webapp.py 51 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432
  1. #!/usr/bin/env python
  2. # SPDX-License-Identifier: AGPL-3.0-or-later
  3. """WebbApp
  4. """
  5. # pylint: disable=use-dict-literal
  6. from __future__ import annotations
  7. import inspect
  8. import json
  9. import os
  10. import sys
  11. import base64
  12. from timeit import default_timer
  13. from html import escape
  14. from io import StringIO
  15. import typing
  16. import urllib
  17. import urllib.parse
  18. from urllib.parse import urlencode, urlparse, unquote
  19. import warnings
  20. import httpx
  21. from pygments import highlight
  22. from pygments.lexers import get_lexer_by_name
  23. from pygments.formatters import HtmlFormatter # pylint: disable=no-name-in-module
  24. from werkzeug.serving import is_running_from_reloader
  25. import flask
  26. from flask import (
  27. Flask,
  28. render_template,
  29. url_for,
  30. make_response,
  31. redirect,
  32. send_from_directory,
  33. )
  34. from flask.wrappers import Response
  35. from flask.json import jsonify
  36. from flask_babel import (
  37. Babel,
  38. gettext,
  39. format_decimal,
  40. )
  41. import searx
  42. from searx.extended_types import sxng_request
  43. from searx import (
  44. logger,
  45. get_setting,
  46. settings,
  47. )
  48. from searx import infopage
  49. from searx import limiter
  50. from searx.botdetection import link_token
  51. from searx.data import ENGINE_DESCRIPTIONS
  52. from searx.result_types import Answer
  53. from searx.settings_defaults import OUTPUT_FORMATS
  54. from searx.settings_loader import DEFAULT_SETTINGS_FILE
  55. from searx.exceptions import SearxParameterException
  56. from searx.engines import (
  57. DEFAULT_CATEGORY,
  58. categories,
  59. engines,
  60. engine_shortcuts,
  61. )
  62. from searx import webutils
  63. from searx.webutils import (
  64. highlight_content,
  65. get_result_templates,
  66. get_themes,
  67. exception_classname_to_text,
  68. new_hmac,
  69. is_hmac_of,
  70. group_engines_in_tab,
  71. )
  72. from searx.webadapter import (
  73. get_search_query_from_webapp,
  74. get_selected_categories,
  75. parse_lang,
  76. )
  77. from searx.utils import gen_useragent, dict_subset
  78. from searx.version import VERSION_STRING, GIT_URL, GIT_BRANCH
  79. from searx.query import RawTextQuery
  80. from searx.plugins.oa_doi_rewrite import get_doi_resolver
  81. from searx.preferences import (
  82. Preferences,
  83. ClientPref,
  84. ValidationException,
  85. )
  86. import searx.answerers
  87. import searx.plugins
  88. from searx.metrics import get_engines_stats, get_engine_errors, get_reliabilities, histogram, counter, openmetrics
  89. from searx.flaskfix import patch_application
  90. from searx.locales import (
  91. LOCALE_BEST_MATCH,
  92. LOCALE_NAMES,
  93. RTL_LOCALES,
  94. localeselector,
  95. locales_initialize,
  96. match_locale,
  97. )
  98. # renaming names from searx imports ...
  99. from searx.autocomplete import search_autocomplete, backends as autocomplete_backends
  100. from searx import favicons
  101. from searx.valkeydb import initialize as valkey_initialize
  102. from searx.sxng_locales import sxng_locales
  103. import searx.search
  104. from searx.network import stream as http_stream, set_context_network_name
  105. from searx.search.checker import get_result as checker_get_result
  106. logger = logger.getChild('webapp')
  107. warnings.simplefilter("always")
  108. # about static
  109. logger.debug('static directory is %s', settings['ui']['static_path'])
  110. # about templates
  111. logger.debug('templates directory is %s', settings['ui']['templates_path'])
  112. default_theme = settings['ui']['default_theme']
  113. templates_path = settings['ui']['templates_path']
  114. themes = get_themes(templates_path)
  115. result_templates = get_result_templates(templates_path)
  116. STATS_SORT_PARAMETERS = {
  117. 'name': (False, 'name', ''),
  118. 'score': (True, 'score_per_result', 0),
  119. 'result_count': (True, 'result_count', 0),
  120. 'time': (False, 'total', 0),
  121. 'reliability': (False, 'reliability', 100),
  122. }
  123. # Flask app
  124. app = Flask(__name__, static_folder=settings['ui']['static_path'], template_folder=templates_path)
  125. app.jinja_env.trim_blocks = True
  126. app.jinja_env.lstrip_blocks = True
  127. app.jinja_env.add_extension('jinja2.ext.loopcontrols') # pylint: disable=no-member
  128. app.jinja_env.filters['group_engines_in_tab'] = group_engines_in_tab # pylint: disable=no-member
  129. app.secret_key = settings['server']['secret_key']
  130. def get_locale():
  131. locale = localeselector()
  132. logger.debug("%s uses locale `%s`", urllib.parse.quote(sxng_request.url), locale)
  133. return locale
  134. babel = Babel(app, locale_selector=get_locale)
  135. def _get_browser_language(req, lang_list):
  136. client = ClientPref.from_http_request(req)
  137. locale = match_locale(client.locale_tag, lang_list, fallback='en')
  138. return locale
  139. def _get_locale_rfc5646(locale):
