webapp.py 51 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424
  1. #!/usr/bin/env python
  2. # SPDX-License-Identifier: AGPL-3.0-or-later
  3. """WebbApp
  4. """
  5. # pylint: disable=use-dict-literal
  6. import hashlib
  7. import hmac
  8. import json
  9. import os
  10. import sys
  11. import base64
  12. from timeit import default_timer
  13. from html import escape
  14. from io import StringIO
  15. import typing
  16. from typing import List, Dict, Iterable
  17. import urllib
  18. import urllib.parse
  19. from urllib.parse import urlencode, urlparse, unquote
  20. import httpx
  21. from pygments import highlight
  22. from pygments.lexers import get_lexer_by_name
  23. from pygments.formatters import HtmlFormatter # pylint: disable=no-name-in-module
  24. import flask
  25. from flask import (
  26. Flask,
  27. render_template,
  28. url_for,
  29. make_response,
  30. redirect,
  31. send_from_directory,
  32. )
  33. from flask.wrappers import Response
  34. from flask.json import jsonify
  35. from flask_babel import (
  36. Babel,
  37. gettext,
  38. format_decimal,
  39. )
  40. from searx import (
  41. logger,
  42. get_setting,
  43. settings,
  44. searx_debug,
  45. )
  46. from searx import infopage
  47. from searx import limiter
  48. from searx.botdetection import link_token
  49. from searx.data import ENGINE_DESCRIPTIONS
  50. from searx.results import Timing
  51. from searx.settings_defaults import OUTPUT_FORMATS
  52. from searx.settings_loader import DEFAULT_SETTINGS_FILE
  53. from searx.exceptions import SearxParameterException
  54. from searx.engines import (
  55. DEFAULT_CATEGORY,
  56. categories,
  57. engines,
  58. engine_shortcuts,
  59. )
  60. from searx import webutils
  61. from searx.webutils import (
  62. highlight_content,
  63. get_static_files,
  64. get_result_templates,
  65. get_themes,
  66. exception_classname_to_text,
  67. new_hmac,
  68. is_hmac_of,
  69. is_flask_run_cmdline,
  70. group_engines_in_tab,
  71. )
  72. from searx.webadapter import (
  73. get_search_query_from_webapp,
  74. get_selected_categories,
  75. parse_lang,
  76. )
  77. from searx.utils import (
  78. gen_useragent,
  79. dict_subset,
  80. )
  81. from searx.version import VERSION_STRING, GIT_URL, GIT_BRANCH
  82. from searx.query import RawTextQuery
  83. from searx.plugins import Plugin, plugins, initialize as plugin_initialize
  84. from searx.plugins.oa_doi_rewrite import get_doi_resolver
  85. from searx.preferences import (
  86. Preferences,
  87. ClientPref,
  88. ValidationException,
  89. )
  90. from searx.answerers import (
  91. answerers,
  92. ask,
  93. )
  94. from searx.metrics import (
  95. get_engines_stats,
  96. get_engine_errors,
  97. get_reliabilities,
  98. histogram,
  99. counter,
  100. )
  101. from searx.flaskfix import patch_application
  102. from searx.locales import (
  103. LOCALE_NAMES,
  104. RTL_LOCALES,
  105. localeselector,
  106. locales_initialize,
  107. match_locale,
  108. )
  109. # renaming names from searx imports ...
  110. from searx.autocomplete import search_autocomplete, backends as autocomplete_backends
  111. from searx.favicon_resolver import search_favicon, backends as favicon_backends
  112. from searx.redisdb import initialize as redis_initialize
  113. from searx.sxng_locales import sxng_locales
  114. from searx.search import SearchWithPlugins, initialize as search_initialize
  115. from searx.network import stream as http_stream, set_context_network_name
  116. from searx.search.checker import get_result as checker_get_result
  117. logger = logger.getChild('webapp')
  118. # check secret_key
  119. if not searx_debug and settings['server']['secret_key'] == 'ultrasecretkey':
  120. logger.error('server.secret_key is not changed. Please use something else instead of ultrasecretkey.')
  121. sys.exit(1)
  122. # about static
  123. logger.debug('static directory is %s', settings['ui']['static_path'])
  124. static_files = get_static_files(settings['ui']['static_path'])
  125. # about templates
  126. logger.debug('templates directory is %s', settings['ui']['templates_path'])
  127. default_theme = settings['ui']['default_theme']
  128. templates_path = settings['ui']['templates_path']
  129. themes = get_themes(templates_path)
  130. result_templates = get_result_templates(templates_path)
  131. STATS_SORT_PARAMETERS = {
  132. 'name': (False, 'name', ''),
  133. 'score': (True, 'score_per_result', 0),
  134. 'result_count': (True, 'result_count', 0),
  135. 'time': (False, 'total', 0),
  136. 'reliability': (False, 'reliability', 100),
  137. }
  138. # Flask app
  139. app = Flask(__name__, static_folder=settings['ui']['static_path'], template_folder=templates_path)
  140. app.jinja_env.trim_blocks = True
  141. app.jinja_env.lstrip_blocks = True
  142. app.jinja_env.add_extension('jinja2.ext.loopcontrols') # pylint: disable=no-member
  143. app.jinja_env.filters['group_engines_in_tab'] = group_engines_in_tab # pylint: disable=no-member
  144. app.secret_key = settings['server']['secret_key']
  145. class ExtendedRequest(flask.Request):
  146. """This class is never initialized and only used for type checking."""
  147. preferences: Preferences
  148. errors: List[str]
  149. user_plugins: List[Plugin]
  150. form: Dict[str, str]
  151. start_time: float
  152. render_time: float
  153. timings: List[Timing]
  154. request = typing.cast(ExtendedRequest, flask.request)
  155. def get_locale():
  156. locale = localeselector()
  157. logger.debug("%s uses locale `%s`", urllib.parse.quote(request.url), locale)
  158. return locale
  159. babel = Babel(app, locale_selector=get_locale)
  160. def _get_browser_language(req, lang_list):
  161. client = ClientPref.from_http_request(req)
  162. locale = match_locale(client.locale_tag, lang_list, fallback='en')
  163. return locale
  164. def _get_locale_rfc5646(locale):
