webapp.py 51 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453
  1. #!/usr/bin/env python
  2. # SPDX-License-Identifier: AGPL-3.0-or-later
  3. """WebbApp
  4. """
  5. # pylint: disable=use-dict-literal
  6. from __future__ import annotations
  7. import inspect
  8. import json
  9. import os
  10. import sys
  11. import base64
  12. from timeit import default_timer
  13. from html import escape
  14. from io import StringIO
  15. import typing
  16. import urllib
  17. import urllib.parse
  18. from urllib.parse import urlencode, urlparse, unquote
  19. import warnings
  20. import httpx
  21. from pygments import highlight
  22. from pygments.lexers import get_lexer_by_name
  23. from pygments.formatters import HtmlFormatter # pylint: disable=no-name-in-module
  24. from werkzeug.serving import is_running_from_reloader
  25. from whitenoise import WhiteNoise
  26. from whitenoise.base import Headers
  27. import flask
  28. from flask import (
  29. Flask,
  30. render_template,
  31. url_for,
  32. make_response,
  33. redirect,
  34. send_from_directory,
  35. )
  36. from flask.wrappers import Response
  37. from flask.json import jsonify
  38. from flask_babel import (
  39. Babel,
  40. gettext,
  41. format_decimal,
  42. )
  43. import searx
  44. from searx.extended_types import sxng_request
  45. from searx import (
  46. logger,
  47. get_setting,
  48. settings,
  49. )
  50. from searx import infopage
  51. from searx import limiter
  52. from searx.botdetection import link_token
  53. from searx.data import ENGINE_DESCRIPTIONS
  54. from searx.result_types import Answer
  55. from searx.settings_defaults import OUTPUT_FORMATS
  56. from searx.settings_loader import DEFAULT_SETTINGS_FILE
  57. from searx.exceptions import SearxParameterException
  58. from searx.engines import (
  59. DEFAULT_CATEGORY,
  60. categories,
  61. engines,
  62. engine_shortcuts,
  63. )
  64. from searx import webutils
  65. from searx.webutils import (
  66. highlight_content,
  67. get_result_templates,
  68. get_themes,
  69. exception_classname_to_text,
  70. new_hmac,
  71. is_hmac_of,
  72. group_engines_in_tab,
  73. )
  74. from searx.webadapter import (
  75. get_search_query_from_webapp,
  76. get_selected_categories,
  77. parse_lang,
  78. )
  79. from searx.utils import gen_useragent, dict_subset
  80. from searx.version import VERSION_STRING, GIT_URL, GIT_BRANCH
  81. from searx.query import RawTextQuery
  82. from searx.plugins.oa_doi_rewrite import get_doi_resolver
  83. from searx.preferences import (
  84. Preferences,
  85. ClientPref,
  86. ValidationException,
  87. )
  88. import searx.answerers
  89. import searx.plugins
  90. from searx.metrics import get_engines_stats, get_engine_errors, get_reliabilities, histogram, counter, openmetrics
  91. from searx.flaskfix import patch_application
  92. from searx.locales import (
  93. LOCALE_BEST_MATCH,
  94. LOCALE_NAMES,
  95. RTL_LOCALES,
  96. localeselector,
  97. locales_initialize,
  98. match_locale,
  99. )
  100. # renaming names from searx imports ...
  101. from searx.autocomplete import search_autocomplete, backends as autocomplete_backends
  102. from searx import favicons
  103. from searx.valkeydb import initialize as valkey_initialize
  104. from searx.sxng_locales import sxng_locales
  105. import searx.search
  106. from searx.network import stream as http_stream, set_context_network_name
  107. from searx.search.checker import get_result as checker_get_result
  108. logger = logger.getChild('webapp')
  109. warnings.simplefilter("always")
  110. # about static
  111. logger.debug('static directory is %s', settings['ui']['static_path'])
  112. # about templates
  113. logger.debug('templates directory is %s', settings['ui']['templates_path'])
  114. default_theme = settings['ui']['default_theme']
  115. templates_path = settings['ui']['templates_path']
  116. themes = get_themes(templates_path)
  117. result_templates = get_result_templates(templates_path)
  118. STATS_SORT_PARAMETERS = {
  119. 'name': (False, 'name', ''),
  120. 'score': (True, 'score_per_result', 0),
  121. 'result_count': (True, 'result_count', 0),
  122. 'time': (False, 'total', 0),
  123. 'reliability': (False, 'reliability', 100),
  124. }
  125. # Flask app
  126. app = Flask(__name__, static_folder=None, template_folder=templates_path)
  127. app.jinja_env.trim_blocks = True
  128. app.jinja_env.lstrip_blocks = True
  129. app.jinja_env.add_extension('jinja2.ext.loopcontrols') # pylint: disable=no-member
  130. app.jinja_env.filters['group_engines_in_tab'] = group_engines_in_tab # pylint: disable=no-member
  131. app.secret_key = settings['server']['secret_key']
  132. def get_locale():
  133. locale = localeselector()
  134. logger.debug("%s uses locale `%s`", urllib.parse.quote(sxng_request.url), locale)
  135. return locale
  136. babel = Babel(app, locale_selector=get_locale)
  137. def _get_browser_language(req, lang_list):
  138. client = ClientPref.from_http_request(req)
  139. locale = match_locale(client.locale_tag, lang_list, fallback='en')
  140. return locale
  141. def _get_locale_rfc5646(locale):