  140. """Get locale name for <html lang="...">
  141. Chrom* browsers don't detect the language when there is a subtag (ie a territory).
  142. For example "zh-TW" is detected but not "zh-Hant-TW".
  143. This function returns a locale without the subtag.
  144. """
  145. parts = locale.split('-')
  146. return parts[0].lower() + '-' + parts[-1].upper()
  147. # code-highlighter
  148. @app.template_filter('code_highlighter')
  149. def code_highlighter(codelines, language=None):
  150. if not language:
  151. language = 'text'
  152. try:
  153. # find lexer by programming language
  154. lexer = get_lexer_by_name(language, stripall=True)
  155. except Exception as e: # pylint: disable=broad-except
  156. logger.warning("pygments lexer: %s " % e)
  157. # if lexer is not found, using default one
  158. lexer = get_lexer_by_name('text', stripall=True)
  159. html_code = ''
  160. tmp_code = ''
  161. last_line = None
  162. line_code_start = None
  163. # parse lines
  164. for line, code in codelines:
  165. if not last_line:
  166. line_code_start = line
  167. # new codeblock is detected
  168. if last_line is not None and last_line + 1 != line:
  169. # highlight last codepart
  170. formatter = HtmlFormatter(linenos='inline', linenostart=line_code_start, cssclass="code-highlight")
  171. html_code = html_code + highlight(tmp_code, lexer, formatter)
  172. # reset conditions for next codepart
  173. tmp_code = ''
  174. line_code_start = line
  175. # add codepart
  176. tmp_code += code + '\n'
  177. # update line
  178. last_line = line
  179. # highlight last codepart
  180. formatter = HtmlFormatter(linenos='inline', linenostart=line_code_start, cssclass="code-highlight")
  181. html_code = html_code + highlight(tmp_code, lexer, formatter)
  182. return html_code
  183. def get_result_template(theme_name: str, template_name: str):
  184. themed_path = theme_name + '/result_templates/' + template_name
  185. if themed_path in result_templates:
  186. return themed_path
  187. return 'result_templates/' + template_name
  188. _STATIC_FILES: list[str] = []
  189. def custom_url_for(endpoint: str, **values):
  190. global _STATIC_FILES # pylint: disable=global-statement
  191. if not _STATIC_FILES:
  192. _STATIC_FILES = webutils.get_static_file_list()
  193. if endpoint == "static" and values.get("filename"):
  194. # We need to verify the "filename" argument: in the jinja templates
  195. # there could be call like:
  196. # url_for('static', filename='img/favicon.png')
  197. # which should map to:
  198. # static/themes/<theme_name>/img/favicon.png
  199. arg_filename = values["filename"]
  200. if arg_filename not in _STATIC_FILES:
  201. # try file in the current theme
  202. theme_name = sxng_request.preferences.get_value("theme")
  203. arg_filename = f"themes/{theme_name}/{arg_filename}"
  204. if arg_filename in _STATIC_FILES:
  205. values["filename"] = arg_filename
  206. if endpoint == "info" and "locale" not in values:
  207. # We need to verify the "locale" argument: in the jinja templates there
  208. # could be call like:
  209. # url_for('info', pagename='about')
  210. # which should map to:
  211. # info/<locale>/about
  212. locale = sxng_request.preferences.get_value("locale")
  213. if infopage.INFO_PAGES.get_page(values["pagename"], locale) is None:
  214. locale = infopage.INFO_PAGES.locale_default
  215. values["locale"] = locale
  216. return url_for(endpoint, **values)
  217. def image_proxify(url: str):
  218. if not url:
  219. return url
  220. if url.startswith('//'):
  221. url = 'https:' + url
  222. if not sxng_request.preferences.get_value('image_proxy'):
  223. return url
  224. if url.startswith('data:image/'):
  225. # 50 is an arbitrary number to get only the beginning of the image.
  226. partial_base64 = url[len('data:image/') : 50].split(';')
  227. if (
  228. len(partial_base64) == 2
  229. and partial_base64[0] in ['gif', 'png', 'jpeg', 'pjpeg', 'webp', 'tiff', 'bmp']
  230. and partial_base64[1].startswith('base64,')
  231. ):
  232. return url
  233. return None
  234. h = new_hmac(settings['server']['secret_key'], url.encode())
  235. return '{0}?{1}'.format(url_for('image_proxy'), urlencode(dict(url=url.encode(), h=h)))
  236. def get_translations():
  237. return {
  238. # when there is autocompletion
  239. 'no_item_found': gettext('No item found'),
  240. # /preferences: the source of the engine description (wikipedata, wikidata, website)
  241. 'Source': gettext('Source'),
  242. # infinite scroll
  243. 'error_loading_next_page': gettext('Error loading the next page'),
  244. }
  245. def get_enabled_categories(category_names: typing.Iterable[str]):
  246. """The categories in ``category_names```for which there is no active engine
  247. are filtered out and a reduced list is returned."""
  248. enabled_engines = [item[0] for item in sxng_request.preferences.engines.get_enabled()]
  249. enabled_categories = set()
  250. for engine_name in enabled_engines:
  251. enabled_categories.update(engines[engine_name].categories)
  252. return [x for x in category_names if x in enabled_categories]
  253. def get_pretty_url(parsed_url: urllib.parse.ParseResult):
  254. url_formatting_pref = sxng_request.preferences.get_value('url_formatting')
  255. if url_formatting_pref == 'full':
  256. return [parsed_url.geturl()]
  257. if url_formatting_pref == 'host':
  258. return [parsed_url.netloc]
  259. path = parsed_url.path
  260. path = path[:-1] if len(path) > 0 and path[-1] == '/' else path
  261. path = unquote(path.replace("/", " › "))
  262. return [parsed_url.scheme + "://" + parsed_url.netloc, path]
  263. def get_client_settings():
  264. req_pref = sxng_request.preferences
  265. return {
  266. 'autocomplete': req_pref.get_value('autocomplete'),
  267. 'autocomplete_min': get_setting('search.autocomplete_min'),
  268. 'method': req_pref.get_value('method'),
  269. 'infinite_scroll': req_pref.get_value('infinite_scroll'),
  270. 'translations': get_translations(),
  271. 'search_on_category_select': req_pref.get_value('search_on_category_select'),
  272. 'hotkeys': req_pref.get_value('hotkeys'),
  273. 'url_formatting': req_pref.get_value('url_formatting'),
  274. 'theme_static_path': custom_url_for('static', filename='themes/simple'),
  275. 'results_on_new_tab': req_pref.get_value('results_on_new_tab'),
  276. 'favicon_resolver': req_pref.get_value('favicon_resolver'),
  277. 'advanced_search': req_pref.get_value('advanced_search'),
  278. 'query_in_title': req_pref.get_value('query_in_title'),
  279. 'safesearch': str(req_pref.get_value('safesearch')),
  280. 'theme': req_pref.get_value('theme'),
  281. 'doi_resolver': get_doi_resolver(),
  282. }
  283. def render(template_name: str, **kwargs):
  284. # values from the preferences
  285. # pylint: disable=too-many-statements
  286. client_settings = get_client_settings()
  287. kwargs['client_settings'] = str(
  288. base64.b64encode(
  289. bytes(
  290. json.dumps(client_settings),
  291. encoding='utf-8',
  292. )
  293. ),
  294. encoding='utf-8',
  295. )
  296. kwargs['preferences'] = sxng_request.preferences
  297. kwargs.update(client_settings)
  298. # values from the HTTP requests
  299. kwargs['endpoint'] = 'results' if 'q' in kwargs else sxng_request.endpoint
  300. kwargs['cookies'] = sxng_request.cookies
  301. kwargs['errors'] = sxng_request.errors
  302. kwargs['link_token'] = link_token.get_token()
  303. kwargs['categories_as_tabs'] = list(settings['categories_as_tabs'].keys())
  304. kwargs['categories'] = get_enabled_categories(settings['categories_as_tabs'].keys())
  305. kwargs['DEFAULT_CATEGORY'] = DEFAULT_CATEGORY
  306. # i18n
  307. kwargs['sxng_locales'] = [l for l in sxng_locales if l[0] in settings['search']['languages']]
  308. locale = sxng_request.preferences.get_value('locale')
  309. kwargs['locale_rfc5646'] = _get_locale_rfc5646(locale)
  310. if locale in RTL_LOCALES and 'rtl' not in kwargs:
  311. kwargs['rtl'] = True
  312. if 'current_language' not in kwargs:
  313. kwargs['current_language'] = parse_lang(sxng_request.preferences, {}, RawTextQuery('', []))
  314. # values from settings
  315. kwargs['search_formats'] = [x for x in settings['search']['formats'] if x != 'html']
  316. kwargs['instance_name'] = get_setting('general.instance_name')
  317. kwargs['searx_version'] = VERSION_STRING
  318. kwargs['searx_git_url'] = GIT_URL
  319. kwargs['enable_metrics'] = get_setting('general.enable_metrics')
  320. kwargs['get_setting'] = get_setting
  321. kwargs['get_pretty_url'] = get_pretty_url
  322. # values from settings: donation_url
  323. donation_url = get_setting('general.donation_url')
  324. if donation_url is True:
  325. donation_url = custom_url_for('info', pagename='donate')
  326. kwargs['donation_url'] = donation_url
  327. # helpers to create links to other pages
  328. kwargs['url_for'] = custom_url_for # override url_for function in templates
  329. kwargs['image_proxify'] = image_proxify
  330. kwargs['favicon_url'] = favicons.favicon_url
  331. kwargs['cache_url'] = settings['ui']['cache_url']
  332. kwargs['get_result_template'] = get_result_template
  333. kwargs['opensearch_url'] = (
  334. url_for('opensearch')
  335. + '?'
