summaryrefslogtreecommitdiff
path: root/hostnix/elmo/privacy-frontends.nix
blob: 3838e1998bd6ad787bb5a57c7fd585b104808624 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
{ pkgs, ... }:

{
  services.libreddit = {
    enable = true;
    address = "[::1]";
    port = 7682;
  };

  systemd.services.libreddit = {
    environment = {
      LIBREDDIT_DEFAULT_SHOW_NSFW = "on";
      LIBREDDIT_DEFAULT_USE_HLS = "on";
      LIBREDDIT_DEFAULT_WIDE = "on";
      # v0.30.0 is too old for these settings
      # LIBREDDIT_PUSHSHIFT_FRONTEND = "www.reveddit.com";
      # LIBREDDIT_ROBOTS_DISABLE_INDEXING = "on";
    };
  };

  services.nginx.virtualHosts."lr.mou.fo" = {
    enableACME = true;
    forceSSL = true;
    locations."/".proxyPass = "http://[::1]:7682";
  };

  systemd.tmpfiles.rules = [
    "d /var/secrets/nitter 0750 root wheel"
  ];

  systemd.services.nitter-refresh-guest-account-token = {
    serviceConfig = {
      Type = "oneshot";
    };
    path = [ pkgs.curl pkgs.jq ];
    # Lightly edited from https://github.com/zedeus/nitter/wiki/Guest-Account-Branch-Deployment
    script = ''
      set -e

      guest_token=$(curl -s -XPOST https://api.twitter.com/1.1/guest/activate.json -H 'Authorization: Bearer AAAAAAAAAAAAAAAAAAAAAFXzAwAAAAAAMHCxpeSDG1gLNLghVe8d74hl6k4%3DRUMF4xAQLsbeBhTSRrCiQpJtxoGWeyHrDb5te2jpGskWDFW82F' | jq -r '.guest_token')

      flow_token=$(curl -s -XPOST 'https://api.twitter.com/1.1/onboarding/task.json?flow_name=welcome' \
                -H 'Authorization: Bearer AAAAAAAAAAAAAAAAAAAAAFXzAwAAAAAAMHCxpeSDG1gLNLghVe8d74hl6k4%3DRUMF4xAQLsbeBhTSRrCiQpJtxoGWeyHrDb5te2jpGskWDFW82F' \
                -H 'Content-Type: application/json' \
                -H "User-Agent: TwitterAndroid/10.10.0" \
                -H "X-Guest-Token: $guest_token" \
                -d '{"flow_token":null,"input_flow_data":{"flow_context":{"start_location":{"location":"splash_screen"}}}}' | jq -r .flow_token)

      umask 077
      exec > /var/secrets/nitter/guest-accounts.jsonl
      curl -s -XPOST 'https://api.twitter.com/1.1/onboarding/task.json' \
                -H 'Authorization: Bearer AAAAAAAAAAAAAAAAAAAAAFXzAwAAAAAAMHCxpeSDG1gLNLghVe8d74hl6k4%3DRUMF4xAQLsbeBhTSRrCiQpJtxoGWeyHrDb5te2jpGskWDFW82F' \
                -H 'Content-Type: application/json' \
                -H "User-Agent: TwitterAndroid/10.10.0" \
                -H "X-Guest-Token: $guest_token" \
                -d "{\"flow_token\":\"$flow_token\",\"subtask_inputs\":[{\"open_link\":{\"link\":\"next_link\"},\"subtask_id\":\"NextTaskOpenLink\"}]}" | jq -c -r '.subtasks[0]|if(.open_account) then {oauth_token: .open_account.oauth_token, oauth_token_secret: .open_account.oauth_token_secret} else empty end'
    '';
  };

  services.nitter = {
    enable = true;
    # Enable stack traces per https://github.com/zedeus/nitter/issues/541#issuecomment-1036031286
    package = pkgs.nitter.overrideAttrs (old: {
      nimFlags = old.nimFlags ++ [
        "--excessiveStackTrace:on"
        "--stackTrace:on"
        "--lineTrace:on"
        "--lineDir:on"
      ];
    });
    guestAccounts = "/var/secrets/nitter/guest-accounts.jsonl";
    server = {
      port = 7873;
      https = true;
      hostname = "ni.mou.fo";
      address = "127.0.0.1";
    };
    preferences = {
      hlsPlayback = true;
    };
  };

  systemd.services.nitter = {
    unitConfig = {
      AssertPathExists = "/var/secrets/nitter/guest-accounts.jsonl";
    };
  };

  services.nginx.virtualHosts."ni.mou.fo" = {
    enableACME = true;
    forceSSL = true;
    locations."/".proxyPass = "http://127.0.0.1:7873";
  };
}