. last_line = line
  157. # highlight last codepart
  158. formatter = HtmlFormatter(linenos='inline', linenostart=line_code_start)
  159. html_code = html_code + highlight(tmp_code, lexer, formatter)
  160. return html_code
  161. # Extract domain from url
  162. @app.template_filter('extract_domain')
  163. def extract_domain(url):
  164. return urlparse(url)[1]
  165. def get_base_url():
  166. if settings['server']['base_url']:
  167. hostname = settings['server']['base_url']
  168. else:
  169. scheme = 'http'
  170. if request.is_secure:
  171. scheme = 'https'
  172. hostname = url_for('index', _external=True, _scheme=scheme)
  173. return hostname
  174. def get_current_theme_name(override=None):
  175. """Returns theme name.
  176. Checks in this order:
  177. 1. override
  178. 2. cookies
  179. 3. settings"""
  180. if override and (override in themes or override == '__common__'):
  181. return override
  182. theme_name = request.args.get('theme', request.preferences.get_value('theme'))
  183. if theme_name not in themes:
  184. theme_name = default_theme
  185. return theme_name
  186. def get_result_template(theme, template_name):
  187. themed_path = theme + '/result_templates/' + template_name
  188. if themed_path in result_templates:
  189. return themed_path
  190. return 'result_templates/' + template_name
  191. def url_for_theme(endpoint, override_theme=None, **values):
  192. if endpoint == 'static' and values.get('filename'):
  193. theme_name = get_current_theme_name(override=override_theme)
  194. filename_with_theme = "themes/{}/{}".format(theme_name, values['filename'])
  195. if filename_with_theme in static_files:
  196. values['filename'] = filename_with_theme
  197. return url_for(endpoint, **values)
  198. def proxify(url):
  199. if url.startswith('//'):
  200. url = 'https:' + url
  201. if not settings.get('result_proxy'):
  202. return url
  203. url_params = dict(mortyurl=url.encode('utf-8'))
  204. if settings['result_proxy'].get('key'):
  205. url_params['mortyhash'] = hmac.new(settings['result_proxy']['key'],
  206. url.encode('utf-8'),
  207. hashlib.sha256).hexdigest()
  208. return '{0}?{1}'.format(settings['result_proxy']['url'],
  209. urlencode(url_params))
  210. def image_proxify(url):
  211. if url.startswith('//'):
  212. url = 'https:' + url
  213. if not request.preferences.get_value('image_proxy'):
  214. return url
  215. if settings.get('result_proxy'):
  216. return proxify(url)
  217. h = hmac.new(settings['server']['secret_key'], url.encode('utf-8'), hashlib.sha256).hexdigest()
  218. return '{0}?{1}'.format(url_for('image_proxy'),
  219. urlencode(dict(url=url.encode('utf-8'), h=h)))
  220. def render(template_name, override_theme=None, **kwargs):
  221. disabled_engines = request.preferences.engines.get_disabled()
  222. enabled_categories = set(category for engine_name in engines
  223. for category in engines[engine_name].categories
  224. if (engine_name, category) not in disabled_engines)
  225. if 'categories' not in kwargs:
  226. kwargs['categories'] = ['general']
  227. kwargs['categories'].extend(x for x in
  228. sorted(categories.keys())
  229. if x != 'general'
  230. and x in enabled_categories)
  231. if 'all_categories' not in kwargs:
  232. kwargs['all_categories'] = ['general']
  233. kwargs['all_categories'].extend(x for x in
  234. sorted(categories.keys())
  235. if x != 'general')
  236. if 'selected_categories' not in kwargs:
  237. kwargs['selected_categories'] = []
  238. for arg in request.args:
  239. if arg.startswith('category_'):
  240. c = arg.split('_', 1)[1]
  241. if c in categories:
  242. kwargs['selected_categories'].append(c)
  243. if not kwargs['selected_categories']:
  244. cookie_categories = request.preferences.get_value('categories')
