router.ex 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401
  1. defmodule PlausibleWeb.Router do
  2. use PlausibleWeb, :router
  3. use Plausible
  4. import Phoenix.LiveView.Router
  5. @two_weeks_in_seconds 60 * 60 * 24 * 14
  6. pipeline :browser do
  7. plug :accepts, ["html"]
  8. plug :fetch_session
  9. plug :fetch_live_flash
  10. plug :put_secure_browser_headers
  11. plug PlausibleWeb.Plugs.NoRobots
  12. on_ee(do: nil, else: plug(PlausibleWeb.FirstLaunchPlug, redirect_to: "/register"))
  13. plug PlausibleWeb.SessionTimeoutPlug, timeout_after_seconds: @two_weeks_in_seconds
  14. plug PlausibleWeb.AuthPlug
  15. plug PlausibleWeb.LastSeenPlug
  16. end
  17. pipeline :shared_link do
  18. plug :accepts, ["html"]
  19. plug :put_secure_browser_headers
  20. plug PlausibleWeb.Plugs.NoRobots
  21. end
  22. pipeline :csrf do
  23. plug :protect_from_forgery
  24. end
  25. pipeline :focus_layout do
  26. plug :put_root_layout, html: {PlausibleWeb.LayoutView, :focus}
  27. end
  28. pipeline :app_layout do
  29. plug :put_root_layout, html: {PlausibleWeb.LayoutView, :app}
  30. end
  31. pipeline :api do
  32. plug :accepts, ["json"]
  33. plug :fetch_session
  34. plug PlausibleWeb.AuthPlug
  35. end
  36. pipeline :internal_stats_api do
  37. plug :accepts, ["json"]
  38. plug :fetch_session
  39. plug PlausibleWeb.AuthorizeSiteAccess
  40. plug PlausibleWeb.Plugs.NoRobots
  41. end
  42. pipeline :public_api do
  43. plug :accepts, ["json"]
  44. end
  45. on_ee do
  46. pipeline :flags do
  47. plug :accepts, ["html"]
  48. plug :put_secure_browser_headers
  49. plug PlausibleWeb.Plugs.NoRobots
  50. plug :fetch_session
  51. plug PlausibleWeb.CRMAuthPlug
  52. end
  53. end
  54. if Mix.env() in [:dev, :ce_dev] do
  55. forward "/sent-emails", Bamboo.SentEmailViewerPlug
  56. end
  57. on_ee do
  58. use Kaffy.Routes,
  59. scope: "/crm",
  60. pipe_through: [PlausibleWeb.Plugs.NoRobots, PlausibleWeb.CRMAuthPlug]
  61. end
  62. on_ee do
  63. scope "/crm", PlausibleWeb do
  64. pipe_through :flags
  65. get "/auth/user/:user_id/usage", AdminController, :usage
  66. end
  67. end
  68. on_ee do
  69. scope path: "/flags" do
  70. pipe_through :flags
  71. forward "/", FunWithFlags.UI.Router, namespace: "flags"
  72. end
  73. end
  74. scope path: "/api/plugins", as: :plugins_api do
  75. pipeline :plugins_api_auth do
  76. plug(PlausibleWeb.Plugs.AuthorizePluginsAPI)
  77. end
  78. pipeline :plugins_api do
  79. plug(:accepts, ["json"])
  80. plug(OpenApiSpex.Plug.PutApiSpec, module: PlausibleWeb.Plugins.API.Spec)
  81. end
  82. scope "/spec" do
  83. pipe_through(:plugins_api)
  84. get("/openapi", OpenApiSpex.Plug.RenderSpec, [])
  85. get("/swagger-ui", OpenApiSpex.Plug.SwaggerUI, path: "/api/plugins/spec/openapi")
  86. end
  87. scope "/v1/capabilities", PlausibleWeb.Plugins.API.Controllers, assigns: %{plugins_api: true} do
  88. pipe_through([:plugins_api])
  89. get("/", Capabilities, :index)
  90. end
  91. scope "/v1", PlausibleWeb.Plugins.API.Controllers, assigns: %{plugins_api: true} do
  92. pipe_through([:plugins_api, :plugins_api_auth])
  93. get("/shared_links", SharedLinks, :index)
  94. get("/shared_links/:id", SharedLinks, :get)
  95. put("/shared_links", SharedLinks, :create)
  96. get("/goals", Goals, :index)
  97. get("/goals/:id", Goals, :get)
  98. put("/goals", Goals, :create)
  99. delete("/goals/:id", Goals, :delete)
  100. delete("/goals", Goals, :delete_bulk)
  101. put("/custom_props", CustomProps, :enable)
  102. delete("/custom_props", CustomProps, :disable)
  103. end
  104. end
  105. scope "/api/stats", PlausibleWeb.Api do
  106. pipe_through :internal_stats_api
  107. on_ee do
  108. get "/:domain/funnels/:id", StatsController, :funnel
  109. end
  110. get "/:domain/current-visitors", StatsController, :current_visitors
  111. get "/:domain/main-graph", StatsController, :main_graph
  112. get "/:domain/top-stats", StatsController, :top_stats
  113. get "/:domain/sources", StatsController, :sources
  114. get "/:domain/utm_mediums", StatsController, :utm_mediums
  115. get "/:domain/utm_sources", StatsController, :utm_sources
  116. get "/:domain/utm_campaigns", StatsController, :utm_campaigns
