webapp.py 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524
  1. #!/usr/bin/env python
  2. '''
  3. searx is free software: you can redistribute it and/or modify
  4. it under the terms of the GNU Affero General Public License as published by
  5. the Free Software Foundation, either version 3 of the License, or
  6. (at your option) any later version.
  7. searx is distributed in the hope that it will be useful,
  8. but WITHOUT ANY WARRANTY; without even the implied warranty of
  9. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  10. GNU Affero General Public License for more details.
  11. You should have received a copy of the GNU Affero General Public License
  12. along with searx. If not, see < http://www.gnu.org/licenses/ >.
  13. (C) 2013- by Adam Tauber, <asciimoo@gmail.com>
  14. '''
  15. from gevent import monkey
  16. monkey.patch_all()
  17. if __name__ == '__main__':
  18. from sys import path
  19. from os.path import realpath, dirname
  20. path.append(realpath(dirname(realpath(__file__))+'/../'))
  21. import json
  22. import cStringIO
  23. import os
  24. from datetime import datetime, timedelta
  25. from itertools import chain
  26. from flask import (
  27. Flask, request, render_template, url_for, Response, make_response,
  28. redirect, send_from_directory
  29. )
  30. from flask.ext.babel import Babel, gettext, format_date
  31. from searx import settings, searx_dir
  32. from searx.engines import (
  33. categories, engines, get_engines_stats, engine_shortcuts
  34. )
  35. from searx.utils import (
  36. UnicodeWriter, highlight_content, html_to_text, get_themes
  37. )
  38. from searx.https_rewrite import https_rules
  39. from searx.languages import language_codes
  40. from searx.search import Search
  41. from searx.autocomplete import backends as autocomplete_backends
  42. from urlparse import urlparse
  43. import re
  44. static_path, templates_path, themes =\
  45. get_themes(settings['themes_path']
  46. if settings.get('themes_path')
  47. else searx_dir)
  48. default_theme = settings['default_theme'] if \
  49. settings.get('default_theme', None) else 'default'
  50. app = Flask(
  51. __name__,
  52. static_folder=static_path,
  53. template_folder=templates_path
  54. )
  55. app.secret_key = settings['server']['secret_key']
  56. babel = Babel(app)
  57. #TODO configurable via settings.yml
  58. favicons = ['wikipedia', 'youtube', 'vimeo', 'soundcloud',
  59. 'twitter', 'stackoverflow', 'github']
  60. cookie_max_age = 60 * 60 * 24 * 365 * 23 # 23 years
  61. @babel.localeselector
  62. def get_locale():
  63. locale = request.accept_languages.best_match(settings['locales'].keys())
  64. if request.cookies.get('locale', '') in settings['locales']:
  65. locale = request.cookies.get('locale', '')
  66. if 'locale' in request.args\
  67. and request.args['locale'] in settings['locales']:
  68. locale = request.args['locale']
  69. if 'locale' in request.form\
  70. and request.form['locale'] in settings['locales']:
  71. locale = request.form['locale']
  72. return locale
  73. def get_base_url():
  74. if settings['server']['base_url']:
  75. hostname = settings['server']['base_url']
  76. else:
  77. scheme = 'http'
  78. if request.is_secure:
  79. scheme = 'https'
  80. hostname = url_for('index', _external=True, _scheme=scheme)
  81. return hostname
  82. def get_current_theme_name(override=None):
  83. """Returns theme name.
