webapp.py 51 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437
  1. #!/usr/bin/env python
  2. # SPDX-License-Identifier: AGPL-3.0-or-later
  3. """WebbApp
  4. """
  5. # pylint: disable=use-dict-literal
  6. from __future__ import annotations
  7. import inspect
  8. import hashlib
  9. import hmac
  10. import json
  11. import os
  12. import sys
  13. import base64
  14. from timeit import default_timer
  15. from html import escape
  16. from io import StringIO
  17. import typing
  18. import urllib
  19. import urllib.parse
  20. from urllib.parse import urlencode, urlparse, unquote
  21. import warnings
  22. import httpx
  23. from pygments import highlight
  24. from pygments.lexers import get_lexer_by_name
  25. from pygments.formatters import HtmlFormatter # pylint: disable=no-name-in-module
  26. from werkzeug.serving import is_running_from_reloader
  27. import flask
  28. from flask import (
  29. Flask,
  30. render_template,
  31. url_for,
  32. make_response,
  33. redirect,
  34. send_from_directory,
  35. )
  36. from flask.wrappers import Response
  37. from flask.json import jsonify
  38. from flask_babel import (
  39. Babel,
  40. gettext,
  41. format_decimal,
  42. )
  43. import searx
  44. from searx.extended_types import sxng_request
  45. from searx import (
  46. logger,
  47. get_setting,
  48. settings,
  49. )
  50. from searx import infopage
  51. from searx import limiter
  52. from searx.botdetection import link_token
  53. from searx.data import ENGINE_DESCRIPTIONS
  54. from searx.result_types import Answer
  55. from searx.settings_defaults import OUTPUT_FORMATS
  56. from searx.settings_loader import DEFAULT_SETTINGS_FILE
  57. from searx.exceptions import SearxParameterException
  58. from searx.engines import (
  59. DEFAULT_CATEGORY,
  60. categories,
  61. engines,
  62. engine_shortcuts,
  63. )
  64. from searx import webutils
  65. from searx.webutils import (
  66. highlight_content,
  67. get_static_files,
  68. get_result_templates,
  69. get_themes,
  70. exception_classname_to_text,
  71. new_hmac,
  72. is_hmac_of,
  73. group_engines_in_tab,
  74. )
  75. from searx.webadapter import (
  76. get_search_query_from_webapp,
  77. get_selected_categories,
  78. parse_lang,
  79. )
  80. from searx.utils import gen_useragent, dict_subset
  81. from searx.version import VERSION_STRING, GIT_URL, GIT_BRANCH
  82. from searx.query import RawTextQuery
  83. from searx.plugins.oa_doi_rewrite import get_doi_resolver
  84. from searx.preferences import (
  85. Preferences,
  86. ClientPref,
  87. ValidationException,
  88. )
  89. import searx.answerers
  90. import searx.plugins
  91. from searx.metrics import get_engines_stats, get_engine_errors, get_reliabilities, histogram, counter, openmetrics
  92. from searx.flaskfix import patch_application
  93. from searx.locales import (
  94. LOCALE_NAMES,
  95. RTL_LOCALES,
  96. localeselector,
  97. locales_initialize,
  98. match_locale,
  99. )
  100. # renaming names from searx imports ...
  101. from searx.autocomplete import search_autocomplete, backends as autocomplete_backends
  102. from searx import favicons
  103. from searx.redisdb import initialize as redis_initialize
  104. from searx.sxng_locales import sxng_locales
  105. import searx.search
  106. from searx.network import stream as http_stream, set_context_network_name
  107. from searx.search.checker import get_result as checker_get_result
  108. logger = logger.getChild('webapp')
  109. warnings.simplefilter("always")
  110. # about static
  111. logger.debug('static directory is %s', settings['ui']['static_path'])
  112. static_files = get_static_files(settings['ui']['static_path'])
  113. # about templates
  114. logger.debug('templates directory is %s', settings['ui']['templates_path'])
  115. default_theme = settings['ui']['default_theme']
  116. templates_path = settings['ui']['templates_path']
  117. themes = get_themes(templates_path)
  118. result_templates = get_result_templates(templates_path)
  119. STATS_SORT_PARAMETERS = {
  120. 'name': (False, 'name', ''),
  121. 'score': (True, 'score_per_result', 0),
  122. 'result_count': (True, 'result_count', 0),
  123. 'time': (False, 'total', 0),
  124. 'reliability': (False, 'reliability', 100),
  125. }
  126. # Flask app
  127. app = Flask(__name__, static_folder=settings['ui']['static_path'], template_folder=templates_path)
  128. app.jinja_env.trim_blocks = True
  129. app.jinja_env.lstrip_blocks = True
  130. app.jinja_env.add_extension('jinja2.ext.loopcontrols') # pylint: disable=no-member
  131. app.jinja_env.filters['group_engines_in_tab'] = group_engines_in_tab # pylint: disable=no-member
  132. app.secret_key = settings['server']['secret_key']
  133. def get_locale():
  134. locale = localeselector()
  135. logger.debug("%s uses locale `%s`", urllib.parse.quote(sxng_request.url), locale)
  136. return locale
  137. babel = Babel(app, locale_selector=get_locale)
  138. def _get_browser_language(req, lang_list):
  139. client = ClientPref.from_http_request(req)
  140. locale = match_locale(client.locale_tag, lang_list, fallback='en')
  141. return locale
  142. def _get_locale_rfc5646(locale):