  336. + urlencode(
  337. {
  338. 'method': sxng_request.preferences.get_value('method'),
  339. 'autocomplete': sxng_request.preferences.get_value('autocomplete'),
  340. }
  341. )
  342. )
  343. kwargs['urlparse'] = urlparse
  344. start_time = default_timer()
  345. result = render_template('{}/{}'.format(kwargs['theme'], template_name), **kwargs)
  346. sxng_request.render_time += default_timer() - start_time # pylint: disable=assigning-non-slot
  347. return result
  348. @app.before_request
  349. def pre_request():
  350. sxng_request.start_time = default_timer() # pylint: disable=assigning-non-slot
  351. sxng_request.render_time = 0 # pylint: disable=assigning-non-slot
  352. sxng_request.timings = [] # pylint: disable=assigning-non-slot
  353. sxng_request.errors = [] # pylint: disable=assigning-non-slot
  354. client_pref = ClientPref.from_http_request(sxng_request)
  355. # pylint: disable=redefined-outer-name
  356. preferences = Preferences(themes, list(categories.keys()), engines, searx.plugins.STORAGE, client_pref)
  357. user_agent = sxng_request.headers.get('User-Agent', '').lower()
  358. if 'webkit' in user_agent and 'android' in user_agent:
  359. preferences.key_value_settings['method'].value = 'GET'
  360. sxng_request.preferences = preferences # pylint: disable=assigning-non-slot
  361. try:
  362. preferences.parse_dict(sxng_request.cookies)
  363. except Exception as e: # pylint: disable=broad-except
  364. logger.exception(e, exc_info=True)
  365. sxng_request.errors.append(gettext('Invalid settings, please edit your preferences'))
  366. # merge GET, POST vars
  367. # HINT request.form is of type werkzeug.datastructures.ImmutableMultiDict
  368. sxng_request.form = dict(sxng_request.form.items()) # type: ignore
  369. for k, v in sxng_request.args.items():
  370. if k not in sxng_request.form:
  371. sxng_request.form[k] = v
  372. if sxng_request.form.get('preferences'):
  373. preferences.parse_encoded_data(sxng_request.form['preferences'])
  374. else:
  375. try:
  376. preferences.parse_dict(sxng_request.form)
  377. except Exception as e: # pylint: disable=broad-except
  378. logger.exception(e, exc_info=True)
  379. sxng_request.errors.append(gettext('Invalid settings'))
  380. # language is defined neither in settings nor in preferences
  381. # use browser headers
  382. if not preferences.get_value("language"):
  383. language = _get_browser_language(sxng_request, settings['search']['languages'])
  384. preferences.parse_dict({"language": language})
  385. logger.debug('set language %s (from browser)', preferences.get_value("language"))
  386. # UI locale is defined neither in settings nor in preferences
  387. # use browser headers
  388. if not preferences.get_value("locale"):
  389. locale = _get_browser_language(sxng_request, LOCALE_NAMES.keys())
  390. preferences.parse_dict({"locale": locale})
  391. logger.debug('set locale %s (from browser)', preferences.get_value("locale"))
  392. # request.user_plugins
  393. sxng_request.user_plugins = [] # pylint: disable=assigning-non-slot
  394. allowed_plugins = preferences.plugins.get_enabled()
  395. disabled_plugins = preferences.plugins.get_disabled()
  396. for plugin in searx.plugins.STORAGE:
  397. if (plugin.id not in disabled_plugins) or plugin.id in allowed_plugins:
  398. sxng_request.user_plugins.append(plugin.id)
  399. @app.after_request
  400. def add_default_headers(response: flask.Response):
  401. # set default http headers
  402. for header, value in settings['server']['default_http_headers'].items():
  403. if header in response.headers:
  404. continue
  405. response.headers[header] = value
  406. return response
  407. @app.after_request
  408. def post_request(response: flask.Response):
  409. total_time = default_timer() - sxng_request.start_time
  410. timings_all = [
  411. 'total;dur=' + str(round(total_time * 1000, 3)),
  412. 'render;dur=' + str(round(sxng_request.render_time * 1000, 3)),
  413. ]
  414. if len(sxng_request.timings) > 0:
  415. timings = sorted(sxng_request.timings, key=lambda t: t.total)
  416. timings_total = [
  417. 'total_' + str(i) + '_' + t.engine + ';dur=' + str(round(t.total * 1000, 3)) for i, t in enumerate(timings)
  418. ]
  419. timings_load = [
  420. 'load_' + str(i) + '_' + t.engine + ';dur=' + str(round(t.load * 1000, 3))
  421. for i, t in enumerate(timings)
  422. if t.load
  423. ]
  424. timings_all = timings_all + timings_total + timings_load
  425. response.headers.add('Server-Timing', ', '.join(timings_all))
  426. return response
  427. def index_error(output_format: str, error_message: str):
  428. if output_format == 'json':
  429. return Response(json.dumps({'error': error_message}), mimetype='application/json')
  430. if output_format == 'csv':
  431. response = Response('', mimetype='application/csv')
  432. cont_disp = 'attachment;Filename=searx.csv'
  433. response.headers.add('Content-Disposition', cont_disp)
  434. return response
  435. if output_format == 'rss':
  436. response_rss = render(
  437. 'opensearch_response_rss.xml',
  438. results=[],
  439. q=sxng_request.form['q'] if 'q' in sxng_request.form else '',
  440. number_of_results=0,
  441. error_message=error_message,
  442. )
  443. return Response(response_rss, mimetype='text/xml')
  444. # html
  445. sxng_request.errors.append(gettext('search error'))
  446. return render(
  447. # fmt: off
  448. 'index.html',
  449. selected_categories=get_selected_categories(sxng_request.preferences, sxng_request.form),
  450. # fmt: on
  451. )
  452. @app.route('/', methods=['GET', 'POST'])
  453. def index():
  454. """Render index page."""
