diff options
Diffstat (limited to 'hostnix/elmo')
| -rw-r--r-- | hostnix/elmo/privacy-frontends.nix | 70 |
1 files changed, 69 insertions, 1 deletions
diff --git a/hostnix/elmo/privacy-frontends.nix b/hostnix/elmo/privacy-frontends.nix index 6030d96..3838e19 100644 --- a/hostnix/elmo/privacy-frontends.nix +++ b/hostnix/elmo/privacy-frontends.nix @@ -1,4 +1,4 @@ -{ ... }: +{ pkgs, ... }: { services.libreddit = { @@ -23,4 +23,72 @@ forceSSL = true; locations."/".proxyPass = "http://[::1]:7682"; }; + + systemd.tmpfiles.rules = [ + "d /var/secrets/nitter 0750 root wheel" + ]; + + systemd.services.nitter-refresh-guest-account-token = { + serviceConfig = { + Type = "oneshot"; + }; + path = [ pkgs.curl pkgs.jq ]; + # Lightly edited from https://github.com/zedeus/nitter/wiki/Guest-Account-Branch-Deployment + script = '' + set -e + + guest_token=$(curl -s -XPOST https://api.twitter.com/1.1/guest/activate.json -H 'Authorization: Bearer AAAAAAAAAAAAAAAAAAAAAFXzAwAAAAAAMHCxpeSDG1gLNLghVe8d74hl6k4%3DRUMF4xAQLsbeBhTSRrCiQpJtxoGWeyHrDb5te2jpGskWDFW82F' | jq -r '.guest_token') + + flow_token=$(curl -s -XPOST 'https://api.twitter.com/1.1/onboarding/task.json?flow_name=welcome' \ + -H 'Authorization: Bearer AAAAAAAAAAAAAAAAAAAAAFXzAwAAAAAAMHCxpeSDG1gLNLghVe8d74hl6k4%3DRUMF4xAQLsbeBhTSRrCiQpJtxoGWeyHrDb5te2jpGskWDFW82F' \ + -H 'Content-Type: application/json' \ + -H "User-Agent: TwitterAndroid/10.10.0" \ + -H "X-Guest-Token: $guest_token" \ + -d '{"flow_token":null,"input_flow_data":{"flow_context":{"start_location":{"location":"splash_screen"}}}}' | jq -r .flow_token) + + umask 077 + exec > /var/secrets/nitter/guest-accounts.jsonl + curl -s -XPOST 'https://api.twitter.com/1.1/onboarding/task.json' \ + -H 'Authorization: Bearer AAAAAAAAAAAAAAAAAAAAAFXzAwAAAAAAMHCxpeSDG1gLNLghVe8d74hl6k4%3DRUMF4xAQLsbeBhTSRrCiQpJtxoGWeyHrDb5te2jpGskWDFW82F' \ + -H 'Content-Type: application/json' \ + -H "User-Agent: TwitterAndroid/10.10.0" \ + -H "X-Guest-Token: $guest_token" \ + -d "{\"flow_token\":\"$flow_token\",\"subtask_inputs\":[{\"open_link\":{\"link\":\"next_link\"},\"subtask_id\":\"NextTaskOpenLink\"}]}" | jq -c -r '.subtasks[0]|if(.open_account) then {oauth_token: .open_account.oauth_token, oauth_token_secret: .open_account.oauth_token_secret} else empty end' + ''; + }; + + services.nitter = { + enable = true; + # Enable stack traces per https://github.com/zedeus/nitter/issues/541#issuecomment-1036031286 + package = pkgs.nitter.overrideAttrs (old: { + nimFlags = old.nimFlags ++ [ + "--excessiveStackTrace:on" + "--stackTrace:on" + "--lineTrace:on" + "--lineDir:on" + ]; + }); + guestAccounts = "/var/secrets/nitter/guest-accounts.jsonl"; + server = { + port = 7873; + https = true; + hostname = "ni.mou.fo"; + address = "127.0.0.1"; + }; + preferences = { + hlsPlayback = true; + }; + }; + + systemd.services.nitter = { + unitConfig = { + AssertPathExists = "/var/secrets/nitter/guest-accounts.jsonl"; + }; + }; + + services.nginx.virtualHosts."ni.mou.fo" = { + enableACME = true; + forceSSL = true; + locations."/".proxyPass = "http://127.0.0.1:7873"; + }; } |