  143. """Get locale name for <html lang="...">
  144. Chrom* browsers don't detect the language when there is a subtag (ie a territory).
  145. For example "zh-TW" is detected but not "zh-Hant-TW".
  146. This function returns a locale without the subtag.
  147. """
  148. parts = locale.split('-')
  149. return parts[0].lower() + '-' + parts[-1].upper()
  150. # code-highlighter
  151. @app.template_filter('code_highlighter')
  152. def code_highlighter(codelines, language=None):
  153. if not language:
  154. language = 'text'
  155. try:
  156. # find lexer by programming language
  157. lexer = get_lexer_by_name(language, stripall=True)
  158. except Exception as e: # pylint: disable=broad-except
  159. logger.warning("pygments lexer: %s " % e)
  160. # if lexer is not found, using default one
  161. lexer = get_lexer_by_name('text', stripall=True)
  162. html_code = ''
  163. tmp_code = ''
  164. last_line = None
  165. line_code_start = None
  166. # parse lines
  167. for line, code in codelines:
  168. if not last_line:
  169. line_code_start = line
  170. # new codeblock is detected
  171. if last_line is not None and last_line + 1 != line:
  172. # highlight last codepart
  173. formatter = HtmlFormatter(linenos='inline', linenostart=line_code_start, cssclass="code-highlight")
  174. html_code = html_code + highlight(tmp_code, lexer, formatter)
  175. # reset conditions for next codepart
  176. tmp_code = ''
  177. line_code_start = line
  178. # add codepart
  179. tmp_code += code + '\n'
  180. # update line
  181. last_line = line
  182. # highlight last codepart
  183. formatter = HtmlFormatter(linenos='inline', linenostart=line_code_start, cssclass="code-highlight")
  184. html_code = html_code + highlight(tmp_code, lexer, formatter)
  185. return html_code
  186. def get_result_template(theme_name: str, template_name: str):
  187. themed_path = theme_name + '/result_templates/' + template_name
  188. if themed_path in result_templates:
  189. return themed_path
  190. return 'result_templates/' + template_name
  191. def custom_url_for(endpoint: str, **values):
  192. suffix = ""
  193. if endpoint == 'static' and values.get('filename'):
  194. file_hash = static_files.get(values['filename'])
  195. if not file_hash:
  196. # try file in the current theme
  197. theme_name = sxng_request.preferences.get_value('theme')
  198. filename_with_theme = "themes/{}/{}".format(theme_name, values['filename'])
  199. file_hash = static_files.get(filename_with_theme)
  200. if file_hash:
  201. values['filename'] = filename_with_theme
  202. if get_setting('ui.static_use_hash') and file_hash:
  203. suffix = "?" + file_hash
  204. if endpoint == 'info' and 'locale' not in values:
  205. locale = sxng_request.preferences.get_value('locale')
  206. if infopage.INFO_PAGES.get_page(values['pagename'], locale) is None:
  207. locale = infopage.INFO_PAGES.locale_default
  208. values['locale'] = locale
  209. return url_for(endpoint, **values) + suffix
  210. def morty_proxify(url: str):
  211. if not url:
  212. return url
  213. if url.startswith('//'):
  214. url = 'https:' + url
  215. if not settings['result_proxy']['url']:
  216. return url
  217. url_params = dict(mortyurl=url)
  218. if settings['result_proxy']['key']:
  219. url_params['mortyhash'] = hmac.new(settings['result_proxy']['key'], url.encode(), hashlib.sha256).hexdigest()
  220. return '{0}?{1}'.format(settings['result_proxy']['url'], urlencode(url_params))
  221. def image_proxify(url: str):
  222. if not url:
  223. return url
  224. if url.startswith('//'):
  225. url = 'https:' + url
  226. if not sxng_request.preferences.get_value('image_proxy'):
  227. return url
  228. if url.startswith('data:image/'):
  229. # 50 is an arbitrary number to get only the beginning of the image.
  230. partial_base64 = url[len('data:image/') : 50].split(';')
  231. if (
  232. len(partial_base64) == 2
  233. and partial_base64[0] in ['gif', 'png', 'jpeg', 'pjpeg', 'webp', 'tiff', 'bmp']
  234. and partial_base64[1].startswith('base64,')
  235. ):
  236. return url
  237. return None
  238. if settings['result_proxy']['url']:
  239. return morty_proxify(url)
  240. h = new_hmac(settings['server']['secret_key'], url.encode())
  241. return '{0}?{1}'.format(url_for('image_proxy'), urlencode(dict(url=url.encode(), h=h)))
  242. def get_translations():
  243. return {
  244. # when there is autocompletion
  245. 'no_item_found': gettext('No item found'),
  246. # /preferences: the source of the engine description (wikipedata, wikidata, website)
  247. 'Source': gettext('Source'),
  248. # infinite scroll
  249. 'error_loading_next_page': gettext('Error loading the next page'),
  250. }
  251. def get_enabled_categories(category_names: typing.Iterable[str]):
  252. """The categories in ``category_names```for which there is no active engine
  253. are filtered out and a reduced list is returned."""
  254. enabled_engines = [item[0] for item in sxng_request.preferences.engines.get_enabled()]
  255. enabled_categories = set()
  256. for engine_name in enabled_engines:
  257. enabled_categories.update(engines[engine_name].categories)
  258. return [x for x in category_names if x in enabled_categories]
  259. def get_pretty_url(parsed_url: urllib.parse.ParseResult):
  260. url_formatting_pref = sxng_request.preferences.get_value('url_formatting')
  261. if url_formatting_pref == 'full':
  262. return [parsed_url.geturl()]
  263. if url_formatting_pref == 'host':
  264. return [parsed_url.netloc]
  265. path = parsed_url.path
  266. path = path[:-1] if len(path) > 0 and path[-1] == '/' else path
  267. path = unquote(path.replace("/", " › "))
  268. return [parsed_url.scheme + "://" + parsed_url.netloc, path]
  269. def get_client_settings():
  270. req_pref = sxng_request.preferences
  271. return {
  272. 'autocomplete': req_pref.get_value('autocomplete'),
  273. 'autocomplete_min': get_setting('search.autocomplete_min'),
  274. 'method': req_pref.get_value('method'),
  275. 'infinite_scroll': req_pref.get_value('infinite_scroll'),
  276. 'translations': get_translations(),
  277. 'search_on_category_select': req_pref.get_value('search_on_category_select'),
  278. 'hotkeys': req_pref.get_value('hotkeys'),
  279. 'url_formatting': req_pref.get_value('url_formatting'),
  280. 'theme_static_path': custom_url_for('static', filename='themes/simple'),
  281. 'results_on_new_tab': req_pref.get_value('results_on_new_tab'),
  282. 'favicon_resolver': req_pref.get_value('favicon_resolver'),
  283. 'advanced_search': req_pref.get_value('advanced_search'),
  284. 'query_in_title': req_pref.get_value('query_in_title'),
  285. 'safesearch': str(req_pref.get_value('safesearch')),
  286. 'theme': req_pref.get_value('theme'),
  287. 'doi_resolver': get_doi_resolver(),
  288. }
  289. def render(template_name: str, **kwargs):
  290. # values from the preferences
  291. # pylint: disable=too-many-statements
  292. client_settings = get_client_settings()
  293. kwargs['client_settings'] = str(
  294. base64.b64encode(
  295. bytes(
  296. json.dumps(client_settings),
  297. encoding='utf-8',
  298. )
  299. ),
  300. encoding='utf-8',
  301. )
  302. kwargs['preferences'] = sxng_request.preferences
  303. kwargs.update(client_settings)
  304. # values from the HTTP requests
  305. kwargs['endpoint'] = 'results' if 'q' in kwargs else sxng_request.endpoint
  306. kwargs['cookies'] = sxng_request.cookies
  307. kwargs['errors'] = sxng_request.errors
  308. kwargs['link_token'] = link_token.get_token()
  309. kwargs['categories_as_tabs'] = list(settings['categories_as_tabs'].keys())
  310. kwargs['categories'] = get_enabled_categories(settings['categories_as_tabs'].keys())
  311. kwargs['DEFAULT_CATEGORY'] = DEFAULT_CATEGORY
  312. # i18n
  313. kwargs['sxng_locales'] = [l for l in sxng_locales if l[0] in settings['search']['languages']]
  314. locale = sxng_request.preferences.get_value('locale')
  315. kwargs['locale_rfc5646'] = _get_locale_rfc5646(locale)
  316. if locale in RTL_LOCALES and 'rtl' not in kwargs:
  317. kwargs['rtl'] = True
  318. if 'current_language' not in kwargs:
  319. kwargs['current_language'] = parse_lang(sxng_request.preferences, {}, RawTextQuery('', []))
  320. # values from settings
  321. kwargs['search_formats'] = [x for x in settings['search']['formats'] if x != 'html']
  322. kwargs['instance_name'] = get_setting('general.instance_name')
  323. kwargs['searx_version'] = VERSION_STRING
  324. kwargs['searx_git_url'] = GIT_URL
  325. kwargs['enable_metrics'] = get_setting('general.enable_metrics')
  326. kwargs['get_setting'] = get_setting
  327. kwargs['get_pretty_url'] = get_pretty_url
  328. # values from settings: donation_url
  329. donation_url = get_setting('general.donation_url')
  330. if donation_url is True:
  331. donation_url = custom_url_for('info', pagename='donate')
  332. kwargs['donation_url'] = donation_url
  333. # helpers to create links to other pages
  334. kwargs['url_for'] = custom_url_for # override url_for function in templates
  335. kwargs['image_proxify'] = image_proxify
  336. kwargs['favicon_url'] = favicons.favicon_url
  337. kwargs['proxify'] = morty_proxify if settings['result_proxy']['url'] is not None else None
  338. kwargs['proxify_results'] = settings['result_proxy']['proxify_results']
  339. kwargs['cache_url'] = settings['ui']['cache_url']
  340. kwargs['get_result_template'] = get_result_template
  341. kwargs['opensearch_url'] = (
  342. url_for('opensearch')
  343. + '?'