  455. # redirect to search if there's a query in the request
  456. if sxng_request.form.get('q'):
  457. query = ('?' + sxng_request.query_string.decode()) if sxng_request.query_string else ''
  458. return redirect(url_for('search') + query, 308)
  459. return render(
  460. # fmt: off
  461. 'index.html',
  462. selected_categories=get_selected_categories(sxng_request.preferences, sxng_request.form),
  463. current_locale = sxng_request.preferences.get_value("locale"),
  464. # fmt: on
  465. )
  466. @app.route('/healthz', methods=['GET'])
  467. def health():
  468. return Response('OK', mimetype='text/plain')
  469. @app.route('/client<token>.css', methods=['GET', 'POST'])
  470. def client_token(token=None):
  471. link_token.ping(sxng_request, token)
  472. return Response('', mimetype='text/css', headers={"Cache-Control": "no-store, max-age=0"})
  473. @app.route('/rss.xsl', methods=['GET', 'POST'])
  474. def rss_xsl():
  475. return render_template(
  476. f"{sxng_request.preferences.get_value('theme')}/rss.xsl",
  477. url_for=custom_url_for,
  478. )
  479. @app.route('/search', methods=['GET', 'POST'])
  480. def search():
  481. """Search query in q and return results.
  482. Supported outputs: html, json, csv, rss.
  483. """
  484. # pylint: disable=too-many-locals, too-many-return-statements, too-many-branches
  485. # pylint: disable=too-many-statements
  486. # output_format
  487. output_format = sxng_request.form.get('format', 'html')
  488. if output_format not in OUTPUT_FORMATS:
  489. output_format = 'html'
  490. if output_format not in settings['search']['formats']:
  491. flask.abort(403)
  492. # check if there is query (not None and not an empty string)
  493. if not sxng_request.form.get('q'):
  494. if output_format == 'html':
  495. return render(
  496. # fmt: off
  497. 'index.html',
  498. selected_categories=get_selected_categories(sxng_request.preferences, sxng_request.form),
  499. # fmt: on
  500. )
  501. return index_error(output_format, 'No query'), 400
  502. # search
  503. search_query = None
  504. raw_text_query = None
  505. result_container = None
  506. try:
  507. search_query, raw_text_query, _, _, selected_locale = get_search_query_from_webapp(
  508. sxng_request.preferences, sxng_request.form
  509. )
  510. search_obj = searx.search.SearchWithPlugins(search_query, sxng_request, sxng_request.user_plugins)
  511. result_container = search_obj.search()
  512. except SearxParameterException as e:
  513. logger.exception('search error: SearxParameterException')
  514. return index_error(output_format, e.message), 400
  515. except Exception as e: # pylint: disable=broad-except
  516. logger.exception(e, exc_info=True)
  517. return index_error(output_format, gettext('search error')), 500
  518. # 1. check if the result is a redirect for an external bang
  519. if result_container.redirect_url:
  520. return redirect(result_container.redirect_url)
  521. # 2. add Server-Timing header for measuring performance characteristics of
  522. # web applications
  523. sxng_request.timings = result_container.get_timings() # pylint: disable=assigning-non-slot
  524. # 3. formats without a template
  525. if output_format == 'json':
  526. response = webutils.get_json_response(search_query, result_container)
  527. return Response(response, mimetype='application/json')
  528. if output_format == 'csv':
  529. csv = webutils.CSVWriter(StringIO())
  530. webutils.write_csv_response(csv, result_container)
  531. csv.stream.seek(0)
  532. response = Response(csv.stream.read(), mimetype='application/csv')
  533. cont_disp = 'attachment;Filename=searx_-_{0}.csv'.format(search_query.query)
  534. response.headers.add('Content-Disposition', cont_disp)
  535. return response
  536. # 4. formats rendered by a template / RSS & HTML
  537. current_template = None
  538. previous_result = None
  539. results = result_container.get_ordered_results()
  540. if search_query.redirect_to_first_result and results:
  541. return redirect(results[0]['url'], 302)
  542. for result in results:
  543. if output_format == 'html':
  544. if 'content' in result and result['content']:
  545. result['content'] = highlight_content(escape(result['content'][:1024]), search_query.query)
  546. if 'title' in result and result['title']:
  547. result['title'] = highlight_content(escape(result['title'] or ''), search_query.query)
  548. # set result['open_group'] = True when the template changes from the previous result
  549. # set result['close_group'] = True when the template changes on the next result
  550. if current_template != result.template:
  551. result.open_group = True
  552. if previous_result:
  553. previous_result.close_group = True # pylint: disable=unsupported-assignment-operation
  554. current_template = result.template
  555. previous_result = result
  556. if previous_result:
  557. previous_result.close_group = True
  558. # 4.a RSS
  559. if output_format == 'rss':
  560. response_rss = render(
  561. 'opensearch_response_rss.xml',
  562. results=results,
  563. q=sxng_request.form['q'],
  564. number_of_results=result_container.number_of_results,
  565. )
  566. return Response(response_rss, mimetype='text/xml')
  567. # 4.b HTML
  568. # suggestions: use RawTextQuery to get the suggestion URLs with the same bang
  569. suggestion_urls = list(
  570. map(
  571. lambda suggestion: {'url': raw_text_query.changeQuery(suggestion).getFullQuery(), 'title': suggestion},
  572. result_container.suggestions,
  573. )
  574. )
  575. correction_urls = list(
  576. map(
  577. lambda correction: {'url': raw_text_query.changeQuery(correction).getFullQuery(), 'title': correction},
  578. result_container.corrections,
  579. )
  580. )
  581. # engine_timings: get engine response times sorted from slowest to fastest
  582. engine_timings = sorted(result_container.get_timings(), reverse=True, key=lambda e: e.total)
  583. max_response_time = engine_timings[0].total if engine_timings else None
  584. engine_timings_pairs = [(timing.engine, timing.total) for timing in engine_timings]
  585. # search_query.lang contains the user choice (all, auto, en, ...)