  245. for ccateg in cookie_categories:
  246. kwargs['selected_categories'].append(ccateg)
  247. if not kwargs['selected_categories']:
  248. kwargs['selected_categories'] = ['general']
  249. if 'autocomplete' not in kwargs:
  250. kwargs['autocomplete'] = request.preferences.get_value('autocomplete')
  251. if get_locale() in rtl_locales and 'rtl' not in kwargs:
  252. kwargs['rtl'] = True
  253. kwargs['searx_version'] = VERSION_STRING
  254. kwargs['method'] = request.preferences.get_value('method')
  255. kwargs['safesearch'] = str(request.preferences.get_value('safesearch'))
  256. kwargs['language_codes'] = language_codes
  257. if 'current_language' not in kwargs:
  258. kwargs['current_language'] = request.preferences.get_value('language')
  259. # override url_for function in templates
  260. kwargs['url_for'] = url_for_theme
  261. kwargs['image_proxify'] = image_proxify
  262. kwargs['proxify'] = proxify if settings.get('result_proxy') else None
  263. kwargs['get_result_template'] = get_result_template
  264. kwargs['theme'] = get_current_theme_name(override=override_theme)
  265. kwargs['template_name'] = template_name
  266. kwargs['cookies'] = request.cookies
  267. kwargs['errors'] = request.errors
  268. kwargs['instance_name'] = settings['general']['instance_name']
  269. kwargs['results_on_new_tab'] = request.preferences.get_value('results_on_new_tab')
  270. kwargs['scripts'] = set()
  271. for plugin in request.user_plugins:
  272. for script in plugin.js_dependencies:
  273. kwargs['scripts'].add(script)
  274. kwargs['styles'] = set()
  275. for plugin in request.user_plugins:
  276. for css in plugin.css_dependencies:
  277. kwargs['styles'].add(css)
  278. return render_template(
  279. '{}/{}'.format(kwargs['theme'], template_name), **kwargs)
  280. @app.before_request
  281. def pre_request():
  282. request.errors = []
  283. preferences = Preferences(themes, categories.keys(), engines, plugins)
  284. request.preferences = preferences
  285. try:
  286. preferences.parse_cookies(request.cookies)
  287. except:
  288. request.errors.append(gettext('Invalid settings, please edit your preferences'))
  289. # merge GET, POST vars
  290. # request.form
  291. request.form = dict(request.form.items())
  292. for k, v in request.args.items():
  293. if k not in request.form:
  294. request.form[k] = v
  295. # request.user_plugins
  296. request.user_plugins = []
  297. allowed_plugins = preferences.plugins.get_enabled()
  298. disabled_plugins = preferences.plugins.get_disabled()
  299. for plugin in plugins:
  300. if ((plugin.default_on and plugin.id not in disabled_plugins)
  301. or plugin.id in allowed_plugins):
  302. request.user_plugins.append(plugin)
  303. def index_error(output_format, error_message):
  304. if output_format == 'json':
  305. return Response(json.dumps({'error': error_message}),
  306. mimetype='application/json')
  307. elif output_format == 'csv':
  308. response = Response('', mimetype='application/csv')
  309. cont_disp = 'attachment;Filename=searx.csv'
  310. response.headers.add('Content-Disposition', cont_disp)
  311. return response
  312. elif output_format == 'rss':
  313. response_rss = render(
  314. 'opensearch_response_rss.xml',
  315. results=[],
  316. q=request.form['q'] if 'q' in request.form else '',
  317. number_of_results=0,
  318. base_url=get_base_url(),
  319. error_message=error_message
  320. )
  321. return Response(response_rss, mimetype='text/xml')
  322. else:
  323. # html
  324. request.errors.append(gettext('search error'))
  325. return render(
  326. 'index.html',
  327. )
  328. @app.route('/search', methods=['GET', 'POST'])
  329. @app.route('/', methods=['GET', 'POST'])
  330. def index():
  331. """Render index page.