  344. + urlencode(
  345. {
  346. 'method': sxng_request.preferences.get_value('method'),
  347. 'autocomplete': sxng_request.preferences.get_value('autocomplete'),
  348. }
  349. )
  350. )
  351. kwargs['urlparse'] = urlparse
  352. start_time = default_timer()
  353. result = render_template('{}/{}'.format(kwargs['theme'], template_name), **kwargs)
  354. sxng_request.render_time += default_timer() - start_time # pylint: disable=assigning-non-slot
  355. return result
  356. @app.before_request
  357. def pre_request():
  358. sxng_request.start_time = default_timer() # pylint: disable=assigning-non-slot
  359. sxng_request.render_time = 0 # pylint: disable=assigning-non-slot
  360. sxng_request.timings = [] # pylint: disable=assigning-non-slot
  361. sxng_request.errors = [] # pylint: disable=assigning-non-slot
  362. client_pref = ClientPref.from_http_request(sxng_request)
  363. # pylint: disable=redefined-outer-name
  364. preferences = Preferences(themes, list(categories.keys()), engines, searx.plugins.STORAGE, client_pref)
  365. user_agent = sxng_request.headers.get('User-Agent', '').lower()
  366. if 'webkit' in user_agent and 'android' in user_agent:
  367. preferences.key_value_settings['method'].value = 'GET'
  368. sxng_request.preferences = preferences # pylint: disable=assigning-non-slot
  369. try:
  370. preferences.parse_dict(sxng_request.cookies)
  371. except Exception as e: # pylint: disable=broad-except
  372. logger.exception(e, exc_info=True)
  373. sxng_request.errors.append(gettext('Invalid settings, please edit your preferences'))
  374. # merge GET, POST vars
  375. # HINT request.form is of type werkzeug.datastructures.ImmutableMultiDict
  376. sxng_request.form = dict(sxng_request.form.items()) # type: ignore
  377. for k, v in sxng_request.args.items():
  378. if k not in sxng_request.form:
  379. sxng_request.form[k] = v
  380. if sxng_request.form.get('preferences'):
  381. preferences.parse_encoded_data(sxng_request.form['preferences'])
  382. else:
  383. try:
  384. preferences.parse_dict(sxng_request.form)
  385. except Exception as e: # pylint: disable=broad-except
  386. logger.exception(e, exc_info=True)
  387. sxng_request.errors.append(gettext('Invalid settings'))
  388. # language is defined neither in settings nor in preferences
  389. # use browser headers
  390. if not preferences.get_value("language"):
  391. language = _get_browser_language(sxng_request, settings['search']['languages'])
  392. preferences.parse_dict({"language": language})
  393. logger.debug('set language %s (from browser)', preferences.get_value("language"))
  394. # UI locale is defined neither in settings nor in preferences
  395. # use browser headers
  396. if not preferences.get_value("locale"):
  397. locale = _get_browser_language(sxng_request, LOCALE_NAMES.keys())
  398. preferences.parse_dict({"locale": locale})
  399. logger.debug('set locale %s (from browser)', preferences.get_value("locale"))
  400. # request.user_plugins
  401. sxng_request.user_plugins = [] # pylint: disable=assigning-non-slot
  402. allowed_plugins = preferences.plugins.get_enabled()
  403. disabled_plugins = preferences.plugins.get_disabled()
  404. for plugin in searx.plugins.STORAGE:
  405. if (plugin.id not in disabled_plugins) or plugin.id in allowed_plugins:
  406. sxng_request.user_plugins.append(plugin.id)
  407. @app.after_request
  408. def add_default_headers(response: flask.Response):
  409. # set default http headers
  410. for header, value in settings['server']['default_http_headers'].items():
  411. if header in response.headers:
  412. continue
  413. response.headers[header] = value
  414. return response
  415. @app.after_request
  416. def post_request(response: flask.Response):
  417. total_time = default_timer() - sxng_request.start_time
  418. timings_all = [
  419. 'total;dur=' + str(round(total_time * 1000, 3)),
  420. 'render;dur=' + str(round(sxng_request.render_time * 1000, 3)),
  421. ]
  422. if len(sxng_request.timings) > 0:
  423. timings = sorted(sxng_request.timings, key=lambda t: t.total)
  424. timings_total = [
  425. 'total_' + str(i) + '_' + t.engine + ';dur=' + str(round(t.total * 1000, 3)) for i, t in enumerate(timings)
  426. ]
  427. timings_load = [
  428. 'load_' + str(i) + '_' + t.engine + ';dur=' + str(round(t.load * 1000, 3))
  429. for i, t in enumerate(timings)
  430. if t.load
  431. ]
  432. timings_all = timings_all + timings_total + timings_load
  433. response.headers.add('Server-Timing', ', '.join(timings_all))
  434. return response
  435. def index_error(output_format: str, error_message: str):
  436. if output_format == 'json':
  437. return Response(json.dumps({'error': error_message}), mimetype='application/json')
  438. if output_format == 'csv':
  439. response = Response('', mimetype='application/csv')
  440. cont_disp = 'attachment;Filename=searx.csv'
  441. response.headers.add('Content-Disposition', cont_disp)
  442. return response
  443. if output_format == 'rss':
  444. response_rss = render(
  445. 'opensearch_response_rss.xml',
  446. results=[],
  447. q=sxng_request.form['q'] if 'q' in sxng_request.form else '',
  448. number_of_results=0,
  449. error_message=error_message,
  450. )
  451. return Response(response_rss, mimetype='text/xml')
  452. # html
  453. sxng_request.errors.append(gettext('search error'))
  454. return render(
  455. # fmt: off
  456. 'index.html',
  457. selected_categories=get_selected_categories(sxng_request.preferences, sxng_request.form),
  458. # fmt: on
  459. )
  460. @app.route('/', methods=['GET', 'POST'])
  461. def index():
  462. """Render index page."""