  142. """Get locale name for <html lang="...">
  143. Chrom* browsers don't detect the language when there is a subtag (ie a territory).
  144. For example "zh-TW" is detected but not "zh-Hant-TW".
  145. This function returns a locale without the subtag.
  146. """
  147. parts = locale.split('-')
  148. return parts[0].lower() + '-' + parts[-1].upper()
  149. # code-highlighter
  150. @app.template_filter('code_highlighter')
  151. def code_highlighter(codelines, language=None):
  152. if not language:
  153. language = 'text'
  154. try:
  155. # find lexer by programming language
  156. lexer = get_lexer_by_name(language, stripall=True)
  157. except Exception as e: # pylint: disable=broad-except
  158. logger.warning("pygments lexer: %s " % e)
  159. # if lexer is not found, using default one
  160. lexer = get_lexer_by_name('text', stripall=True)
  161. html_code = ''
  162. tmp_code = ''
  163. last_line = None
  164. line_code_start = None
  165. # parse lines
  166. for line, code in codelines:
  167. if not last_line:
  168. line_code_start = line
  169. # new codeblock is detected
  170. if last_line is not None and last_line + 1 != line:
  171. # highlight last codepart
  172. formatter = HtmlFormatter(linenos='inline', linenostart=line_code_start, cssclass="code-highlight")
  173. html_code = html_code + highlight(tmp_code, lexer, formatter)
  174. # reset conditions for next codepart
  175. tmp_code = ''
  176. line_code_start = line
  177. # add codepart
  178. tmp_code += code + '\n'
  179. # update line
  180. last_line = line
  181. # highlight last codepart
  182. formatter = HtmlFormatter(linenos='inline', linenostart=line_code_start, cssclass="code-highlight")
  183. html_code = html_code + highlight(tmp_code, lexer, formatter)
  184. return html_code
  185. def get_result_template(theme_name: str, template_name: str):
  186. themed_path = theme_name + '/result_templates/' + template_name
  187. if themed_path in result_templates:
  188. return themed_path
  189. return 'result_templates/' + template_name
  190. _STATIC_FILES: list[str] = []
  191. def custom_url_for(endpoint: str, **values):
  192. global _STATIC_FILES # pylint: disable=global-statement
  193. if not _STATIC_FILES:
  194. _STATIC_FILES = webutils.get_static_file_list()
  195. # handled by WhiteNoise
  196. if endpoint == "static" and values.get("filename"):
  197. # We need to verify the "filename" argument: in the jinja templates
  198. # there could be call like:
  199. # url_for('static', filename='img/favicon.png')
  200. # which should map to:
  201. # static/themes/<theme_name>/img/favicon.png
  202. arg_filename = values["filename"]
  203. if arg_filename not in _STATIC_FILES:
  204. # try file in the current theme
  205. theme_name = sxng_request.preferences.get_value("theme")
  206. theme_filename = f"themes/{theme_name}/{arg_filename}"
  207. if theme_filename in _STATIC_FILES:
  208. values["filename"] = theme_filename
  209. return f"/static/{values['filename']}"
  210. if endpoint == "info" and "locale" not in values:
  211. # We need to verify the "locale" argument: in the jinja templates there
  212. # could be call like:
  213. # url_for('info', pagename='about')
  214. # which should map to:
  215. # info/<locale>/about
  216. locale = sxng_request.preferences.get_value("locale")
  217. if infopage.INFO_PAGES.get_page(values["pagename"], locale) is None:
  218. locale = infopage.INFO_PAGES.locale_default
  219. values["locale"] = locale
  220. return url_for(endpoint, **values)
  221. def image_proxify(url: str):
  222. if not url:
  223. return url
  224. if url.startswith('//'):
  225. url = 'https:' + url
  226. if not sxng_request.preferences.get_value('image_proxy'):
  227. return url
  228. if url.startswith('data:image/'):
  229. # 50 is an arbitrary number to get only the beginning of the image.
  230. partial_base64 = url[len('data:image/') : 50].split(';')
  231. if (
  232. len(partial_base64) == 2
  233. and partial_base64[0] in ['gif', 'png', 'jpeg', 'pjpeg', 'webp', 'tiff', 'bmp']
  234. and partial_base64[1].startswith('base64,')
  235. ):
  236. return url
  237. return None
  238. h = new_hmac(settings['server']['secret_key'], url.encode())
  239. return '{0}?{1}'.format(url_for('image_proxy'), urlencode(dict(url=url.encode(), h=h)))
  240. def get_translations():
  241. return {
  242. # when there is autocompletion
  243. 'no_item_found': gettext('No item found'),
  244. # /preferences: the source of the engine description (wikipedata, wikidata, website)
  245. 'Source': gettext('Source'),
  246. # infinite scroll
  247. 'error_loading_next_page': gettext('Error loading the next page'),
  248. }
  249. def get_enabled_categories(category_names: typing.Iterable[str]):
  250. """The categories in ``category_names```for which there is no active engine
  251. are filtered out and a reduced list is returned."""
  252. enabled_engines = [item[0] for item in sxng_request.preferences.engines.get_enabled()]
  253. enabled_categories = set()
  254. for engine_name in enabled_engines:
  255. enabled_categories.update(engines[engine_name].categories)
  256. return [x for x in category_names if x in enabled_categories]
  257. def get_pretty_url(parsed_url: urllib.parse.ParseResult):
  258. url_formatting_pref = sxng_request.preferences.get_value('url_formatting')
  259. if url_formatting_pref == 'full':
  260. return [parsed_url.geturl()]
  261. if url_formatting_pref == 'host':
  262. return [parsed_url.netloc]
  263. path = parsed_url.path
  264. path = path[:-1] if len(path) > 0 and path[-1] == '/' else path
  265. path = unquote(path.replace("/", " › "))
  266. return [parsed_url.scheme + "://" + parsed_url.netloc, path]
  267. def get_client_settings():
  268. req_pref = sxng_request.preferences
  269. return {
  270. 'autocomplete': req_pref.get_value('autocomplete'),
  271. 'autocomplete_min': get_setting('search.autocomplete_min'),
  272. 'method': req_pref.get_value('method'),
  273. 'infinite_scroll': req_pref.get_value('infinite_scroll'),
  274. 'translations': get_translations(),
  275. 'search_on_category_select': req_pref.get_value('search_on_category_select'),
  276. 'hotkeys': req_pref.get_value('hotkeys'),
  277. 'url_formatting': req_pref.get_value('url_formatting'),
  278. 'theme_static_path': custom_url_for('static', filename='themes/simple'),
  279. 'results_on_new_tab': req_pref.get_value('results_on_new_tab'),
  280. 'favicon_resolver': req_pref.get_value('favicon_resolver'),
  281. 'advanced_search': req_pref.get_value('advanced_search'),
  282. 'query_in_title': req_pref.get_value('query_in_title'),
  283. 'safesearch': str(req_pref.get_value('safesearch')),
  284. 'theme': req_pref.get_value('theme'),
  285. 'doi_resolver': get_doi_resolver(),
  286. }
  287. def render(template_name: str, **kwargs):
  288. # values from the preferences
  289. # pylint: disable=too-many-statements
  290. client_settings = get_client_settings()
  291. kwargs['client_settings'] = str(
  292. base64.b64encode(
  293. bytes(
  294. json.dumps(client_settings),
  295. encoding='utf-8',
  296. )
  297. ),
  298. encoding='utf-8',
  299. )
  300. kwargs['preferences'] = sxng_request.preferences
  301. kwargs.update(client_settings)
  302. # values from the HTTP requests
  303. kwargs['endpoint'] = 'results' if 'q' in kwargs else sxng_request.endpoint
  304. kwargs['cookies'] = sxng_request.cookies
  305. kwargs['errors'] = sxng_request.errors
  306. kwargs['link_token'] = link_token.get_token()
  307. kwargs['categories_as_tabs'] = list(settings['categories_as_tabs'].keys())
  308. kwargs['categories'] = get_enabled_categories(settings['categories_as_tabs'].keys())
  309. kwargs['DEFAULT_CATEGORY'] = DEFAULT_CATEGORY
  310. # i18n
  311. kwargs['sxng_locales'] = [l for l in sxng_locales if l[0] in settings['search']['languages']]
  312. locale = sxng_request.preferences.get_value('locale')
  313. kwargs['locale_rfc5646'] = _get_locale_rfc5646(locale)
  314. if locale in RTL_LOCALES and 'rtl' not in kwargs:
  315. kwargs['rtl'] = True
  316. if 'current_language' not in kwargs:
  317. kwargs['current_language'] = parse_lang(sxng_request.preferences, {}, RawTextQuery('', []))
  318. # values from settings
  319. kwargs['search_formats'] = [x for x in settings['search']['formats'] if x != 'html']
  320. kwargs['instance_name'] = get_setting('general.instance_name')
  321. kwargs['searx_version'] = VERSION_STRING
  322. kwargs['searx_git_url'] = GIT_URL
  323. kwargs['enable_metrics'] = get_setting('general.enable_metrics')
  324. kwargs['get_setting'] = get_setting
  325. kwargs['get_pretty_url'] = get_pretty_url
  326. # values from settings: donation_url
  327. donation_url = get_setting('general.donation_url')
  328. if donation_url is True:
  329. donation_url = custom_url_for('info', pagename='donate')
  330. kwargs['donation_url'] = donation_url
  331. # helpers to create links to other pages
  332. kwargs['url_for'] = custom_url_for # override url_for function in templates
  333. kwargs['image_proxify'] = image_proxify
  334. kwargs['favicon_url'] = favicons.favicon_url
  335. kwargs['cache_url'] = settings['ui']['cache_url']
  336. kwargs['get_result_template'] = get_result_template
  337. kwargs['opensearch_url'] = (
  338. url_for('opensearch')
  339. + '?'
