duckduckgo.py 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496
  1. # SPDX-License-Identifier: AGPL-3.0-or-later
  2. """
  3. DuckDuckGo WEB
  4. ~~~~~~~~~~~~~~
  5. """
  6. from __future__ import annotations
  7. import json
  8. import re
  9. import typing
  10. from urllib.parse import quote_plus
  11. import babel
  12. import lxml.html
  13. from searx import (
  14. locales,
  15. external_bang,
  16. )
  17. from searx.utils import (
  18. eval_xpath,
  19. eval_xpath_getindex,
  20. extr,
  21. extract_text,
  22. )
  23. from searx.network import get # see https://github.com/searxng/searxng/issues/762
  24. from searx.enginelib.traits import EngineTraits
  25. from searx.enginelib import EngineCache
  26. from searx.exceptions import SearxEngineCaptchaException
  27. from searx.result_types import EngineResults
  28. if typing.TYPE_CHECKING:
  29. import logging
  30. logger: logging.Logger
  31. traits: EngineTraits
  32. about = {
  33. "website": 'https://lite.duckduckgo.com/lite/',
  34. "wikidata_id": 'Q12805',
  35. "use_official_api": False,
  36. "require_api_key": False,
  37. "results": 'HTML',
  38. }
  39. send_accept_language_header = True
  40. """DuckDuckGo-Lite tries to guess user's preferred language from the HTTP
  41. ``Accept-Language``. Optional the user can select a region filter (but not a
  42. language).
  43. """
  44. # engine dependent config
  45. categories = ['general', 'web']
  46. paging = True
  47. time_range_support = True
  48. safesearch = True # user can't select but the results are filtered
  49. url = "https://html.duckduckgo.com/html/"
  50. time_range_dict = {'day': 'd', 'week': 'w', 'month': 'm', 'year': 'y'}
  51. form_data = {'v': 'l', 'api': 'd.js', 'o': 'json'}
  52. _CACHE: EngineCache = None # type: ignore
  53. """Persistent (SQLite) key/value cache that deletes its values after ``expire``
  54. seconds."""
  55. def get_cache():
  56. global _CACHE # pylint: disable=global-statement
  57. if _CACHE is None:
  58. _CACHE = EngineCache("duckduckgo") # type:ignore
  59. return _CACHE
  60. def get_vqd(query: str, region: str, force_request: bool = False) -> str:
  61. """Returns the ``vqd`` that fits to the *query*.
  62. :param query: The query term
  63. :param region: DDG's region code
  64. :param force_request: force a request to get a vqd value from DDG
  65. TL;DR; the ``vqd`` value is needed to pass DDG's bot protection and is used
  66. by all request to DDG:
  67. - DuckDuckGo Lite: ``https://lite.duckduckgo.com/lite`` (POST form data)
  68. - DuckDuckGo Web: ``https://links.duckduckgo.com/d.js?q=...&vqd=...``
  69. - DuckDuckGo Images: ``https://duckduckgo.com/i.js??q=...&vqd=...``
  70. - DuckDuckGo Videos: ``https://duckduckgo.com/v.js??q=...&vqd=...``
  71. - DuckDuckGo News: ``https://duckduckgo.com/news.js??q=...&vqd=...``
  72. DDG's bot detection is sensitive to the ``vqd`` value. For some search terms
  73. (such as extremely long search terms that are often sent by bots), no ``vqd``
  74. value can be determined.
  75. If SearXNG cannot determine a ``vqd`` value, then no request should go out
  76. to DDG.
