diff options
Diffstat (limited to 'lib')
35 files changed, 392 insertions, 295 deletions
diff --git a/lib/pleroma/emoji/formatter.ex b/lib/pleroma/emoji/formatter.ex index 59ff2cac3..dc45b8a38 100644 --- a/lib/pleroma/emoji/formatter.ex +++ b/lib/pleroma/emoji/formatter.ex @@ -38,22 +38,14 @@ defmodule Pleroma.Emoji.Formatter do    def demojify(text, nil), do: text -  @doc "Outputs a list of the emoji-shortcodes in a text" -  def get_emoji(text) when is_binary(text) do -    Enum.filter(Emoji.get_all(), fn {emoji, %Emoji{}} -> -      String.contains?(text, ":#{emoji}:") -    end) -  end - -  def get_emoji(_), do: [] -    @doc "Outputs a list of the emoji-Maps in a text"    def get_emoji_map(text) when is_binary(text) do -    get_emoji(text) +    Emoji.get_all() +    |> Enum.filter(fn {emoji, %Emoji{}} -> String.contains?(text, ":#{emoji}:") end)      |> Enum.reduce(%{}, fn {name, %Emoji{file: file}}, acc ->        Map.put(acc, name, "#{Pleroma.Web.Endpoint.static_url()}#{file}")      end)    end -  def get_emoji_map(_), do: [] +  def get_emoji_map(_), do: %{}  end diff --git a/lib/pleroma/formatter.ex b/lib/pleroma/formatter.ex index c44e7fc8b..02a93a8dc 100644 --- a/lib/pleroma/formatter.ex +++ b/lib/pleroma/formatter.ex @@ -31,7 +31,7 @@ defmodule Pleroma.Formatter do    def mention_handler("@" <> nickname, buffer, opts, acc) do      case User.get_cached_by_nickname(nickname) do        %User{id: id} = user -> -        ap_id = get_ap_id(user) +        user_url = user.uri || user.ap_id          nickname_text = get_nickname_text(nickname, opts)          link = @@ -42,7 +42,7 @@ defmodule Pleroma.Formatter do                ["@", Phoenix.HTML.Tag.content_tag(:span, nickname_text)],                "data-user": id,                class: "u-url mention", -              href: ap_id, +              href: user_url,                rel: "ugc"              ),              class: "h-card" @@ -146,9 +146,6 @@ defmodule Pleroma.Formatter do      end    end -  defp get_ap_id(%User{source_data: %{"url" => url}}) when is_binary(url), do: url -  defp get_ap_id(%User{ap_id: ap_id}), do: ap_id -    defp get_nickname_text(nickname, %{mentions_format: :full}), do: User.full_nickname(nickname)    defp get_nickname_text(nickname, _), do: User.local_nickname(nickname)  end diff --git a/lib/pleroma/plugs/auth_expected_plug.ex b/lib/pleroma/plugs/auth_expected_plug.ex new file mode 100644 index 000000000..f79597dc3 --- /dev/null +++ b/lib/pleroma/plugs/auth_expected_plug.ex @@ -0,0 +1,17 @@ +# Pleroma: A lightweight social networking server +# Copyright © 2017-2020 Pleroma Authors <https://pleroma.social/> +# SPDX-License-Identifier: AGPL-3.0-only + +defmodule Pleroma.Plugs.AuthExpectedPlug do +  import Plug.Conn + +  def init(options), do: options + +  def call(conn, _) do +    put_private(conn, :auth_expected, true) +  end + +  def auth_expected?(conn) do +    conn.private[:auth_expected] +  end +end diff --git a/lib/pleroma/plugs/oauth_scopes_plug.ex b/lib/pleroma/plugs/oauth_scopes_plug.ex index 38df074ad..66f48c28c 100644 --- a/lib/pleroma/plugs/oauth_scopes_plug.ex +++ b/lib/pleroma/plugs/oauth_scopes_plug.ex @@ -8,12 +8,15 @@ defmodule Pleroma.Plugs.OAuthScopesPlug do    alias Pleroma.Config    alias Pleroma.Plugs.EnsurePublicOrAuthenticatedPlug +  alias Pleroma.Plugs.PlugHelper + +  use Pleroma.Web, :plug    @behaviour Plug    def init(%{scopes: _} = options), do: options -  def call(%Plug.Conn{assigns: assigns} = conn, %{scopes: scopes} = options) do +  def perform(%Plug.Conn{assigns: assigns} = conn, %{scopes: scopes} = options) do      op = options[:op] || :|      token = assigns[:token] diff --git a/lib/pleroma/plugs/plug_helper.ex b/lib/pleroma/plugs/plug_helper.ex new file mode 100644 index 000000000..4f83e9414 --- /dev/null +++ b/lib/pleroma/plugs/plug_helper.ex @@ -0,0 +1,38 @@ +# Pleroma: A lightweight social networking server +# Copyright © 2017-2020 Pleroma Authors <https://pleroma.social/> +# SPDX-License-Identifier: AGPL-3.0-only + +defmodule Pleroma.Plugs.PlugHelper do +  @moduledoc "Pleroma Plug helper" + +  def append_to_called_plugs(conn, plug_module) do +    append_to_private_list(conn, :called_plugs, plug_module) +  end + +  def append_to_skipped_plugs(conn, plug_module) do +    append_to_private_list(conn, :skipped_plugs, plug_module) +  end + +  def plug_called?(conn, plug_module) do +    contained_in_private_list?(conn, :called_plugs, plug_module) +  end + +  def plug_skipped?(conn, plug_module) do +    contained_in_private_list?(conn, :skipped_plugs, plug_module) +  end + +  def plug_called_or_skipped?(conn, plug_module) do +    plug_called?(conn, plug_module) || plug_skipped?(conn, plug_module) +  end + +  defp append_to_private_list(conn, private_variable, value) do +    list = conn.private[private_variable] || [] +    modified_list = Enum.uniq(list ++ [value]) +    Plug.Conn.put_private(conn, private_variable, modified_list) +  end + +  defp contained_in_private_list?(conn, private_variable, value) do +    list = conn.private[private_variable] || [] +    value in list +  end +end diff --git a/lib/pleroma/tests/oauth_test_controller.ex b/lib/pleroma/tests/oauth_test_controller.ex new file mode 100644 index 000000000..58d517f78 --- /dev/null +++ b/lib/pleroma/tests/oauth_test_controller.ex @@ -0,0 +1,31 @@ +# Pleroma: A lightweight social networking server +# Copyright © 2017-2020 Pleroma Authors <https://pleroma.social/> +# SPDX-License-Identifier: AGPL-3.0-only + +# A test controller reachable only in :test env. +# Serves to test OAuth scopes check skipping / enforcement. +defmodule Pleroma.Tests.OAuthTestController do +  @moduledoc false + +  use Pleroma.Web, :controller + +  alias Pleroma.Plugs.OAuthScopesPlug + +  plug(:skip_plug, OAuthScopesPlug when action == :skipped_oauth) + +  plug(OAuthScopesPlug, %{scopes: ["read"]} when action != :missed_oauth) + +  def skipped_oauth(conn, _params) do +    noop(conn) +  end + +  def performed_oauth(conn, _params) do +    noop(conn) +  end + +  def missed_oauth(conn, _params) do +    noop(conn) +  end + +  defp noop(conn), do: json(conn, %{}) +end diff --git a/lib/pleroma/user.ex b/lib/pleroma/user.ex index 670ce397b..896bab140 100644 --- a/lib/pleroma/user.ex +++ b/lib/pleroma/user.ex @@ -15,6 +15,7 @@ defmodule Pleroma.User do    alias Pleroma.Config    alias Pleroma.Conversation.Participation    alias Pleroma.Delivery +  alias Pleroma.Emoji    alias Pleroma.FollowingRelationship    alias Pleroma.Formatter    alias Pleroma.HTML @@ -28,6 +29,7 @@ defmodule Pleroma.User do    alias Pleroma.UserRelationship    alias Pleroma.Web    alias