  165. """Get locale name for <html lang="...">
  166. Chrom* browsers don't detect the language when there is a subtag (ie a territory).
  167. For example "zh-TW" is detected but not "zh-Hant-TW".
  168. This function returns a locale without the subtag.
  169. """
  170. parts = locale.split('-')
  171. return parts[0].lower() + '-' + parts[-1].upper()
  172. # code-highlighter
  173. @app.template_filter('code_highlighter')
  174. def code_highlighter(codelines, language=None):
  175. if not language:
  176. language = 'text'
  177. try:
  178. # find lexer by programming language
  179. lexer = get_lexer_by_name(language, stripall=True)
  180. except Exception as e: # pylint: disable=broad-except
  181. logger.warning("pygments lexer: %s " % e)
  182. # if lexer is not found, using default one
  183. lexer = get_lexer_by_name('text', stripall=True)
  184. html_code = ''
  185. tmp_code = ''
  186. last_line = None
  187. line_code_start = None
  188. # parse lines
  189. for line, code in codelines:
  190. if not last_line:
  191. line_code_start = line
  192. # new codeblock is detected
  193. if last_line is not None and last_line + 1 != line:
  194. # highlight last codepart
  195. formatter = HtmlFormatter(linenos='inline', linenostart=line_code_start, cssclass="code-highlight")
  196. html_code = html_code + highlight(tmp_code, lexer, formatter)
  197. # reset conditions for next codepart
  198. tmp_code = ''
  199. line_code_start = line
  200. # add codepart
  201. tmp_code += code + '\n'
  202. # update line
  203. last_line = line
  204. # highlight last codepart
  205. formatter = HtmlFormatter(linenos='inline', linenostart=line_code_start, cssclass="code-highlight")
  206. html_code = html_code + highlight(tmp_code, lexer, formatter)
  207. return html_code
  208. def get_result_template(theme_name: str, template_name: str):
  209. themed_path = theme_name + '/result_templates/' + template_name
  210. if themed_path in result_templates:
  211. return themed_path
  212. return 'result_templates/' + template_name
  213. def custom_url_for(endpoint: str, **values):
  214. suffix = ""
  215. if endpoint == 'static' and values.get('filename'):
  216. file_hash = static_files.get(values['filename'])
  217. if not file_hash:
  218. # try file in the current theme
  219. theme_name = request.preferences.get_value('theme')
  220. filename_with_theme = "themes/{}/{}".format(theme_name, values['filename'])
  221. file_hash = static_files.get(filename_with_theme)
  222. if file_hash:
  223. values['filename'] = filename_with_theme
  224. if get_setting('ui.static_use_hash') and file_hash:
  225. suffix = "?" + file_hash
  226. if endpoint == 'info' and 'locale' not in values:
  227. locale = request.preferences.get_value('locale')
  228. if infopage.INFO_PAGES.get_page(values['pagename'], locale) is None:
  229. locale = infopage.INFO_PAGES.locale_default
  230. values['locale'] = locale
  231. return url_for(endpoint, **values) + suffix
  232. def morty_proxify(url: str):
  233. if url.startswith('//'):
  234. url = 'https:' + url
  235. if not settings['result_proxy']['url']:
  236. return url
  237. url_params = dict(mortyurl=url)
  238. if settings['result_proxy']['key']:
  239. url_params['mortyhash'] = hmac.new(settings['result_proxy']['key'], url.encode(), hashlib.sha256).hexdigest()
  240. return '{0}?{1}'.format(settings['result_proxy']['url'], urlencode(url_params))
  241. def favicon_proxify(url: str):
  242. # url is a FQDN (e.g. example.com, en.wikipedia.org)
  243. resolver = request.preferences.get_value('favicon_resolver')
  244. # if resolver is empty, just return nothing
  245. if not resolver:
  246. return ""
  247. # check resolver is valid
  248. if resolver not in favicon_backends:
  249. return ""
  250. h = new_hmac(settings['server']['secret_key'], url.encode())
  251. return '{0}?{1}'.format(url_for('favicon_proxy'), urlencode(dict(q=url.encode(), h=h)))
  252. def image_proxify(url: str):
  253. if url.startswith('//'):
  254. url = 'https:' + url
  255. if not request.preferences.get_value('image_proxy'):
  256. return url
  257. if url.startswith('data:image/'):
  258. # 50 is an arbitrary number to get only the beginning of the image.
  259. partial_base64 = url[len('data:image/') : 50].split(';')
  260. if (
  261. len(partial_base64) == 2
  262. and partial_base64[0] in ['gif', 'png', 'jpeg', 'pjpeg', 'webp', 'tiff', 'bmp']
  263. and partial_base64[1].startswith('base64,')
  264. ):
  265. return url
  266. return None
  267. if settings['result_proxy']['url']:
  268. return morty_proxify(url)
  269. h = new_hmac(settings['server']['secret_key'], url.encode())
  270. return '{0}?{1}'.format(url_for('image_proxy'), urlencode(dict(url=url.encode(), h=h)))
  271. def get_translations():
  272. return {
  273. # when there is autocompletion
  274. 'no_item_found': gettext('No item found'),
  275. # /preferences: the source of the engine description (wikipedata, wikidata, website)
  276. 'Source': gettext('Source'),
  277. # infinite scroll
  278. 'error_loading_next_page': gettext('Error loading the next page'),
  279. }
  280. def get_enabled_categories(category_names: Iterable[str]):
  281. """The categories in ``category_names```for which there is no active engine
  282. are filtered out and a reduced list is returned."""