  586. # when the user choice is "auto", search.search_query.lang contains the detected language
  587. # otherwise it is equals to search_query.lang
  588. return render(
  589. # fmt: off
  590. 'results.html',
  591. results = results,
  592. q=sxng_request.form['q'],
  593. selected_categories = search_query.categories,
  594. pageno = search_query.pageno,
  595. time_range = search_query.time_range or '',
  596. number_of_results = format_decimal(result_container.number_of_results),
  597. suggestions = suggestion_urls,
  598. answers = result_container.answers,
  599. corrections = correction_urls,
  600. infoboxes = result_container.infoboxes,
  601. engine_data = result_container.engine_data,
  602. paging = result_container.paging,
  603. unresponsive_engines = webutils.get_translated_errors(
  604. result_container.unresponsive_engines
  605. ),
  606. current_locale = sxng_request.preferences.get_value("locale"),
  607. current_language = selected_locale,
  608. search_language = match_locale(
  609. search_obj.search_query.lang,
  610. settings['search']['languages'],
  611. fallback=sxng_request.preferences.get_value("language")
  612. ),
  613. timeout_limit = sxng_request.form.get('timeout_limit', None),
  614. timings = engine_timings_pairs,
  615. max_response_time = max_response_time
  616. # fmt: on
  617. )
  618. @app.route('/about', methods=['GET'])
  619. def about():
  620. """Redirect to about page"""
  621. # custom_url_for is going to add the locale
  622. return redirect(custom_url_for('info', pagename='about'))
  623. @app.route('/info/<locale>/<pagename>', methods=['GET'])
  624. def info(pagename, locale):
  625. """Render page of online user documentation"""
  626. page = infopage.INFO_PAGES.get_page(pagename, locale)
  627. if page is None:
  628. flask.abort(404)
  629. user_locale = sxng_request.preferences.get_value('locale')
  630. return render(
  631. 'info.html',
  632. all_pages=infopage.INFO_PAGES.iter_pages(user_locale, fallback_to_default=True),
  633. active_page=page,
  634. active_pagename=pagename,
  635. )
  636. @app.route('/autocompleter', methods=['GET', 'POST'])
  637. def autocompleter():
  638. """Return autocompleter results"""
  639. # run autocompleter
  640. results = []
  641. # set blocked engines
  642. disabled_engines = sxng_request.preferences.engines.get_disabled()
  643. # parse query
  644. raw_text_query = RawTextQuery(sxng_request.form.get('q', ''), disabled_engines)
  645. sug_prefix = raw_text_query.getQuery()
  646. for obj in searx.answerers.STORAGE.ask(sug_prefix):
  647. if isinstance(obj, Answer):
  648. results.append(obj.answer)
  649. # normal autocompletion results only appear if no inner results returned
  650. # and there is a query part
  651. if len(raw_text_query.autocomplete_list) == 0 and len(sug_prefix) > 0:
  652. # get SearXNG's locale and autocomplete backend from cookie
  653. sxng_locale = sxng_request.preferences.get_value('language')
  654. backend_name = sxng_request.preferences.get_value('autocomplete')
  655. for result in search_autocomplete(backend_name, sug_prefix, sxng_locale):
  656. # attention: this loop will change raw_text_query object and this is
  657. # the reason why the sug_prefix was stored before (see above)
  658. if result != sug_prefix:
  659. results.append(raw_text_query.changeQuery(result).getFullQuery())
  660. if len(raw_text_query.autocomplete_list) > 0:
  661. for autocomplete_text in raw_text_query.autocomplete_list:
  662. results.append(raw_text_query.get_autocomplete_full_query(autocomplete_text))
  663. if sxng_request.headers.get('X-Requested-With') == 'XMLHttpRequest':
  664. # the suggestion request comes from the searx search form
  665. suggestions = json.dumps(results)
  666. mimetype = 'application/json'
  667. else:
  668. # the suggestion request comes from browser's URL bar
  669. suggestions = json.dumps([sug_prefix, results])
  670. mimetype = 'application/x-suggestions+json'
  671. suggestions = escape(suggestions, False)
  672. return Response(suggestions, mimetype=mimetype)
  673. @app.route('/preferences', methods=['GET', 'POST'])
  674. def preferences():
  675. """Render preferences page && save user preferences"""
  676. # pylint: disable=too-many-locals, too-many-return-statements, too-many-branches
  677. # pylint: disable=too-many-statements
  678. # save preferences using the link the /preferences?preferences=...
  679. if sxng_request.args.get('preferences') or sxng_request.form.get('preferences'):
  680. resp = make_response(redirect(url_for('index', _external=True)))
  681. return sxng_request.preferences.save(resp)
  682. # save preferences
  683. if sxng_request.method == 'POST':
  684. resp = make_response(redirect(url_for('index', _external=True)))
  685. try:
  686. sxng_request.preferences.parse_form(sxng_request.form)
  687. except ValidationException:
  688. sxng_request.errors.append(gettext('Invalid settings, please edit your preferences'))
  689. return resp
  690. return sxng_request.preferences.save(resp)
  691. # render preferences
  692. image_proxy = sxng_request.preferences.get_value('image_proxy') # pylint: disable=redefined-outer-name
  693. disabled_engines = sxng_request.preferences.engines.get_disabled()
  694. allowed_plugins = sxng_request.preferences.plugins.get_enabled()
  695. # stats for preferences page
  696. filtered_engines = dict(filter(lambda kv: sxng_request.preferences.validate_token(kv[1]), engines.items()))
  697. engines_by_category = {}
  698. for c in categories: # pylint: disable=consider-using-dict-items
  699. engines_by_category[c] = [e for e in categories[c] if e.name in filtered_engines]
  700. # sort the engines alphabetically since the order in settings.yml is meaningless.
  701. list.sort(engines_by_category[c], key=lambda e: e.name)
  702. # get first element [0], the engine time,
  703. # and then the second element [1] : the time (the first one is the label)
  704. stats = {} # pylint: disable=redefined-outer-name
  705. max_rate95 = 0
  706. for _, e in filtered_engines.items():
  707. h = histogram('engine', e.name, 'time', 'total')
  708. median = round(h.percentage(50), 1) if h.count > 0 else None
  709. rate80 = round(h.percentage(80), 1) if h.count > 0 else None
  710. rate95 = round(h.percentage(95), 1) if h.count > 0 else None
  711. max_rate95 = max(max_rate95, rate95 or 0)
  712. result_count_sum = histogram('engine', e.name, 'result', 'count').sum
  713. successful_count = counter('engine', e.name, 'search', 'count', 'successful')
  714. result_count = int(result_count_sum / float(successful_count)) if successful_count else 0
  715. stats[e.name] = {
  716. 'time': median,
  717. 'rate80': rate80,
  718. 'rate95': rate95,
  719. 'warn_timeout': e.timeout > settings['outgoing']['request_timeout'],
  720. 'supports_selected_language': e.traits.is_locale_supported(
  721. str(sxng_request.preferences.get_value('language') or 'all')
  722. ),
  723. 'result_count': result_count,
  724. }
  725. # end of stats
  726. # reliabilities
  727. reliabilities = {}
  728. engine_errors = get_engine_errors(filtered_engines)
  729. checker_results = checker_get_result()
  730. checker_results = (
  731. checker_results['engines'] if checker_results['status'] == 'ok' and 'engines' in checker_results else {}
  732. )
  733. for _, e in filtered_engines.items():
  734. checker_result = checker_results.get(e.name, {})
  735. checker_success = checker_result.get('success', True)
  736. errors = engine_errors.get(e.name) or []
  737. if counter('engine', e.name, 'search', 'count', 'sent') == 0:
  738. # no request
  739. reliability = None
  740. elif checker_success and not errors:
  741. reliability = 100
  742. elif 'simple' in checker_result.get('errors', {}):
  743. # the basic (simple) test doesn't work: the engine is broken according to the checker
  744. # even if there is no exception
  745. reliability = 0
  746. else:
  747. # pylint: disable=consider-using-generator
  748. reliability = 100 - sum([error['percentage'] for error in errors if not error.get('secondary')])
  749. reliabilities[e.name] = {
  750. 'reliability': reliability,
  751. 'errors': [],
  752. 'checker': checker_results.get(e.name, {}).get('errors', {}).keys(),
  753. }
  754. # keep the order of the list checker_results[e.name]['errors'] and deduplicate.
