diff --git a/.gitignore b/.gitignore index c00883fef..8982613ac 100644 --- a/.gitignore +++ b/.gitignore @@ -14,6 +14,7 @@ dump.rdb test/e2e/reports coverage/ +plugins.json plugins/* !plugins/coral-plugin-facebook-auth !plugins/coral-plugin-respect diff --git a/PLUGINS.md b/PLUGINS.md index e5cf8d760..8bf00229d 100644 --- a/PLUGINS.md +++ b/PLUGINS.md @@ -3,11 +3,18 @@ Plugins for Talk can take various forms, currently we are only supporting server side plugins. -## Plugin Registration: `plugins.json` +## Plugin Registration -All plugins must be registered in the root file `plugins.json`. +The parsing order for the plugin registration is as follows: -The format for this file is thus: +- `TALK_PLUGINS_JSON` environment variable +- `plugins.json` file +- `plugins.default.json` file + +If you need to "disable all plugins", you can simply provide `{}` as the +contents of `process.env.TALK_PLUGINS_JSON` or the `plugins.json`. + +The format for this is thus: ```json { @@ -18,7 +25,7 @@ The format for this file is thus: ``` Where we have a `server` key with an array of plugins that match the folder -name in the `plugins/` folder. For example, the above `plugins.json` would +name in the `plugins/` folder. For example, the above config would require a plugin from `plugins/people`, which must provide a `index.js` file that returns an object that matches the Plugin Specification. diff --git a/README.md b/README.md index b88138425..ef621b59c 100644 --- a/README.md +++ b/README.md @@ -37,6 +37,7 @@ available in the format: `://` without the path. - `TALK_INSTALL_LOCK` (_optional for dynamic setup_) - Defaults to `FALSE`. When `TRUE`, disables the dynamic setup endpoint. - `TALK_RECAPTCHA_SECRET` (*required for reCAPTCHA support*) - server secret used for enabling reCAPTCHA powered logins. If not provided it will instead default to providing only a time based lockout. - `TALK_RECAPTCHA_PUBLIC` (*required for reCAPTCHA support*) - client secret used for enabling reCAPTCHA powered logins. If not provided it will instead default to providing only a time based lockout. +- `TALK_PLUGINS_JSON` (_optional_) - used to specify the plugin config via the environment Refer to the wiki page on [Configuration Loading](https://github.com/coralproject/talk/wiki/Configuration-Loading) for alternative methods of loading configuration during development. diff --git a/package.json b/package.json index d5e4b30f5..d11a8ecea 100644 --- a/package.json +++ b/package.json @@ -74,6 +74,7 @@ "graphql-tools": "^0.9.0", "helmet": "^3.5.0", "inquirer": "^3.0.6", + "joi": "^10.4.1", "jsonwebtoken": "^7.3.0", "kue": "^0.11.5", "linkify-it": "^2.0.3", diff --git a/plugins.json b/plugins.default.json similarity index 100% rename from plugins.json rename to plugins.default.json diff --git a/plugins.js b/plugins.js index d7c9f9426..949a5b9ab 100644 --- a/plugins.js +++ b/plugins.js @@ -2,6 +2,7 @@ const fs = require('fs'); const path = require('path'); const resolve = require('resolve'); const debug = require('debug')('talk:plugins'); +const Joi = require('joi'); // Add support for require rewriting. require('app-module-path').addPath(__dirname); @@ -12,15 +13,42 @@ let plugins = {}; // file isn't loaded, but continuing. Else, like a parsing error, throw it and // crash the program. try { - plugins = JSON.parse(fs.readFileSync(path.join(__dirname, 'plugins.json'), 'utf8')); + let defaultPlugins = path.join(__dirname, 'plugins.default.json'); + let customPlugins = path.join(__dirname, 'plugins.json'); + let envPluginJSON = process.env.TALK_PLUGINS_JSON; + + if (envPluginJSON && envPluginJSON.length > 0) { + debug('Now using TALK_PLUGINS_JSON environment variable for plugins'); + plugins = JSON.parse(envPluginJSON); + } else if (fs.existsSync(customPlugins)) { + debug(`Now using ${customPlugins} for plugins`); + plugins = JSON.parse(fs.readFileSync(customPlugins, 'utf8')); + } else { + debug(`Now using ${defaultPlugins} for plugins`); + plugins = JSON.parse(fs.readFileSync(defaultPlugins, 'utf8')); + } } catch (err) { if (err.code === 'ENOENT') { - console.error('plugins.json not found, plugins will not be active'); + console.error('plugins.json and plugins.default.json not found, plugins will not be active'); } else { throw err; } } +const hookSchemas = { + passport: Joi.func().arity(1), + router: Joi.func().arity(1), + context: Joi.object().pattern(/\w/, Joi.func().maxArity(1)), + hooks: Joi.object({ + pre: Joi.func(), + post: Joi.func() + }), + loaders: Joi.object().pattern(/\w/, Joi.object().pattern(/\w/, Joi.func())), + mutators: Joi.object().pattern(/\w/, Joi.object().pattern(/\w/, Joi.func())), + resolvers: Joi.object().pattern(/\w/, Joi.object().pattern(/\w/, Joi.func())), + typeDefs: Joi.string() +}; + /** * isInternal checks to see if a given plugin is internal, and returns true * if it is. @@ -122,6 +150,15 @@ class PluginSection { hook(hook) { return this.plugins .filter(({module}) => hook in module) + .filter((plugin) => { + + // Validate the hook. + if (hook in hookSchemas) { + Joi.assert(plugin.module[hook], hookSchemas[hook], `Plugin '${plugin.name}' failed validation for the '${hook}' hook`); + } + + return true; + }) .map((plugin) => ({ plugin, [hook]: plugin.module[hook] diff --git a/yarn.lock b/yarn.lock index 650c78f70..378e5a6c0 100644 --- a/yarn.lock +++ b/yarn.lock @@ -3665,6 +3665,10 @@ hoek@2.x.x: version "2.16.3" resolved "https://registry.yarnpkg.com/hoek/-/hoek-2.16.3.tgz#20bb7403d3cea398e91dc4710a8ff1b8274a25ed" +hoek@4.x.x: + version "4.1.1" + resolved "https://registry.yarnpkg.com/hoek/-/hoek-4.1.1.tgz#9cc573ffba2b7b408fb5e9c2a13796be94cddce9" + hoist-non-react-statics@^1.0.3, hoist-non-react-statics@^1.2.0: version "1.2.0" resolved "https://registry.yarnpkg.com/hoist-non-react-statics/-/hoist-non-react-statics-1.2.0.tgz#aa448cf0986d55cc40773b17174b7dd066cb7cfb" @@ -4195,6 +4199,10 @@ isemail@1.x.x: version "1.2.0" resolved "https://registry.yarnpkg.com/isemail/-/isemail-1.2.0.tgz#be03df8cc3e29de4d2c5df6501263f1fa4595e9a" +isemail@2.x.x: + version "2.2.1" + resolved "https://registry.yarnpkg.com/isemail/-/isemail-2.2.1.tgz#0353d3d9a62951080c262c2aa0a42b8ea8e9e2a6" + isexe@^1.1.1: version "1.1.2" resolved "https://registry.yarnpkg.com/isexe/-/isexe-1.1.2.tgz#36f3e22e60750920f5e7241a476a8c6a42275ad0" @@ -4293,6 +4301,10 @@ istanbul@^1.1.0-alpha.1: which "^1.1.1" wordwrap "^1.0.0" +items@2.x.x: + version "2.1.1" + resolved "https://registry.yarnpkg.com/items/-/items-2.1.1.tgz#8bd16d9c83b19529de5aea321acaada78364a198" + iterall@1.0.2: version "1.0.2" resolved "https://registry.yarnpkg.com/iterall/-/iterall-1.0.2.tgz#41a2e96ce9eda5e61c767ee5dc312373bb046e91" @@ -4314,6 +4326,15 @@ jodid25519@^1.0.0: dependencies: jsbn "~0.1.0" +joi@^10.4.1: + version "10.4.1" + resolved "https://registry.yarnpkg.com/joi/-/joi-10.4.1.tgz#a2fca1f0d603d1b843f2c1e086b52461f6be1f36" + dependencies: + hoek "4.x.x" + isemail "2.x.x" + items "2.x.x" + topo "2.x.x" + joi@^6.10.1: version "6.10.1" resolved "https://registry.yarnpkg.com/joi/-/joi-6.10.1.tgz#4d50c318079122000fe5f16af1ff8e1917b77e06" @@ -7770,6 +7791,12 @@ topo@1.x.x: dependencies: hoek "2.x.x" +topo@2.x.x: + version "2.0.2" + resolved "https://registry.yarnpkg.com/topo/-/topo-2.0.2.tgz#cd5615752539057c0dc0491a621c3bc6fbe1d182" + dependencies: + hoek "4.x.x" + touch@1.0.0: version "1.0.0" resolved "https://registry.yarnpkg.com/touch/-/touch-1.0.0.tgz#449cbe2dbae5a8c8038e30d71fa0ff464947c4de"