  340. + urlencode(
  341. {
  342. 'method': sxng_request.preferences.get_value('method'),
  343. 'autocomplete': sxng_request.preferences.get_value('autocomplete'),
  344. }
  345. )
  346. )
  347. kwargs['urlparse'] = urlparse
  348. start_time = default_timer()
  349. result = render_template('{}/{}'.format(kwargs['theme'], template_name), **kwargs)
  350. sxng_request.render_time += default_timer() - start_time # pylint: disable=assigning-non-slot
  351. return result
  352. @app.before_request
  353. def pre_request():
  354. sxng_request.start_time = default_timer() # pylint: disable=assigning-non-slot
  355. sxng_request.render_time = 0 # pylint: disable=assigning-non-slot
  356. sxng_request.timings = [] # pylint: disable=assigning-non-slot
  357. sxng_request.errors = [] # pylint: disable=assigning-non-slot
  358. client_pref = ClientPref.from_http_request(sxng_request)
  359. # pylint: disable=redefined-outer-name
  360. preferences = Preferences(themes, list(categories.keys()), engines, searx.plugins.STORAGE, client_pref)
  361. user_agent = sxng_request.headers.get('User-Agent', '').lower()
  362. if 'webkit' in user_agent and 'android' in user_agent:
  363. preferences.key_value_settings['method'].value = 'GET'
  364. sxng_request.preferences = preferences # pylint: disable=assigning-non-slot
  365. try:
  366. preferences.parse_dict(sxng_request.cookies)
  367. except Exception as e: # pylint: disable=broad-except
  368. logger.exception(e, exc_info=True)
  369. sxng_request.errors.append(gettext('Invalid settings, please edit your preferences'))
  370. # merge GET, POST vars
  371. # HINT request.form is of type werkzeug.datastructures.ImmutableMultiDict
  372. sxng_request.form = dict(sxng_request.form.items()) # type: ignore
  373. for k, v in sxng_request.args.items():
  374. if k not in sxng_request.form:
  375. sxng_request.form[k] = v
  376. if sxng_request.form.get('preferences'):
  377. preferences.parse_encoded_data(sxng_request.form['preferences'])
  378. else:
  379. try:
  380. preferences.parse_dict(sxng_request.form)
  381. except Exception as e: # pylint: disable=broad-except
  382. logger.exception(e, exc_info=True)
  383. sxng_request.errors.append(gettext('Invalid settings'))
  384. # language is defined neither in settings nor in preferences
  385. # use browser headers
  386. if not preferences.get_value("language"):
  387. language = _get_browser_language(sxng_request, settings['search']['languages'])
  388. preferences.parse_dict({"language": language})
  389. logger.debug('set language %s (from browser)', preferences.get_value("language"))
  390. # UI locale is defined neither in settings nor in preferences
  391. # use browser headers
  392. if not preferences.get_value("locale"):
  393. locale = _get_browser_language(sxng_request, LOCALE_NAMES.keys())
  394. preferences.parse_dict({"locale": locale})
  395. logger.debug('set locale %s (from browser)', preferences.get_value("locale"))
  396. # request.user_plugins
  397. sxng_request.user_plugins = [] # pylint: disable=assigning-non-slot
  398. allowed_plugins = preferences.plugins.get_enabled()
  399. disabled_plugins = preferences.plugins.get_disabled()
  400. for plugin in searx.plugins.STORAGE:
  401. if (plugin.id not in disabled_plugins) or plugin.id in allowed_plugins:
  402. sxng_request.user_plugins.append(plugin.id)
  403. @app.after_request
  404. def add_default_headers(response: flask.Response):
  405. # set default http headers
  406. for header, value in settings['server']['default_http_headers'].items():
  407. if header in response.headers:
  408. continue
  409. response.headers[header] = value
  410. return response
  411. @app.after_request
  412. def post_request(response: flask.Response):
  413. total_time = default_timer() - sxng_request.start_time
  414. timings_all = [
  415. 'total;dur=' + str(round(total_time * 1000, 3)),
  416. 'render;dur=' + str(round(sxng_request.render_time * 1000, 3)),
  417. ]
  418. if len(sxng_request.timings) > 0:
  419. timings = sorted(sxng_request.timings, key=lambda t: t.total)
  420. timings_total = [
  421. 'total_' + str(i) + '_' + t.engine + ';dur=' + str(round(t.total * 1000, 3)) for i, t in enumerate(timings)
  422. ]
  423. timings_load = [
  424. 'load_' + str(i) + '_' + t.engine + ';dur=' + str(round(t.load * 1000, 3))
  425. for i, t in enumerate(timings)
  426. if t.load
  427. ]
  428. timings_all = timings_all + timings_total + timings_load
  429. response.headers.add('Server-Timing', ', '.join(timings_all))
  430. return response
  431. def index_error(output_format: str, error_message: str):
  432. if output_format == 'json':
  433. return Response(json.dumps({'error': error_message}), mimetype='application/json')
  434. if output_format == 'csv':
  435. response = Response('', mimetype='application/csv')
  436. cont_disp = 'attachment;Filename=searx.csv'
  437. response.headers.add('Content-Disposition', cont_disp)
  438. return response
  439. if output_format == 'rss':
  440. response_rss = render(
  441. 'opensearch_response_rss.xml',
  442. results=[],
  443. q=sxng_request.form['q'] if 'q' in sxng_request.form else '',
  444. number_of_results=0,
  445. error_message=error_message,
  446. )
  447. return Response(response_rss, mimetype='text/xml')
  448. # html
  449. sxng_request.errors.append(gettext('search error'))
  450. return render(
  451. # fmt: off
  452. 'index.html',
  453. selected_categories=get_selected_categories(sxng_request.preferences, sxng_request.form),
  454. # fmt: on
  455. )
  456. @app.route('/', methods=['GET', 'POST'])
  457. def index():
  458. """Render index page."""