  283. enabled_engines = [item[0] for item in request.preferences.engines.get_enabled()]
  284. enabled_categories = set()
  285. for engine_name in enabled_engines:
  286. enabled_categories.update(engines[engine_name].categories)
  287. return [x for x in category_names if x in enabled_categories]
  288. def get_pretty_url(parsed_url: urllib.parse.ParseResult):
  289. path = parsed_url.path
  290. path = path[:-1] if len(path) > 0 and path[-1] == '/' else path
  291. path = unquote(path.replace("/", " › "))
  292. return [parsed_url.scheme + "://" + parsed_url.netloc, path]
  293. def get_client_settings():
  294. req_pref = request.preferences
  295. return {
  296. 'autocomplete_provider': req_pref.get_value('autocomplete'),
  297. 'autocomplete_min': get_setting('search.autocomplete_min'),
  298. 'favicon_resolver': req_pref.get_value('favicon_resolver'),
  299. 'http_method': req_pref.get_value('method'),
  300. 'infinite_scroll': req_pref.get_value('infinite_scroll'),
  301. 'translations': get_translations(),
  302. 'search_on_category_select': req_pref.get_value('search_on_category_select'),
  303. 'hotkeys': req_pref.get_value('hotkeys'),
  304. 'theme_static_path': custom_url_for('static', filename='themes/simple'),
  305. }
  306. def render(template_name: str, **kwargs):
  307. # pylint: disable=too-many-statements
  308. kwargs['client_settings'] = str(
  309. base64.b64encode(
  310. bytes(
  311. json.dumps(get_client_settings()),
  312. encoding='utf-8',
  313. )
  314. ),
  315. encoding='utf-8',
  316. )
  317. # values from the HTTP requests
  318. kwargs['endpoint'] = 'results' if 'q' in kwargs else request.endpoint
  319. kwargs['cookies'] = request.cookies
  320. kwargs['errors'] = request.errors
  321. kwargs['link_token'] = link_token.get_token()
  322. # values from the preferences
  323. kwargs['preferences'] = request.preferences
  324. kwargs['autocomplete'] = request.preferences.get_value('autocomplete')
  325. kwargs['favicon_resolver'] = request.preferences.get_value('favicon_resolver')
  326. kwargs['infinite_scroll'] = request.preferences.get_value('infinite_scroll')
  327. kwargs['search_on_category_select'] = request.preferences.get_value('search_on_category_select')
  328. kwargs['hotkeys'] = request.preferences.get_value('hotkeys')
  329. kwargs['results_on_new_tab'] = request.preferences.get_value('results_on_new_tab')
  330. kwargs['advanced_search'] = request.preferences.get_value('advanced_search')
  331. kwargs['query_in_title'] = request.preferences.get_value('query_in_title')
  332. kwargs['safesearch'] = str(request.preferences.get_value('safesearch'))
  333. kwargs['theme'] = request.preferences.get_value('theme')
  334. kwargs['method'] = request.preferences.get_value('method')
  335. kwargs['categories_as_tabs'] = list(settings['categories_as_tabs'].keys())
  336. kwargs['categories'] = get_enabled_categories(settings['categories_as_tabs'].keys())
  337. kwargs['DEFAULT_CATEGORY'] = DEFAULT_CATEGORY
  338. # i18n
  339. kwargs['sxng_locales'] = [l for l in sxng_locales if l[0] in settings['search']['languages']]
  340. locale = request.preferences.get_value('locale')
  341. kwargs['locale_rfc5646'] = _get_locale_rfc5646(locale)
  342. if locale in RTL_LOCALES and 'rtl' not in kwargs:
  343. kwargs['rtl'] = True
  344. if 'current_language' not in kwargs:
  345. kwargs['current_language'] = parse_lang(request.preferences, {}, RawTextQuery('', []))
  346. # values from settings
  347. kwargs['search_formats'] = [x for x in settings['search']['formats'] if x != 'html']
  348. kwargs['instance_name'] = get_setting('general.instance_name')
  349. kwargs['searx_version'] = VERSION_STRING
  350. kwargs['searx_git_url'] = GIT_URL
  351. kwargs['enable_metrics'] = get_setting('general.enable_metrics')
  352. kwargs['get_setting'] = get_setting
  353. kwargs['get_pretty_url'] = get_pretty_url
  354. # values from settings: donation_url
  355. donation_url = get_setting('general.donation_url')
  356. if donation_url is True:
  357. donation_url = custom_url_for('info', pagename='donate')
  358. kwargs['donation_url'] = donation_url
  359. # helpers to create links to other pages
  360. kwargs['url_for'] = custom_url_for # override url_for function in templates
  361. kwargs['image_proxify'] = image_proxify
  362. kwargs['favicon_proxify'] = favicon_proxify
  363. kwargs['proxify'] = morty_proxify if settings['result_proxy']['url'] is not None else None
  364. kwargs['proxify_results'] = settings['result_proxy']['proxify_results']
  365. kwargs['cache_url'] = settings['ui']['cache_url']
  366. kwargs['get_result_template'] = get_result_template
  367. kwargs['doi_resolver'] = get_doi_resolver(request.preferences)
  368. kwargs['opensearch_url'] = (
  369. url_for('opensearch')
  370. + '?'
  371. + urlencode(
  372. {
  373. 'method': request.preferences.get_value('method'),
  374. 'autocomplete': request.preferences.get_value('autocomplete'),
  375. }
  376. )
  377. )
  378. kwargs['urlparse'] = urlparse
  379. # scripts from plugins
  380. kwargs['scripts'] = set()
  381. for plugin in request.user_plugins:
  382. for script in plugin.js_dependencies:
  383. kwargs['scripts'].add(script)
  384. # styles from plugins
  385. kwargs['styles'] = set()
  386. for plugin in request.user_plugins:
  387. for css in plugin.css_dependencies:
  388. kwargs['styles'].add(css)
  389. start_time = default_timer()
  390. result = render_template('{}/{}'.format(kwargs['theme'], template_name), **kwargs)
  391. request.render_time += default_timer() - start_time # pylint: disable=assigning-non-slot
  392. return result
  393. @app.before_request
  394. def pre_request():
  395. request.start_time = default_timer() # pylint: disable=assigning-non-slot
  396. request.render_time = 0 # pylint: disable=assigning-non-slot
  397. request.timings = [] # pylint: disable=assigning-non-slot
  398. request.errors = [] # pylint: disable=assigning-non-slot
  399. client_pref = ClientPref.from_http_request(request)
  400. # pylint: disable=redefined-outer-name
  401. preferences = Preferences(themes, list(categories.keys()), engines, plugins, client_pref)
  402. user_agent = request.headers.get('User-Agent', '').lower()
  403. if 'webkit' in user_agent and 'android' in user_agent:
  404. preferences.key_value_settings['method'].value = 'GET'
  405. request.preferences = preferences # pylint: disable=assigning-non-slot
  406. try:
  407. preferences.parse_dict(request.cookies)
  408. except Exception as e: # pylint: disable=broad-except
  409. logger.exception(e, exc_info=True)
  410. request.errors.append(gettext('Invalid settings, please edit your preferences'))
  411. # merge GET, POST vars
  412. # request.form
  413. request.form = dict(request.form.items()) # pylint: disable=assigning-non-slot
  414. for k, v in request.args.items():
  415. if k not in request.form:
  416. request.form[k] = v
  417. if request.form.get('preferences'):
  418. preferences.parse_encoded_data(request.form['preferences'])
  419. else:
  420. try:
  421. preferences.parse_dict(request.form)
  422. except Exception as e: # pylint: disable=broad-except
  423. logger.exception(e, exc_info=True)
  424. request.errors.append(gettext('Invalid settings'))
  425. # language is defined neither in settings nor in preferences
  426. # use browser headers
  427. if not preferences.get_value("language"):
  428. language = _get_browser_language(request, settings['search']['languages'])
  429. preferences.parse_dict({"language": language})
  430. logger.debug('set language %s (from browser)', preferences.get_value("language"))
  431. # locale is defined neither in settings nor in preferences
  432. # use browser headers
  433. if not preferences.get_value("locale"):
  434. locale = _get_browser_language(request, LOCALE_NAMES.keys())
  435. preferences.parse_dict({"locale": locale})
  436. logger.debug('set locale %s (from browser)', preferences.get_value("locale"))
  437. # request.user_plugins
  438. request.user_plugins = [] # pylint: disable=assigning-non-slot
  439. allowed_plugins = preferences.plugins.get_enabled()
  440. disabled_plugins = preferences.plugins.get_disabled()
  441. for plugin in plugins:
  442. if (plugin.default_on and plugin.id not in disabled_plugins) or plugin.id in allowed_plugins:
  443. request.user_plugins.append(plugin)
  444. @app.after_request
  445. def add_default_headers(response: flask.Response):
  446. # set default http headers
  447. for header, value in settings['server']['default_http_headers'].items():