  332. Supported outputs: html, json, csv, rss.
  333. """
  334. # output_format
  335. output_format = request.form.get('format', 'html')
  336. if output_format not in ['html', 'csv', 'json', 'rss']:
  337. output_format = 'html'
  338. # check if there is query
  339. if request.form.get('q') is None:
  340. if output_format == 'html':
  341. return render(
  342. 'index.html',
  343. )
  344. else:
  345. return index_error(output_format, 'No query'), 400
  346. # search
  347. search_query = None
  348. result_container = None
  349. try:
  350. search_query = get_search_query_from_webapp(request.preferences, request.form)
  351. # search = Search(search_query) # without plugins
  352. search = SearchWithPlugins(search_query, request.user_plugins, request)
  353. result_container = search.search()
  354. except Exception as e:
  355. # log exception
  356. logger.exception('search error')
  357. # is it an invalid input parameter or something else ?
  358. if (issubclass(e.__class__, SearxParameterException)):
  359. return index_error(output_format, e.message), 400
  360. else:
  361. return index_error(output_format, gettext('search error')), 500
  362. # results
  363. results = result_container.get_ordered_results()
  364. number_of_results = result_container.results_number()
  365. if number_of_results < result_container.results_length():
  366. number_of_results = 0
  367. # UI
  368. advanced_search = request.form.get('advanced_search', None)
  369. # output
  370. for result in results:
  371. if output_format == 'html':
  372. if 'content' in result and result['content']:
  373. result['content'] = highlight_content(escape(result['content'][:1024]),
  374. search_query.query.encode('utf-8'))
  375. result['title'] = highlight_content(escape(result['title'] or u''),
  376. search_query.query.encode('utf-8'))
  377. else:
  378. if result.get('content'):
  379. result['content'] = html_to_text(result['content']).strip()
  380. # removing html content and whitespace duplications
  381. result['title'] = ' '.join(html_to_text(result['title']).strip().split())
  382. result['pretty_url'] = prettify_url(result['url'])
  383. # TODO, check if timezone is calculated right
  384. if 'publishedDate' in result:
  385. try: # test if publishedDate >= 1900 (datetime module bug)
  386. result['pubdate'] = result['publishedDate'].strftime('%Y-%m-%d %H:%M:%S%z')
  387. except ValueError:
  388. result['publishedDate'] = None
  389. else:
  390. if result['publishedDate'].replace(tzinfo=None) >= datetime.now() - timedelta(days=1):
  391. timedifference = datetime.now() - result['publishedDate'].replace(tzinfo=None)
  392. minutes = int((timedifference.seconds / 60) % 60)
  393. hours = int(timedifference.seconds / 60 / 60)
  394. if hours == 0:
  395. result['publishedDate'] = gettext(u'{minutes} minute(s) ago').format(minutes=minutes)
  396. else:
  397. result['publishedDate'] = gettext(u'{hours} hour(s), {minutes} minute(s) ago').format(hours=hours, minutes=minutes) # noqa
  398. else:
  399. result['publishedDate'] = format_date(result['publishedDate'])
  400. if output_format == 'json':
  401. return Response(json.dumps({'query': search_query.query,
  402. 'number_of_results': number_of_results,
  403. 'results': results,
  404. 'answers': list(result_container.answers),
  405. 'corrections': list(result_container.corrections),
  406. 'infoboxes': result_container.infoboxes,
  407. 'suggestions': list(result_container.suggestions)}),
  408. mimetype='application/json')
  409. elif output_format == 'csv':
  410. csv = UnicodeWriter(cStringIO.StringIO())
  411. keys = ('title', 'url', 'content', 'host', 'engine', 'score')
  412. csv.writerow(keys)
  413. for row in results:
  414. row['host'] = row['parsed_url'].netloc
  415. csv.writerow([row.get(key, '') for key in keys])