  77. .. attention::
  78. A request with a wrong ``vqd`` value leads to DDG temporarily putting
  79. SearXNG's IP on a block list.
  80. Requests from IPs in this block list run into timeouts. Not sure, but it
  81. seems the block list is a sliding window: to get my IP rid from the bot list
  82. I had to cool down my IP for 1h (send no requests from that IP to DDG).
  83. """
  84. cache = get_cache()
  85. key = cache.secret_hash(f"{query}//{region}")
  86. value = cache.get(key=key)
  87. if value is not None and not force_request:
  88. logger.debug("vqd: re-use cached value: %s", value)
  89. return value
  90. logger.debug("vqd: request value from from duckduckgo.com")
  91. resp = get(f'https://duckduckgo.com/?q={quote_plus(query)}')
  92. if resp.status_code == 200: # type: ignore
  93. value = extr(resp.text, 'vqd="', '"') # type: ignore
  94. if value:
  95. logger.debug("vqd value from duckduckgo.com request: '%s'", value)
  96. else:
  97. logger.error("vqd: can't parse value from ddg response (return empty string)")
  98. return ""
  99. else:
  100. logger.error("vqd: got HTTP %s from duckduckgo.com", resp.status_code)
  101. if value:
  102. cache.set(key=key, value=value)
  103. else:
  104. logger.error("vqd value from duckduckgo.com ", resp.status_code)
  105. return value
  106. def set_vqd(query: str, region: str, value: str):
  107. cache = get_cache()
  108. key = cache.secret_hash(f"{query}//{region}")
  109. cache.set(key=key, value=value, expire=3600)
  110. def get_ddg_lang(eng_traits: EngineTraits, sxng_locale, default='en_US'):
  111. """Get DuckDuckGo's language identifier from SearXNG's locale.
  112. DuckDuckGo defines its languages by region codes (see
  113. :py:obj:`fetch_traits`).
  114. To get region and language of a DDG service use:
  115. .. code: python
  116. eng_region = traits.get_region(params['searxng_locale'], traits.all_locale)
  117. eng_lang = get_ddg_lang(traits, params['searxng_locale'])
  118. It might confuse, but the ``l`` value of the cookie is what SearXNG calls
  119. the *region*:
  120. .. code:: python
  121. # !ddi paris :es-AR --> {'ad': 'es_AR', 'ah': 'ar-es', 'l': 'ar-es'}
  122. params['cookies']['ad'] = eng_lang
  123. params['cookies']['ah'] = eng_region
  124. params['cookies']['l'] = eng_region
  125. .. hint::
  126. `DDG-lite <https://lite.duckduckgo.com/lite>`__ and the *no Javascript*
  127. page https://html.duckduckgo.com/html do not offer a language selection
  128. to the user, only a region can be selected by the user (``eng_region``
  129. from the example above). DDG-lite and *no Javascript* store the selected
  130. region in a cookie::
  131. params['cookies']['kl'] = eng_region # 'ar-es'
  132. """
  133. return eng_traits.custom['lang_region'].get( # type: ignore
  134. sxng_locale, eng_traits.get_language(sxng_locale, default)
  135. )
  136. ddg_reg_map = {
  137. 'tw-tzh': 'zh_TW',
  138. 'hk-tzh': 'zh_HK',
  139. 'ct-ca': 'skip', # ct-ca and es-ca both map to ca_ES
  140. 'es-ca': 'ca_ES',
  141. 'id-en': 'id_ID',
  142. 'no-no': 'nb_NO',
  143. 'jp-jp': 'ja_JP',
  144. 'kr-kr': 'ko_KR',
  145. 'xa-ar': 'ar_SA',
  146. 'sl-sl': 'sl_SI',
  147. 'th-en': 'th_TH',
  148. 'vn-en': 'vi_VN',
  149. }
  150. ddg_lang_map = {
  151. # use ar --> ar_EG (Egypt's arabic)
  152. "ar_DZ": 'lang_region',
  153. "ar_JO": 'lang_region',
  154. "ar_SA": 'lang_region',
  155. # use bn --> bn_BD
  156. 'bn_IN': 'lang_region',
  157. # use de --> de_DE
  158. 'de_CH': 'lang_region',