  448. if header in response.headers:
  449. continue
  450. response.headers[header] = value
  451. return response
  452. @app.after_request
  453. def post_request(response: flask.Response):
  454. total_time = default_timer() - request.start_time
  455. timings_all = [
  456. 'total;dur=' + str(round(total_time * 1000, 3)),
  457. 'render;dur=' + str(round(request.render_time * 1000, 3)),
  458. ]
  459. if len(request.timings) > 0:
  460. timings = sorted(request.timings, key=lambda t: t.total)
  461. timings_total = [
  462. 'total_' + str(i) + '_' + t.engine + ';dur=' + str(round(t.total * 1000, 3)) for i, t in enumerate(timings)
  463. ]
  464. timings_load = [
  465. 'load_' + str(i) + '_' + t.engine + ';dur=' + str(round(t.load * 1000, 3))
  466. for i, t in enumerate(timings)
  467. if t.load
  468. ]
  469. timings_all = timings_all + timings_total + timings_load
  470. response.headers.add('Server-Timing', ', '.join(timings_all))
  471. return response
  472. def index_error(output_format: str, error_message: str):
  473. if output_format == 'json':
  474. return Response(json.dumps({'error': error_message}), mimetype='application/json')
  475. if output_format == 'csv':
  476. response = Response('', mimetype='application/csv')
  477. cont_disp = 'attachment;Filename=searx.csv'
  478. response.headers.add('Content-Disposition', cont_disp)
  479. return response
  480. if output_format == 'rss':
  481. response_rss = render(
  482. 'opensearch_response_rss.xml',
  483. results=[],
  484. q=request.form['q'] if 'q' in request.form else '',
  485. number_of_results=0,
  486. error_message=error_message,
  487. )
  488. return Response(response_rss, mimetype='text/xml')
  489. # html
  490. request.errors.append(gettext('search error'))
  491. return render(
  492. # fmt: off
  493. 'index.html',
  494. selected_categories=get_selected_categories(request.preferences, request.form),
  495. # fmt: on
  496. )
  497. @app.route('/', methods=['GET', 'POST'])
  498. def index():
  499. """Render index page."""
  500. # redirect to search if there's a query in the request
  501. if request.form.get('q'):
  502. query = ('?' + request.query_string.decode()) if request.query_string else ''
  503. return redirect(url_for('search') + query, 308)
  504. return render(
  505. # fmt: off
  506. 'index.html',
  507. selected_categories=get_selected_categories(request.preferences, request.form),
  508. current_locale = request.preferences.get_value("locale"),
  509. # fmt: on
  510. )
  511. @app.route('/healthz', methods=['GET'])
  512. def health():
  513. return Response('OK', mimetype='text/plain')
  514. @app.route('/client<token>.css', methods=['GET', 'POST'])
  515. def client_token(token=None):
  516. link_token.ping(request, token)
  517. return Response('', mimetype='text/css')
  518. @app.route('/search', methods=['GET', 'POST'])
  519. def search():
  520. """Search query in q and return results.
  521. Supported outputs: html, json, csv, rss.
  522. """
  523. # pylint: disable=too-many-locals, too-many-return-statements, too-many-branches
  524. # pylint: disable=too-many-statements
  525. # output_format
  526. output_format = request.form.get('format', 'html')
  527. if output_format not in OUTPUT_FORMATS:
  528. output_format = 'html'
  529. if output_format not in settings['search']['formats']:
  530. flask.abort(403)
  531. # check if there is query (not None and not an empty string)
  532. if not request.form.get('q'):
  533. if output_format == 'html':
  534. return render(
  535. # fmt: off
  536. 'index.html',
  537. selected_categories=get_selected_categories(request.preferences, request.form),
  538. # fmt: on
  539. )
  540. return index_error(output_format, 'No query'), 400
  541. # search
  542. search_query = None
  543. raw_text_query = None
  544. result_container = None
  545. try:
  546. search_query, raw_text_query, _, _, selected_locale = get_search_query_from_webapp(
  547. request.preferences, request.form
  548. )
  549. search = SearchWithPlugins(search_query, request.user_plugins, request) # pylint: disable=redefined-outer-name
  550. result_container = search.search()
  551. except SearxParameterException as e:
  552. logger.exception('search error: SearxParameterException')
  553. return index_error(output_format, e.message), 400
  554. except Exception as e: # pylint: disable=broad-except
  555. logger.exception(e, exc_info=True)
  556. return index_error(output_format, gettext('search error')), 500
  557. # 1. check if the result is a redirect for an external bang
  558. if result_container.redirect_url:
  559. return redirect(result_container.redirect_url)
  560. # 2. add Server-Timing header for measuring performance characteristics of
  561. # web applications
  562. request.timings = result_container.get_timings() # pylint: disable=assigning-non-slot
  563. # 3. formats without a template
  564. if output_format == 'json':
  565. response = webutils.get_json_response(search_query, result_container)
  566. return Response(response, mimetype='application/json')
  567. if output_format == 'csv':
  568. csv = webutils.CSVWriter(StringIO())
  569. webutils.write_csv_response(csv, result_container)
  570. csv.stream.seek(0)
  571. response = Response(csv.stream.read(), mimetype='application/csv')
  572. cont_disp = 'attachment;Filename=searx_-_{0}.csv'.format(search_query.query)
  573. response.headers.add('Content-Disposition', cont_disp)
  574. return response
  575. # 4. formats rendered by a template / RSS & HTML
  576. current_template = None
  577. previous_result = None
  578. results = result_container.get_ordered_results()
  579. if search_query.redirect_to_first_result and results:
  580. return redirect(results[0]['url'], 302)
  581. for result in results:
  582. if output_format == 'html':
  583. if 'content' in result and result['content']:
  584. result['content'] = highlight_content(escape(result['content'][:1024]), search_query.query)
  585. if 'title' in result and result['title']:
  586. result['title'] = highlight_content(escape(result['title'] or ''), search_query.query)
  587. if 'url' in result:
  588. result['pretty_url'] = webutils.prettify_url(result['url'])
  589. if result.get('publishedDate'): # do not try to get a date from an empty string or a None type
  590. try: # test if publishedDate >= 1900 (datetime module bug)
  591. result['pubdate'] = result['publishedDate'].strftime('%Y-%m-%d %H:%M:%S%z')
  592. except ValueError:
  593. result['publishedDate'] = None
  594. else:
  595. result['publishedDate'] = webutils.searxng_l10n_timespan(result['publishedDate'])
  596. # set result['open_group'] = True when the template changes from the previous result
  597. # set result['close_group'] = True when the template changes on the next result
  598. if current_template != result.get('template'):
  599. result['open_group'] = True
  600. if previous_result:
  601. previous_result['close_group'] = True # pylint: disable=unsupported-assignment-operation
  602. current_template = result.get('template')
  603. previous_result = result
  604. if previous_result:
  605. previous_result['close_group'] = True
  606. # 4.a RSS
  607. if output_format == 'rss':
  608. response_rss = render(
  609. 'opensearch_response_rss.xml',
  610. results=results,
  611. answers=result_container.answers,
  612. corrections=result_container.corrections,
  613. suggestions=result_container.suggestions,
  614. q=request.form['q'],
  615. number_of_results=result_container.number_of_results,
  616. )
  617. return Response(response_rss, mimetype='text/xml')
  618. # 4.b HTML
  619. # suggestions: use RawTextQuery to get the suggestion URLs with the same bang
  620. suggestion_urls = list(
  621. map(
  622. lambda suggestion: {'url': raw_text_query.changeQuery(suggestion).getFullQuery(), 'title': suggestion},
  623. result_container.suggestions,
  624. )
  625. )
  626. correction_urls = list(
  627. map(
  628. lambda correction: {'url': raw_text_query.changeQuery(correction).getFullQuery(), 'title': correction},
  629. result_container.corrections,
  630. )
  631. )
  632. # engine_timings: get engine response times sorted from slowest to fastest
  633. engine_timings = sorted(result_container.get_timings(), reverse=True, key=lambda e: e.total)
  634. max_response_time = engine_timings[0].total if engine_timings else None
  635. engine_timings_pairs = [(timing.engine, timing.total) for timing in engine_timings]
  636. # search_query.lang contains the user choice (all, auto, en, ...)