  463. # redirect to search if there's a query in the request
  464. if sxng_request.form.get('q'):
  465. query = ('?' + sxng_request.query_string.decode()) if sxng_request.query_string else ''
  466. return redirect(url_for('search') + query, 308)
  467. return render(
  468. # fmt: off
  469. 'index.html',
  470. selected_categories=get_selected_categories(sxng_request.preferences, sxng_request.form),
  471. current_locale = sxng_request.preferences.get_value("locale"),
  472. # fmt: on
  473. )
  474. @app.route('/healthz', methods=['GET'])
  475. def health():
  476. return Response('OK', mimetype='text/plain')
  477. @app.route('/client<token>.css', methods=['GET', 'POST'])
  478. def client_token(token=None):
  479. link_token.ping(sxng_request, token)
  480. return Response('', mimetype='text/css', headers={"Cache-Control": "no-store, max-age=0"})
  481. @app.route('/rss.xsl', methods=['GET', 'POST'])
  482. def rss_xsl():
  483. return render_template(
  484. f"{sxng_request.preferences.get_value('theme')}/rss.xsl",
  485. url_for=custom_url_for,
  486. )
  487. @app.route('/search', methods=['GET', 'POST'])
  488. def search():
  489. """Search query in q and return results.
  490. Supported outputs: html, json, csv, rss.
  491. """
  492. # pylint: disable=too-many-locals, too-many-return-statements, too-many-branches
  493. # pylint: disable=too-many-statements
  494. # output_format
  495. output_format = sxng_request.form.get('format', 'html')
  496. if output_format not in OUTPUT_FORMATS:
  497. output_format = 'html'
  498. if output_format not in settings['search']['formats']:
  499. flask.abort(403)
  500. # check if there is query (not None and not an empty string)
  501. if not sxng_request.form.get('q'):
  502. if output_format == 'html':
  503. return render(
  504. # fmt: off
  505. 'index.html',
  506. selected_categories=get_selected_categories(sxng_request.preferences, sxng_request.form),
  507. # fmt: on
  508. )
  509. return index_error(output_format, 'No query'), 400
  510. # search
  511. search_query = None
  512. raw_text_query = None
  513. result_container = None
  514. try:
  515. search_query, raw_text_query, _, _, selected_locale = get_search_query_from_webapp(
  516. sxng_request.preferences, sxng_request.form
  517. )
  518. search_obj = searx.search.SearchWithPlugins(search_query, sxng_request, sxng_request.user_plugins)
  519. result_container = search_obj.search()
  520. except SearxParameterException as e:
  521. logger.exception('search error: SearxParameterException')
  522. return index_error(output_format, e.message), 400
  523. except Exception as e: # pylint: disable=broad-except
  524. logger.exception(e, exc_info=True)
  525. return index_error(output_format, gettext('search error')), 500
  526. # 1. check if the result is a redirect for an external bang
  527. if result_container.redirect_url:
  528. return redirect(result_container.redirect_url)
  529. # 2. add Server-Timing header for measuring performance characteristics of
  530. # web applications
  531. sxng_request.timings = result_container.get_timings() # pylint: disable=assigning-non-slot
  532. # 3. formats without a template
  533. if output_format == 'json':
  534. response = webutils.get_json_response(search_query, result_container)
  535. return Response(response, mimetype='application/json')
  536. if output_format == 'csv':
  537. csv = webutils.CSVWriter(StringIO())
  538. webutils.write_csv_response(csv, result_container)
  539. csv.stream.seek(0)
  540. response = Response(csv.stream.read(), mimetype='application/csv')
  541. cont_disp = 'attachment;Filename=searx_-_{0}.csv'.format(search_query.query)
  542. response.headers.add('Content-Disposition', cont_disp)
  543. return response
  544. # 4. formats rendered by a template / RSS & HTML
  545. current_template = None
  546. previous_result = None
  547. results = result_container.get_ordered_results()
  548. if search_query.redirect_to_first_result and results:
  549. return redirect(results[0]['url'], 302)
  550. for result in results:
  551. if output_format == 'html':
  552. if 'content' in result and result['content']:
  553. result['content'] = highlight_content(escape(result['content'][:1024]), search_query.query)
  554. if 'title' in result and result['title']:
  555. result['title'] = highlight_content(escape(result['title'] or ''), search_query.query)
  556. # set result['open_group'] = True when the template changes from the previous result
  557. # set result['close_group'] = True when the template changes on the next result
  558. if current_template != result.template:
  559. result.open_group = True
  560. if previous_result:
  561. previous_result.close_group = True # pylint: disable=unsupported-assignment-operation
  562. current_template = result.template
  563. previous_result = result
  564. if previous_result:
  565. previous_result.close_group = True
  566. # 4.a RSS
  567. if output_format == 'rss':
  568. response_rss = render(
  569. 'opensearch_response_rss.xml',
  570. results=results,
  571. q=sxng_request.form['q'],
  572. number_of_results=result_container.number_of_results,
  573. )
  574. return Response(response_rss, mimetype='text/xml')
  575. # 4.b HTML
  576. # suggestions: use RawTextQuery to get the suggestion URLs with the same bang
  577. suggestion_urls = list(
  578. map(
  579. lambda suggestion: {'url': raw_text_query.changeQuery(suggestion).getFullQuery(), 'title': suggestion},
  580. result_container.suggestions,
  581. )
  582. )
  583. correction_urls = list(
  584. map(
  585. lambda correction: {'url': raw_text_query.changeQuery(correction).getFullQuery(), 'title': correction},
  586. result_container.corrections,
  587. )
  588. )
  589. # engine_timings: get engine response times sorted from slowest to fastest
  590. engine_timings = sorted(result_container.get_timings(), reverse=True, key=lambda e: e.total)
  591. max_response_time = engine_timings[0].total if engine_timings else None
  592. engine_timings_pairs = [(timing.engine, timing.total) for timing in engine_timings]
  593. # search_query.lang contains the user choice (all, auto, en, ...)