  159. # use en --> en_US,
  160. 'en_AU': 'lang_region',
  161. 'en_CA': 'lang_region',
  162. 'en_GB': 'lang_region',
  163. # Esperanto
  164. 'eo_XX': 'eo',
  165. # use es --> es_ES,
  166. 'es_AR': 'lang_region',
  167. 'es_CL': 'lang_region',
  168. 'es_CO': 'lang_region',
  169. 'es_CR': 'lang_region',
  170. 'es_EC': 'lang_region',
  171. 'es_MX': 'lang_region',
  172. 'es_PE': 'lang_region',
  173. 'es_UY': 'lang_region',
  174. 'es_VE': 'lang_region',
  175. # use fr --> rf_FR
  176. 'fr_CA': 'lang_region',
  177. 'fr_CH': 'lang_region',
  178. 'fr_BE': 'lang_region',
  179. # use nl --> nl_NL
  180. 'nl_BE': 'lang_region',
  181. # use pt --> pt_PT
  182. 'pt_BR': 'lang_region',
  183. # skip these languages
  184. 'od_IN': 'skip',
  185. 'io_XX': 'skip',
  186. 'tokipona_XX': 'skip',
  187. }
  188. def quote_ddg_bangs(query):
  189. # quote ddg bangs
  190. query_parts = []
  191. # for val in re.split(r'(\s+)', query):
  192. for val in re.split(r'(\s+)', query):
  193. if not val.strip():
  194. continue
  195. if val.startswith('!') and external_bang.get_node(external_bang.EXTERNAL_BANGS, val[1:]):
  196. val = f"'{val}'"
  197. query_parts.append(val)
  198. return ' '.join(query_parts)
  199. def request(query, params):
  200. query = quote_ddg_bangs(query)
  201. if len(query) >= 500:
  202. # DDG does not accept queries with more than 499 chars
  203. params["url"] = None
  204. return
  205. eng_region: str = traits.get_region(params['searxng_locale'], traits.all_locale) # type: ignore
  206. # Note: The API is reverse-engineered from DuckDuckGo's HTML webpage
  207. # (https://html.duckduckgo.com/html/) and may be subject to additional bot detection mechanisms
  208. # and breaking changes in the future.
  209. #
  210. # The params['data'] dictionary can have the following key parameters, in this order:
  211. # - q (str): Search query string
  212. # - b (str): Beginning parameter - empty string for first page requests
  213. # - s (int): Search offset for pagination
  214. # - nextParams (str): Continuation parameters from previous page response, typically empty
  215. # - v (str): Typically 'l' for subsequent pages
  216. # - o (str): Output format, typically 'json'
  217. # - dc (int): Display count - value equal to offset (s) + 1
  218. # - api (str): API endpoint identifier, typically 'd.js'
  219. # - vqd (str): Validation query digest
  220. # - kl (str): Keyboard language/region code (e.g., 'en-us')
  221. # - df (str): Time filter, maps to values like 'd' (day), 'w' (week), 'm' (month), 'y' (year)
  222. params['data']['q'] = query
  223. if params['pageno'] == 1:
  224. params['data']['b'] = ""
  225. elif params['pageno'] >= 2:
  226. offset = 10 + (params['pageno'] - 2) * 15 # Page 2 = 10, Page 3+ = 10 + n*15
  227. params['data']['s'] = offset
  228. params['data']['nextParams'] = form_data.get('nextParams', '')
  229. params['data']['v'] = form_data.get('v', 'l')
  230. params['data']['o'] = form_data.get('o', 'json')
  231. params['data']['dc'] = offset + 1
  232. params['data']['api'] = form_data.get('api', 'd.js')
  233. # vqd is required to request other pages after the first one
  234. vqd = get_vqd(query, eng_region, force_request=False)
  235. if vqd:
  236. params['data']['vqd'] = vqd
  237. else:
  238. # Don't try to call follow up pages without a vqd value.
  239. # DDG recognizes this as a request from a bot. This lowers the
  240. # reputation of the SearXNG IP and DDG starts to activate CAPTCHAs.