  755. # the first element has the highest percentage rate.
  756. reliabilities_errors = []
  757. for error in errors:
  758. error_user_text = None
  759. if error.get('secondary') or 'exception_classname' not in error:
  760. continue
  761. error_user_text = exception_classname_to_text.get(error.get('exception_classname'))
  762. if not error:
  763. error_user_text = exception_classname_to_text[None]
  764. if error_user_text not in reliabilities_errors:
  765. reliabilities_errors.append(error_user_text)
  766. reliabilities[e.name]['errors'] = reliabilities_errors
  767. # supports
  768. supports = {}
  769. for _, e in filtered_engines.items():
  770. supports_selected_language = e.traits.is_locale_supported(
  771. str(sxng_request.preferences.get_value('language') or 'all')
  772. )
  773. safesearch = e.safesearch
  774. time_range_support = e.time_range_support
  775. for checker_test_name in checker_results.get(e.name, {}).get('errors', {}):
  776. if supports_selected_language and checker_test_name.startswith('lang_'):
  777. supports_selected_language = '?'
  778. elif safesearch and checker_test_name == 'safesearch':
  779. safesearch = '?'
  780. elif time_range_support and checker_test_name == 'time_range':
  781. time_range_support = '?'
  782. supports[e.name] = {
  783. 'supports_selected_language': supports_selected_language,
  784. 'safesearch': safesearch,
  785. 'time_range_support': time_range_support,
  786. }
  787. return render(
  788. # fmt: off
  789. 'preferences.html',
  790. preferences = True,
  791. selected_categories = get_selected_categories(sxng_request.preferences, sxng_request.form),
  792. locales = LOCALE_NAMES,
  793. current_locale = sxng_request.preferences.get_value("locale"),
  794. image_proxy = image_proxy,
  795. engines_by_category = engines_by_category,
  796. stats = stats,
  797. max_rate95 = max_rate95,
  798. reliabilities = reliabilities,
  799. supports = supports,
  800. answer_storage = searx.answerers.STORAGE.info,
  801. disabled_engines = disabled_engines,
  802. autocomplete_backends = autocomplete_backends,
  803. favicon_resolver_names = favicons.proxy.CFG.resolver_map.keys(),
  804. shortcuts = {y: x for x, y in engine_shortcuts.items()},
  805. themes = themes,
  806. plugins_storage = searx.plugins.STORAGE.info,
  807. current_doi_resolver = get_doi_resolver(),
  808. allowed_plugins = allowed_plugins,
  809. preferences_url_params = sxng_request.preferences.get_as_url_params(),
  810. locked_preferences = get_setting("preferences.lock", []),
  811. doi_resolvers = get_setting("doi_resolvers", {}),
  812. # fmt: on
  813. )
  814. app.add_url_rule('/favicon_proxy', methods=['GET'], endpoint="favicon_proxy", view_func=favicons.favicon_proxy)
  815. @app.route('/image_proxy', methods=['GET'])
  816. def image_proxy():
  817. # pylint: disable=too-many-return-statements, too-many-branches
  818. url = sxng_request.args.get('url')
  819. if not url:
  820. return '', 400
  821. if not is_hmac_of(settings['server']['secret_key'], url.encode(), sxng_request.args.get('h', '')):
  822. return '', 400
  823. maximum_size = 5 * 1024 * 1024
  824. forward_resp = False
  825. resp = None
  826. try:
  827. request_headers = {
  828. 'User-Agent': gen_useragent(),
  829. 'Accept': 'image/webp,*/*',
  830. 'Accept-Encoding': 'gzip, deflate',
  831. 'Sec-GPC': '1',
  832. 'DNT': '1',
  833. }
  834. set_context_network_name('image_proxy')
  835. resp, stream = http_stream(method='GET', url=url, headers=request_headers, allow_redirects=True)
  836. content_length = resp.headers.get('Content-Length')
  837. if content_length and content_length.isdigit() and int(content_length) > maximum_size:
  838. return 'Max size', 400
  839. if resp.status_code != 200:
  840. logger.debug('image-proxy: wrong response code: %i', resp.status_code)
  841. if resp.status_code >= 400:
  842. return '', resp.status_code
  843. return '', 400
  844. if not resp.headers.get('Content-Type', '').startswith('image/') and not resp.headers.get(
  845. 'Content-Type', ''
  846. ).startswith('binary/octet-stream'):
  847. logger.debug('image-proxy: wrong content-type: %s', resp.headers.get('Content-Type', ''))
  848. return '', 400
  849. forward_resp = True
  850. except httpx.HTTPError:
  851. logger.exception('HTTP error')
  852. return '', 400
  853. finally:
  854. if resp and not forward_resp:
  855. # the code is about to return an HTTP 400 error to the browser
  856. # we make sure to close the response between searxng and the HTTP server
  857. try:
  858. resp.close()
  859. except httpx.HTTPError:
  860. logger.exception('HTTP error on closing')
  861. def close_stream():
  862. nonlocal resp, stream
  863. try:
  864. if resp:
  865. resp.close()
  866. del resp
  867. del stream
  868. except httpx.HTTPError as e:
  869. logger.debug('Exception while closing response', e)
  870. try:
  871. headers = dict_subset(resp.headers, {'Content-Type', 'Content-Encoding', 'Content-Length', 'Length'})
  872. response = Response(stream, mimetype=resp.headers['Content-Type'], headers=headers, direct_passthrough=True)
  873. response.call_on_close(close_stream)
  874. return response
  875. except httpx.HTTPError:
  876. close_stream()
  877. return '', 400
  878. @app.route('/engine_descriptions.json', methods=['GET'])
  879. def engine_descriptions():
  880. sxng_ui_lang_tag = get_locale().replace("_", "-")
  881. sxng_ui_lang_tag = LOCALE_BEST_MATCH.get(sxng_ui_lang_tag, sxng_ui_lang_tag)
  882. result = ENGINE_DESCRIPTIONS['en'].copy()
  883. if sxng_ui_lang_tag != 'en':
  884. for engine, description in ENGINE_DESCRIPTIONS.get(sxng_ui_lang_tag, {}).items():
  885. result[engine] = description
  886. for engine, description in result.items():
  887. if len(description) == 2 and description[1] == 'ref':
  888. ref_engine, ref_lang = description[0].split(':')
  889. description = ENGINE_DESCRIPTIONS[ref_lang][ref_engine]
  890. if isinstance(description, str):
  891. description = [description, 'wikipedia']
  892. result[engine] = description
  893. # overwrite by about:description (from settings)
  894. for engine_name, engine_mod in engines.items():
  895. descr = getattr(engine_mod, 'about', {}).get('description', None)
  896. if descr is not None:
  897. result[engine_name] = [descr, "SearXNG config"]
  898. return jsonify(result)
  899. @app.route('/stats', methods=['GET'])
  900. def stats():
  901. """Render engine statistics page."""