  594. # when the user choice is "auto", search.search_query.lang contains the detected language
  595. # otherwise it is equals to search_query.lang
  596. return render(
  597. # fmt: off
  598. 'results.html',
  599. results = results,
  600. q=sxng_request.form['q'],
  601. selected_categories = search_query.categories,
  602. pageno = search_query.pageno,
  603. time_range = search_query.time_range or '',
  604. number_of_results = format_decimal(result_container.number_of_results),
  605. suggestions = suggestion_urls,
  606. answers = result_container.answers,
  607. corrections = correction_urls,
  608. infoboxes = result_container.infoboxes,
  609. engine_data = result_container.engine_data,
  610. paging = result_container.paging,
  611. unresponsive_engines = webutils.get_translated_errors(
  612. result_container.unresponsive_engines
  613. ),
  614. current_locale = sxng_request.preferences.get_value("locale"),
  615. current_language = selected_locale,
  616. search_language = match_locale(
  617. search_obj.search_query.lang,
  618. settings['search']['languages'],
  619. fallback=sxng_request.preferences.get_value("language")
  620. ),
  621. timeout_limit = sxng_request.form.get('timeout_limit', None),
  622. timings = engine_timings_pairs,
  623. max_response_time = max_response_time
  624. # fmt: on
  625. )
  626. @app.route('/about', methods=['GET'])
  627. def about():
  628. """Redirect to about page"""
  629. # custom_url_for is going to add the locale
  630. return redirect(custom_url_for('info', pagename='about'))
  631. @app.route('/info/<locale>/<pagename>', methods=['GET'])
  632. def info(pagename, locale):
  633. """Render page of online user documentation"""
  634. page = infopage.INFO_PAGES.get_page(pagename, locale)
  635. if page is None:
  636. flask.abort(404)
  637. user_locale = sxng_request.preferences.get_value('locale')
  638. return render(
  639. 'info.html',
  640. all_pages=infopage.INFO_PAGES.iter_pages(user_locale, fallback_to_default=True),
  641. active_page=page,
  642. active_pagename=pagename,
  643. )
  644. @app.route('/autocompleter', methods=['GET', 'POST'])
  645. def autocompleter():
  646. """Return autocompleter results"""
  647. # run autocompleter
  648. results = []
  649. # set blocked engines
  650. disabled_engines = sxng_request.preferences.engines.get_disabled()
  651. # parse query
  652. raw_text_query = RawTextQuery(sxng_request.form.get('q', ''), disabled_engines)
  653. sug_prefix = raw_text_query.getQuery()
  654. for obj in searx.answerers.STORAGE.ask(sug_prefix):
  655. if isinstance(obj, Answer):
  656. results.append(obj.answer)
  657. # normal autocompletion results only appear if no inner results returned
  658. # and there is a query part
  659. if len(raw_text_query.autocomplete_list) == 0 and len(sug_prefix) > 0:
  660. # get SearXNG's locale and autocomplete backend from cookie
  661. sxng_locale = sxng_request.preferences.get_value('language')
  662. backend_name = sxng_request.preferences.get_value('autocomplete')
  663. for result in search_autocomplete(backend_name, sug_prefix, sxng_locale):
  664. # attention: this loop will change raw_text_query object and this is
  665. # the reason why the sug_prefix was stored before (see above)
  666. if result != sug_prefix:
  667. results.append(raw_text_query.changeQuery(result).getFullQuery())
  668. if len(raw_text_query.autocomplete_list) > 0:
  669. for autocomplete_text in raw_text_query.autocomplete_list:
  670. results.append(raw_text_query.get_autocomplete_full_query(autocomplete_text))
  671. if sxng_request.headers.get('X-Requested-With') == 'XMLHttpRequest':
  672. # the suggestion request comes from the searx search form
  673. suggestions = json.dumps(results)
  674. mimetype = 'application/json'
  675. else:
  676. # the suggestion request comes from browser's URL bar
  677. suggestions = json.dumps([sug_prefix, results])
  678. mimetype = 'application/x-suggestions+json'
  679. suggestions = escape(suggestions, False)
  680. return Response(suggestions, mimetype=mimetype)
  681. @app.route('/preferences', methods=['GET', 'POST'])
  682. def preferences():
  683. """Render preferences page && save user preferences"""
  684. # pylint: disable=too-many-locals, too-many-return-statements, too-many-branches
  685. # pylint: disable=too-many-statements
  686. # save preferences using the link the /preferences?preferences=...
  687. if sxng_request.args.get('preferences') or sxng_request.form.get('preferences'):
  688. resp = make_response(redirect(url_for('index', _external=True)))
  689. return sxng_request.preferences.save(resp)
  690. # save preferences
  691. if sxng_request.method == 'POST':
  692. resp = make_response(redirect(url_for('index', _external=True)))
  693. try:
  694. sxng_request.preferences.parse_form(sxng_request.form)
  695. except ValidationException:
  696. sxng_request.errors.append(gettext('Invalid settings, please edit your preferences'))
  697. return resp
  698. return sxng_request.preferences.save(resp)
  699. # render preferences
  700. image_proxy = sxng_request.preferences.get_value('image_proxy') # pylint: disable=redefined-outer-name
  701. disabled_engines = sxng_request.preferences.engines.get_disabled()
  702. allowed_plugins = sxng_request.preferences.plugins.get_enabled()
  703. # stats for preferences page
  704. filtered_engines = dict(filter(lambda kv: sxng_request.preferences.validate_token(kv[1]), engines.items()))
  705. engines_by_category = {}
  706. for c in categories: # pylint: disable=consider-using-dict-items
  707. engines_by_category[c] = [e for e in categories[c] if e.name in filtered_engines]
  708. # sort the engines alphabetically since the order in settings.yml is meaningless.