  416. csv.stream.seek(0)
  417. response = Response(csv.stream.read(), mimetype='application/csv')
  418. cont_disp = 'attachment;Filename=searx_-_{0}.csv'.format(search_query.query.encode('utf-8'))
  419. response.headers.add('Content-Disposition', cont_disp)
  420. return response
  421. elif output_format == 'rss':
  422. response_rss = render(
  423. 'opensearch_response_rss.xml',
  424. results=results,
  425. q=request.form['q'],
  426. number_of_results=number_of_results,
  427. base_url=get_base_url(),
  428. override_theme='__common__',
  429. )
  430. return Response(response_rss, mimetype='text/xml')
  431. return render(
  432. 'results.html',
  433. results=results,
  434. q=request.form['q'],
  435. selected_categories=search_query.categories,
  436. pageno=search_query.pageno,
  437. time_range=search_query.time_range,
  438. number_of_results=format_decimal(number_of_results),
  439. advanced_search=advanced_search,
  440. suggestions=result_container.suggestions,
  441. answers=result_container.answers,
  442. corrections=result_container.corrections,
  443. infoboxes=result_container.infoboxes,
  444. paging=result_container.paging,
  445. current_language=search_query.lang,
  446. base_url=get_base_url(),
  447. theme=get_current_theme_name(),
  448. favicons=global_favicons[themes.index(get_current_theme_name())]
  449. )
  450. @app.route('/about', methods=['GET'])
  451. def about():
  452. """Render about page"""
  453. return render(
  454. 'about.html',
  455. )
  456. @app.route('/autocompleter', methods=['GET', 'POST'])
  457. def autocompleter():
  458. """Return autocompleter results"""
  459. # set blocked engines
  460. disabled_engines = request.preferences.engines.get_disabled()
  461. # parse query
  462. raw_text_query = RawTextQuery(request.form.get('q', '').encode('utf-8'), disabled_engines)
  463. raw_text_query.parse_query()
  464. # check if search query is set
  465. if not raw_text_query.getSearchQuery():
  466. return '', 400
  467. # run autocompleter
  468. completer = autocomplete_backends.get(request.preferences.get_value('autocomplete'))
  469. # parse searx specific autocompleter results like !bang
  470. raw_results = searx_bang(raw_text_query)
  471. # normal autocompletion results only appear if max 3 inner results returned
  472. if len(raw_results) <= 3 and completer:
  473. # get language from cookie
  474. language = request.preferences.get_value('language')
  475. if not language or language == 'all':
  476. language = 'en'
  477. else:
  478. language = language.split('-')[0]
  479. # run autocompletion
  480. raw_results.extend(completer(raw_text_query.getSearchQuery(), language))
  481. # parse results (write :language and !engine back to result string)
  482. results = []
  483. for result in raw_results:
  484. raw_text_query.changeSearchQuery(result)
  485. # add parsed result
  486. results.append(raw_text_query.getFullQuery())
  487. # return autocompleter results
  488. if request.form.get('format') == 'x-suggestions':
  489. return Response(json.dumps([raw_text_query.query, results]),
  490. mimetype='application/json')
  491. return Response(json.dumps(results),
  492. mimetype='application/json')
  493. @app.route('/preferences', methods=['GET', 'POST'])
  494. def preferences():
  495. """Render preferences page && save user preferences"""
  496. # save preferences
  497. if request.method == 'POST':
  498. resp = make_response(redirect(urljoin(settings['server']['base_url'], url_for('index'))))
  499. try:
  500. request.preferences.parse_form(request.form)
  501. except ValidationException:
  502. request.errors.append(gettext('Invalid settings, please edit your preferences'))
  503. return resp
  504. return request.preferences.save(resp)
  505. # render preferences