  459. # redirect to search if there's a query in the request
  460. if sxng_request.form.get('q'):
  461. query = ('?' + sxng_request.query_string.decode()) if sxng_request.query_string else ''
  462. return redirect(url_for('search') + query, 308)
  463. return render(
  464. # fmt: off
  465. 'index.html',
  466. selected_categories=get_selected_categories(sxng_request.preferences, sxng_request.form),
  467. current_locale = sxng_request.preferences.get_value("locale"),
  468. # fmt: on
  469. )
  470. @app.route('/healthz', methods=['GET'])
  471. def health():
  472. return Response('OK', mimetype='text/plain')
  473. @app.route('/client<token>.css', methods=['GET', 'POST'])
  474. def client_token(token=None):
  475. link_token.ping(sxng_request, token)
  476. return Response('', mimetype='text/css', headers={"Cache-Control": "no-store, max-age=0"})
  477. @app.route('/rss.xsl', methods=['GET', 'POST'])
  478. def rss_xsl():
  479. return render_template(
  480. f"{sxng_request.preferences.get_value('theme')}/rss.xsl",
  481. url_for=custom_url_for,
  482. )
  483. @app.route('/search', methods=['GET', 'POST'])
  484. def search():
  485. """Search query in q and return results.
  486. Supported outputs: html, json, csv, rss.
  487. """
  488. # pylint: disable=too-many-locals, too-many-return-statements, too-many-branches
  489. # pylint: disable=too-many-statements
  490. # output_format
  491. output_format = sxng_request.form.get('format', 'html')
  492. if output_format not in OUTPUT_FORMATS:
  493. output_format = 'html'
  494. if output_format not in settings['search']['formats']:
  495. flask.abort(403)
  496. # check if there is query (not None and not an empty string)
  497. if not sxng_request.form.get('q'):
  498. if output_format == 'html':
  499. return render(
  500. # fmt: off
  501. 'index.html',
  502. selected_categories=get_selected_categories(sxng_request.preferences, sxng_request.form),
  503. # fmt: on
  504. )
  505. return index_error(output_format, 'No query'), 400
  506. # search
  507. search_query = None
  508. raw_text_query = None
  509. result_container = None
  510. try:
  511. search_query, raw_text_query, _, _, selected_locale = get_search_query_from_webapp(
  512. sxng_request.preferences, sxng_request.form
  513. )
  514. search_obj = searx.search.SearchWithPlugins(search_query, sxng_request, sxng_request.user_plugins)
  515. result_container = search_obj.search()
  516. except SearxParameterException as e:
  517. logger.exception('search error: SearxParameterException')
  518. return index_error(output_format, e.message), 400
  519. except Exception as e: # pylint: disable=broad-except
  520. logger.exception(e, exc_info=True)
  521. return index_error(output_format, gettext('search error')), 500
  522. # 1. check if the result is a redirect for an external bang
  523. if result_container.redirect_url:
  524. return redirect(result_container.redirect_url)
  525. # 2. add Server-Timing header for measuring performance characteristics of
  526. # web applications
  527. sxng_request.timings = result_container.get_timings() # pylint: disable=assigning-non-slot
  528. # 3. formats without a template
  529. if output_format == 'json':
  530. response = webutils.get_json_response(search_query, result_container)
  531. return Response(response, mimetype='application/json')
  532. if output_format == 'csv':
  533. csv = webutils.CSVWriter(StringIO())
  534. webutils.write_csv_response(csv, result_container)
  535. csv.stream.seek(0)
  536. response = Response(csv.stream.read(), mimetype='application/csv')
  537. cont_disp = 'attachment;Filename=searx_-_{0}.csv'.format(search_query.query)
  538. response.headers.add('Content-Disposition', cont_disp)
  539. return response
  540. # 4. formats rendered by a template / RSS & HTML
  541. current_template = None
  542. previous_result = None
  543. results = result_container.get_ordered_results()
  544. if search_query.redirect_to_first_result and results:
  545. return redirect(results[0]['url'], 302)
  546. for result in results:
  547. if output_format == 'html':
  548. if 'content' in result and result['content']:
  549. result['content'] = highlight_content(escape(result['content'][:1024]), search_query.query)
  550. if 'title' in result and result['title']:
  551. result['title'] = highlight_content(escape(result['title'] or ''), search_query.query)
  552. # set result['open_group'] = True when the template changes from the previous result
  553. # set result['close_group'] = True when the template changes on the next result
  554. if current_template != result.template:
  555. result.open_group = True
  556. if previous_result:
  557. previous_result.close_group = True # pylint: disable=unsupported-assignment-operation
  558. current_template = result.template
  559. previous_result = result
  560. if previous_result:
  561. previous_result.close_group = True
  562. # 4.a RSS
  563. if output_format == 'rss':
  564. response_rss = render(
  565. 'opensearch_response_rss.xml',
  566. results=results,
  567. q=sxng_request.form['q'],
  568. number_of_results=result_container.number_of_results,
  569. )
  570. return Response(response_rss, mimetype='text/xml')
  571. # 4.b HTML
  572. # suggestions: use RawTextQuery to get the suggestion URLs with the same bang
  573. suggestion_urls = list(
  574. map(
  575. lambda suggestion: {'url': raw_text_query.changeQuery(suggestion).getFullQuery(), 'title': suggestion},
  576. result_container.suggestions,
  577. )
  578. )
  579. correction_urls = list(
  580. map(
  581. lambda correction: {'url': raw_text_query.changeQuery(correction).getFullQuery(), 'title': correction},
  582. result_container.corrections,
  583. )
  584. )
  585. # engine_timings: get engine response times sorted from slowest to fastest
  586. engine_timings = sorted(result_container.get_timings(), reverse=True, key=lambda e: e.total)
  587. max_response_time = engine_timings[0].total if engine_timings else None
  588. engine_timings_pairs = [(timing.engine, timing.total) for timing in engine_timings]
  589. # search_query.lang contains the user choice (all, auto, en, ...)