Pleroma.Web.ActivityPub.ActivityPub +  alias Pleroma.Web.ActivityPub.ObjectValidators.Types    alias Pleroma.Web.ActivityPub.Utils    alias Pleroma.Web.CommonAPI    alias Pleroma.Web.CommonAPI.Utils, as: CommonUtils @@ -82,6 +84,7 @@ defmodule Pleroma.User do      field(:password, :string, virtual: true)      field(:password_confirmation, :string, virtual: true)      field(:keys, :string) +    field(:public_key, :string)      field(:ap_id, :string)      field(:avatar, :map)      field(:local, :boolean, default: true) @@ -94,7 +97,6 @@ defmodule Pleroma.User do      field(:last_digest_emailed_at, :naive_datetime)      field(:banner, :map, default: %{})      field(:background, :map, default: %{}) -    field(:source_data, :map, default: %{})      field(:note_count, :integer, default: 0)      field(:follower_count, :integer, default: 0)      field(:following_count, :integer, default: 0) @@ -112,7 +114,7 @@ defmodule Pleroma.User do      field(:show_role, :boolean, default: true)      field(:settings, :map, default: nil)      field(:magic_key, :string, default: nil) -    field(:uri, :string, default: nil) +    field(:uri, Types.Uri, default: nil)      field(:hide_followers_count, :boolean, default: false)      field(:hide_follows_count, :boolean, default: false)      field(:hide_followers, :boolean, default: false) @@ -122,7 +124,7 @@ defmodule Pleroma.User do      field(:pinned_activities, {:array, :string}, default: [])      field(:email_notifications, :map, default: %{"digest" => false})      field(:mascot, :map, default: nil) -    field(:emoji, {:array, :map}, default: []) +    field(:emoji, :map, default: %{})      field(:pleroma_settings_store, :map, default: %{})      field(:fields, {:array, :map}, default: [])      field(:raw_fields, {:array, :map}, default: []) @@ -132,6 +134,8 @@ defmodule Pleroma.User do      field(:skip_thread_containment, :boolean, default: false)      field(:actor_type, :string, default: "Person")      field(:also_known_as, {:array, :string}, default: []) +    field(:inbox, :string) +    field(:shared_inbox, :string)      embeds_one(        :notification_settings, @@ -306,6 +310,7 @@ defmodule Pleroma.User do      end    end +  # Should probably be renamed or removed    def ap_id(%User{nickname: nickname}), do: "#{Web.base_url()}/users/#{nickname}"    def ap_followers(%User{follower_address: fa}) when is_binary(fa), do: fa @@ -339,62 +344,72 @@ defmodule Pleroma.User do      end    end -  def remote_user_creation(params) do +  defp fix_follower_address(%{follower_address: _, following_address: _} = params), do: params + +  defp fix_follower_address(%{nickname: nickname} = params), +    do: Map.put(params, :follower_address, ap_followers(%User{nickname: nickname})) + +  defp fix_follower_address(params), do: params + +  def remote_user_changeset(struct \\ %User{local: false}, params) do      bio_limit = Pleroma.Config.get([:instance, :user_bio_length], 5000)      name_limit = Pleroma.Config.get([:instance, :user_name_length], 100) +    name = +      case params[:name] do +        name when is_binary(name) and byte_size(name) > 0 -> name +        _ -> params[:nickname] +      end +      params =        params +      |> Map.put(:name, name) +      |> Map.put_new(:last_refreshed_at, NaiveDateTime.utc_now())        |> truncate_if_exists(:name, name_limit)        |> truncate_if_exists(:bio, bio_limit)        |> truncate_fields_param() +      |> fix_follower_address() -    changeset = -      %User{local: false} -      |> cast( -        params, -        [ -          :bio, -          :name, -          :ap_id, -          :nickname, -          :avatar, -          :ap_enabled, -          :source_data, -          :banner, -          :locked, -          :magic_key, -          :uri, -          :hide_followers, -          :hide_follows, -          :hide_followers_count, -          :hide_follows_count, -          :follower_count, -          :fields, -          :following_count, -          :discoverable, -          :invisible, -          :actor_type, -          :also_known_as -        ] -      ) -      |> validate_required([:name, :ap_id]) -      |> unique_constraint(:nickname) -      |> validate_format(:nickname, @email_regex) -      |> validate_length(:bio, max: bio_limit) -      |> validate_length(:name, max: name_limit) -      |> validate_fields(true) - -    case params[:source_data] do -      %{"followers" => followers, "following" => following} -> -        changeset -        |> put_change(:follower_address, followers) -        |> put_change(:following_address, following) - -      _ -> -        followers = ap_followers(%User{nickname: get_field(changeset, :nickname)}) -        put_change(changeset, :follower_address, followers) -    end +    struct +    |> cast( +      params, +      [ +        :bio, +        :name, +        :emoji, +        :ap_id, +        :inbox, +        :shared_inbox, +        :nickname, +        :public_key, +        :avatar, +        :ap_enabled, +        :banner, +        :locked, +        :last_refreshed_at, +        :magic_key, +        :uri, +        :follower_address, +        :following_address, +        :hide_followers, +        :hide_follows, +        :hide_followers_count, +        :hide_follows_count, +        :follower_count, +        :fields, +        :following_count, +        :discoverable, +        :invisible, +        :actor_type, +        :also_known_as +      ] +    ) +    |> validate_required([:name, :ap_id]) +    |> unique_constraint(:nickname) +    |> validate_format(:nickname, @email_regex) +    |> validate_length(:bio, max: bio_limit) +    |> validate_length(:name, max: name_limit) +    |> validate_fields(true)    end    def update_changeset(struct, params \\ %{}) do @@ -407,7 +422,11 @@ defmodule Pleroma.User do        [          :bio,          :name, +        :emoji,          :avatar, +        :public_key, +        :inbox, +        :shared_inbox,          :locked,          :no_rich_text,          :default_scope, @@ -434,6 +453,7 @@ defmodule Pleroma.User do      |> validate_length(:bio, max: bio_limit)      |> validate_length(:name, min: 1, max: name_limit)      |> put_fields() +    |> put_emoji()      |> put_change_if_present(:bio, &{:ok, parse_bio(&1, struct)})      |> put_change_if_present(:avatar, &put_upload(&1, :avatar))      |> put_change_if_present(:banner, &put_upload(&1, :banner)) @@ -469,6 +489,18 @@ defmodule Pleroma.User do      |> elem(0)    end +  defp put_emoji(changeset) do +    bio = get_change(changeset, :bio) +    name = get_change(changeset, :name) + +    if bio || name do +      emoji = Map.merge(Emoji.Formatter.get_emoji_map(bio), Emoji.Formatter.get_emoji_map(name)) +      put_change(changeset, :emoji, emoji) +    else +      changeset +    end +  end +    defp put_change_if_present(changeset, map_field, value_function) do      if value = get_change(changeset, map_field) do        with {:ok, new_value} <- value_function.