mirror of
https://github.com/freedombox/FreedomBox.git
synced 2026-08-26 12:46:08 +00:00
Closes: Debian #1144740. - When one of the applications such as bepasty, radicale, or searx need it, then install it. - Reduces the number of dependencies for freedombox package. - Reduces size of the disk image. - Ensures that uwsgi does not run on every freedombox machine. - Apache's proxy_uwsgi module (provided by apache2-bin, apache2) can still be enabled by default because uwsgi is not a dependency for the Apache module and uwsgi socket connections are not attempted until specific configuration is enabled and requests arrive. - Change dependency from uwsgi-core to uwsgi. uwsgi-core does not have init scripts but uwsgi package has init script (but only on trixie and not forky and up). The init script is disabled and masked by bepasty, radicale, and searx apps. So, this should not be a problem. Tests: - On a freshly installed Debian forky and trixie machines, install freedombox deb package built with changes. Installation succeeds. uwsgi is not installed at all. bepasty and radicale can be installed and basic requests to web UI work. uwsgi init script is not started and is masked. - Functional tests for bepasty and radicale work. - On a Trixie machine, setup freedombox from trixie. Then install freedombox deb package with the patch. uwsgi is not marked as manually installed and running unattended-updates will remove it. Install bepasty and uwsgi package is installed and marked as manually installed. - On a Trixie machine, setup freedombox from trixie. Install the bepasty app. Then install freedombox deb package with the patch. uwsgi is marked as manually installed and running unattended-updates will not remove it. Signed-off-by: Sunil Mohan Adapa <sunil@medhas.org> Reviewed-by: James Valleroy <jvalleroy@mailbox.org>
161 lines
5.6 KiB
Python
161 lines
5.6 KiB
Python
# SPDX-License-Identifier: AGPL-3.0-or-later
|
|
"""FreedomBox app to configure Searx."""
|
|
|
|
import os
|
|
|
|
from django.utils.translation import gettext_lazy as _
|
|
|
|
from plinth import app as app_module
|
|
from plinth import frontpage, menu
|
|
from plinth.config import DropinConfigs
|
|
from plinth.daemon import Daemon, RelatedDaemon
|
|
from plinth.modules.apache.components import Webserver
|
|
from plinth.modules.backups.components import BackupRestore
|
|
from plinth.modules.firewall.components import Firewall
|
|
from plinth.modules.users.components import UsersAndGroups
|
|
from plinth.package import Packages
|
|
from plinth.privileged import service as service_privileged
|
|
|
|
from . import manifest, privileged
|
|
|
|
_description = [
|
|
_('Searx is a privacy-respecting Internet metasearch engine. '
|
|
'It aggregrates and displays results from multiple search engines.'),
|
|
_('Searx can be used to avoid tracking and profiling by search engines. '
|
|
'It stores no cookies by default.')
|
|
]
|
|
|
|
|
|
class SearxApp(app_module.App):
|
|
"""FreedomBox app for Searx."""
|
|
|
|
app_id = 'searx'
|
|
|
|
_version = 8
|
|
|
|
def __init__(self) -> None:
|
|
"""Create components for the app."""
|
|
super().__init__()
|
|
|
|
groups = {'web-search': _('Search the web')}
|
|
|
|
info = app_module.Info(
|
|
app_id=self.app_id, version=self._version, name=_('Searx'),
|
|
icon_filename='searx', description=_description,
|
|
manual_page='Searx', clients=manifest.clients, tags=manifest.tags,
|
|
donation_url='https://searx.me/static/donate.html')
|
|
self.add(info)
|
|
|
|
menu_item = menu.Menu('menu-searx', info.name, info.icon_filename,
|
|
info.tags, 'searx:index', parent_url_name='apps')
|
|
self.add(menu_item)
|
|
|
|
shortcut = frontpage.Shortcut(
|
|
'shortcut-searx', info.name, icon=info.icon_filename,
|
|
url='/searx/', clients=info.clients, tags=info.tags,
|
|
login_required=(not is_public_access_enabled()),
|
|
allowed_groups=list(groups))
|
|
self.add(shortcut)