  241. params["url"] = None
  242. return
  243. if params['searxng_locale'].startswith("zh"):
  244. # Some locales (at least China) do not have a "next page" button and DDG
  245. # will return a HTTP/2 403 Forbidden for a request of such a page.
  246. params["url"] = None
  247. return
  248. # Put empty kl in form data if language/region set to all
  249. if eng_region == "wt-wt":
  250. params['data']['kl'] = ""
  251. else:
  252. params['data']['kl'] = eng_region
  253. params['data']['df'] = ''
  254. if params['time_range'] in time_range_dict:
  255. params['data']['df'] = time_range_dict[params['time_range']]
  256. params['cookies']['df'] = time_range_dict[params['time_range']]
  257. params['cookies']['kl'] = eng_region
  258. params['url'] = url
  259. params['method'] = 'POST'
  260. params['headers']['Content-Type'] = 'application/x-www-form-urlencoded'
  261. params['headers']['Referer'] = url
  262. params['headers']['Sec-Fetch-Dest'] = "document"
  263. params['headers']['Sec-Fetch-Mode'] = "navigate" # at least this one is used by ddg's bot detection
  264. params['headers']['Sec-Fetch-Site'] = "same-origin"
  265. params['headers']['Sec-Fetch-User'] = "?1"
  266. logger.debug("param headers: %s", params['headers'])
  267. logger.debug("param data: %s", params['data'])
  268. logger.debug("param cookies: %s", params['cookies'])
  269. def is_ddg_captcha(dom):
  270. """In case of CAPTCHA ddg response its own *not a Robot* dialog and is not
  271. redirected to a CAPTCHA page."""
  272. return bool(eval_xpath(dom, "//form[@id='challenge-form']"))
  273. def response(resp) -> EngineResults:
  274. results = EngineResults()
  275. if resp.status_code == 303:
  276. return results
  277. doc = lxml.html.fromstring(resp.text)
  278. if is_ddg_captcha(doc):
  279. # set suspend time to zero is OK --> ddg does not block the IP
  280. raise SearxEngineCaptchaException(suspended_time=0, message=f"CAPTCHA ({resp.search_params['data'].get('kl')})")
  281. form = eval_xpath(doc, '//input[@name="vqd"]/..')
  282. if len(form):
  283. # some locales (at least China) does not have a "next page" button
  284. form = form[0]
  285. form_vqd = eval_xpath(form, '//input[@name="vqd"]/@value')[0]
  286. set_vqd(
  287. query=resp.search_params['data']['q'],
  288. region=resp.search_params['data']['kl'],
  289. value=str(form_vqd),
  290. )
  291. # just select "web-result" and ignore results of class "result--ad result--ad--small"
  292. for div_result in eval_xpath(doc, '//div[@id="links"]/div[contains(@class, "web-result")]'):
  293. item = {}
  294. title = eval_xpath(div_result, './/h2/a')
  295. if not title:
  296. # this is the "No results." item in the result list
  297. continue
  298. item["title"] = extract_text(title)
  299. item["url"] = eval_xpath(div_result, './/h2/a/@href')[0]
  300. item["content"] = extract_text(
  301. eval_xpath_getindex(div_result, './/a[contains(@class, "result__snippet")]', 0, [])
  302. )
  303. results.append(item)
  304. zero_click_info_xpath = '//div[@id="zero_click_abstract"]'
  305. zero_click = extract_text(eval_xpath(doc, zero_click_info_xpath)).strip() # type: ignore
  306. if zero_click and (
  307. "Your IP address is" not in zero_click
  308. and "Your user agent:" not in zero_click
  309. and "URL Decoded:" not in zero_click
  310. ):
  311. results.add(
  312. results.types.Answer(
  313. answer=zero_click,
  314. url=eval_xpath_getindex(doc, '//div[@id="zero_click_abstract"]/a/@href', 0), # type: ignore
  315. )
  316. )
  317. return results
  318. def fetch_traits(engine_traits: EngineTraits):
  319. """Fetch languages & regions from DuckDuckGo.