  506. image_proxy = request.preferences.get_value('image_proxy')
  507. lang = request.preferences.get_value('language')
  508. disabled_engines = request.preferences.engines.get_disabled()
  509. allowed_plugins = request.preferences.plugins.get_enabled()
  510. # stats for preferences page
  511. stats = {}
  512. for c in categories:
  513. for e in categories[c]:
  514. stats[e.name] = {'time': None,
  515. 'warn_timeout': False,
  516. 'warn_time': False}
  517. if e.timeout > settings['outgoing']['request_timeout']:
  518. stats[e.name]['warn_timeout'] = True
  519. # get first element [0], the engine time,
  520. # and then the second element [1] : the time (the first one is the label)
  521. for engine_stat in get_engines_stats()[0][1]:
  522. stats[engine_stat.get('name')]['time'] = round(engine_stat.get('avg'), 3)
  523. if engine_stat.get('avg') > settings['outgoing']['request_timeout']:
  524. stats[engine_stat.get('name')]['warn_time'] = True
  525. # end of stats
  526. return render('preferences.html',
  527. locales=settings['locales'],
  528. current_locale=get_locale(),
  529. image_proxy=image_proxy,
  530. engines_by_category=categories,
  531. stats=stats,
  532. answerers=[{'info': a.self_info(), 'keywords': a.keywords} for a in answerers],
  533. disabled_engines=disabled_engines,
  534. autocomplete_backends=autocomplete_backends,
  535. shortcuts={y: x for x, y in engine_shortcuts.items()},
  536. themes=themes,
  537. plugins=plugins,
  538. allowed_plugins=allowed_plugins,
  539. theme=get_current_theme_name(),
  540. preferences=True)
  541. @app.route('/image_proxy', methods=['GET'])
  542. def image_proxy():
  543. url = request.args.get('url').encode('utf-8')
  544. if not url:
  545. return '', 400
  546. h = hmac.new(settings['server']['secret_key'], url, hashlib.sha256).hexdigest()
  547. if h != request.args.get('h'):
  548. return '', 400
  549. headers = dict_subset(request.headers, {'If-Modified-Since', 'If-None-Match'})
  550. headers['User-Agent'] = gen_useragent()
  551. resp = requests.get(url,
  552. stream=True,
  553. timeout=settings['outgoing']['request_timeout'],
  554. headers=headers,
  555. proxies=outgoing_proxies)
  556. if resp.status_code == 304:
  557. return '', resp.status_code
  558. if resp.status_code != 200:
  559. logger.debug('image-proxy: wrong response code: {0}'.format(resp.status_code))
  560. if resp.status_code >= 400:
  561. return '', resp.status_code
  562. return '', 400
  563. if not resp.headers.get('content-type', '').startswith('image/'):
  564. logger.debug('image-proxy: wrong content-type: {0}'.format(resp.headers.get('content-type')))
  565. return '', 400
  566. img = ''
  567. chunk_counter = 0
  568. for chunk in resp.iter_content(1024 * 1024):
  569. chunk_counter += 1
  570. if chunk_counter > 5:
  571. return '', 502 # Bad gateway - file is too big (>5M)
  572. img += chunk
  573. headers = dict_subset(resp.headers, {'Content-Length', 'Length', 'Date', 'Last-Modified', 'Expires', 'Etag'})
  574. return Response(img, mimetype=resp.headers['content-type'], headers=headers)
  575. @app.route('/stats', methods=['GET'])
  576. def stats():
  577. """Render engine statistics page."""
  578. stats = get_engines_stats()
  579. return render(
  580. 'stats.html',
  581. stats=stats,
  582. )
  583. @app.route('/robots.txt', methods=['GET'])
  584. def robots():
  585. return Response("""User-agent: *
  586. Allow: /
  587. Allow: /about
  588. Disallow: /stats
  589. Disallow: /preferences
  590. Disallow: /*?*q=*
  591. """, mimetype='text/plain')
  592. @app.route('/opensearch.xml', methods=['GET'])
  593. def opensearch():
  594. method = 'post'
  595. if request.preferences.get_value('method') == 'GET':
  596. method = 'get'
  597. # chrome/chromium only supports HTTP GET....