(value) do @@ -488,49 +520,6 @@ defmodule Pleroma.User do      end    end -  def upgrade_changeset(struct, params \\ %{}, remote? \\ false) do -    bio_limit = Pleroma.Config.get([:instance, :user_bio_length], 5000) -    name_limit = Pleroma.Config.get([:instance, :user_name_length], 100) - -    params = Map.put(params, :last_refreshed_at, NaiveDateTime.utc_now()) - -    params = if remote?, do: truncate_fields_param(params), else: params - -    struct -    |> cast( -      params, -      [ -        :bio, -        :name, -        :follower_address, -        :following_address, -        :avatar, -        :last_refreshed_at, -        :ap_enabled, -        :source_data, -        :banner, -        :locked, -        :magic_key, -        :follower_count, -        :following_count, -        :hide_follows, -        :fields, -        :hide_followers, -        :allow_following_move, -        :discoverable, -        :hide_followers_count, -        :hide_follows_count, -        :actor_type, -        :also_known_as -      ] -    ) -    |> unique_constraint(:nickname) -    |> validate_format(:nickname, local_nickname_regex()) -    |> validate_length(:bio, max: bio_limit) -    |> validate_length(:name, max: name_limit) -    |> validate_fields(remote?) -  end -    def update_as_admin_changeset(struct, params) do      struct      |> update_changeset(params) @@ -606,7 +595,7 @@ defmodule Pleroma.User do      struct      |> confirmation_changeset(need_confirmation: need_confirmation?) -    |> cast(params, [:bio, :email, :name, :nickname, :password, :password_confirmation]) +    |> cast(params, [:bio, :email, :name, :nickname, :password, :password_confirmation, :emoji])      |> validate_required([:name, :nickname, :password, :password_confirmation])      |> validate_confirmation(:password)      |> unique_constraint(:email) @@ -1621,8 +1610,7 @@ defmodule Pleroma.User do      |> set_cache()    end -  # AP style -  def public_key(%{source_data: %{"publicKey" => %{"publicKeyPem" => public_key_pem}}}) do +  def public_key(%{public_key: public_key_pem}) when is_binary(public_key_pem) do      key =        public_key_pem        |> :public_key.pem_decode() @@ -1632,7 +1620,7 @@ defmodule Pleroma.User do      {:ok, key}    end -  def public_key(_), do: {:error, "not found key"} +  def public_key(_), do: {:error, "key not found"}    def get_public_key_for_ap_id(ap_id) do      with {:ok, %User{} = user} <- get_or_fetch_by_ap_id(ap_id), @@ -1643,17 +1631,6 @@ defmodule Pleroma.User do      end    end -  defp blank?(""), do: nil -  defp blank?(n), do: n - -  def insert_or_update_user(data) do -    data -    |> Map.put(:name, blank?(data[:name]) || data[:nickname]) -    |> remote_user_creation() -    |> Repo.insert(on_conflict: {:replace_all_except, [:id]}, conflict_target: :nickname) -    |> set_cache() -  end -    def ap_enabled?(%User{local: true}), do: true    def ap_enabled?(%User{ap_enabled: ap_enabled}), do: ap_enabled    def ap_enabled?(_), do: false @@ -1962,12 +1939,6 @@ defmodule Pleroma.User do      |> update_and_set_cache()    end -  def update_source_data(user, source_data) do -    user -    |> cast(%{source_data: source_data}, [:source_data]) -    |> update_and_set_cache() -  end -    def roles(%{is_moderator: is_moderator, is_admin: is_admin}) do      %{        admin: is_admin, @@ -1975,21 +1946,6 @@ defmodule Pleroma.User do      }    end -  # ``fields`` is an array of mastodon profile field, containing ``{"name": "…", "value": "…"}``. -  # For example: [{"name": "Pronoun", "value": "she/her"}, …] -  def fields(%{fields: nil, source_data: %{"attachment" => attachment}}) do -    limit = Pleroma.Config.get([:instance, :max_remote_account_fields], 0) - -    attachment -    |> Enum.filter(fn %{"type" => t} -> t == "PropertyValue" end) -    |> Enum.map(fn fields -> Map.take(fields, ["name", "value"]) end) -    |> Enum.take(limit) -  end - -  def fields(%{fields: nil}), do: [] - -  def fields(%{fields: fields}), do: fields -    def validate_fields(changeset, remote? \\ false) do      limit_name = if remote?, do: :max_remote_account_fields, else: :max_account_fields      limit = Pleroma.Config.get([:instance, limit_name], 0) @@ -2177,9 +2133,7 @@ defmodule Pleroma.User do    # - display name    def sanitize_html(%User{} = user, filter) do      fields = -      user -      |> User.fields() -      |> Enum.map(fn %{"name" => name, "value" => value} -> +      Enum.map(user.fields, fn %{"name" => name, "value" => value} ->          %{            "name" => name,            "value" => HTML.filter_tags(value, Pleroma.HTML.Scrubber.LinksOnly) diff --git a/lib/pleroma/web/activity_pub/activity_pub.ex b/lib/pleroma/web/activity_pub/activity_pub.ex index 86b105b7f..35af0f7dc 100644 --- a/lib/pleroma/web/activity_pub/activity_pub.ex +++ b/lib/pleroma/web/activity_pub/activity_pub.ex @@ -1427,19 +1427,41 @@ defmodule Pleroma.Web.ActivityPub.ActivityPub do        |> Enum.filter(fn %{"type" => t} -> t == "PropertyValue" end)        |> Enum.map(fn fields -> Map.take(fields, ["name", "value"]) end) +    emojis = +      data +      |> Map.get("tag", []) +      |> Enum.filter(fn %{"type" => t} -> t == "Emoji" end) +      |> Enum.reduce(%{}, fn %{"icon" => %{"url" => url}, "name" => name}, acc -> +        Map.put(acc, String.trim(name, ":"), url) +      end) +      locked = data["manuallyApprovesFollowers"] || false      data = Transmogrifier.maybe_fix_user_object(data)      discoverable = data["discoverable"] || false      invisible = data["invisible"] || false      actor_type = data["type"] || "Person" +    public_key = +      if is_map(data["publicKey"]) && is_binary(data["publicKey"]["publicKeyPem"]) do +        data["publicKey"]["publicKeyPem"] +      else +        nil +      end + +    shared_inbox = +      if is_map(data["endpoints"]) && is_binary(data["endpoints"]["sharedInbox"]) do +        data["endpoints"]["sharedInbox"] +      else +        nil +      end +      user_data = %{        ap_id: data["id"],        uri: get_actor_url(data["url"]),        ap_enabled: true, -      source_data: data,        banner: banner,        fields: fields, +      emoji: emojis,        locked: locked,        discoverable: discoverable,        invisible: invisible, @@ -1449,7 +1471,10 @@ defmodule Pleroma.Web.ActivityPub.ActivityPub do        following_address: data["following"],        bio: data["summary"],        actor_type: actor_type, -      also_known_as: Map.get(data, "alsoKnownAs", []) +      also_known_as: Map.get(data, "alsoKnownAs", []), +      public_key: public_key, +      inbox: data["inbox"], +      shared_inbox: shared_inbox      }      # nickname can be nil because of virtual actors @@ -1551,11 +1576,22 @@ defmodule Pleroma.Web.ActivityPub.ActivityPub do    end    def make_user_from_ap_id(ap_id) do -    if _user = User.get_cached_by_ap_id(ap_id) do +    user = User.get_cached_by_ap_id(ap_id) + +    if user && !User.ap_enabled?