  590. # when the user choice is "auto", search.search_query.lang contains the detected language
  591. # otherwise it is equals to search_query.lang
  592. return render(
  593. # fmt: off
  594. 'results.html',
  595. results = results,
  596. q=sxng_request.form['q'],
  597. selected_categories = search_query.categories,
  598. pageno = search_query.pageno,
  599. time_range = search_query.time_range or '',
  600. number_of_results = format_decimal(result_container.number_of_results),
  601. suggestions = suggestion_urls,
  602. answers = result_container.answers,
  603. corrections = correction_urls,
  604. infoboxes = result_container.infoboxes,
  605. engine_data = result_container.engine_data,
  606. paging = result_container.paging,
  607. unresponsive_engines = webutils.get_translated_errors(
  608. result_container.unresponsive_engines
  609. ),
  610. current_locale = sxng_request.preferences.get_value("locale"),
  611. current_language = selected_locale,
  612. search_language = match_locale(
  613. search_obj.search_query.lang,
  614. settings['search']['languages'],
  615. fallback=sxng_request.preferences.get_value("language")
  616. ),
  617. timeout_limit = sxng_request.form.get('timeout_limit', None),
  618. timings = engine_timings_pairs,
  619. max_response_time = max_response_time
  620. # fmt: on
  621. )
  622. @app.route('/about', methods=['GET'])
  623. def about():
  624. """Redirect to about page"""
  625. # custom_url_for is going to add the locale
  626. return redirect(custom_url_for('info', pagename='about'))
  627. @app.route('/info/<locale>/<pagename>', methods=['GET'])
  628. def info(pagename, locale):
  629. """Render page of online user documentation"""
  630. page = infopage.INFO_PAGES.get_page(pagename, locale)
  631. if page is None:
  632. flask.abort(404)
  633. user_locale = sxng_request.preferences.get_value('locale')
  634. return render(
  635. 'info.html',
  636. all_pages=infopage.INFO_PAGES.iter_pages(user_locale, fallback_to_default=True),
  637. active_page=page,
  638. active_pagename=pagename,
  639. )
  640. @app.route('/autocompleter', methods=['GET', 'POST'])
  641. def autocompleter():
  642. """Return autocompleter results"""
  643. # run autocompleter
  644. results = []
  645. # set blocked engines
  646. disabled_engines = sxng_request.preferences.engines.get_disabled()
  647. # parse query
  648. raw_text_query = RawTextQuery(sxng_request.form.get('q', ''), disabled_engines)
  649. sug_prefix = raw_text_query.getQuery()
  650. for obj in searx.answerers.STORAGE.ask(sug_prefix):
  651. if isinstance(obj, Answer):
  652. results.append(obj.answer)
  653. # normal autocompletion results only appear if no inner results returned
  654. # and there is a query part
  655. if len(raw_text_query.autocomplete_list) == 0 and len(sug_prefix) > 0:
  656. # get SearXNG's locale and autocomplete backend from cookie
  657. sxng_locale = sxng_request.preferences.get_value('language')
  658. backend_name = sxng_request.preferences.get_value('autocomplete')
  659. for result in search_autocomplete(backend_name, sug_prefix, sxng_locale):
  660. # attention: this loop will change raw_text_query object and this is
  661. # the reason why the sug_prefix was stored before (see above)
  662. if result != sug_prefix:
  663. results.append(raw_text_query.changeQuery(result).getFullQuery())
  664. if len(raw_text_query.autocomplete_list) > 0:
  665. for autocomplete_text in raw_text_query.autocomplete_list:
  666. results.append(raw_text_query.get_autocomplete_full_query(autocomplete_text))
  667. if sxng_request.headers.get('X-Requested-With') == 'XMLHttpRequest':
  668. # the suggestion request comes from the searx search form
  669. suggestions = json.dumps(results)
  670. mimetype = 'application/json'
  671. else:
  672. # the suggestion request comes from browser's URL bar
  673. suggestions = json.dumps([sug_prefix, results])
  674. mimetype = 'application/x-suggestions+json'
  675. suggestions = escape(suggestions, False)
  676. return Response(suggestions, mimetype=mimetype)
  677. @app.route('/preferences', methods=['GET', 'POST'])
  678. def preferences():
  679. """Render preferences page && save user preferences"""
  680. # pylint: disable=too-many-locals, too-many-return-statements, too-many-branches
  681. # pylint: disable=too-many-statements
  682. # save preferences using the link the /preferences?preferences=...
  683. if sxng_request.args.get('preferences') or sxng_request.form.get('preferences'):
  684. resp = make_response(redirect(url_for('index', _external=True)))
  685. return sxng_request.preferences.save(resp)
  686. # save preferences
  687. if sxng_request.method == 'POST':
  688. resp = make_response(redirect(url_for('index', _external=True)))
  689. try:
  690. sxng_request.preferences.parse_form(sxng_request.form)
  691. except ValidationException:
  692. sxng_request.errors.append(gettext('Invalid settings, please edit your preferences'))
  693. return resp
  694. return sxng_request.preferences.save(resp)
  695. # render preferences
  696. image_proxy = sxng_request.preferences.get_value('image_proxy') # pylint: disable=redefined-outer-name
  697. disabled_engines = sxng_request.preferences.engines.get_disabled()
  698. allowed_plugins = sxng_request.preferences.plugins.get_enabled()
  699. # stats for preferences page
  700. filtered_engines = dict(filter(lambda kv: sxng_request.preferences.validate_token(kv[1]), engines.items()))
  701. engines_by_category = {}
  702. for c in categories: # pylint: disable=consider-using-dict-items
  703. engines_by_category[c] = [e for e in categories[c] if e.name in filtered_engines]
  704. # sort the engines alphabetically since the order in settings.yml is meaningless.
  705. list.sort(engines_by_category[c], key=lambda e: e.name)
  706. # get first element [0], the engine time,
  707. # and then the second element [1] : the time (the first one is the label)
  708. stats = {} # pylint: disable=redefined-outer-name
  709. max_rate95 = 0
  710. for _, e in filtered_engines.items():
  711. h = histogram('engine', e.name, 'time', 'total')
  712. median = round(h.percentage(50), 1) if h.count > 0 else None
  713. rate80 = round(h.percentage(80), 1) if h.count > 0 else None
  714. rate95 = round(h.percentage(95), 1) if h.count > 0 else None
  715. max_rate95 = max(max_rate95, rate95 or 0)
  716. result_count_sum = histogram('engine', e.name, 'result', 'count').sum
  717. successful_count = counter('engine', e.name, 'search', 'count', 'successful')
  718. result_count = int(result_count_sum / float(successful_count)) if successful_count else 0
  719. stats[e.name] = {
  720. 'time': median,
  721. 'rate80': rate80,
  722. 'rate95': rate95,
  723. 'warn_timeout': e.timeout > settings['outgoing']['request_timeout'],
  724. 'supports_selected_language': e.traits.is_locale_supported(
  725. str(sxng_request.preferences.get_value('language') or 'all')
  726. ),
  727. 'result_count': result_count,
  728. }
  729. # end of stats
  730. # reliabilities
  731. reliabilities = {}
  732. engine_errors = get_engine_errors(filtered_engines)
  733. checker_results = checker_get_result()
  734. checker_results = (
  735. checker_results['engines'] if checker_results['status'] == 'ok' and 'engines' in checker_results else {}
  736. )
  737. for _, e in filtered_engines.items():
  738. checker_result = checker_results.get(e.name, {})
  739. checker_success = checker_result.get('success', True)
  740. errors = engine_errors.get(e.name) or []
  741. if counter('engine', e.name, 'search', 'count', 'sent') == 0:
  742. # no request
  743. reliability = None
  744. elif checker_success and not errors:
  745. reliability = 100
  746. elif 'simple' in checker_result.get('errors', {}):
  747. # the basic (simple) test doesn't work: the engine is broken according to the checker
  748. # even if there is no exception
  749. reliability = 0
  750. else:
  751. # pylint: disable=consider-using-generator
  752. reliability = 100 - sum([error['percentage'] for error in errors if not error.get('secondary')])
  753. reliabilities[e.name] = {
  754. 'reliability': reliability,
  755. 'errors': [],
  756. 'checker': checker_results.get(e.name, {}).get('errors', {}).keys(),
  757. }
  758. # keep the order of the list checker_results[e.name]['errors'] and deduplicate.