  637. # when the user choice is "auto", search.search_query.lang contains the detected language
  638. # otherwise it is equals to search_query.lang
  639. return render(
  640. # fmt: off
  641. 'results.html',
  642. results = results,
  643. q=request.form['q'],
  644. selected_categories = search_query.categories,
  645. pageno = search_query.pageno,
  646. time_range = search_query.time_range or '',
  647. number_of_results = format_decimal(result_container.number_of_results),
  648. suggestions = suggestion_urls,
  649. answers = result_container.answers,
  650. corrections = correction_urls,
  651. infoboxes = result_container.infoboxes,
  652. engine_data = result_container.engine_data,
  653. paging = result_container.paging,
  654. unresponsive_engines = webutils.get_translated_errors(
  655. result_container.unresponsive_engines
  656. ),
  657. current_locale = request.preferences.get_value("locale"),
  658. current_language = selected_locale,
  659. search_language = match_locale(
  660. search.search_query.lang,
  661. settings['search']['languages'],
  662. fallback=request.preferences.get_value("language")
  663. ),
  664. timeout_limit = request.form.get('timeout_limit', None),
  665. timings = engine_timings_pairs,
  666. max_response_time = max_response_time
  667. # fmt: on
  668. )
  669. @app.route('/about', methods=['GET'])
  670. def about():
  671. """Redirect to about page"""
  672. # custom_url_for is going to add the locale
  673. return redirect(custom_url_for('info', pagename='about'))
  674. @app.route('/info/<locale>/<pagename>', methods=['GET'])
  675. def info(pagename, locale):
  676. """Render page of online user documentation"""
  677. page = infopage.INFO_PAGES.get_page(pagename, locale)
  678. if page is None:
  679. flask.abort(404)
  680. user_locale = request.preferences.get_value('locale')
  681. return render(
  682. 'info.html',
  683. all_pages=infopage.INFO_PAGES.iter_pages(user_locale, fallback_to_default=True),
  684. active_page=page,
  685. active_pagename=pagename,
  686. )
  687. @app.route('/autocompleter', methods=['GET', 'POST'])
  688. def autocompleter():
  689. """Return autocompleter results"""
  690. # run autocompleter
  691. results = []
  692. # set blocked engines
  693. disabled_engines = request.preferences.engines.get_disabled()
  694. # parse query
  695. raw_text_query = RawTextQuery(request.form.get('q', ''), disabled_engines)
  696. sug_prefix = raw_text_query.getQuery()
  697. # normal autocompletion results only appear if no inner results returned
  698. # and there is a query part
  699. if len(raw_text_query.autocomplete_list) == 0 and len(sug_prefix) > 0:
  700. # get SearXNG's locale and autocomplete backend from cookie
  701. sxng_locale = request.preferences.get_value('language')
  702. backend_name = request.preferences.get_value('autocomplete')
  703. for result in search_autocomplete(backend_name, sug_prefix, sxng_locale):
  704. # attention: this loop will change raw_text_query object and this is
  705. # the reason why the sug_prefix was stored before (see above)
  706. if result != sug_prefix:
  707. results.append(raw_text_query.changeQuery(result).getFullQuery())
  708. if len(raw_text_query.autocomplete_list) > 0:
  709. for autocomplete_text in raw_text_query.autocomplete_list:
  710. results.append(raw_text_query.get_autocomplete_full_query(autocomplete_text))
  711. for answers in ask(raw_text_query):
  712. for answer in answers:
  713. results.append(str(answer['answer']))
  714. if request.headers.get('X-Requested-With') == 'XMLHttpRequest':
  715. # the suggestion request comes from the searx search form
  716. suggestions = json.dumps(results)
  717. mimetype = 'application/json'
  718. else:
  719. # the suggestion request comes from browser's URL bar
  720. suggestions = json.dumps([sug_prefix, results])
  721. mimetype = 'application/x-suggestions+json'
  722. suggestions = escape(suggestions, False)
  723. return Response(suggestions, mimetype=mimetype)
  724. @app.route('/favicon', methods=['GET'])
  725. def favicon_proxy():
  726. """Return proxied favicon results"""
  727. url = request.args.get('q')
  728. # malformed request
  729. if not url:
  730. return '', 400
  731. # malformed request / does not have authorisation
  732. if not is_hmac_of(settings['server']['secret_key'], url.encode(), request.args.get('h', '')):
  733. return '', 400
  734. resolver = request.preferences.get_value('favicon_resolver')
  735. # check if the favicon resolver is valid
  736. if not resolver or resolver not in favicon_backends:
  737. return '', 400
  738. # parse query
  739. raw_text_query = RawTextQuery(url, [])
  740. resp = search_favicon(resolver, raw_text_query)
  741. # return 404 if the favicon is not found
  742. if not resp:
  743. theme = request.preferences.get_value("theme")
  744. # return favicon from /static/themes/simple/img/empty_favicon.svg
  745. # we can't rely on an onerror event in the img tag to display a default favicon as this violates the CSP.