  117. get "/:domain/utm_contents", StatsController, :utm_contents
  118. get "/:domain/utm_terms", StatsController, :utm_terms
  119. get "/:domain/referrers/:referrer", StatsController, :referrer_drilldown
  120. get "/:domain/pages", StatsController, :pages
  121. get "/:domain/entry-pages", StatsController, :entry_pages
  122. get "/:domain/exit-pages", StatsController, :exit_pages
  123. get "/:domain/countries", StatsController, :countries
  124. get "/:domain/regions", StatsController, :regions
  125. get "/:domain/cities", StatsController, :cities
  126. get "/:domain/browsers", StatsController, :browsers
  127. get "/:domain/browser-versions", StatsController, :browser_versions
  128. get "/:domain/operating-systems", StatsController, :operating_systems
  129. get "/:domain/operating-system-versions", StatsController, :operating_system_versions
  130. get "/:domain/screen-sizes", StatsController, :screen_sizes
  131. get "/:domain/conversions", StatsController, :conversions
  132. get "/:domain/custom-prop-values/:prop_key", StatsController, :custom_prop_values
  133. get "/:domain/suggestions/:filter_name", StatsController, :filter_suggestions
  134. end
  135. scope "/api/v1/stats", PlausibleWeb.Api do
  136. pipe_through [:public_api, PlausibleWeb.AuthorizeStatsApiPlug]
  137. get "/realtime/visitors", ExternalStatsController, :realtime_visitors
  138. get "/aggregate", ExternalStatsController, :aggregate
  139. get "/breakdown", ExternalStatsController, :breakdown
  140. get "/timeseries", ExternalStatsController, :timeseries
  141. end
  142. on_ee do
  143. scope "/api/v1/sites", PlausibleWeb.Api do
  144. pipe_through [:public_api, PlausibleWeb.AuthorizeSitesApiPlug]
  145. post "/", ExternalSitesController, :create_site
  146. put "/shared-links", ExternalSitesController, :find_or_create_shared_link
  147. put "/goals", ExternalSitesController, :find_or_create_goal
  148. delete "/goals/:goal_id", ExternalSitesController, :delete_goal
  149. get "/:site_id", ExternalSitesController, :get_site
  150. put "/:site_id", ExternalSitesController, :update_site
  151. delete "/:site_id", ExternalSitesController, :delete_site
  152. end
  153. end
  154. scope "/api", PlausibleWeb do
  155. pipe_through :api
  156. post "/event", Api.ExternalController, :event
  157. get "/error", Api.ExternalController, :error
  158. get "/health", Api.ExternalController, :health
  159. get "/system", Api.ExternalController, :info
  160. post "/paddle/webhook", Api.PaddleController, :webhook
  161. get "/:domain/status", Api.InternalController, :domain_status
  162. put "/:domain/disable-feature", Api.InternalController, :disable_feature
  163. get "/sites", Api.InternalController, :sites
  164. end
  165. scope "/", PlausibleWeb do
  166. pipe_through [:browser, :csrf]
  167. scope alias: Live, assigns: %{connect_live_socket: true} do
  168. pipe_through [PlausibleWeb.RequireLoggedOutPlug, :focus_layout]
  169. scope assigns: %{disable_registration_for: [:invite_only, true]} do
  170. pipe_through PlausibleWeb.Plugs.MaybeDisableRegistration
  171. live "/register", RegisterForm, :register_form, as: :auth
  172. end
  173. scope assigns: %{
  174. disable_registration_for: true,
  175. dogfood_page_path: "/register/invitation/:invitation_id"
  176. } do
  177. pipe_through PlausibleWeb.Plugs.MaybeDisableRegistration
  178. live "/register/invitation/:invitation_id", RegisterForm, :register_from_invitation_form,
  179. as: :auth
  180. end
  181. end
  182. post "/register", AuthController, :register
  183. post "/register/invitation/:invitation_id", AuthController, :register_from_invitation
  184. get "/activate", AuthController, :activate_form
  185. post "/activate/request-code", AuthController, :request_activation_code
  186. post "/activate", AuthController, :activate
  187. get "/login", AuthController, :login_form
  188. post "/login", AuthController, :login
  189. get "/password/request-reset", AuthController, :password_reset_request_form
  190. post "/password/request-reset", AuthController, :password_reset_request
  191. post "/2fa/setup/initiate", AuthController, :initiate_2fa_setup