  84. Checks in this order:
  85. 1. override
  86. 2. cookies
  87. 3. settings"""
  88. if override and override in themes:
  89. return override
  90. theme_name = request.cookies.get('theme', default_theme)
  91. if theme_name not in themes:
  92. theme_name = default_theme
  93. return theme_name
  94. def url_for_theme(endpoint, override_theme=None, **values):
  95. if endpoint == 'static' and values.get('filename', None):
  96. theme_name = get_current_theme_name(override=override_theme)
  97. values['filename'] = "{}/{}".format(theme_name, values['filename'])
  98. return url_for(endpoint, **values)
  99. def render(template_name, override_theme=None, **kwargs):
  100. blocked_engines = request.cookies.get('blocked_engines', '').split(',')
  101. autocomplete = request.cookies.get('autocomplete')
  102. if autocomplete not in autocomplete_backends:
  103. autocomplete = None
  104. nonblocked_categories = (engines[e].categories
  105. for e in engines
  106. if e not in blocked_engines)
  107. nonblocked_categories = set(chain.from_iterable(nonblocked_categories))
  108. if not 'categories' in kwargs:
  109. kwargs['categories'] = ['general']
  110. kwargs['categories'].extend(x for x in
  111. sorted(categories.keys())
  112. if x != 'general'
  113. and x in nonblocked_categories)
  114. if not 'selected_categories' in kwargs:
  115. kwargs['selected_categories'] = []
  116. cookie_categories = request.cookies.get('categories', '').split(',')
  117. for ccateg in cookie_categories:
  118. if ccateg in categories:
  119. kwargs['selected_categories'].append(ccateg)
  120. if not kwargs['selected_categories']:
  121. kwargs['selected_categories'] = ['general']
  122. if not 'autocomplete' in kwargs:
  123. kwargs['autocomplete'] = autocomplete
  124. kwargs['method'] = request.cookies.get('method', 'POST')
  125. # override url_for function in templates
  126. kwargs['url_for'] = url_for_theme
  127. kwargs['theme'] = get_current_theme_name(override=override_theme)
  128. return render_template(
  129. '{}/{}'.format(kwargs['theme'], template_name), **kwargs)
  130. @app.route('/search', methods=['GET', 'POST'])
  131. @app.route('/', methods=['GET', 'POST'])
  132. def index():
  133. """Render index page.
  134. Supported outputs: html, json, csv, rss.
  135. """
  136. if not request.args and not request.form:
  137. return render(
  138. 'index.html',
  139. )
  140. try:
  141. search = Search(request)
  142. except:
  143. return render(
  144. 'index.html',
  145. )
  146. search.results, search.suggestions = search.search(request)
  147. for result in search.results:
  148. if not search.paging and engines[result['engine']].paging:
  149. search.paging = True
  150. # check if HTTPS rewrite is required
  151. if settings['server']['https_rewrite']\
  152. and result['parsed_url'].scheme == 'http':
  153. skip_https_rewrite = False
  154. # check if HTTPS rewrite is possible
  155. for target, rules, exclusions in https_rules:
  156. # check if target regex match with url
  157. if target.match(result['url']):
  158. # process exclusions
  159. for exclusion in exclusions:
  160. # check if exclusion match with url
  161. if exclusion.match(result['url']):
  162. skip_https_rewrite = True
  163. break
  164. # skip https rewrite if required
  165. if skip_https_rewrite:
  166. break
  167. # process rules
  168. for rule in rules:
  169. # TODO, precompile rule
  170. p = re.compile(rule[0])
  171. # rewrite url if possible
  172. new_result_url = p.sub(rule[1], result['url'])
  173. # parse new url
  174. new_parsed_url = urlparse(new_result_url)
  175. # continiue if nothing was rewritten
  176. if result['url'] == new_result_url:
  177. continue
  178. # get domainname from result
  179. # TODO, does only work correct with TLD's like asdf.com, not for asdf.com.de
  180. # TODO, using publicsuffix instead of this rewrite rule
  181. old_result_domainname = '.'.join(result['parsed_url'].hostname.split('.')[-2:])
  182. new_result_domainname = '.'.join(new_parsed_url.hostname.split('.')[-2:])
  183. # check if rewritten hostname is the same, to protect against wrong or malicious rewrite rules
  184. if old_result_domainname == new_result_domainname:
  185. # set new url