  746. # using redirect to save network bandwidth (user will have this location cached).
  747. return redirect(url_for('static', filename='themes/' + theme + '/img/empty_favicon.svg'))
  748. # will always return a PNG image
  749. return Response(resp, mimetype='image/png')
  750. @app.route('/preferences', methods=['GET', 'POST'])
  751. def preferences():
  752. """Render preferences page && save user preferences"""
  753. # pylint: disable=too-many-locals, too-many-return-statements, too-many-branches
  754. # pylint: disable=too-many-statements
  755. # save preferences using the link the /preferences?preferences=...
  756. if request.args.get('preferences') or request.form.get('preferences'):
  757. resp = make_response(redirect(url_for('index', _external=True)))
  758. return request.preferences.save(resp)
  759. # save preferences
  760. if request.method == 'POST':
  761. resp = make_response(redirect(url_for('index', _external=True)))
  762. try:
  763. request.preferences.parse_form(request.form)
  764. except ValidationException:
  765. request.errors.append(gettext('Invalid settings, please edit your preferences'))
  766. return resp
  767. return request.preferences.save(resp)
  768. # render preferences
  769. image_proxy = request.preferences.get_value('image_proxy') # pylint: disable=redefined-outer-name
  770. disabled_engines = request.preferences.engines.get_disabled()
  771. allowed_plugins = request.preferences.plugins.get_enabled()
  772. # stats for preferences page
  773. filtered_engines = dict(filter(lambda kv: request.preferences.validate_token(kv[1]), engines.items()))
  774. engines_by_category = {}
  775. for c in categories: # pylint: disable=consider-using-dict-items
  776. engines_by_category[c] = [e for e in categories[c] if e.name in filtered_engines]
  777. # sort the engines alphabetically since the order in settings.yml is meaningless.
  778. list.sort(engines_by_category[c], key=lambda e: e.name)
  779. # get first element [0], the engine time,
  780. # and then the second element [1] : the time (the first one is the label)
  781. stats = {} # pylint: disable=redefined-outer-name
  782. max_rate95 = 0
  783. for _, e in filtered_engines.items():
  784. h = histogram('engine', e.name, 'time', 'total')
  785. median = round(h.percentage(50), 1) if h.count > 0 else None
  786. rate80 = round(h.percentage(80), 1) if h.count > 0 else None
  787. rate95 = round(h.percentage(95), 1) if h.count > 0 else None
  788. max_rate95 = max(max_rate95, rate95 or 0)
  789. result_count_sum = histogram('engine', e.name, 'result', 'count').sum
  790. successful_count = counter('engine', e.name, 'search', 'count', 'successful')
  791. result_count = int(result_count_sum / float(successful_count)) if successful_count else 0
  792. stats[e.name] = {
  793. 'time': median,
  794. 'rate80': rate80,
  795. 'rate95': rate95,
  796. 'warn_timeout': e.timeout > settings['outgoing']['request_timeout'],
  797. 'supports_selected_language': e.traits.is_locale_supported(
  798. str(request.preferences.get_value('language') or 'all')
  799. ),
  800. 'result_count': result_count,
  801. }
  802. # end of stats
  803. # reliabilities
  804. reliabilities = {}
  805. engine_errors = get_engine_errors(filtered_engines)
  806. checker_results = checker_get_result()
  807. checker_results = (
  808. checker_results['engines'] if checker_results['status'] == 'ok' and 'engines' in checker_results else {}
  809. )
  810. for _, e in filtered_engines.items():
  811. checker_result = checker_results.get(e.name, {})
  812. checker_success = checker_result.get('success', True)
  813. errors = engine_errors.get(e.name) or []
  814. if counter('engine', e.name, 'search', 'count', 'sent') == 0:
  815. # no request
  816. reliability = None
  817. elif checker_success and not errors:
  818. reliability = 100
  819. elif 'simple' in checker_result.get('errors', {}):
  820. # the basic (simple) test doesn't work: the engine is broken according to the checker
  821. # even if there is no exception
  822. reliability = 0
  823. else:
  824. # pylint: disable=consider-using-generator
  825. reliability = 100 - sum([error['percentage'] for error in errors if not error.get('secondary')])
  826. reliabilities[e.name] = {
  827. 'reliability': reliability,
  828. 'errors': [],
  829. 'checker': checker_results.get(e.name, {}).get('errors', {}).keys(),
  830. }
  831. # keep the order of the list checker_results[e.name]['errors'] and deduplicate.
  832. # the first element has the highest percentage rate.
  833. reliabilities_errors = []
  834. for error in errors:
  835. error_user_text = None
  836. if error.get('secondary') or 'exception_classname' not in error:
  837. continue
  838. error_user_text = exception_classname_to_text.get(error.get('exception_classname'))
  839. if not error:
  840. error_user_text = exception_classname_to_text[None]
  841. if error_user_text not in reliabilities_errors:
  842. reliabilities_errors.append(error_user_text)
  843. reliabilities[e.name]['errors'] = reliabilities_errors
  844. # supports
  845. supports = {}
  846. for _, e in filtered_engines.items():
  847. supports_selected_language = e.traits.is_locale_supported(
  848. str(request.preferences.get_value('language') or 'all')
  849. )
  850. safesearch = e.safesearch
  851. time_range_support = e.time_range_support
  852. for checker_test_name in checker_results.get(e.name, {}).get('errors', {}):
  853. if supports_selected_language and checker_test_name.startswith('lang_'):
  854. supports_selected_language = '?'
  855. elif safesearch and checker_test_name == 'safesearch':
  856. safesearch = '?'
  857. elif time_range_support and checker_test_name == 'time_range':
  858. time_range_support = '?'