  192. get "/2fa/setup/verify", AuthController, :verify_2fa_setup_form
  193. post "/2fa/setup/verify", AuthController, :verify_2fa_setup
  194. post "/2fa/disable", AuthController, :disable_2fa
  195. post "/2fa/recovery_codes", AuthController, :generate_2fa_recovery_codes
  196. get "/2fa/verify", AuthController, :verify_2fa_form
  197. post "/2fa/verify", AuthController, :verify_2fa
  198. get "/2fa/use_recovery_code", AuthController, :verify_2fa_recovery_code_form
  199. post "/2fa/use_recovery_code", AuthController, :verify_2fa_recovery_code
  200. get "/password/reset", AuthController, :password_reset_form
  201. post "/password/reset", AuthController, :password_reset
  202. get "/avatar/:hash", AvatarController, :avatar
  203. post "/error_report", ErrorReportController, :submit_error_report
  204. end
  205. scope "/", PlausibleWeb do
  206. pipe_through [:shared_link]
  207. get "/share/:domain", StatsController, :shared_link
  208. post "/share/:slug/authenticate", StatsController, :authenticate_shared_link
  209. end
  210. scope "/", PlausibleWeb do
  211. pipe_through [:browser, :csrf]
  212. get "/logout", AuthController, :logout
  213. get "/settings", AuthController, :user_settings
  214. put "/settings", AuthController, :save_settings
  215. put "/settings/email", AuthController, :update_email
  216. post "/settings/email/cancel", AuthController, :cancel_update_email
  217. delete "/me", AuthController, :delete_me
  218. get "/settings/api-keys/new", AuthController, :new_api_key
  219. post "/settings/api-keys", AuthController, :create_api_key
  220. delete "/settings/api-keys/:id", AuthController, :delete_api_key
  221. get "/auth/google/callback", AuthController, :google_auth_callback
  222. get "/", PageController, :index
  223. get "/billing/change-plan/preview/:plan_id", BillingController, :change_plan_preview
  224. post "/billing/change-plan/:new_plan_id", BillingController, :change_plan
  225. get "/billing/choose-plan", BillingController, :choose_plan
  226. get "/billing/upgrade-to-enterprise-plan", BillingController, :upgrade_to_enterprise_plan
  227. get "/billing/upgrade-success", BillingController, :upgrade_success
  228. get "/billing/subscription/ping", BillingController, :ping_subscription
  229. scope alias: Live, assigns: %{connect_live_socket: true} do
  230. pipe_through [:app_layout, PlausibleWeb.RequireAccountPlug]
  231. live "/sites", Sites, :index, as: :site
  232. end
  233. get "/sites/new", SiteController, :new
  234. post "/sites", SiteController, :create_site
  235. get "/sites/:website/change-domain", SiteController, :change_domain
  236. put "/sites/:website/change-domain", SiteController, :change_domain_submit
  237. get "/:website/change-domain-snippet", SiteController, :add_snippet_after_domain_change
  238. post "/sites/:website/make-public", SiteController, :make_public
  239. post "/sites/:website/make-private", SiteController, :make_private
  240. post "/sites/:website/weekly-report/enable", SiteController, :enable_weekly_report
  241. post "/sites/:website/weekly-report/disable", SiteController, :disable_weekly_report
  242. post "/sites/:website/weekly-report/recipients", SiteController, :add_weekly_report_recipient
  243. delete "/sites/:website/weekly-report/recipients/:recipient",
  244. SiteController,
  245. :remove_weekly_report_recipient
  246. post "/sites/:website/monthly-report/enable", SiteController, :enable_monthly_report
  247. post "/sites/:website/monthly-report/disable", SiteController, :disable_monthly_report
  248. post "/sites/:website/monthly-report/recipients",
  249. SiteController,
  250. :add_monthly_report_recipient
  251. delete "/sites/:website/monthly-report/recipients/:recipient",
  252. SiteController,
  253. :remove_monthly_report_recipient
  254. post "/sites/:website/spike-notification/enable", SiteController, :enable_spike_notification
  255. post "/sites/:website/spike-notification/disable", SiteController, :disable_spike_notification
  256. put "/sites/:website/spike-notification", SiteController, :update_spike_notification
  257. post "/sites/:website/spike-notification/recipients",
  258. SiteController,
  259. :add_spike_notification_recipient