(user) do        Transmogrifier.upgrade_user_from_ap_id(ap_id)      else        with {:ok, data} <- fetch_and_prepare_user_from_ap_id(ap_id) do -        User.insert_or_update_user(data) +        if user do +          user +          |> User.remote_user_changeset(data) +          |> User.update_and_set_cache() +        else +          data +          |> User.remote_user_changeset() +          |> Repo.insert() +          |> User.set_cache() +        end        else          e -> {:error, e}        end diff --git a/lib/pleroma/web/activity_pub/object_validators/note_validator.ex b/lib/pleroma/web/activity_pub/object_validators/note_validator.ex index c95b622e4..462a5620a 100644 --- a/lib/pleroma/web/activity_pub/object_validators/note_validator.ex +++ b/lib/pleroma/web/activity_pub/object_validators/note_validator.ex @@ -35,6 +35,7 @@ defmodule Pleroma.Web.ActivityPub.ObjectValidators.NoteValidator do      field(:like_count, :integer, default: 0)      field(:announcement_count, :integer, default: 0)      field(:inRepyTo, :string) +    field(:uri, Types.Uri)      field(:likes, {:array, :string}, default: [])      field(:announcements, {:array, :string}, default: []) diff --git a/lib/pleroma/web/activity_pub/object_validators/types/object_id.ex b/lib/pleroma/web/activity_pub/object_validators/types/object_id.ex index f6e749b33..f71f76370 100644 --- a/lib/pleroma/web/activity_pub/object_validators/types/object_id.ex +++ b/lib/pleroma/web/activity_pub/object_validators/types/object_id.ex @@ -15,15 +15,9 @@ defmodule Pleroma.Web.ActivityPub.ObjectValidators.Types.ObjectID do    def cast(%{"id" => object}), do: cast(object) -  def cast(_) do -    :error -  end +  def cast(_), do: :error -  def dump(data) do -    {:ok, data} -  end +  def dump(data), do: {:ok, data} -  def load(data) do -    {:ok, data} -  end +  def load(data), do: {:ok, data}  end diff --git a/lib/pleroma/web/activity_pub/object_validators/types/uri.ex b/lib/pleroma/web/activity_pub/object_validators/types/uri.ex new file mode 100644 index 000000000..24845bcc0 --- /dev/null +++ b/lib/pleroma/web/activity_pub/object_validators/types/uri.ex @@ -0,0 +1,20 @@ +defmodule Pleroma.Web.ActivityPub.ObjectValidators.Types.Uri do +  use Ecto.Type + +  def type, do: :string + +  def cast(uri) when is_binary(uri) do +    case URI.parse(uri) do +      %URI{host: nil} -> :error +      %URI{host: ""} -> :error +      %URI{scheme: scheme} when scheme in ["https", "http"] -> {:ok, uri} +      _ -> :error +    end +  end + +  def cast(_), do: :error + +  def dump(data), do: {:ok, data} + +  def load(data), do: {:ok, data} +end diff --git a/lib/pleroma/web/activity_pub/publisher.ex b/lib/pleroma/web/activity_pub/publisher.ex index 6c558e7f0..b70cbd043 100644 --- a/lib/pleroma/web/activity_pub/publisher.ex +++ b/lib/pleroma/web/activity_pub/publisher.ex @@ -141,8 +141,8 @@ defmodule Pleroma.Web.ActivityPub.Publisher do      |> Enum.map(& &1.ap_id)    end -  defp maybe_use_sharedinbox(%User{source_data: data}), -    do: (is_map(data["endpoints"]) && Map.get(data["endpoints"], "sharedInbox")) || data["inbox"] +  defp maybe_use_sharedinbox(%User{shared_inbox: nil, inbox: inbox}), do: inbox +  defp maybe_use_sharedinbox(%User{shared_inbox: shared_inbox}), do: shared_inbox    @doc """    Determine a user inbox to use based on heuristics.  These heuristics @@ -157,7 +157,7 @@ defmodule Pleroma.Web.ActivityPub.Publisher do    """    def determine_inbox(          %Activity{data: activity_data}, -        %User{source_data: data} = user +        %User{inbox: inbox} = user        ) do      to = activity_data["to"] || []      cc = activity_data["cc"] || [] @@ -174,7 +174,7 @@ defmodule Pleroma.Web.ActivityPub.Publisher do          maybe_use_sharedinbox(user)        true -> -        data["inbox"] +        inbox      end    end @@ -192,14 +192,13 @@ defmodule Pleroma.Web.ActivityPub.Publisher do      inboxes =        recipients        |> Enum.filter(&User.ap_enabled?/1) -      |> Enum.map(fn %{source_data: data} -> data["inbox"] end) +      |> Enum.map(fn actor -> actor.inbox end)        |> Enum.filter(fn inbox -> should_federate?(inbox, public) end)        |> Instances.filter_reachable()      Repo.checkout(fn ->        Enum.each(inboxes, fn {inbox, unreachable_since} -> -        %User{ap_id: ap_id} = -          Enum.find(recipients, fn %{source_data: data} -> data["inbox"] == inbox end) +        %User{ap_id: ap_id} = Enum.find(recipients, fn actor -> actor.inbox == inbox end)          # Get all the recipients on the same host and add them to cc. Otherwise, a remote          # instance would only accept a first message for the first recipient and ignore the rest. diff --git a/lib/pleroma/web/activity_pub/transmogrifier.ex b/lib/pleroma/web/activity_pub/transmogrifier.ex index 39feae285..09119137b 100644 --- a/lib/pleroma/web/activity_pub/transmogrifier.ex +++ b/lib/pleroma/web/activity_pub/transmogrifier.ex @@ -711,7 +711,7 @@ defmodule Pleroma.Web.ActivityPub.Transmogrifier do        {:ok, new_user_data} = ActivityPub.user_data_from_user_object(object)        actor -      |> User.upgrade_changeset(new_user_data, true) +      |> User.remote_user_changeset(new_user_data)        |> User.update_and_set_cache()        ActivityPub.update(%{ @@ -1160,7 +1160,7 @@ defmodule Pleroma.Web.ActivityPub.Transmogrifier do    def take_emoji_tags(%User{emoji: emoji}) do      emoji -    |> Enum.flat_map(&Map.to_list/1) +    |> Map.to_list()      |> Enum.map(&build_emoji_tag/1)    end @@ -1254,12 +1254,8 @@ defmodule Pleroma.Web.ActivityPub.Transmogrifier do    def upgrade_user_from_ap_id(ap_id) do      with %User{local: false} = user <- User.get_cached_by_ap_id(ap_id),           {:ok, data} <- ActivityPub.fetch_and_prepare_user_from_ap_id(ap_id), -         already_ap <- User.ap_enabled?