  902. sort_order = sxng_request.args.get('sort', default='name', type=str)
  903. selected_engine_name = sxng_request.args.get('engine', default=None, type=str)
  904. filtered_engines = dict(filter(lambda kv: sxng_request.preferences.validate_token(kv[1]), engines.items()))
  905. if selected_engine_name:
  906. if selected_engine_name not in filtered_engines:
  907. selected_engine_name = None
  908. else:
  909. filtered_engines = [selected_engine_name]
  910. checker_results = checker_get_result()
  911. checker_results = (
  912. checker_results['engines'] if checker_results['status'] == 'ok' and 'engines' in checker_results else {}
  913. )
  914. engine_stats = get_engines_stats(filtered_engines)
  915. engine_reliabilities = get_reliabilities(filtered_engines, checker_results)
  916. if sort_order not in STATS_SORT_PARAMETERS:
  917. sort_order = 'name'
  918. reverse, key_name, default_value = STATS_SORT_PARAMETERS[sort_order]
  919. def get_key(engine_stat):
  920. reliability = engine_reliabilities.get(engine_stat['name'], {}).get('reliability', 0)
  921. reliability_order = 0 if reliability else 1
  922. if key_name == 'reliability':
  923. key = reliability
  924. reliability_order = 0
  925. else:
  926. key = engine_stat.get(key_name) or default_value
  927. if reverse:
  928. reliability_order = 1 - reliability_order
  929. return (reliability_order, key, engine_stat['name'])
  930. technical_report = []
  931. for error in engine_reliabilities.get(selected_engine_name, {}).get('errors', []):
  932. technical_report.append(
  933. f"\
  934. Error: {error['exception_classname'] or error['log_message']} \
  935. Parameters: {error['log_parameters']} \
  936. File name: {error['filename'] }:{ error['line_no'] } \
  937. Error Function: {error['function']} \
  938. Code: {error['code']} \
  939. ".replace(
  940. ' ' * 12, ''
  941. ).strip()
  942. )
  943. technical_report = ' '.join(technical_report)
  944. engine_stats['time'] = sorted(engine_stats['time'], reverse=reverse, key=get_key)
  945. return render(
  946. # fmt: off
  947. 'stats.html',
  948. sort_order = sort_order,
  949. engine_stats = engine_stats,
  950. engine_reliabilities = engine_reliabilities,
  951. selected_engine_name = selected_engine_name,
  952. searx_git_branch = GIT_BRANCH,
  953. technical_report = technical_report,
  954. # fmt: on
  955. )
  956. @app.route('/stats/errors', methods=['GET'])
  957. def stats_errors():
  958. filtered_engines = dict(filter(lambda kv: sxng_request.preferences.validate_token(kv[1]), engines.items()))
  959. result = get_engine_errors(filtered_engines)
  960. return jsonify(result)
  961. @app.route('/stats/checker', methods=['GET'])
  962. def stats_checker():
  963. result = checker_get_result()
  964. return jsonify(result)
  965. @app.route('/metrics')
  966. def stats_open_metrics():
  967. password = settings['general'].get("open_metrics")
  968. if not (settings['general'].get("enable_metrics") and password):
  969. return Response('open metrics is disabled', status=404, mimetype='text/plain')
  970. if not sxng_request.authorization or sxng_request.authorization.password != password:
  971. return Response('access forbidden', status=401, mimetype='text/plain')
  972. filtered_engines = dict(filter(lambda kv: sxng_request.preferences.validate_token(kv[1]), engines.items()))
  973. checker_results = checker_get_result()
  974. checker_results = (
  975. checker_results['engines'] if checker_results['status'] == 'ok' and 'engines' in checker_results else {}
  976. )
  977. engine_stats = get_engines_stats(filtered_engines)
  978. engine_reliabilities = get_reliabilities(filtered_engines, checker_results)
  979. metrics_text = openmetrics(engine_stats, engine_reliabilities)
  980. return Response(metrics_text, mimetype='text/plain')
  981. @app.route('/robots.txt', methods=['GET'])
  982. def robots():
  983. return Response(
  984. """User-agent: *
  985. Allow: /info/en/about
  986. Disallow: /stats
  987. Disallow: /image_proxy
  988. Disallow: /preferences
  989. Disallow: /*?*q=*
  990. """,
  991. mimetype='text/plain',
  992. )
  993. @app.route('/opensearch.xml', methods=['GET'])
  994. def opensearch():
  995. method = sxng_request.preferences.get_value('method')
  996. autocomplete = sxng_request.preferences.get_value('autocomplete')
  997. # chrome/chromium only supports HTTP GET....
  998. if sxng_request.headers.get('User-Agent', '').lower().find('webkit') >= 0:
  999. method = 'GET'
  1000. if method not in ('POST', 'GET'):
  1001. method = 'POST'
  1002. ret = render('opensearch.xml', opensearch_method=method, autocomplete=autocomplete)
  1003. resp = Response(response=ret, status=200, mimetype="application/opensearchdescription+xml")
  1004. return resp
  1005. @app.route('/favicon.ico')
  1006. def favicon():
  1007. theme = sxng_request.preferences.get_value("theme")
  1008. return send_from_directory(
  1009. os.path.join(app.root_path, settings['ui']['static_path'], 'themes', theme, 'img'), # type: ignore
  1010. 'favicon.png',
  1011. mimetype='image/vnd.microsoft.icon',
  1012. )
  1013. @app.route('/clear_cookies')
  1014. def clear_cookies():
  1015. resp = make_response(redirect(url_for('index', _external=True)))
  1016. for cookie_name in sxng_request.cookies:
  1017. resp.delete_cookie(cookie_name)
  1018. return resp
  1019. @app.route('/config')
  1020. def config():
  1021. """Return configuration in JSON format."""