  759. # the first element has the highest percentage rate.
  760. reliabilities_errors = []
  761. for error in errors:
  762. error_user_text = None
  763. if error.get('secondary') or 'exception_classname' not in error:
  764. continue
  765. error_user_text = exception_classname_to_text.get(error.get('exception_classname'))
  766. if not error:
  767. error_user_text = exception_classname_to_text[None]
  768. if error_user_text not in reliabilities_errors:
  769. reliabilities_errors.append(error_user_text)
  770. reliabilities[e.name]['errors'] = reliabilities_errors
  771. # supports
  772. supports = {}
  773. for _, e in filtered_engines.items():
  774. supports_selected_language = e.traits.is_locale_supported(
  775. str(sxng_request.preferences.get_value('language') or 'all')
  776. )
  777. safesearch = e.safesearch
  778. time_range_support = e.time_range_support
  779. for checker_test_name in checker_results.get(e.name, {}).get('errors', {}):
  780. if supports_selected_language and checker_test_name.startswith('lang_'):
  781. supports_selected_language = '?'
  782. elif safesearch and checker_test_name == 'safesearch':
  783. safesearch = '?'
  784. elif time_range_support and checker_test_name == 'time_range':
  785. time_range_support = '?'
  786. supports[e.name] = {
  787. 'supports_selected_language': supports_selected_language,
  788. 'safesearch': safesearch,
  789. 'time_range_support': time_range_support,
  790. }
  791. return render(
  792. # fmt: off
  793. 'preferences.html',
  794. preferences = True,
  795. selected_categories = get_selected_categories(sxng_request.preferences, sxng_request.form),
  796. locales = LOCALE_NAMES,
  797. current_locale = sxng_request.preferences.get_value("locale"),
  798. image_proxy = image_proxy,
  799. engines_by_category = engines_by_category,
  800. stats = stats,
  801. max_rate95 = max_rate95,
  802. reliabilities = reliabilities,
  803. supports = supports,
  804. answer_storage = searx.answerers.STORAGE.info,
  805. disabled_engines = disabled_engines,
  806. autocomplete_backends = autocomplete_backends,
  807. favicon_resolver_names = favicons.proxy.CFG.resolver_map.keys(),
  808. shortcuts = {y: x for x, y in engine_shortcuts.items()},
  809. themes = themes,
  810. plugins_storage = searx.plugins.STORAGE.info,
  811. current_doi_resolver = get_doi_resolver(),
  812. allowed_plugins = allowed_plugins,
  813. preferences_url_params = sxng_request.preferences.get_as_url_params(),
  814. locked_preferences = get_setting("preferences.lock", []),
  815. doi_resolvers = get_setting("doi_resolvers", {}),
  816. # fmt: on
  817. )
  818. app.add_url_rule('/favicon_proxy', methods=['GET'], endpoint="favicon_proxy", view_func=favicons.favicon_proxy)
  819. @app.route('/image_proxy', methods=['GET'])
  820. def image_proxy():
  821. # pylint: disable=too-many-return-statements, too-many-branches
  822. url = sxng_request.args.get('url')
  823. if not url:
  824. return '', 400
  825. if not is_hmac_of(settings['server']['secret_key'], url.encode(), sxng_request.args.get('h', '')):
  826. return '', 400
  827. maximum_size = 5 * 1024 * 1024
  828. forward_resp = False
  829. resp = None
  830. try:
  831. request_headers = {
  832. 'User-Agent': gen_useragent(),
  833. 'Accept': 'image/webp,*/*',
  834. 'Accept-Encoding': 'gzip, deflate',
  835. 'Sec-GPC': '1',
  836. 'DNT': '1',
  837. }
  838. set_context_network_name('image_proxy')
  839. resp, stream = http_stream(method='GET', url=url, headers=request_headers, allow_redirects=True)
  840. content_length = resp.headers.get('Content-Length')
  841. if content_length and content_length.isdigit() and int(content_length) > maximum_size:
  842. return 'Max size', 400
  843. if resp.status_code != 200:
  844. logger.debug('image-proxy: wrong response code: %i', resp.status_code)
  845. if resp.status_code >= 400:
  846. return '', resp.status_code
  847. return '', 400
  848. if not resp.headers.get('Content-Type', '').startswith('image/') and not resp.headers.get(
  849. 'Content-Type', ''
  850. ).startswith('binary/octet-stream'):
  851. logger.debug('image-proxy: wrong content-type: %s', resp.headers.get('Content-Type', ''))
  852. return '', 400
  853. forward_resp = True
  854. except httpx.HTTPError:
  855. logger.exception('HTTP error')
  856. return '', 400
  857. finally:
  858. if resp and not forward_resp:
  859. # the code is about to return an HTTP 400 error to the browser
  860. # we make sure to close the response between searxng and the HTTP server
  861. try:
  862. resp.close()
  863. except httpx.HTTPError:
  864. logger.exception('HTTP error on closing')
  865. def close_stream():
  866. nonlocal resp, stream
  867. try:
  868. if resp:
  869. resp.close()
  870. del resp
  871. del stream
  872. except httpx.HTTPError as e:
  873. logger.debug('Exception while closing response', e)
  874. try:
  875. headers = dict_subset(resp.headers, {'Content-Type', 'Content-Encoding', 'Content-Length', 'Length'})
  876. response = Response(stream, mimetype=resp.headers['Content-Type'], headers=headers, direct_passthrough=True)
  877. response.call_on_close(close_stream)
  878. return response
  879. except httpx.HTTPError:
  880. close_stream()
  881. return '', 400
  882. @app.route('/engine_descriptions.json', methods=['GET'])
  883. def engine_descriptions():
  884. sxng_ui_lang_tag = get_locale().replace("_", "-")
  885. sxng_ui_lang_tag = LOCALE_BEST_MATCH.get(sxng_ui_lang_tag, sxng_ui_lang_tag)
  886. result = ENGINE_DESCRIPTIONS['en'].copy()
  887. if sxng_ui_lang_tag != 'en':
  888. for engine, description in ENGINE_DESCRIPTIONS.get(sxng_ui_lang_tag, {}).items():
  889. result[engine] = description
  890. for engine, description in result.items():
  891. if len(description) == 2 and description[1] == 'ref':
  892. ref_engine, ref_lang = description[0].split(':')
  893. description = ENGINE_DESCRIPTIONS[ref_lang][ref_engine]
  894. if isinstance(description, str):
  895. description = [description, 'wikipedia']
  896. result[engine] = description
  897. # overwrite by about:description (from settings)
  898. for engine_name, engine_mod in engines.items():
  899. descr = getattr(engine_mod, 'about', {}).get('description', None)
  900. if descr is not None:
  901. result[engine_name] = [descr, "SearXNG config"]
  902. return jsonify(result)
  903. @app.route('/stats', methods=['GET'])
  904. def stats():
  905. """Render engine statistics page."""