  709. list.sort(engines_by_category[c], key=lambda e: e.name)
  710. # get first element [0], the engine time,
  711. # and then the second element [1] : the time (the first one is the label)
  712. stats = {} # pylint: disable=redefined-outer-name
  713. max_rate95 = 0
  714. for _, e in filtered_engines.items():
  715. h = histogram('engine', e.name, 'time', 'total')
  716. median = round(h.percentage(50), 1) if h.count > 0 else None
  717. rate80 = round(h.percentage(80), 1) if h.count > 0 else None
  718. rate95 = round(h.percentage(95), 1) if h.count > 0 else None
  719. max_rate95 = max(max_rate95, rate95 or 0)
  720. result_count_sum = histogram('engine', e.name, 'result', 'count').sum
  721. successful_count = counter('engine', e.name, 'search', 'count', 'successful')
  722. result_count = int(result_count_sum / float(successful_count)) if successful_count else 0
  723. stats[e.name] = {
  724. 'time': median,
  725. 'rate80': rate80,
  726. 'rate95': rate95,
  727. 'warn_timeout': e.timeout > settings['outgoing']['request_timeout'],
  728. 'supports_selected_language': e.traits.is_locale_supported(
  729. str(sxng_request.preferences.get_value('language') or 'all')
  730. ),
  731. 'result_count': result_count,
  732. }
  733. # end of stats
  734. # reliabilities
  735. reliabilities = {}
  736. engine_errors = get_engine_errors(filtered_engines)
  737. checker_results = checker_get_result()
  738. checker_results = (
  739. checker_results['engines'] if checker_results['status'] == 'ok' and 'engines' in checker_results else {}
  740. )
  741. for _, e in filtered_engines.items():
  742. checker_result = checker_results.get(e.name, {})
  743. checker_success = checker_result.get('success', True)
  744. errors = engine_errors.get(e.name) or []
  745. if counter('engine', e.name, 'search', 'count', 'sent') == 0:
  746. # no request
  747. reliability = None
  748. elif checker_success and not errors:
  749. reliability = 100
  750. elif 'simple' in checker_result.get('errors', {}):
  751. # the basic (simple) test doesn't work: the engine is broken according to the checker
  752. # even if there is no exception
  753. reliability = 0
  754. else:
  755. # pylint: disable=consider-using-generator
  756. reliability = 100 - sum([error['percentage'] for error in errors if not error.get('secondary')])
  757. reliabilities[e.name] = {
  758. 'reliability': reliability,
  759. 'errors': [],
  760. 'checker': checker_results.get(e.name, {}).get('errors', {}).keys(),
  761. }
  762. # keep the order of the list checker_results[e.name]['errors'] and deduplicate.
  763. # the first element has the highest percentage rate.
  764. reliabilities_errors = []
  765. for error in errors:
  766. error_user_text = None
  767. if error.get('secondary') or 'exception_classname' not in error:
  768. continue
  769. error_user_text = exception_classname_to_text.get(error.get('exception_classname'))
  770. if not error:
  771. error_user_text = exception_classname_to_text[None]
  772. if error_user_text not in reliabilities_errors:
  773. reliabilities_errors.append(error_user_text)
  774. reliabilities[e.name]['errors'] = reliabilities_errors
  775. # supports
  776. supports = {}
  777. for _, e in filtered_engines.items():
  778. supports_selected_language = e.traits.is_locale_supported(
  779. str(sxng_request.preferences.get_value('language') or 'all')
  780. )
  781. safesearch = e.safesearch
  782. time_range_support = e.time_range_support
  783. for checker_test_name in checker_results.get(e.name, {}).get('errors', {}):
  784. if supports_selected_language and checker_test_name.startswith('lang_'):
  785. supports_selected_language = '?'
  786. elif safesearch and checker_test_name == 'safesearch':
  787. safesearch = '?'
  788. elif time_range_support and checker_test_name == 'time_range':
  789. time_range_support = '?'
  790. supports[e.name] = {
  791. 'supports_selected_language': supports_selected_language,
  792. 'safesearch': safesearch,
  793. 'time_range_support': time_range_support,
  794. }
  795. return render(
  796. # fmt: off
  797. 'preferences.html',
  798. preferences = True,
  799. selected_categories = get_selected_categories(sxng_request.preferences, sxng_request.form),
  800. locales = LOCALE_NAMES,
  801. current_locale = sxng_request.preferences.get_value("locale"),
  802. image_proxy = image_proxy,
  803. engines_by_category = engines_by_category,
  804. stats = stats,
  805. max_rate95 = max_rate95,
  806. reliabilities = reliabilities,
  807. supports = supports,
  808. answer_storage = searx.answerers.STORAGE.info,
  809. disabled_engines = disabled_engines,
  810. autocomplete_backends = autocomplete_backends,
  811. favicon_resolver_names = favicons.proxy.CFG.resolver_map.keys(),
  812. shortcuts = {y: x for x, y in engine_shortcuts.items()},
  813. themes = themes,
  814. plugins_storage = searx.plugins.STORAGE.info,
  815. current_doi_resolver = get_doi_resolver(),
  816. allowed_plugins = allowed_plugins,
  817. preferences_url_params = sxng_request.preferences.get_as_url_params(),
  818. locked_preferences = get_setting("preferences.lock", []),
  819. doi_resolvers = get_setting("doi_resolvers", {}),
  820. # fmt: on
  821. )
  822. app.add_url_rule('/favicon_proxy', methods=['GET'], endpoint="favicon_proxy", view_func=favicons.favicon_proxy)
  823. @app.route('/image_proxy', methods=['GET'])
  824. def image_proxy():
  825. # pylint: disable=too-many-return-statements, too-many-branches
  826. url = sxng_request.args.get('url')
  827. if not url:
  828. return '', 400
  829. if not is_hmac_of(settings['server']['secret_key'], url.encode(), sxng_request.args.get('h', '')):
  830. return '', 400
  831. maximum_size = 5 * 1024 * 1024
  832. forward_resp = False
  833. resp = None
  834. try:
  835. request_headers = {
  836. 'User-Agent': gen_useragent(),
  837. 'Accept': 'image/webp,*/*',
  838. 'Accept-Encoding': 'gzip, deflate',
  839. 'Sec-GPC': '1',
  840. 'DNT': '1',
  841. }
  842. set_context_network_name('image_proxy')
  843. resp, stream = http_stream(method='GET', url=url, headers=request_headers, allow_redirects=True)
  844. content_length = resp.headers.get('Content-Length')
  845. if content_length and content_length.isdigit() and int(content_length) > maximum_size:
  846. return 'Max size', 400
  847. if resp.status_code != 200:
  848. logger.debug('image-proxy: wrong response code: %i', resp.status_code)
  849. if resp.status_code >= 400:
  850. return '', resp.status_code
  851. return '', 400
  852. if not resp.headers.get('Content-Type', '').startswith('image/') and not resp.headers.get(
  853. 'Content-Type', ''
  854. ).startswith('binary/octet-stream'):
  855. logger.debug('image-proxy: wrong content-type: %s', resp.headers.get('Content-Type', ''))
  856. return '', 400
  857. forward_resp = True
  858. except httpx.HTTPError:
  859. logger.exception('HTTP error')
  860. return '', 400
  861. finally:
  862. if resp and not forward_resp:
  863. # the code is about to return an HTTP 400 error to the browser
  864. # we make sure to close the response between searxng and the HTTP server
  865. try:
  866. resp.close()
  867. except httpx.HTTPError:
  868. logger.exception('HTTP error on closing')
  869. def close_stream():
  870. nonlocal resp, stream
  871. try:
  872. if resp:
  873. resp.close()
  874. del resp
  875. del stream
  876. except httpx.HTTPError as e:
  877. logger.debug('Exception while closing response', e)
  878. try:
  879. headers = dict_subset(resp.headers, {'Content-Type', 'Content-Encoding', 'Content-Length', 'Length'})
  880. response = Response(stream, mimetype=resp.headers['Content-Type'], headers=headers, direct_passthrough=True)
  881. response.call_on_close(close_stream)
  882. return response
  883. except httpx.HTTPError:
  884. close_stream()
  885. return '', 400
  886. @app.route('/engine_descriptions.json', methods=['GET'])
  887. def engine_descriptions():
  888. locale = get_locale().split('_')[0]
  889. result = ENGINE_DESCRIPTIONS['en'].copy()
  890. if locale != 'en':
  891. for engine, description in ENGINE_DESCRIPTIONS.get(locale, {}).items():
  892. result[engine] = description
  893. for engine, description in result.items():
  894. if len(description) == 2 and description[1] == 'ref':
  895. ref_engine, ref_lang = description[0].split(':')
  896. description = ENGINE_DESCRIPTIONS[ref_lang][ref_engine]
  897. if isinstance(description, str):
  898. description = [description, 'wikipedia']
  899. result[engine] = description
  900. # overwrite by about:description (from settings)
  901. for engine_name, engine_mod in engines.items():
  902. descr = getattr(engine_mod, 'about', {}).get('description', None)
  903. if descr is not None:
  904. result[engine_name] = [descr, "SearXNG config"]
  905. return jsonify(result)
  906. @app.route('/stats', methods=['GET'])
  907. def stats():
  908. """Render engine statistics page."""