  186. result['url'] = new_result_url
  187. if search.request_data.get('format', 'html') == 'html':
  188. if 'content' in result:
  189. result['content'] = highlight_content(result['content'],
  190. search.query.encode('utf-8')) # noqa
  191. result['title'] = highlight_content(result['title'],
  192. search.query.encode('utf-8'))
  193. else:
  194. if 'content' in result:
  195. result['content'] = html_to_text(result['content']).strip()
  196. # removing html content and whitespace duplications
  197. result['title'] = ' '.join(html_to_text(result['title'])
  198. .strip().split())
  199. if len(result['url']) > 74:
  200. url_parts = result['url'][:35], result['url'][-35:]
  201. result['pretty_url'] = u'{0}[...]{1}'.format(*url_parts)
  202. else:
  203. result['pretty_url'] = result['url']
  204. for engine in result['engines']:
  205. if engine in favicons:
  206. result['favicon'] = engine
  207. # TODO, check if timezone is calculated right
  208. if 'publishedDate' in result:
  209. if result['publishedDate'].replace(tzinfo=None)\
  210. >= datetime.now() - timedelta(days=1):
  211. timedifference = datetime.now() - result['publishedDate']\
  212. .replace(tzinfo=None)
  213. minutes = int((timedifference.seconds / 60) % 60)
  214. hours = int(timedifference.seconds / 60 / 60)
  215. if hours == 0:
  216. result['publishedDate'] = gettext(u'{minutes} minute(s) ago').format(minutes=minutes) # noqa
  217. else:
  218. result['publishedDate'] = gettext(u'{hours} hour(s), {minutes} minute(s) ago').format(hours=hours, minutes=minutes) # noqa
  219. else:
  220. result['pubdate'] = result['publishedDate']\
  221. .strftime('%a, %d %b %Y %H:%M:%S %z')
  222. result['publishedDate'] = format_date(result['publishedDate'])
  223. if search.request_data.get('format') == 'json':
  224. return Response(json.dumps({'query': search.query,
  225. 'results': search.results}),
  226. mimetype='application/json')
  227. elif search.request_data.get('format') == 'csv':
  228. csv = UnicodeWriter(cStringIO.StringIO())
  229. keys = ('title', 'url', 'content', 'host', 'engine', 'score')
  230. if search.results:
  231. csv.writerow(keys)
  232. for row in search.results:
  233. row['host'] = row['parsed_url'].netloc
  234. csv.writerow([row.get(key, '') for key in keys])
  235. csv.stream.seek(0)
  236. response = Response(csv.stream.read(), mimetype='application/csv')
  237. cont_disp = 'attachment;Filename=searx_-_{0}.csv'.format(search.query)
  238. response.headers.add('Content-Disposition', cont_disp)
  239. return response
  240. elif search.request_data.get('format') == 'rss':
  241. response_rss = render(
  242. 'opensearch_response_rss.xml',
  243. results=search.results,
  244. q=search.request_data['q'],
  245. number_of_results=len(search.results),
  246. base_url=get_base_url()
  247. )
  248. return Response(response_rss, mimetype='text/xml')
  249. return render(
  250. 'results.html',
  251. results=search.results,
  252. q=search.request_data['q'],
  253. selected_categories=search.categories,
  254. paging=search.paging,
  255. pageno=search.pageno,
  256. base_url=get_base_url(),
  257. suggestions=search.suggestions,
  258. theme=get_current_theme_name()
  259. )
  260. @app.route('/about', methods=['GET'])
  261. def about():
  262. """Render about page"""
  263. return render(
  264. 'about.html',
  265. )
  266. @app.route('/autocompleter', methods=['GET', 'POST'])
  267. def autocompleter():
  268. """Return autocompleter results"""
  269. request_data = {}
  270. if request.method == 'POST':
  271. request_data = request.form
  272. else:
  273. request_data = request.args
  274. # TODO fix XSS-vulnerability
  275. query = request_data.get('q', '').encode('utf-8')
  276. if not query:
  277. return
  278. completer = autocomplete_backends.get(request.cookies.get('autocomplete'))
  279. if not completer:
  280. return
  281. results = completer(query)
  282. if request_data.get('format') == 'x-suggestions':
  283. return Response(json.dumps([query, results]),
  284. mimetype='application/json')
  285. else:
  286. return Response(json.dumps(results),
  287. mimetype='application/json')
  288. @app.route('/preferences', methods=['GET', 'POST'])
  289. def preferences():
  290. """Render preferences page.