  906. sort_order = sxng_request.args.get('sort', default='name', type=str)
  907. selected_engine_name = sxng_request.args.get('engine', default=None, type=str)
  908. filtered_engines = dict(filter(lambda kv: sxng_request.preferences.validate_token(kv[1]), engines.items()))
  909. if selected_engine_name:
  910. if selected_engine_name not in filtered_engines:
  911. selected_engine_name = None
  912. else:
  913. filtered_engines = [selected_engine_name]
  914. checker_results = checker_get_result()
  915. checker_results = (
  916. checker_results['engines'] if checker_results['status'] == 'ok' and 'engines' in checker_results else {}
  917. )
  918. engine_stats = get_engines_stats(filtered_engines)
  919. engine_reliabilities = get_reliabilities(filtered_engines, checker_results)
  920. if sort_order not in STATS_SORT_PARAMETERS:
  921. sort_order = 'name'
  922. reverse, key_name, default_value = STATS_SORT_PARAMETERS[sort_order]
  923. def get_key(engine_stat):
  924. reliability = engine_reliabilities.get(engine_stat['name'], {}).get('reliability', 0)
  925. reliability_order = 0 if reliability else 1
  926. if key_name == 'reliability':
  927. key = reliability
  928. reliability_order = 0
  929. else:
  930. key = engine_stat.get(key_name) or default_value
  931. if reverse:
  932. reliability_order = 1 - reliability_order
  933. return (reliability_order, key, engine_stat['name'])
  934. technical_report = []
  935. for error in engine_reliabilities.get(selected_engine_name, {}).get('errors', []):
  936. technical_report.append(
  937. f"\
  938. Error: {error['exception_classname'] or error['log_message']} \
  939. Parameters: {error['log_parameters']} \
  940. File name: {error['filename'] }:{ error['line_no'] } \
  941. Error Function: {error['function']} \
  942. Code: {error['code']} \
  943. ".replace(
  944. ' ' * 12, ''
  945. ).strip()
  946. )
  947. technical_report = ' '.join(technical_report)
  948. engine_stats['time'] = sorted(engine_stats['time'], reverse=reverse, key=get_key)
  949. return render(
  950. # fmt: off
  951. 'stats.html',
  952. sort_order = sort_order,
  953. engine_stats = engine_stats,
  954. engine_reliabilities = engine_reliabilities,
  955. selected_engine_name = selected_engine_name,
  956. searx_git_branch = GIT_BRANCH,
  957. technical_report = technical_report,
  958. # fmt: on
  959. )
  960. @app.route('/stats/errors', methods=['GET'])
  961. def stats_errors():
  962. filtered_engines = dict(filter(lambda kv: sxng_request.preferences.validate_token(kv[1]), engines.items()))
  963. result = get_engine_errors(filtered_engines)
  964. return jsonify(result)
  965. @app.route('/stats/checker', methods=['GET'])
  966. def stats_checker():
  967. result = checker_get_result()
  968. return jsonify(result)
  969. @app.route('/metrics')
  970. def stats_open_metrics():
  971. password = settings['general'].get("open_metrics")
  972. if not (settings['general'].get("enable_metrics") and password):
  973. return Response('open metrics is disabled', status=404, mimetype='text/plain')
  974. if not sxng_request.authorization or sxng_request.authorization.password != password:
  975. return Response('access forbidden', status=401, mimetype='text/plain')
  976. filtered_engines = dict(filter(lambda kv: sxng_request.preferences.validate_token(kv[1]), engines.items()))
  977. checker_results = checker_get_result()
  978. checker_results = (
  979. checker_results['engines'] if checker_results['status'] == 'ok' and 'engines' in checker_results else {}
  980. )
  981. engine_stats = get_engines_stats(filtered_engines)
  982. engine_reliabilities = get_reliabilities(filtered_engines, checker_results)
  983. metrics_text = openmetrics(engine_stats, engine_reliabilities)
  984. return Response(metrics_text, mimetype='text/plain')
  985. @app.route('/robots.txt', methods=['GET'])
  986. def robots():
  987. return Response(
  988. """User-agent: *
  989. Allow: /info/en/about
  990. Disallow: /stats
  991. Disallow: /image_proxy
  992. Disallow: /preferences
  993. Disallow: /*?*q=*
  994. """,
  995. mimetype='text/plain',
  996. )
  997. @app.route('/opensearch.xml', methods=['GET'])
  998. def opensearch():
  999. method = sxng_request.preferences.get_value('method')
  1000. autocomplete = sxng_request.preferences.get_value('autocomplete')
  1001. # chrome/chromium only supports HTTP GET....
  1002. if sxng_request.headers.get('User-Agent', '').lower().find('webkit') >= 0:
  1003. method = 'GET'
  1004. if method not in ('POST', 'GET'):
  1005. method = 'POST'
  1006. ret = render('opensearch.xml', opensearch_method=method, autocomplete=autocomplete)
  1007. resp = Response(response=ret, status=200, mimetype="application/opensearchdescription+xml")
  1008. return resp
  1009. @app.route('/favicon.ico')
  1010. def favicon():
  1011. theme = sxng_request.preferences.get_value("theme")
  1012. return send_from_directory(
  1013. os.path.join(app.root_path, settings['ui']['static_path'], 'themes', theme, 'img'), # type: ignore
  1014. 'favicon.png',
  1015. mimetype='image/vnd.microsoft.icon',
  1016. )
  1017. @app.route('/clear_cookies')
  1018. def clear_cookies():
  1019. resp = make_response(redirect(url_for('index', _external=True)))
  1020. for cookie_name in sxng_request.cookies:
  1021. resp.delete_cookie(cookie_name)
  1022. return resp
  1023. @app.route('/config')
  1024. def config():
  1025. """Return configuration in JSON format."""