  909. sort_order = sxng_request.args.get('sort', default='name', type=str)
  910. selected_engine_name = sxng_request.args.get('engine', default=None, type=str)
  911. filtered_engines = dict(filter(lambda kv: sxng_request.preferences.validate_token(kv[1]), engines.items()))
  912. if selected_engine_name:
  913. if selected_engine_name not in filtered_engines:
  914. selected_engine_name = None
  915. else:
  916. filtered_engines = [selected_engine_name]
  917. checker_results = checker_get_result()
  918. checker_results = (
  919. checker_results['engines'] if checker_results['status'] == 'ok' and 'engines' in checker_results else {}
  920. )
  921. engine_stats = get_engines_stats(filtered_engines)
  922. engine_reliabilities = get_reliabilities(filtered_engines, checker_results)
  923. if sort_order not in STATS_SORT_PARAMETERS:
  924. sort_order = 'name'
  925. reverse, key_name, default_value = STATS_SORT_PARAMETERS[sort_order]
  926. def get_key(engine_stat):
  927. reliability = engine_reliabilities.get(engine_stat['name'], {}).get('reliability', 0)
  928. reliability_order = 0 if reliability else 1
  929. if key_name == 'reliability':
  930. key = reliability
  931. reliability_order = 0
  932. else:
  933. key = engine_stat.get(key_name) or default_value
  934. if reverse:
  935. reliability_order = 1 - reliability_order
  936. return (reliability_order, key, engine_stat['name'])
  937. technical_report = []
  938. for error in engine_reliabilities.get(selected_engine_name, {}).get('errors', []):
  939. technical_report.append(
  940. f"\
  941. Error: {error['exception_classname'] or error['log_message']} \
  942. Parameters: {error['log_parameters']} \
  943. File name: {error['filename'] }:{ error['line_no'] } \
  944. Error Function: {error['function']} \
  945. Code: {error['code']} \
  946. ".replace(
  947. ' ' * 12, ''
  948. ).strip()
  949. )
  950. technical_report = ' '.join(technical_report)
  951. engine_stats['time'] = sorted(engine_stats['time'], reverse=reverse, key=get_key)
  952. return render(
  953. # fmt: off
  954. 'stats.html',
  955. sort_order = sort_order,
  956. engine_stats = engine_stats,
  957. engine_reliabilities = engine_reliabilities,
  958. selected_engine_name = selected_engine_name,
  959. searx_git_branch = GIT_BRANCH,
  960. technical_report = technical_report,
  961. # fmt: on
  962. )
  963. @app.route('/stats/errors', methods=['GET'])
  964. def stats_errors():
  965. filtered_engines = dict(filter(lambda kv: sxng_request.preferences.validate_token(kv[1]), engines.items()))
  966. result = get_engine_errors(filtered_engines)
  967. return jsonify(result)
  968. @app.route('/stats/checker', methods=['GET'])
  969. def stats_checker():
  970. result = checker_get_result()
  971. return jsonify(result)
  972. @app.route('/metrics')
  973. def stats_open_metrics():
  974. password = settings['general'].get("open_metrics")
  975. if not (settings['general'].get("enable_metrics") and password):
  976. return Response('open metrics is disabled', status=404, mimetype='text/plain')
  977. if not sxng_request.authorization or sxng_request.authorization.password != password:
  978. return Response('access forbidden', status=401, mimetype='text/plain')
  979. filtered_engines = dict(filter(lambda kv: sxng_request.preferences.validate_token(kv[1]), engines.items()))
  980. checker_results = checker_get_result()
  981. checker_results = (
  982. checker_results['engines'] if checker_results['status'] == 'ok' and 'engines' in checker_results else {}
  983. )
  984. engine_stats = get_engines_stats(filtered_engines)
  985. engine_reliabilities = get_reliabilities(filtered_engines, checker_results)
  986. metrics_text = openmetrics(engine_stats, engine_reliabilities)
  987. return Response(metrics_text, mimetype='text/plain')
  988. @app.route('/robots.txt', methods=['GET'])
  989. def robots():
  990. return Response(
  991. """User-agent: *
  992. Allow: /info/en/about
  993. Disallow: /stats
  994. Disallow: /image_proxy
  995. Disallow: /preferences
  996. Disallow: /*?*q=*
  997. """,
  998. mimetype='text/plain',
  999. )
  1000. @app.route('/opensearch.xml', methods=['GET'])
  1001. def opensearch():
  1002. method = sxng_request.preferences.get_value('method')
  1003. autocomplete = sxng_request.preferences.get_value('autocomplete')
  1004. # chrome/chromium only supports HTTP GET....
  1005. if sxng_request.headers.get('User-Agent', '').lower().find('webkit') >= 0:
  1006. method = 'GET'
  1007. if method not in ('POST', 'GET'):
  1008. method = 'POST'
  1009. ret = render('opensearch.xml', opensearch_method=method, autocomplete=autocomplete)
  1010. resp = Response(response=ret, status=200, mimetype="application/opensearchdescription+xml")
  1011. return resp
  1012. @app.route('/favicon.ico')
  1013. def favicon():
  1014. theme = sxng_request.preferences.get_value("theme")
  1015. return send_from_directory(
  1016. os.path.join(app.root_path, settings['ui']['static_path'], 'themes', theme, 'img'), # type: ignore
  1017. 'favicon.png',
  1018. mimetype='image/vnd.microsoft.icon',
  1019. )
  1020. @app.route('/clear_cookies')
  1021. def clear_cookies():
  1022. resp = make_response(redirect(url_for('index', _external=True)))
  1023. for cookie_name in sxng_request.cookies:
  1024. resp.delete_cookie(cookie_name)
  1025. return resp
  1026. @app.route('/config')
  1027. def config():
  1028. """Return configuration in JSON format."""