|
|
|
|
# Include libjs-bootstrap to prevent accidental uninstall (see
|
|
# issue #2298).
|
|
packages = Packages(
|
|
'packages-searx',
|
|
['searx', 'libjs-bootstrap', 'uwsgi', 'uwsgi-plugin-python3'])
|
|
self.add(packages)
|
|
|
|
dropin_configs = DropinConfigs('dropin-configs-searx', [
|
|
'/etc/apache2/conf-available/searx-freedombox-auth.conf',
|
|
'/etc/apache2/conf-available/searx-freedombox.conf',
|
|
])
|
|
self.add(dropin_configs)
|
|
|
|
firewall = Firewall('firewall-searx', info.name,
|
|
ports=['http', 'https'], is_external=True)
|
|
self.add(firewall)
|
|
|
|
webserver = Webserver('webserver-searx', 'searx-freedombox',
|
|
urls=['https://{host}/searx/'])
|
|
self.add(webserver)
|
|
|
|
webserver = SearxWebserverAuth('webserver-searx-auth',
|
|
'searx-freedombox-auth')
|
|
self.add(webserver)
|
|
|
|
daemon = Daemon('daemon-searx', 'uwsgi-app@searx.socket')
|
|
self.add(daemon)
|
|
|
|
users_and_groups = UsersAndGroups('users-and-groups-searx',
|
|
groups=groups)
|
|
self.add(users_and_groups)
|
|
|
|
backup_restore = BackupRestore('backup-restore-searx',
|
|
**manifest.backup)
|
|
self.add(backup_restore)
|
|
|
|
# To be able to disable the old uwsgi init.d script.
|
|
related_daemon = RelatedDaemon('related-daemon-searx', 'uwsgi')
|
|
self.add(related_daemon)
|
|
|
|
def set_shortcut_login_required(self, login_required):
|
|
"""Change the login_required property of shortcut."""
|
|
self.get_component('shortcut-searx').login_required = login_required
|
|
|
|
def setup(self, old_version):
|
|
"""Install and configure the app."""
|
|
super().setup(old_version)
|
|
privileged.setup()
|
|
if not old_version or old_version < 3:
|
|
privileged.disable_public_access()
|
|
self.enable()
|
|
self.set_shortcut_login_required(True)
|
|
|
|
if old_version and old_version <= 6:
|
|
webserver = self.get_component('webserver-searx')
|
|
daemon = self.get_component('daemon-searx')
|
|
if webserver.is_enabled():
|
|
daemon.enable()
|
|
|
|
# Vanquish the old uwsgi init.d script.
|
|
service_privileged.disable('uwsgi')
|
|
service_privileged.mask('uwsgi')
|
|
|
|
def uninstall(self):
|
|
"""De-configure and uninstall the app."""
|
|
super().uninstall()
|
|
privileged.uninstall()
|
|
|
|
|
|
class SearxWebserverAuth(Webserver):
|
|
"""Component to handle Searx authentication webserver configuration."""
|
|
|
|
def is_enabled(self):
|
|
"""Return if configuration is enabled or public access is enabled."""
|
|
return is_public_access_enabled() or super().is_enabled()
|
|
|
|
def enable(self):
|
|
"""Enable apache configuration only if public access is disabled."""
|
|
if not is_public_access_enabled():
|
|
super().enable()
|
|
|
|
|
|
def is_public_access_enabled():
|
|
"""Check whether public access is enabled for Searx."""
|
|
return os.path.exists(manifest.PUBLIC_ACCESS_SETTING_FILE)
|
|
|
|
|
|
def enable_public_access():
|
|
"""Allow Searx app to be accessed by anyone with access."""
|
|
privileged.enable_public_access()
|
|
app = app_module.App.get('searx')
|
|
app.get_component('webserver-searx-auth').disable()
|
|
app.set_shortcut_login_required(False)
|
|
|
|
|
|
def disable_public_access():
|
|
"""Allow Searx app to be accessed by logged-in users only."""
|
|
privileged.disable_public_access()
|
|
app = app_module.App.get('searx')
|
|
app.get_component('webserver-searx-auth').enable()
|
|
app.set_shortcut_login_required(True)
|