(user), -         {:ok, user} <- upgrade_user(user, data) do -      if not already_ap do -        TransmogrifierWorker.enqueue("user_upgrade", %{"user_id" => user.id}) -      end - +         {:ok, user} <- update_user(user, data) do +      TransmogrifierWorker.enqueue("user_upgrade", %{"user_id" => user.id})        {:ok, user}      else        %User{} = user -> {:ok, user} @@ -1267,9 +1263,9 @@ defmodule Pleroma.Web.ActivityPub.Transmogrifier do      end    end -  defp upgrade_user(user, data) do +  defp update_user(user, data) do      user -    |> User.upgrade_changeset(data, true) +    |> User.remote_user_changeset(data)      |> User.update_and_set_cache()    end diff --git a/lib/pleroma/web/activity_pub/views/user_view.ex b/lib/pleroma/web/activity_pub/views/user_view.ex index bc21ac6c7..34590b16d 100644 --- a/lib/pleroma/web/activity_pub/views/user_view.ex +++ b/lib/pleroma/web/activity_pub/views/user_view.ex @@ -79,10 +79,7 @@ defmodule Pleroma.Web.ActivityPub.UserView do      emoji_tags = Transmogrifier.take_emoji_tags(user) -    fields = -      user -      |> User.fields() -      |> Enum.map(&Map.put(&1, "type", "PropertyValue")) +    fields = Enum.map(user.fields, &Map.put(&1, "type", "PropertyValue"))      %{        "id" => user.ap_id, @@ -103,7 +100,7 @@ defmodule Pleroma.Web.ActivityPub.UserView do        },        "endpoints" => endpoints,        "attachment" => fields, -      "tag" => (user.source_data["tag"] || []) ++ emoji_tags, +      "tag" => emoji_tags,        "discoverable" => user.discoverable      }      |> Map.merge(maybe_make_image(&User.avatar_url/2, "icon", user)) diff --git a/lib/pleroma/web/common_api/common_api.ex b/lib/pleroma/web/common_api/common_api.ex index c56756a3d..f50a909aa 100644 --- a/lib/pleroma/web/common_api/common_api.ex +++ b/lib/pleroma/web/common_api/common_api.ex @@ -332,26 +332,6 @@ defmodule Pleroma.Web.CommonAPI do    defp maybe_create_activity_expiration(result, _), do: result -  # Updates the emojis for a user based on their profile -  def update(user) do -    emoji = emoji_from_profile(user) -    source_data = Map.put(user.source_data, "tag", emoji) - -    user = -      case User.update_source_data(user, source_data) do -        {:ok, user} -> user -        _ -> user -      end - -    ActivityPub.update(%{ -      local: true, -      to: [Pleroma.Constants.as_public(), user.follower_address], -      cc: [], -      actor: user.ap_id, -      object: Pleroma.Web.ActivityPub.UserView.render("user.json", %{user: user}) -    }) -  end -    def pin(id_or_ap_id, %{ap_id: user_ap_id} = user) do      with %Activity{             actor: ^user_ap_id, diff --git a/lib/pleroma/web/common_api/utils.ex b/lib/pleroma/web/common_api/utils.ex index 635e7cd38..7eec5aa09 100644 --- a/lib/pleroma/web/common_api/utils.ex +++ b/lib/pleroma/web/common_api/utils.ex @@ -10,7 +10,6 @@ defmodule Pleroma.Web.CommonAPI.Utils do    alias Pleroma.Activity    alias Pleroma.Config    alias Pleroma.Conversation.Participation -  alias Pleroma.Emoji    alias Pleroma.Formatter    alias Pleroma.Object    alias Pleroma.Plugs.AuthenticationPlug @@ -18,7 +17,6 @@ defmodule Pleroma.Web.CommonAPI.Utils do    alias Pleroma.User    alias Pleroma.Web.ActivityPub.Utils    alias Pleroma.Web.ActivityPub.Visibility -  alias Pleroma.Web.Endpoint    alias Pleroma.Web.MediaProxy    require Logger @@ -175,7 +173,7 @@ defmodule Pleroma.Web.CommonAPI.Utils do              "replies" => %{"type" => "Collection", "totalItems" => 0}            } -          {note, Map.merge(emoji, Emoji.Formatter.get_emoji_map(option))} +          {note, Map.merge(emoji, Pleroma.Emoji.Formatter.get_emoji_map(option))}          end)        end_time = @@ -431,19 +429,6 @@ defmodule Pleroma.Web.CommonAPI.Utils do      end    end -  def emoji_from_profile(%User{bio: bio, name: name}) do -    [bio, name] -    |> Enum.map(&Emoji.Formatter.get_emoji/1) -    |> Enum.concat() -    |> Enum.map(fn {shortcode, %Emoji{file: path}} -> -      %{ -        "type" => "Emoji", -        "icon" => %{"type" => "Image", "url" => "#{Endpoint.url()}#{path}"}, -        "name" => ":#{shortcode}:" -      } -    end) -  end -    def maybe_notify_to_recipients(          recipients,          %Activity{data: %{"to" => to, "type" => _type}} = _activity diff --git a/lib/pleroma/web/feed/feed_view.ex b/lib/pleroma/web/feed/feed_view.ex index e18adaea8..1ae03e7e2 100644 --- a/lib/pleroma/web/feed/feed_view.ex +++ b/lib/pleroma/web/feed/feed_view.ex @@ -23,7 +23,7 @@ defmodule Pleroma.Web.Feed.FeedView do    def pub_date(%DateTime{} = date), do: Timex.format!(date, "{RFC822}")    def prepare_activity(activity, opts \\ []) do -    object = activity_object(activity) +    object = Object.normalize(activity)      actor =        if opts[:actor] do @@ -33,7 +33,6 @@ defmodule Pleroma.Web.Feed.FeedView do      %{        activity: activity,        data: Map.get(object, :data), -      object: object,        actor: actor      }    end @@ -68,9 +67,7 @@ defmodule Pleroma.Web.Feed.FeedView do    def last_activity(activities), do: List.last(activities) -  def activity_object(activity), do: Object.normalize(activity) - -  def activity_title(%{data: %{"content" => content}}, opts \\ %{}) do +  def activity_title(%{"content" => content}, opts \\ %{}) do      content      |> Pleroma.Web.Metadata.Utils.scrub_html()      |> Pleroma.Emoji.Formatter.demojify() @@ -78,7 +75,7 @@ defmodule Pleroma.Web.Feed.FeedView do      |> escape()    end -  def activity_content(%{data: %{"content" => content}}) do +  def activity_content(%{"content" => content}) do      content      |> String.replace(~r/[\n\r]/, "")      |> escape() diff --git a/lib/pleroma/web/masto_fe_controller.ex b/lib/pleroma/web/masto_fe_controller.ex index 43649ad26..557cde328 100644 --- a/lib/pleroma/web/masto_fe_controller.ex +++ b/lib/pleroma/web/masto_fe_controller.ex @@ -17,7 +17,7 @@ defmodule Pleroma.Web.MastoFEController do      when action == :index    ) -  plug(Pleroma.Plugs.EnsurePublicOrAuthenticatedPlug when action != :index) +  plug(Pleroma.Plugs.EnsurePublicOrAuthenticatedPlug when action not in [:index, :manifest])    @doc "GET /web/*path"    def index(%{assigns: %{user: user, token: token}} = conn, _params) diff --git a/lib/pleroma/web/mastodon_api/controllers/account_controller.ex b/lib/pleroma/web/mastodon_api/controllers/account_controller.ex index 7da1a11f6..28e80789d 100644 --- a/lib/pleroma/web/mastodon_api/controllers/account_controller.ex +++ b/lib/pleroma/web/mastodon_api/controllers/account_controller.ex @@ -21,10 +21,13 @@ defmodule Pleroma.Web.MastodonAPI.AccountController do    alias Pleroma.Web.CommonAPI    alias Pleroma.Web.MastodonAPI.ListView    alias Pleroma.Web.MastodonAPI.MastodonAPI +  alias Pleroma.Web.MastodonAPI.MastodonAPIController    alias