  260. delete "/sites/:website/spike-notification/recipients/:recipient",
  261. SiteController,
  262. :remove_spike_notification_recipient
  263. get "/sites/:website/shared-links/new", SiteController, :new_shared_link
  264. post "/sites/:website/shared-links", SiteController, :create_shared_link
  265. get "/sites/:website/shared-links/:slug/edit", SiteController, :edit_shared_link
  266. put "/sites/:website/shared-links/:slug", SiteController, :update_shared_link
  267. delete "/sites/:website/shared-links/:slug", SiteController, :delete_shared_link
  268. get "/sites/:website/memberships/invite", Site.MembershipController, :invite_member_form
  269. post "/sites/:website/memberships/invite", Site.MembershipController, :invite_member
  270. post "/sites/invitations/:invitation_id/accept", InvitationController, :accept_invitation
  271. post "/sites/invitations/:invitation_id/reject", InvitationController, :reject_invitation
  272. delete "/sites/:website/invitations/:invitation_id", InvitationController, :remove_invitation
  273. get "/sites/:website/transfer-ownership", Site.MembershipController, :transfer_ownership_form
  274. post "/sites/:website/transfer-ownership", Site.MembershipController, :transfer_ownership
  275. put "/sites/:website/memberships/:id/role/:new_role", Site.MembershipController, :update_role
  276. delete "/sites/:website/memberships/:id", Site.MembershipController, :remove_member
  277. get "/sites/:website/weekly-report/unsubscribe", UnsubscribeController, :weekly_report
  278. get "/sites/:website/monthly-report/unsubscribe", UnsubscribeController, :monthly_report
  279. get "/:website/snippet", SiteController, :add_snippet
  280. get "/:website/settings", SiteController, :settings
  281. get "/:website/settings/general", SiteController, :settings_general
  282. get "/:website/settings/people", SiteController, :settings_people
  283. get "/:website/settings/visibility", SiteController, :settings_visibility
  284. get "/:website/settings/goals", SiteController, :settings_goals
  285. get "/:website/settings/properties", SiteController, :settings_props
  286. on_ee do
  287. get "/:website/settings/funnels", SiteController, :settings_funnels
  288. end
  289. get "/:website/settings/email-reports", SiteController, :settings_email_reports
  290. get "/:website/settings/danger-zone", SiteController, :settings_danger_zone
  291. get "/:website/settings/integrations", SiteController, :settings_integrations
  292. get "/:website/settings/shields/:shield", SiteController, :settings_shields
  293. get "/:website/settings/imports-exports", SiteController, :settings_imports_exports
  294. put "/:website/settings/features/visibility/:setting",
  295. SiteController,
  296. :update_feature_visibility
  297. put "/:website/settings", SiteController, :update_settings
  298. put "/:website/settings/google", SiteController, :update_google_auth
  299. delete "/:website/settings/google-search", SiteController, :delete_google_auth
  300. delete "/:website/settings/google-import", SiteController, :delete_google_auth
  301. delete "/:website", SiteController, :delete_site
  302. delete "/:website/stats", SiteController, :reset_stats
  303. get "/:website/import/google-analytics/property-or-view",
  304. GoogleAnalyticsController,
  305. :property_or_view_form
  306. post "/:website/import/google-analytics/property-or-view",
  307. GoogleAnalyticsController,
  308. :property_or_view
  309. get "/:website/import/google-analytics/user-metric",
  310. GoogleAnalyticsController,
  311. :user_metric_notice
  312. get "/:website/import/google-analytics/confirm", GoogleAnalyticsController, :confirm
  313. post "/:website/settings/google-import", GoogleAnalyticsController, :import
  314. delete "/:website/settings/forget-imported", SiteController, :forget_imported
  315. delete "/:website/settings/forget-import/:import_id", SiteController, :forget_import
  316. get "/:website/download/export", SiteController, :download_export
  317. get "/:website/settings/import", SiteController, :csv_import
  318. get "/:domain/export", StatsController, :csv_export
  319. get "/:domain/*path", StatsController, :stats
  320. end
  321. end