  859. supports[e.name] = {
  860. 'supports_selected_language': supports_selected_language,
  861. 'safesearch': safesearch,
  862. 'time_range_support': time_range_support,
  863. }
  864. return render(
  865. # fmt: off
  866. 'preferences.html',
  867. selected_categories = get_selected_categories(request.preferences, request.form),
  868. locales = LOCALE_NAMES,
  869. current_locale = request.preferences.get_value("locale"),
  870. image_proxy = image_proxy,
  871. engines_by_category = engines_by_category,
  872. stats = stats,
  873. max_rate95 = max_rate95,
  874. reliabilities = reliabilities,
  875. supports = supports,
  876. answerers = [
  877. {'info': a.self_info(), 'keywords': a.keywords}
  878. for a in answerers
  879. ],
  880. disabled_engines = disabled_engines,
  881. autocomplete_backends = autocomplete_backends,
  882. favicon_backends = favicon_backends,
  883. shortcuts = {y: x for x, y in engine_shortcuts.items()},
  884. themes = themes,
  885. plugins = plugins,
  886. doi_resolvers = settings['doi_resolvers'],
  887. current_doi_resolver = get_doi_resolver(request.preferences),
  888. allowed_plugins = allowed_plugins,
  889. preferences_url_params = request.preferences.get_as_url_params(),
  890. locked_preferences = settings['preferences']['lock'],
  891. preferences = True
  892. # fmt: on
  893. )
  894. @app.route('/image_proxy', methods=['GET'])
  895. def image_proxy():
  896. # pylint: disable=too-many-return-statements, too-many-branches
  897. url = request.args.get('url')
  898. if not url:
  899. return '', 400
  900. if not is_hmac_of(settings['server']['secret_key'], url.encode(), request.args.get('h', '')):
  901. return '', 400
  902. maximum_size = 5 * 1024 * 1024
  903. forward_resp = False
  904. resp = None
  905. try:
  906. request_headers = {
  907. 'User-Agent': gen_useragent(),
  908. 'Accept': 'image/webp,*/*',
  909. 'Accept-Encoding': 'gzip, deflate',
  910. 'Sec-GPC': '1',
  911. 'DNT': '1',
  912. }
  913. set_context_network_name('image_proxy')
  914. resp, stream = http_stream(method='GET', url=url, headers=request_headers, allow_redirects=True)
  915. content_length = resp.headers.get('Content-Length')
  916. if content_length and content_length.isdigit() and int(content_length) > maximum_size:
  917. return 'Max size', 400
  918. if resp.status_code != 200:
  919. logger.debug('image-proxy: wrong response code: %i', resp.status_code)
  920. if resp.status_code >= 400:
  921. return '', resp.status_code
  922. return '', 400
  923. if not resp.headers.get('Content-Type', '').startswith('image/') and not resp.headers.get(
  924. 'Content-Type', ''
  925. ).startswith('binary/octet-stream'):
  926. logger.debug('image-proxy: wrong content-type: %s', resp.headers.get('Content-Type', ''))
  927. return '', 400
  928. forward_resp = True
  929. except httpx.HTTPError:
  930. logger.exception('HTTP error')
  931. return '', 400
  932. finally:
  933. if resp and not forward_resp:
  934. # the code is about to return an HTTP 400 error to the browser
  935. # we make sure to close the response between searxng and the HTTP server
  936. try:
  937. resp.close()
  938. except httpx.HTTPError:
  939. logger.exception('HTTP error on closing')
  940. def close_stream():
  941. nonlocal resp, stream
  942. try:
  943. if resp:
  944. resp.close()
  945. del resp
  946. del stream
  947. except httpx.HTTPError as e:
  948. logger.debug('Exception while closing response', e)
  949. try:
  950. headers = dict_subset(resp.headers, {'Content-Type', 'Content-Encoding', 'Content-Length', 'Length'})
  951. response = Response(stream, mimetype=resp.headers['Content-Type'], headers=headers, direct_passthrough=True)
  952. response.call_on_close(close_stream)
  953. return response
  954. except httpx.HTTPError:
  955. close_stream()
  956. return '', 400
  957. @app.route('/engine_descriptions.json', methods=['GET'])
  958. def engine_descriptions():
  959. locale = get_locale().split('_')[0]
  960. result = ENGINE_DESCRIPTIONS['en'].copy()
  961. if locale != 'en':
  962. for engine, description in ENGINE_DESCRIPTIONS.get(locale, {}).items():
  963. result[engine] = description
  964. for engine, description in result.items():
  965. if len(description) == 2 and description[1] == 'ref':
  966. ref_engine, ref_lang = description[0].split(':')
  967. description = ENGINE_DESCRIPTIONS[ref_lang][ref_engine]
  968. if isinstance(description, str):
  969. description = [description, 'wikipedia']
  970. result[engine] = description
  971. # overwrite by about:description (from settings)
  972. for engine_name, engine_mod in engines.items():
  973. descr = getattr(engine_mod, 'about', {}).get('description', None)
  974. if descr is not None:
  975. result[engine_name] = [descr, "SearXNG config"]
  976. return jsonify(result)
  977. @app.route('/stats', methods=['GET'])
  978. def stats():
  979. """Render engine statistics page."""
  980. sort_order = request.args.get('sort', default='name', type=str)
  981. selected_engine_name = request.args.get('engine', default=None, type=str)
  982. filtered_engines = dict(filter(lambda kv: request.preferences.validate_token(kv[1]), engines.items()))
  983. if selected_engine_name:
  984. if selected_engine_name not in filtered_engines:
  985. selected_engine_name = None
  986. else:
  987. filtered_engines = [selected_engine_name]
  988. checker_results = checker_get_result()
  989. checker_results = (
  990. checker_results['engines'] if checker_results['status'] == 'ok' and 'engines' in checker_results else {}
  991. )
  992. engine_stats = get_engines_stats(filtered_engines)
  993. engine_reliabilities = get_reliabilities(filtered_engines, checker_results)
  994. if sort_order not in STATS_SORT_PARAMETERS:
  995. sort_order = 'name'
  996. reverse, key_name, default_value = STATS_SORT_PARAMETERS[sort_order]
  997. def get_key(engine_stat):
  998. reliability = engine_reliabilities.get(engine_stat['name'], {}).get('reliability', 0)
  999. reliability_order = 0 if reliability else 1
  1000. if key_name == 'reliability':
  1001. key = reliability
  1002. reliability_order = 0
  1003. else:
  1004. key = engine_stat.get(key_name) or default_value
  1005. if reverse:
  1006. reliability_order = 1 - reliability_order
  1007. return (reliability_order, key, engine_stat['name'])
  1008. technical_report = []
  1009. for error in engine_reliabilities.get(selected_engine_name, {}).get('errors', []):
  1010. technical_report.append(
  1011. f"\
  1012. Error: {error['exception_classname'] or error['log_message']} \
  1013. Parameters: {error['log_parameters']} \
  1014. File name: {error['filename'] }:{ error['line_no'] } \
  1015. Error Function: {error['function']} \
  1016. Code: {error['code']} \
  1017. ".replace(
  1018. ' ' * 12, ''
  1019. ).strip()
  1020. )
  1021. technical_report = ' '.join(technical_report)
  1022. engine_stats['time'] = sorted(engine_stats['time'], reverse=reverse, key=get_key)
  1023. return render(
  1024. # fmt: off
  1025. 'stats.html',
  1026. sort_order = sort_order,
  1027. engine_stats = engine_stats,
  1028. engine_reliabilities = engine_reliabilities,
  1029. selected_engine_name = selected_engine_name,
  1030. searx_git_branch = GIT_BRANCH,
  1031. technical_report = technical_report,
  1032. # fmt: on
  1033. )
  1034. @app.route('/stats/errors', methods=['GET'])
  1035. def stats_errors():
  1036. filtered_engines = dict(filter(lambda kv: request.preferences.validate_token(kv[1]), engines.items()))
  1037. result = get_engine_errors(filtered_engines)
  1038. return jsonify(result)
  1039. @app.route('/stats/checker', methods=['GET'])
  1040. def stats_checker():
  1041. result = checker_get_result()
  1042. return jsonify(result)
  1043. @app.route('/robots.txt', methods=['GET'])
  1044. def robots():
  1045. return Response(
  1046. """User-agent: *
  1047. Allow: /info/en/about
  1048. Disallow: /stats
  1049. Disallow: /image_proxy
  1050. Disallow: /preferences
  1051. Disallow: /*?*q=*
  1052. """,
  1053. mimetype='text/plain',
  1054. )
  1055. @app.route('/opensearch.xml', methods=['GET'])
  1056. def opensearch():
  1057. method = request.preferences.get_value('method')
  1058. autocomplete = request.preferences.get_value('autocomplete')
  1059. # chrome/chromium only supports HTTP GET....