Pleroma.Web.MastodonAPI.StatusView    alias Pleroma.Web.OAuth.Token    alias Pleroma.Web.TwitterAPI.TwitterAPI +  plug(:skip_plug, OAuthScopesPlug when action == :identity_proofs) +    plug(      OAuthScopesPlug,      %{fallback: :proceed_unauthenticated, scopes: ["read:accounts"]} @@ -146,9 +149,7 @@ defmodule Pleroma.Web.MastodonAPI.AccountController do    end    @doc "PATCH /api/v1/accounts/update_credentials" -  def update_credentials(%{assigns: %{user: original_user}} = conn, params) do -    user = original_user - +  def update_credentials(%{assigns: %{user: user}} = conn, params) do      user_params =        [          :no_rich_text, @@ -184,8 +185,6 @@ defmodule Pleroma.Web.MastodonAPI.AccountController do      changeset = User.update_changeset(user, user_params)      with {:ok, user} <- User.update_and_set_cache(changeset) do -      if original_user != user, do: CommonAPI.update(user) -        render(conn, "show.json", user: user, for: user, with_pleroma_settings: true)      else        _e -> render_error(conn, :forbidden, "Invalid request") @@ -380,6 +379,8 @@ defmodule Pleroma.Web.MastodonAPI.AccountController do    end    @doc "GET /api/v1/endorsements" -  def endorsements(conn, params), -    do: Pleroma.Web.MastodonAPI.MastodonAPIController.empty_array(conn, params) +  def endorsements(conn, params), do: MastodonAPIController.empty_array(conn, params) + +  @doc "GET /api/v1/identity_proofs" +  def identity_proofs(conn, params), do: MastodonAPIController.empty_array(conn, params)  end diff --git a/lib/pleroma/web/mastodon_api/controllers/mastodon_api_controller.ex b/lib/pleroma/web/mastodon_api/controllers/mastodon_api_controller.ex index 14075307d..ac8c18f24 100644 --- a/lib/pleroma/web/mastodon_api/controllers/mastodon_api_controller.ex +++ b/lib/pleroma/web/mastodon_api/controllers/mastodon_api_controller.ex @@ -3,21 +3,31 @@  # SPDX-License-Identifier: AGPL-3.0-only  defmodule Pleroma.Web.MastodonAPI.MastodonAPIController do +  @moduledoc """ +  Contains stubs for unimplemented Mastodon API endpoints. + +  Note: instead of routing directly to this controller's action, +    it's preferable to define an action in relevant (non-generic) controller, +    set up OAuth rules for it and call this controller's function from it. +  """ +    use Pleroma.Web, :controller    require Logger +  plug(:skip_plug, Pleroma.Plugs.OAuthScopesPlug when action in [:empty_array, :empty_object]) + +  plug(Pleroma.Plugs.EnsurePublicOrAuthenticatedPlug) +    action_fallback(Pleroma.Web.MastodonAPI.FallbackController) -  # Stubs for unimplemented mastodon api -  #    def empty_array(conn, _) do -    Logger.debug("Unimplemented, returning an empty array") +    Logger.debug("Unimplemented, returning an empty array (list)")      json(conn, [])    end    def empty_object(conn, _) do -    Logger.debug("Unimplemented, returning an empty object") +    Logger.debug("Unimplemented, returning an empty object (map)")      json(conn, %{})    end  end diff --git a/lib/pleroma/web/mastodon_api/controllers/suggestion_controller.ex b/lib/pleroma/web/mastodon_api/controllers/suggestion_controller.ex index 0cdc7bd8d..c93a43969 100644 --- a/lib/pleroma/web/mastodon_api/controllers/suggestion_controller.ex +++ b/lib/pleroma/web/mastodon_api/controllers/suggestion_controller.ex @@ -5,10 +5,13 @@  defmodule Pleroma.Web.MastodonAPI.SuggestionController do    use Pleroma.Web, :controller +  alias Pleroma.Plugs.OAuthScopesPlug +    require Logger +  plug(OAuthScopesPlug, %{scopes: ["read"]} when action == :index) +    @doc "GET /api/v1/suggestions" -  def index(conn, _) do -    json(conn, []) -  end +  def index(conn, params), +    do: Pleroma.Web.MastodonAPI.MastodonAPIController.empty_array(conn, params)  end diff --git a/lib/pleroma/web/mastodon_api/views/account_view.ex b/lib/pleroma/web/mastodon_api/views/account_view.ex index 8fb96a22a..b4b61e74c 100644 --- a/lib/pleroma/web/mastodon_api/views/account_view.ex +++ b/lib/pleroma/web/mastodon_api/views/account_view.ex @@ -181,13 +181,11 @@ defmodule Pleroma.Web.MastodonAPI.AccountView do      bot = user.actor_type in ["Application", "Service"]      emojis = -      (user.source_data["tag"] || []) -      |> Enum.filter(fn %{"type" => t} -> t == "Emoji" end) -      |> Enum.map(fn %{"icon" => %{"url" => url}, "name" => name} -> +      Enum.map(user.emoji, fn {shortcode, url} ->          %{ -          "shortcode" => String.trim(name, ":"), -          "url" => MediaProxy.url(url), -          "static_url" => MediaProxy.url(url), +          "shortcode" => shortcode, +          "url" => url, +          "static_url" => url,            "visible_in_picker" => false          }        end) diff --git a/lib/pleroma/web/oauth/oauth_controller.ex b/lib/pleroma/web/oauth/oauth_controller.ex index 46688db7e..0121cd661 100644 --- a/lib/pleroma/web/oauth/oauth_controller.ex +++ b/lib/pleroma/web/oauth/oauth_controller.ex @@ -27,6 +27,8 @@ defmodule Pleroma.Web.OAuth.OAuthController do    plug(:fetch_flash)    plug(RateLimiter, [name: :authentication] when action == :create_authorization) +  plug(:skip_plug, Pleroma.Plugs.OAuthScopesPlug) +    action_fallback(Pleroma.Web.OAuth.FallbackController)    @oob_token_redirect_uri "urn:ietf:wg:oauth:2.0:oob" diff --git a/lib/pleroma/web/pleroma_api/controllers/account_controller.ex b/lib/pleroma/web/pleroma_api/controllers/account_controller.ex index 9d0b3b1e4..60405fbff 100644 --- a/lib/pleroma/web/pleroma_api/controllers/account_controller.ex +++ b/lib/pleroma/web/pleroma_api/controllers/account_controller.ex @@ -13,7 +13,6 @@ defmodule Pleroma.Web.PleromaAPI.AccountController do    alias Pleroma.Plugs.RateLimiter    alias Pleroma.User    alias Pleroma.Web.ActivityPub.ActivityPub -  alias Pleroma.Web.CommonAPI    alias Pleroma.Web.MastodonAPI.StatusView    require Pleroma.Constants @@ -58,38 +57,32 @@ defmodule Pleroma.Web.PleromaAPI.AccountController do    @doc "PATCH /api/v1/pleroma/accounts/update_avatar"    def update_avatar(%{assigns: %{user: user}} = conn, %{"img" => ""}) do -    {:ok, user} = +    {:ok, _user} =        user        |> Changeset.change(%{avatar: nil})        |> User.update_and_set_cache() -    CommonAPI.update(user) -      json(conn, %{url: nil})    end    def update_avatar(%{assigns: %{user: user}} = conn, params) do      {:ok, %{data: data}} = ActivityPub.upload(params, type: :avatar) -    {:ok, user} = user |> Changeset.change(%{avatar: data}) |> User.update_and_set_cache() +    {:ok, _user} = user |> Changeset.change(%{avatar: data}) |> User.update_and_set_cache()      %{"url" => [%{"href" => href} | _]} = data -    CommonAPI.update(user) -      