  291. Settings that are going to be saved as cookies."""
  292. lang = None
  293. if request.cookies.get('language')\
  294. and request.cookies['language'] in (x[0] for x in language_codes):
  295. lang = request.cookies['language']
  296. blocked_engines = []
  297. if request.method == 'GET':
  298. blocked_engines = request.cookies.get('blocked_engines', '').split(',')
  299. else: # on save
  300. selected_categories = []
  301. locale = None
  302. autocomplete = ''
  303. method = 'POST'
  304. for pd_name, pd in request.form.items():
  305. if pd_name.startswith('category_'):
  306. category = pd_name[9:]
  307. if not category in categories:
  308. continue
  309. selected_categories.append(category)
  310. elif pd_name == 'locale' and pd in settings['locales']:
  311. locale = pd
  312. elif pd_name == 'autocomplete':
  313. autocomplete = pd
  314. elif pd_name == 'language' and (pd == 'all' or
  315. pd in (x[0] for
  316. x in language_codes)):
  317. lang = pd
  318. elif pd_name == 'method':
  319. method = pd
  320. elif pd_name.startswith('engine_'):
  321. engine_name = pd_name.replace('engine_', '', 1)
  322. if engine_name in engines:
  323. blocked_engines.append(engine_name)
  324. elif pd_name == 'theme':
  325. theme = pd if pd in themes else default_theme
  326. resp = make_response(redirect(url_for('index')))
  327. user_blocked_engines = request.cookies.get('blocked_engines', '').split(',') # noqa
  328. if sorted(blocked_engines) != sorted(user_blocked_engines):
  329. resp.set_cookie(
  330. 'blocked_engines', ','.join(blocked_engines),
  331. max_age=cookie_max_age
  332. )
  333. if locale:
  334. resp.set_cookie(
  335. 'locale', locale,
  336. max_age=cookie_max_age
  337. )
  338. if lang:
  339. resp.set_cookie(
  340. 'language', lang,
  341. max_age=cookie_max_age
  342. )
  343. if selected_categories:
  344. # cookie max age: 4 weeks
  345. resp.set_cookie(
  346. 'categories', ','.join(selected_categories),
  347. max_age=cookie_max_age
  348. )
  349. resp.set_cookie(
  350. 'autocomplete', autocomplete,
  351. max_age=cookie_max_age
  352. )
  353. resp.set_cookie('method', method, max_age=cookie_max_age)
  354. resp.set_cookie(
  355. 'theme', theme, max_age=cookie_max_age)
  356. return resp
  357. return render('preferences.html',
  358. locales=settings['locales'],
  359. current_locale=get_locale(),
  360. current_language=lang or 'all',
  361. language_codes=language_codes,
  362. categs=categories.items(),
  363. blocked_engines=blocked_engines,
  364. autocomplete_backends=autocomplete_backends,
  365. shortcuts={y: x for x, y in engine_shortcuts.items()},
  366. themes=themes,
  367. theme=get_current_theme_name())
  368. @app.route('/stats', methods=['GET'])
  369. def stats():
  370. """Render engine statistics page."""
  371. stats = get_engines_stats()
  372. return render(
  373. 'stats.html',
  374. stats=stats,
  375. )
  376. @app.route('/robots.txt', methods=['GET'])
  377. def robots():
  378. return Response("""User-agent: *
  379. Allow: /
  380. Allow: /about
  381. Disallow: /stats
  382. Disallow: /preferences
  383. """, mimetype='text/plain')
  384. @app.route('/opensearch.xml', methods=['GET'])
  385. def opensearch():
  386. method = 'post'
  387. # chrome/chromium only supports HTTP GET....
  388. if request.headers.get('User-Agent', '').lower().find('webkit') >= 0:
  389. method = 'get'
  390. ret = render('opensearch.xml',
  391. opensearch_method=method,
  392. host=get_base_url())
  393. resp = Response(response=ret,
  394. status=200,
  395. mimetype="application/xml")
  396. return resp
  397. @app.route('/favicon.ico')
  398. def favicon():
  399. return send_from_directory(os.path.join(app.root_path,
  400. 'static',
  401. get_current_theme_name(),
  402. 'img'),
  403. 'favicon.png',
  404. mimetype='image/vnd.microsoft.icon')
  405. def run():
  406. app.run(
  407. debug=settings['server']['debug'],
  408. use_debugger=settings['server']['debug'],
  409. port=settings['server']['port']
  410. )
  411. application = app
  412. if __name__ == "__main__":
  413. run()