  598. if request.headers.get('User-Agent', '').lower().find('webkit') >= 0:
  599. method = 'get'
  600. ret = render('opensearch.xml',
  601. opensearch_method=method,
  602. host=get_base_url(),
  603. urljoin=urljoin,
  604. override_theme='__common__')
  605. resp = Response(response=ret,
  606. status=200,
  607. mimetype="text/xml")
  608. return resp
  609. @app.route('/favicon.ico')
  610. def favicon():
  611. return send_from_directory(os.path.join(app.root_path,
  612. 'static/themes',
  613. get_current_theme_name(),
  614. 'img'),
  615. 'favicon.png',
  616. mimetype='image/vnd.microsoft.icon')
  617. @app.route('/clear_cookies')
  618. def clear_cookies():
  619. resp = make_response(redirect(urljoin(settings['server']['base_url'], url_for('index'))))
  620. for cookie_name in request.cookies:
  621. resp.delete_cookie(cookie_name)
  622. return resp
  623. @app.route('/config')
  624. def config():
  625. return jsonify({'categories': categories.keys(),
  626. 'engines': [{'name': engine_name,
  627. 'categories': engine.categories,
  628. 'shortcut': engine.shortcut,
  629. 'enabled': not engine.disabled,
  630. 'paging': engine.paging,
  631. 'language_support': engine.language_support,
  632. 'supported_languages':
  633. engine.supported_languages.keys()
  634. if isinstance(engine.supported_languages, dict)
  635. else engine.supported_languages,
  636. 'safesearch': engine.safesearch,
  637. 'time_range_support': engine.time_range_support,
  638. 'timeout': engine.timeout}
  639. for engine_name, engine in engines.items()],
  640. 'plugins': [{'name': plugin.name,
  641. 'enabled': plugin.default_on}
  642. for plugin in plugins],
  643. 'instance_name': settings['general']['instance_name'],
  644. 'locales': settings['locales'],
  645. 'default_locale': settings['ui']['default_locale'],
  646. 'autocomplete': settings['search']['autocomplete'],
  647. 'safe_search': settings['search']['safe_search'],
  648. 'default_theme': settings['ui']['default_theme'],
  649. 'version': VERSION_STRING})
  650. @app.errorhandler(404)
  651. def page_not_found(e):
  652. return render('404.html'), 404
  653. def run():
  654. app.run(
  655. debug=searx_debug,
  656. use_debugger=searx_debug,
  657. port=settings['server']['port'],
  658. host=settings['server']['bind_address'],
  659. threaded=True
  660. )
  661. class ReverseProxyPathFix(object):
  662. '''Wrap the application in this middleware and configure the
  663. front-end server to add these headers, to let you quietly bind
  664. this to a URL other than / and to an HTTP scheme that is
  665. different than what is used locally.
  666. http://flask.pocoo.org/snippets/35/
  667. In nginx:
  668. location /myprefix {
  669. proxy_pass http://127.0.0.1:8000;
  670. proxy_set_header Host $host;
  671. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  672. proxy_set_header X-Scheme $scheme;
  673. proxy_set_header X-Script-Name /myprefix;
  674. }
  675. :param app: the WSGI application
  676. '''
  677. def __init__(self, app):
  678. self.app = app
  679. def __call__(self, environ, start_response):
  680. script_name = environ.get('HTTP_X_SCRIPT_NAME', '')
  681. if script_name:
  682. environ['SCRIPT_NAME'] = script_name
  683. path_info = environ['PATH_INFO']
  684. if path_info.startswith(script_name):
  685. environ['PATH_INFO'] = path_info[len(script_name):]
  686. scheme = environ.get('HTTP_X_SCHEME', '')
  687. if scheme:
  688. environ['wsgi.url_scheme'] = scheme
  689. return self.app(environ, start_response)
  690. application = app
  691. # patch app to handle non root url-s behind proxy & wsgi
  692. app.wsgi_app = ReverseProxyPathFix(ProxyFix(application.wsgi_app))
  693. if __name__ == "__main__":
  694. run()