  1026. _engines = []
  1027. for name, engine in engines.items():
  1028. if not sxng_request.preferences.validate_token(engine):
  1029. continue
  1030. _languages = engine.traits.languages.keys()
  1031. _engines.append(
  1032. {
  1033. 'name': name,
  1034. 'categories': engine.categories,
  1035. 'shortcut': engine.shortcut,
  1036. 'enabled': not engine.disabled,
  1037. 'paging': engine.paging,
  1038. 'language_support': engine.language_support,
  1039. 'languages': list(_languages),
  1040. 'regions': list(engine.traits.regions.keys()),
  1041. 'safesearch': engine.safesearch,
  1042. 'time_range_support': engine.time_range_support,
  1043. 'timeout': engine.timeout,
  1044. }
  1045. )
  1046. _plugins = []
  1047. for _ in searx.plugins.STORAGE:
  1048. _plugins.append({'name': _.id, 'enabled': _.active})
  1049. _limiter_cfg = limiter.get_cfg()
  1050. return jsonify(
  1051. {
  1052. 'categories': list(categories.keys()),
  1053. 'engines': _engines,
  1054. 'plugins': _plugins,
  1055. 'instance_name': settings['general']['instance_name'],
  1056. 'locales': LOCALE_NAMES,
  1057. 'default_locale': settings['ui']['default_locale'],
  1058. 'autocomplete': settings['search']['autocomplete'],
  1059. 'safe_search': settings['search']['safe_search'],
  1060. 'default_theme': settings['ui']['default_theme'],
  1061. 'version': VERSION_STRING,
  1062. 'brand': {
  1063. 'PRIVACYPOLICY_URL': get_setting('general.privacypolicy_url'),
  1064. 'CONTACT_URL': get_setting('general.contact_url'),
  1065. 'GIT_URL': GIT_URL,
  1066. 'GIT_BRANCH': GIT_BRANCH,
  1067. 'DOCS_URL': get_setting('brand.docs_url'),
  1068. },
  1069. 'limiter': {
  1070. 'enabled': limiter.is_installed(),
  1071. 'botdetection.ip_limit.link_token': _limiter_cfg.get('botdetection.ip_limit.link_token'),
  1072. 'botdetection.ip_lists.pass_searxng_org': _limiter_cfg.get('botdetection.ip_lists.pass_searxng_org'),
  1073. },
  1074. 'doi_resolvers': list(settings['doi_resolvers'].keys()),
  1075. 'default_doi_resolver': settings['default_doi_resolver'],
  1076. 'public_instance': settings['server']['public_instance'],
  1077. }
  1078. )
  1079. @app.errorhandler(404)
  1080. def page_not_found(_e):
  1081. return render('404.html'), 404
  1082. def run():
  1083. """Runs the application on a local development server.
  1084. This run method is only called when SearXNG is started via ``__main__``::
  1085. python -m searx.webapp
  1086. Do not use :ref:`run() <flask.Flask.run>` in a production setting. It is
  1087. not intended to meet security and performance requirements for a production
  1088. server.
  1089. It is not recommended to use this function for development with automatic
  1090. reloading as this is badly supported. Instead you should be using the flask
  1091. command line script’s run support::
  1092. flask --app searx.webapp run --debug --reload --host 127.0.0.1 --port 8888
  1093. .. _Flask.run: https://flask.palletsprojects.com/en/stable/api/#flask.Flask.run
  1094. """
  1095. host: str = get_setting("server.bind_address") # type: ignore
  1096. port: int = get_setting("server.port") # type: ignore
  1097. if searx.sxng_debug:
  1098. logger.debug("run local development server (DEBUG) on %s:%s", host, port)
  1099. app.run(
  1100. debug=True,
  1101. port=port,
  1102. host=host,
  1103. threaded=True,
  1104. extra_files=[DEFAULT_SETTINGS_FILE],
  1105. )
  1106. else:
  1107. logger.debug("run local development server on %s:%s", host, port)
  1108. app.run(port=port, host=host, threaded=True)
  1109. def is_werkzeug_reload_active() -> bool:
  1110. """Returns ``True`` if server is is launched by :ref:`werkzeug.serving` and
  1111. the ``use_reload`` argument was set to ``True``. If this is the case, it
  1112. should be avoided that the server is initialized twice (:py:obj:`init`,
  1113. :py:obj:`run`).
  1114. .. _werkzeug.serving:
  1115. https://werkzeug.palletsprojects.com/en/stable/serving/#werkzeug.serving.run_simple
  1116. """
  1117. logger.debug("sys.argv: %s", sys.argv)
  1118. if "uwsgi" in sys.argv[0] or "granian" in sys.argv[0]:
  1119. # server was launched by granian (or uWSGI)
  1120. return False
  1121. # https://github.com/searxng/searxng/pull/1656#issuecomment-1214198941
  1122. # https://github.com/searxng/searxng/pull/1616#issuecomment-1206137468
  1123. frames = inspect.stack()
  1124. if len(frames) > 1 and frames[-2].filename.endswith('flask/cli.py'):
  1125. # server was launched by "flask run", is argument "--reload" set?
  1126. if "--reload" in sys.argv or "--debug" in sys.argv:
  1127. return True
  1128. elif frames[0].filename.endswith('searx/webapp.py'):
  1129. # server was launched by "python -m searx.webapp" / see run()
  1130. if searx.sxng_debug:
  1131. return True
  1132. return False
  1133. def init():
  1134. if searx.sxng_debug or app.debug:
  1135. app.debug = True
  1136. searx.sxng_debug = True
  1137. # check secret_key in production
  1138. if not app.debug and get_setting("server.secret_key") == 'ultrasecretkey':
  1139. logger.error("server.secret_key is not changed. Please use something else instead of ultrasecretkey.")
  1140. sys.exit(1)
  1141. # When automatic reloading is activated stop Flask from initialising twice.
  1142. # - https://github.com/pallets/flask/issues/5307#issuecomment-1774646119
  1143. # - https://stackoverflow.com/a/25504196
  1144. reloader_active = is_werkzeug_reload_active()
  1145. werkzeug_run_main = is_running_from_reloader()
  1146. if reloader_active and not werkzeug_run_main:
  1147. logger.info("in reloading mode and not in main loop, cancel the initialization")
  1148. return
  1149. locales_initialize()
  1150. valkey_initialize()
  1151. searx.plugins.initialize(app)
  1152. metrics: bool = get_setting("general.enable_metrics") # type: ignore
  1153. searx.search.initialize(enable_checker=True, check_network=True, enable_metrics=metrics)
  1154. limiter.initialize(app, settings)
  1155. favicons.init()
  1156. def static_headers(headers: Headers, _path: str, _url: str) -> None:
  1157. headers['Cache-Control'] = 'public, max-age=30, stale-while-revalidate=60'
  1158. for header, value in settings['server']['default_http_headers'].items():
  1159. headers[header] = value
  1160. app.wsgi_app = WhiteNoise(
  1161. app.wsgi_app,
  1162. root=settings['ui']['static_path'],
  1163. prefix="static",
  1164. max_age=None,
  1165. allow_all_origins=False,
  1166. add_headers_function=static_headers,
  1167. )
  1168. patch_application(app)
  1169. init()
  1170. if __name__ == "__main__":
  1171. run()