  1060. if request.headers.get('User-Agent', '').lower().find('webkit') >= 0:
  1061. method = 'GET'
  1062. if method not in ('POST', 'GET'):
  1063. method = 'POST'
  1064. ret = render('opensearch.xml', opensearch_method=method, autocomplete=autocomplete)
  1065. resp = Response(response=ret, status=200, mimetype="application/opensearchdescription+xml")
  1066. return resp
  1067. @app.route('/favicon.ico')
  1068. def favicon():
  1069. theme = request.preferences.get_value("theme")
  1070. return send_from_directory(
  1071. os.path.join(app.root_path, settings['ui']['static_path'], 'themes', theme, 'img'), # pyright: ignore
  1072. 'favicon.png',
  1073. mimetype='image/vnd.microsoft.icon',
  1074. )
  1075. @app.route('/clear_cookies')
  1076. def clear_cookies():
  1077. resp = make_response(redirect(url_for('index', _external=True)))
  1078. for cookie_name in request.cookies:
  1079. resp.delete_cookie(cookie_name)
  1080. return resp
  1081. @app.route('/config')
  1082. def config():
  1083. """Return configuration in JSON format."""
  1084. _engines = []
  1085. for name, engine in engines.items():
  1086. if not request.preferences.validate_token(engine):
  1087. continue
  1088. _languages = engine.traits.languages.keys()
  1089. _engines.append(
  1090. {
  1091. 'name': name,
  1092. 'categories': engine.categories,
  1093. 'shortcut': engine.shortcut,
  1094. 'enabled': not engine.disabled,
  1095. 'paging': engine.paging,
  1096. 'language_support': engine.language_support,
  1097. 'languages': list(_languages),
  1098. 'regions': list(engine.traits.regions.keys()),
  1099. 'safesearch': engine.safesearch,
  1100. 'time_range_support': engine.time_range_support,
  1101. 'timeout': engine.timeout,
  1102. }
  1103. )
  1104. _plugins = []
  1105. for _ in plugins:
  1106. _plugins.append({'name': _.name, 'enabled': _.default_on})
  1107. _limiter_cfg = limiter.get_cfg()
  1108. return jsonify(
  1109. {
  1110. 'categories': list(categories.keys()),
  1111. 'engines': _engines,
  1112. 'plugins': _plugins,
  1113. 'instance_name': settings['general']['instance_name'],
  1114. 'locales': LOCALE_NAMES,
  1115. 'default_locale': settings['ui']['default_locale'],
  1116. 'autocomplete': settings['search']['autocomplete'],
  1117. 'safe_search': settings['search']['safe_search'],
  1118. 'default_theme': settings['ui']['default_theme'],
  1119. 'version': VERSION_STRING,
  1120. 'brand': {
  1121. 'PRIVACYPOLICY_URL': get_setting('general.privacypolicy_url'),
  1122. 'CONTACT_URL': get_setting('general.contact_url'),
  1123. 'GIT_URL': GIT_URL,
  1124. 'GIT_BRANCH': GIT_BRANCH,
  1125. 'DOCS_URL': get_setting('brand.docs_url'),
  1126. },
  1127. 'limiter': {
  1128. 'enabled': limiter.is_installed(),
  1129. 'botdetection.ip_limit.link_token': _limiter_cfg.get('botdetection.ip_limit.link_token'),
  1130. 'botdetection.ip_lists.pass_searxng_org': _limiter_cfg.get('botdetection.ip_lists.pass_searxng_org'),
  1131. },
  1132. 'doi_resolvers': list(settings['doi_resolvers'].keys()),
  1133. 'default_doi_resolver': settings['default_doi_resolver'],
  1134. 'public_instance': settings['server']['public_instance'],
  1135. }
  1136. )
  1137. @app.errorhandler(404)
  1138. def page_not_found(_e):
  1139. return render('404.html'), 404
  1140. # see https://flask.palletsprojects.com/en/1.1.x/cli/
  1141. # True if "FLASK_APP=searx/webapp.py FLASK_ENV=development flask run"
  1142. flask_run_development = (
  1143. os.environ.get("FLASK_APP") is not None and os.environ.get("FLASK_ENV") == 'development' and is_flask_run_cmdline()
  1144. )
  1145. # True if reload feature is activated of werkzeug, False otherwise (including uwsgi, etc..)
  1146. # __name__ != "__main__" if searx.webapp is imported (make test, make docs, uwsgi...)
  1147. # see run() at the end of this file : searx_debug activates the reload feature.
  1148. werkzeug_reloader = flask_run_development or (searx_debug and __name__ == "__main__")
  1149. # initialize the engines except on the first run of the werkzeug server.
  1150. if not werkzeug_reloader or (werkzeug_reloader and os.environ.get("WERKZEUG_RUN_MAIN") == "true"):
  1151. locales_initialize()
  1152. redis_initialize()
  1153. plugin_initialize(app)
  1154. search_initialize(enable_checker=True, check_network=True, enable_metrics=settings['general']['enable_metrics'])
  1155. limiter.initialize(app, settings)
  1156. def run():
  1157. logger.debug('starting webserver on %s:%s', settings['server']['bind_address'], settings['server']['port'])
  1158. app.run(
  1159. debug=searx_debug,
  1160. use_debugger=searx_debug,
  1161. port=settings['server']['port'],
  1162. host=settings['server']['bind_address'],
  1163. threaded=True,
  1164. extra_files=[DEFAULT_SETTINGS_FILE],
  1165. )
  1166. application = app
  1167. patch_application(app)
  1168. if __name__ == "__main__":
  1169. run()