  1029. _engines = []
  1030. for name, engine in engines.items():
  1031. if not sxng_request.preferences.validate_token(engine):
  1032. continue
  1033. _languages = engine.traits.languages.keys()
  1034. _engines.append(
  1035. {
  1036. 'name': name,
  1037. 'categories': engine.categories,
  1038. 'shortcut': engine.shortcut,
  1039. 'enabled': not engine.disabled,
  1040. 'paging': engine.paging,
  1041. 'language_support': engine.language_support,
  1042. 'languages': list(_languages),
  1043. 'regions': list(engine.traits.regions.keys()),
  1044. 'safesearch': engine.safesearch,
  1045. 'time_range_support': engine.time_range_support,
  1046. 'timeout': engine.timeout,
  1047. }
  1048. )
  1049. _plugins = []
  1050. for _ in searx.plugins.STORAGE:
  1051. _plugins.append({'name': _.id, 'enabled': _.active})
  1052. _limiter_cfg = limiter.get_cfg()
  1053. return jsonify(
  1054. {
  1055. 'categories': list(categories.keys()),
  1056. 'engines': _engines,
  1057. 'plugins': _plugins,
  1058. 'instance_name': settings['general']['instance_name'],
  1059. 'locales': LOCALE_NAMES,
  1060. 'default_locale': settings['ui']['default_locale'],
  1061. 'autocomplete': settings['search']['autocomplete'],
  1062. 'safe_search': settings['search']['safe_search'],
  1063. 'default_theme': settings['ui']['default_theme'],
  1064. 'version': VERSION_STRING,
  1065. 'brand': {
  1066. 'PRIVACYPOLICY_URL': get_setting('general.privacypolicy_url'),
  1067. 'CONTACT_URL': get_setting('general.contact_url'),
  1068. 'GIT_URL': GIT_URL,
  1069. 'GIT_BRANCH': GIT_BRANCH,
  1070. 'DOCS_URL': get_setting('brand.docs_url'),
  1071. },
  1072. 'limiter': {
  1073. 'enabled': limiter.is_installed(),
  1074. 'botdetection.ip_limit.link_token': _limiter_cfg.get('botdetection.ip_limit.link_token'),
  1075. 'botdetection.ip_lists.pass_searxng_org': _limiter_cfg.get('botdetection.ip_lists.pass_searxng_org'),
  1076. },
  1077. 'doi_resolvers': list(settings['doi_resolvers'].keys()),
  1078. 'default_doi_resolver': settings['default_doi_resolver'],
  1079. 'public_instance': settings['server']['public_instance'],
  1080. }
  1081. )
  1082. @app.errorhandler(404)
  1083. def page_not_found(_e):
  1084. return render('404.html'), 404
  1085. def run():
  1086. """Runs the application on a local development server.
  1087. This run method is only called when SearXNG is started via ``__main__``::
  1088. python -m searx.webapp
  1089. Do not use :ref:`run() <flask.Flask.run>` in a production setting. It is
  1090. not intended to meet security and performance requirements for a production
  1091. server.
  1092. It is not recommended to use this function for development with automatic
  1093. reloading as this is badly supported. Instead you should be using the flask
  1094. command line script’s run support::
  1095. flask --app searx.webapp run --debug --reload --host 127.0.0.1 --port 8888
  1096. .. _Flask.run: https://flask.palletsprojects.com/en/stable/api/#flask.Flask.run
  1097. """
  1098. host: str = get_setting("server.bind_address") # type: ignore
  1099. port: int = get_setting("server.port") # type: ignore
  1100. if searx.sxng_debug:
  1101. logger.debug("run local development server (DEBUG) on %s:%s", host, port)
  1102. app.run(
  1103. debug=True,
  1104. port=port,
  1105. host=host,
  1106. threaded=True,
  1107. extra_files=[DEFAULT_SETTINGS_FILE],
  1108. )
  1109. else:
  1110. logger.debug("run local development server on %s:%s", host, port)
  1111. app.run(port=port, host=host, threaded=True)
  1112. def is_werkzeug_reload_active() -> bool:
  1113. """Returns ``True`` if server is is launched by :ref:`werkzeug.serving` and
  1114. the ``use_reload`` argument was set to ``True``. If this is the case, it
  1115. should be avoided that the server is initialized twice (:py:obj:`init`,
  1116. :py:obj:`run`).
  1117. .. _werkzeug.serving:
  1118. https://werkzeug.palletsprojects.com/en/stable/serving/#werkzeug.serving.run_simple
  1119. """
  1120. if "uwsgi" in sys.argv:
  1121. # server was launched by uWSGI
  1122. return False
  1123. # https://github.com/searxng/searxng/pull/1656#issuecomment-1214198941
  1124. # https://github.com/searxng/searxng/pull/1616#issuecomment-1206137468
  1125. frames = inspect.stack()
  1126. if len(frames) > 1 and frames[-2].filename.endswith('flask/cli.py'):
  1127. # server was launched by "flask run", is argument "--reload" set?
  1128. if "--reload" in sys.argv or "--debug" in sys.argv:
  1129. return True
  1130. elif frames[0].filename.endswith('searx/webapp.py'):
  1131. # server was launched by "python -m searx.webapp" / see run()
  1132. if searx.sxng_debug:
  1133. return True
  1134. return False
  1135. def init():
  1136. if searx.sxng_debug or app.debug:
  1137. app.debug = True
  1138. searx.sxng_debug = True
  1139. # check secret_key in production
  1140. if not app.debug and get_setting("server.secret_key") == 'ultrasecretkey':
  1141. logger.error("server.secret_key is not changed. Please use something else instead of ultrasecretkey.")
  1142. sys.exit(1)
  1143. # When automatic reloading is activated stop Flask from initialising twice.
  1144. # - https://github.com/pallets/flask/issues/5307#issuecomment-1774646119
  1145. # - https://stackoverflow.com/a/25504196
  1146. reloader_active = is_werkzeug_reload_active()
  1147. werkzeug_run_main = is_running_from_reloader()
  1148. if reloader_active and not werkzeug_run_main:
  1149. logger.info("in reloading mode and not in main loop, cancel the initialization")
  1150. return
  1151. locales_initialize()
  1152. redis_initialize()
  1153. searx.plugins.initialize(app)
  1154. metrics: bool = get_setting("general.enable_metrics") # type: ignore
  1155. searx.search.initialize(enable_checker=True, check_network=True, enable_metrics=metrics)
  1156. limiter.initialize(app, settings)
  1157. favicons.init()
  1158. application = app
  1159. patch_application(app)
  1160. init()
  1161. if __name__ == "__main__":
  1162. run()