json(conn, %{url: href})    end    @doc "PATCH /api/v1/pleroma/accounts/update_banner"    def update_banner(%{assigns: %{user: user}} = conn, %{"banner" => ""}) do -    with {:ok, user} <- User.update_banner(user, %{}) do -      CommonAPI.update(user) +    with {:ok, _user} <- User.update_banner(user, %{}) do        json(conn, %{url: nil})      end    end    def update_banner(%{assigns: %{user: user}} = conn, params) do      with {:ok, object} <- ActivityPub.upload(%{"img" => params["banner"]}, type: :banner), -         {:ok, user} <- User.update_banner(user, object.data) do -      CommonAPI.update(user) +         {:ok, _user} <- User.update_banner(user, object.data) do        %{"url" => [%{"href" => href} | _]} = object.data        json(conn, %{url: href}) diff --git a/lib/pleroma/web/pleroma_api/controllers/pleroma_api_controller.ex b/lib/pleroma/web/pleroma_api/controllers/pleroma_api_controller.ex index d4c5c5925..fe1b97a20 100644 --- a/lib/pleroma/web/pleroma_api/controllers/pleroma_api_controller.ex +++ b/lib/pleroma/web/pleroma_api/controllers/pleroma_api_controller.ex @@ -34,7 +34,7 @@ defmodule Pleroma.Web.PleromaAPI.PleromaAPIController do    plug(      OAuthScopesPlug, -    %{scopes: ["write:conversations"]} when action == :update_conversation +    %{scopes: ["write:conversations"]} when action in [:update_conversation, :read_conversations]    )    plug(OAuthScopesPlug, %{scopes: ["write:notifications"]} when action == :read_notification) diff --git a/lib/pleroma/web/router.ex b/lib/pleroma/web/router.ex index fd94913a1..e9739983d 100644 --- a/lib/pleroma/web/router.ex +++ b/lib/pleroma/web/router.ex @@ -35,6 +35,7 @@ defmodule Pleroma.Web.Router do    pipeline :authenticated_api do      plug(:accepts, ["json"])      plug(:fetch_session) +    plug(Pleroma.Plugs.AuthExpectedPlug)      plug(Pleroma.Plugs.OAuthPlug)      plug(Pleroma.Plugs.BasicAuthDecoderPlug)      plug(Pleroma.Plugs.UserFetcherPlug) @@ -339,7 +340,7 @@ defmodule Pleroma.Web.Router do      get("/accounts/relationships", AccountController, :relationships)      get("/accounts/:id/lists", AccountController, :lists) -    get("/accounts/:id/identity_proofs", MastodonAPIController, :empty_array) +    get("/accounts/:id/identity_proofs", AccountController, :identity_proofs)      get("/follow_requests", FollowRequestController, :index)      get("/blocks", AccountController, :blocks) @@ -672,6 +673,17 @@ defmodule Pleroma.Web.Router do      end    end +  # Test-only routes needed to test action dispatching and plug chain execution +  if Pleroma.Config.get(:env) == :test do +    scope "/test/authenticated_api", Pleroma.Tests do +      pipe_through(:authenticated_api) + +      for action <- [:skipped_oauth, :performed_oauth, :missed_oauth] do +        get("/#{action}", OAuthTestController, action) +      end +    end +  end +    scope "/", Pleroma.Web.MongooseIM do      get("/user_exists", MongooseIMController, :user_exists)      get("/check_password", MongooseIMController, :check_password) diff --git a/lib/pleroma/web/static_fe/static_fe_view.ex b/lib/pleroma/web/static_fe/static_fe_view.ex index 66d87620c..b3d1d1ec8 100644 --- a/lib/pleroma/web/static_fe/static_fe_view.ex +++ b/lib/pleroma/web/static_fe/static_fe_view.ex @@ -18,15 +18,6 @@ defmodule Pleroma.Web.StaticFE.StaticFEView do    @media_types ["image", "audio", "video"] -  def emoji_for_user(%User{} = user) do -    user.source_data -    |> Map.get("tag", []) -    |> Enum.filter(fn %{"type" => t} -> t == "Emoji" end) -    |> Enum.map(fn %{"icon" => %{"url" => url}, "name" => name} -> -      {String.trim(name, ":"), url} -    end) -  end -    def fetch_media_type(%{"mediaType" => mediaType}) do      Utils.fetch_media_type(@media_types, mediaType)    end diff --git a/lib/pleroma/web/templates/feed/feed/_activity.atom.eex b/lib/pleroma/web/templates/feed/feed/_activity.atom.eex index ac8a75009..78350f2aa 100644 --- a/lib/pleroma/web/templates/feed/feed/_activity.atom.eex +++ b/lib/pleroma/web/templates/feed/feed/_activity.atom.eex @@ -2,10 +2,10 @@    <activity:object-type>http://activitystrea.ms/schema/1.0/note</activity:object-type>    <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>    <id><%= @data["id"] %></id> -  <title><%= activity_title(@object, Keyword.get(@feed_config, :post_title, %{})) %></title> -  <content type="html"><%= activity_content(@object) %></content> -  <published><%= @data["published"] %></published> -  <updated><%= @data["published"] %></updated> +  <title><%= activity_title(@data, Keyword.get(@feed_config, :post_title, %{})) %></title> +  <content type="html"><%= activity_content(@data) %></content> +  <published><%= @activity.data["published"] %></published> +  <updated><%= @activity.data["published"] %></updated>    <ostatus:conversation ref="<%= activity_context(@activity) %>">      <%= activity_context(@activity) %>    </ostatus:conversation> diff --git a/lib/pleroma/web/templates/feed/feed/_activity.rss.eex b/lib/pleroma/web/templates/feed/feed/_activity.rss.eex index a4dbed638..a304a16af 100644 --- a/lib/pleroma/web/templates/feed/feed/_activity.rss.eex +++ b/lib/pleroma/web/templates/feed/feed/_activity.rss.eex @@ -2,10 +2,10 @@    <activity:object-type>http://activitystrea.ms/schema/1.0/note</activity:object-type>    <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>    <guid><%= @data["id"] %></guid> -  <title><%= activity_title(@object, Keyword.get(@feed_config, :post_title, %{})) %></title> -  <description><%= activity_content(@object) %></description> -  <pubDate><%= @data["published"] %></pubDate> -  <updated><%= @data["published"] %></updated> +  <title><%= activity_title(@data, Keyword.get(@feed_config, :post_title, %{})) %></title> +  <description><%= activity_content(@data) %></description> +  <pubDate><%= @activity.data["published"] %></pubDate> +  <updated><%= @activity.data["published"] %></updated>    <ostatus:conversation ref="<%= activity_context(@activity) %>">      <%= activity_context(@activity) %>    </ostatus:conversation> diff --git a/lib/pleroma/web/templates/feed/feed/_tag_activity.atom.eex b/lib/pleroma/web/templates/feed/feed/_tag_activity.atom.eex index da4fa6d6c..cf5874a91 100644 --- a/lib/pleroma/web/templates/feed/feed/_tag_activity.atom.eex +++ b/lib/pleroma/web/templates/feed/feed/_tag_activity.atom.eex @@ -1,12 +1,12 @@  <entry>      <activity:object-type>http://activitystrea.ms/schema/1.0/note</activity:object-type>      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb> -     +      <%= render @view_module, "_tag_author.atom", assigns %> -     +      <id><%= @data["id"] %></id> -    <title><%= activity_title(@object, Keyword.get(@feed_config, :post_title, %{})) %></title> -    <content type="html"><%= activity_content(@object) %></content> +    <title><%= activity_title(@data, Keyword.get(@feed_config, :post_title, %{})) %></title> +    <content type="html"><%= activity_content(@data) %></content>    <%= if @activity.local do %>      <link type="application/atom+xml" href='<%= @data["id"] %>' rel="self"/> @@ -15,8 +15,8 @@      <link type="text/html" href='<%= @data["external_url"] %>' rel="alternate"/>    <% end %> -    <published><%= @data["published"] %></published> -    <updated><%= @data["published"] %></updated> +    <published><%= @activity.data["published"] %></published> +    <updated><%= @activity.data["published"] %></updated>      <ostatus:conversation ref="<%= activity_context(@activity) %>">        <%= activity_context(@activity) %> @@ -26,7 +26,7 @@     <%= if @data["summary"] do %>      <summary><%= @data["summary"] %></summary>     <% end %> -   +      <%= for id <- @activity.recipients do %>        <%= if id == Pleroma.Constants.as_public() do %>          <link rel="mentioned" @@ -40,7 +40,7 @@          <% end %>        <% end %>      <% end %> -   +      <%= for tag <- @data["tag"] || [] do %>        <category term="<%= tag %>"></category>      <% end %> diff --git a/lib/pleroma/web/templates/feed/feed/_tag_activity.xml.eex b/lib/pleroma/web/templates/feed/feed/_tag_activity.xml.eex index 295574df1..2334e24a2 100644 --- a/lib/pleroma/web/templates/feed/feed/_tag_activity.xml.eex +++ b/lib/pleroma/web/templates/feed/feed/_tag_activity.xml.eex @@ -1,15 +1,14 @@  <item> -  <title><%= activity_title(@object, Keyword.get(@feed_config, :post_title, %{})) %></title> -   -   +  <title><%= activity_title(@data, Keyword.get(@feed_config, :post_title, %{})) %></title> + +    <guid isPermalink="true"><%= activity_context(@activity) %></guid>    <link><%= activity_context(@activity) %></link> -  <pubDate><%= pub_date(@data["published"]) %></pubDate> -   -  <description><%= activity_content(@object) %></description> +  <pubDate><%= pub_date(@activity.data["published"]) %></pubDate> + +  <description><%= activity_content(@data) %></description>    <%= for attachment <- @data["attachment"] || [] do %>      <enclosure url="<%= attachment_href(attachment) %>" type="<%= attachment_type(attachment) %>"/>    <% end %> -   -</item> +</item> diff --git a/lib/pleroma/web/templates/static_fe/static_fe/_user_card.html.eex b/lib/pleroma/web/templates/static_fe/static_fe/_user_card.html.eex index 2a7582d45..56f3a1524 100644 --- a/lib/pleroma/web/templates/static_fe/static_fe/_user_card.html.eex +++ b/lib/pleroma/web/templates/static_fe/static_fe/_user_card.html.eex @@ -4,7 +4,7 @@        <img src="<%= User.avatar_url(@user) |> MediaProxy.url %>" width="48" height="48" alt="">      </div>      <span class="display-name"> -      <bdi><%= raw (@user.name |> Formatter.emojify(emoji_for_user(@user))) %></bdi> +      <bdi><%= raw Formatter.emojify(@user.name, @user.emoji) %></bdi>        <span class="nickname"><%= @user.nickname %></span>      </span>    </a> diff --git a/lib/pleroma/web/templates/static_fe/static_fe/profile.html.eex b/lib/pleroma/web/templates/static_fe/static_fe/profile.html.eex index e7d2aecad..3191bf450 100644 --- a/lib/pleroma/web/templates/static_fe/static_fe/profile.html.eex +++ b/lib/pleroma/web/templates/static_fe/static_fe/profile.html.eex @@ -7,7 +7,7 @@        <input type="hidden" name="profile" value="">        <button type="submit" class="collapse">Remote follow</button>      </form> -    <%= raw Formatter.emojify(@user.name, emoji_for_user(@user)) %> | +    <%= raw Formatter.emojify(@user.name, @user.emoji) %> |      <%= link "@#{@user.nickname}@#{Endpoint.host()}", to: (@user.uri || @user.ap_id) %>    </h3>    <p><%= raw @user.bio %></p> diff --git a/lib/pleroma/web/twitter_api/twitter_api_controller.ex b/lib/pleroma/web/twitter_api/twitter_api_controller.ex index 0229aea97..31adc2817 100644 --- a/lib/pleroma/web/twitter_api/twitter_api_controller.ex +++ b/lib/pleroma/web/twitter_api/twitter_api_controller.ex @@ -15,6 +15,8 @@ defmodule Pleroma.Web.TwitterAPI.Controller do    plug(OAuthScopesPlug, %{scopes: ["write:notifications"]} when action == :notifications_read) +  plug(:skip_plug, OAuthScopesPlug when action in [:oauth_tokens, :revoke_token]) +    plug(Pleroma.Plugs.EnsurePublicOrAuthenticatedPlug)    action_fallback(:errors) diff --git a/lib/pleroma/web/web.ex b/lib/pleroma/web/web.ex index cf3ac1287..ae7c94640 100644 --- a/lib/pleroma/web/web.ex +++ b/lib/pleroma/web/web.ex @@ -29,11 +29,40 @@ defmodule Pleroma.Web do        import Pleroma.Web.Router.Helpers        import Pleroma.Web.TranslationHelpers +      alias Pleroma.Plugs.PlugHelper +        plug(:set_put_layout)        defp set_put_layout(conn, _) do          put_layout(conn, Pleroma.Config.get(:app_layout, "app.html"))        end + +      # Marks a plug intentionally skipped and blocks its execution if it's present in plugs chain +      defp skip_plug(conn, plug_module) do +        try do +          plug_module.ensure_skippable() +        rescue +          UndefinedFunctionError -> +            raise "#{plug_module} is not skippable. Append `use Pleroma.Web, :plug` to its code." +        end + +        PlugHelper.append_to_skipped_plugs(conn, plug_module) +      end + +      # Here we can apply before-action hooks (e.g. verify whether auth checks were preformed) +      defp action(conn, params) do +        if Pleroma.Plugs.AuthExpectedPlug.auth_expected?(conn) && +             not PlugHelper.plug_called_or_skipped?(conn, Pleroma.Plugs.OAuthScopesPlug) do +          conn +          |> render_error( +            :forbidden, +            "Security violation: OAuth scopes check was neither handled nor explicitly skipped." +          ) +          |> halt() +        else +          super(conn, params) +        end +      end      end    end @@ -96,6 +125,26 @@ defmodule Pleroma.Web do      end    end +  def plug do +    quote do +      alias Pleroma.Plugs.PlugHelper + +      def ensure_skippable, do: :noop + +      @impl Plug +      @doc "If marked as skipped, returns `conn`, and calls `perform/2` otherwise." +      def call(%Plug.Conn{} = conn, options) do +        if PlugHelper.plug_skipped?(conn, __MODULE__) do +          conn +        else +          conn +          |> PlugHelper.append_to_called_plugs(__MODULE__) +          |> perform(options) +        end +      end +    end +  end +    @doc """    When used, dispatch to the appropriate controller/view/etc.    """  | 