  320. SearXNG's ``all`` locale maps DuckDuckGo's "Alle regions" (``wt-wt``).
  321. DuckDuckGo's language "Browsers preferred language" (``wt_WT``) makes no
  322. sense in a SearXNG request since SearXNG's ``all`` will not add a
  323. ``Accept-Language`` HTTP header. The value in ``engine_traits.all_locale``
  324. is ``wt-wt`` (the region).
  325. Beside regions DuckDuckGo also defines its languages by region codes. By
  326. example these are the english languages in DuckDuckGo:
  327. - en_US
  328. - en_AU
  329. - en_CA
  330. - en_GB
  331. The function :py:obj:`get_ddg_lang` evaluates DuckDuckGo's language from
  332. SearXNG's locale.
  333. """
  334. # pylint: disable=too-many-branches, too-many-statements, disable=import-outside-toplevel
  335. from searx.utils import js_variable_to_python
  336. # fetch regions
  337. engine_traits.all_locale = 'wt-wt'
  338. # updated from u661.js to u.7669f071a13a7daa57cb / should be updated automatically?
  339. resp = get('https://duckduckgo.com/dist/util/u.7669f071a13a7daa57cb.js')
  340. if not resp.ok: # type: ignore
  341. print("ERROR: response from DuckDuckGo is not OK.")
  342. js_code = extr(resp.text, 'regions:', ',snippetLengths') # type: ignore
  343. regions = json.loads(js_code)
  344. for eng_tag, name in regions.items():
  345. if eng_tag == 'wt-wt':
  346. engine_traits.all_locale = 'wt-wt'
  347. continue
  348. region = ddg_reg_map.get(eng_tag)
  349. if region == 'skip':
  350. continue
  351. if not region:
  352. eng_territory, eng_lang = eng_tag.split('-')
  353. region = eng_lang + '_' + eng_territory.upper()
  354. try:
  355. sxng_tag = locales.region_tag(babel.Locale.parse(region))
  356. except babel.UnknownLocaleError:
  357. print("ERROR: %s (%s) -> %s is unknown by babel" % (name, eng_tag, region))
  358. continue
  359. conflict = engine_traits.regions.get(sxng_tag)
  360. if conflict:
  361. if conflict != eng_tag:
  362. print("CONFLICT: babel %s --> %s, %s" % (sxng_tag, conflict, eng_tag))
  363. continue
  364. engine_traits.regions[sxng_tag] = eng_tag
  365. # fetch languages
  366. engine_traits.custom['lang_region'] = {}
  367. js_code = extr(resp.text, 'languages:', ',regions') # type: ignore
  368. languages = js_variable_to_python(js_code)
  369. for eng_lang, name in languages.items():
  370. if eng_lang == 'wt_WT':
  371. continue
  372. babel_tag = ddg_lang_map.get(eng_lang, eng_lang)
  373. if babel_tag == 'skip':
  374. continue
  375. try:
  376. if babel_tag == 'lang_region':
  377. sxng_tag = locales.region_tag(babel.Locale.parse(eng_lang))
  378. engine_traits.custom['lang_region'][sxng_tag] = eng_lang
  379. continue
  380. sxng_tag = locales.language_tag(babel.Locale.parse(babel_tag))
  381. except babel.UnknownLocaleError:
  382. print("ERROR: language %s (%s) is unknown by babel" % (name, eng_lang))
  383. continue
  384. conflict = engine_traits.languages.get(sxng_tag)
  385. if conflict:
  386. if conflict != eng_lang:
  387. print("CONFLICT: babel %s --> %s, %s" % (sxng_tag, conflict, eng_lang))
  388. continue
  389. engine_traits.languages[sxng_tag] = eng_lang