  1022. _engines = []
  1023. for name, engine in engines.items():
  1024. if not sxng_request.preferences.validate_token(engine):
  1025. continue
  1026. _languages = engine.traits.languages.keys()
  1027. _engines.append(
  1028. {
  1029. 'name': name,
  1030. 'categories': engine.categories,
  1031. 'shortcut': engine.shortcut,
  1032. 'enabled': not engine.disabled,
  1033. 'paging': engine.paging,
  1034. 'language_support': engine.language_support,
  1035. 'languages': list(_languages),
  1036. 'regions': list(engine.traits.regions.keys()),
  1037. 'safesearch': engine.safesearch,
  1038. 'time_range_support': engine.time_range_support,
  1039. 'timeout': engine.timeout,
  1040. }
  1041. )
  1042. _plugins = []
  1043. for _ in searx.plugins.STORAGE:
  1044. _plugins.append({'name': _.id, 'enabled': _.active})
  1045. _limiter_cfg = limiter.get_cfg()
  1046. return jsonify(
  1047. {
  1048. 'categories': list(categories.keys()),
  1049. 'engines': _engines,
  1050. 'plugins': _plugins,
  1051. 'instance_name': settings['general']['instance_name'],
  1052. 'locales': LOCALE_NAMES,
  1053. 'default_locale': settings['ui']['default_locale'],
  1054. 'autocomplete': settings['search']['autocomplete'],
  1055. 'safe_search': settings['search']['safe_search'],
  1056. 'default_theme': settings['ui']['default_theme'],
  1057. 'version': VERSION_STRING,
  1058. 'brand': {
  1059. 'PRIVACYPOLICY_URL': get_setting('general.privacypolicy_url'),
  1060. 'CONTACT_URL': get_setting('general.contact_url'),
  1061. 'GIT_URL': GIT_URL,
  1062. 'GIT_BRANCH': GIT_BRANCH,
  1063. 'DOCS_URL': get_setting('brand.docs_url'),
  1064. },
  1065. 'limiter': {
  1066. 'enabled': limiter.is_installed(),
  1067. 'botdetection.ip_limit.link_token': _limiter_cfg.get('botdetection.ip_limit.link_token'),
  1068. 'botdetection.ip_lists.pass_searxng_org': _limiter_cfg.get('botdetection.ip_lists.pass_searxng_org'),
  1069. },
  1070. 'doi_resolvers': list(settings['doi_resolvers'].keys()),
  1071. 'default_doi_resolver': settings['default_doi_resolver'],
  1072. 'public_instance': settings['server']['public_instance'],
  1073. }
  1074. )
  1075. @app.errorhandler(404)
  1076. def page_not_found(_e):
  1077. return render('404.html'), 404
  1078. def run():
  1079. """Runs the application on a local development server.
  1080. This run method is only called when SearXNG is started via ``__main__``::
  1081. python -m searx.webapp
  1082. Do not use :ref:`run() <flask.Flask.run>` in a production setting. It is
  1083. not intended to meet security and performance requirements for a production
  1084. server.
  1085. It is not recommended to use this function for development with automatic
  1086. reloading as this is badly supported. Instead you should be using the flask
  1087. command line script’s run support::
  1088. flask --app searx.webapp run --debug --reload --host 127.0.0.1 --port 8888
  1089. .. _Flask.run: https://flask.palletsprojects.com/en/stable/api/#flask.Flask.run
  1090. """
  1091. host: str = get_setting("server.bind_address") # type: ignore
  1092. port: int = get_setting("server.port") # type: ignore
  1093. if searx.sxng_debug:
  1094. logger.debug("run local development server (DEBUG) on %s:%s", host, port)
  1095. app.run(
  1096. debug=True,
  1097. port=port,
  1098. host=host,
  1099. threaded=True,
  1100. extra_files=[DEFAULT_SETTINGS_FILE],
  1101. )
  1102. else:
  1103. logger.debug("run local development server on %s:%s", host, port)
  1104. app.run(port=port, host=host, threaded=True)
  1105. def is_werkzeug_reload_active() -> bool:
  1106. """Returns ``True`` if server is is launched by :ref:`werkzeug.serving` and
  1107. the ``use_reload`` argument was set to ``True``. If this is the case, it
  1108. should be avoided that the server is initialized twice (:py:obj:`init`,
  1109. :py:obj:`run`).
  1110. .. _werkzeug.serving:
  1111. https://werkzeug.palletsprojects.com/en/stable/serving/#werkzeug.serving.run_simple
  1112. """
  1113. logger.debug("sys.argv: %s", sys.argv)
  1114. if "uwsgi" in sys.argv[0] or "granian" in sys.argv[0]:
  1115. # server was launched by granian (or uWSGI)
  1116. return False
  1117. # https://github.com/searxng/searxng/pull/1656#issuecomment-1214198941
  1118. # https://github.com/searxng/searxng/pull/1616#issuecomment-1206137468
  1119. frames = inspect.stack()
  1120. if len(frames) > 1 and frames[-2].filename.endswith('flask/cli.py'):
  1121. # server was launched by "flask run", is argument "--reload" set?
  1122. if "--reload" in sys.argv or "--debug" in sys.argv:
  1123. return True
  1124. elif frames[0].filename.endswith('searx/webapp.py'):
  1125. # server was launched by "python -m searx.webapp" / see run()
  1126. if searx.sxng_debug:
  1127. return True
  1128. return False
  1129. def init():
  1130. if searx.sxng_debug or app.debug:
  1131. app.debug = True
  1132. searx.sxng_debug = True
  1133. # check secret_key in production
  1134. if not app.debug and get_setting("server.secret_key") == 'ultrasecretkey':
  1135. logger.error("server.secret_key is not changed. Please use something else instead of ultrasecretkey.")
  1136. sys.exit(1)
  1137. # When automatic reloading is activated stop Flask from initialising twice.
  1138. # - https://github.com/pallets/flask/issues/5307#issuecomment-1774646119
  1139. # - https://stackoverflow.com/a/25504196
  1140. reloader_active = is_werkzeug_reload_active()
  1141. werkzeug_run_main = is_running_from_reloader()
  1142. if reloader_active and not werkzeug_run_main:
  1143. logger.info("in reloading mode and not in main loop, cancel the initialization")
  1144. return
  1145. locales_initialize()
  1146. valkey_initialize()
  1147. searx.plugins.initialize(app)
  1148. metrics: bool = get_setting("general.enable_metrics") # type: ignore
  1149. searx.search.initialize(enable_checker=True, check_network=True, enable_metrics=metrics)
  1150. limiter.initialize(app, settings)
  1151. favicons.init()
  1152. application = app
  1153. patch_application(app)
  1154. init()
  1155. if __name__ == "__main__":
  1156. run()