1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2019 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
5 defmodule Pleroma.Web.ActivityPub.ActivityPubController do
6 use Pleroma.Web, :controller
8 alias Pleroma.{Activity, User, Object}
9 alias Pleroma.Web.ActivityPub.{ObjectView, UserView}
10 alias Pleroma.Web.ActivityPub.ActivityPub
11 alias Pleroma.Web.ActivityPub.Relay
12 alias Pleroma.Web.ActivityPub.Utils
13 alias Pleroma.Web.ActivityPub.Transmogrifier
14 alias Pleroma.Web.Federator
18 action_fallback(:errors)
20 plug(Pleroma.Web.FederatingPlug when action in [:inbox, :relay])
21 plug(:set_requester_reachable when action in [:inbox])
22 plug(:relay_active? when action in [:relay])
24 def relay_active?(conn, _) do
25 if Keyword.get(Application.get_env(:pleroma, :instance), :allow_relay) do
30 |> json(%{error: "not found"})
35 def user(conn, %{"nickname" => nickname}) do
36 with %User{} = user <- User.get_cached_by_nickname(nickname),
37 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
39 |> put_resp_header("content-type", "application/activity+json")
40 |> json(UserView.render("user.json", %{user: user}))
42 nil -> {:error, :not_found}
46 def object(conn, %{"uuid" => uuid}) do
47 with ap_id <- o_status_url(conn, :object, uuid),
48 %Object{} = object <- Object.get_cached_by_ap_id(ap_id),
49 {_, true} <- {:public?, ActivityPub.is_public?(object)} do
51 |> put_resp_header("content-type", "application/activity+json")
52 |> json(ObjectView.render("object.json", %{object: object}))
59 def object_likes(conn, %{"uuid" => uuid, "page" => page}) do
60 with ap_id <- o_status_url(conn, :object, uuid),
61 %Object{} = object <- Object.get_cached_by_ap_id(ap_id),
62 {_, true} <- {:public?, ActivityPub.is_public?(object)},
63 likes <- Utils.get_object_likes(object) do
64 {page, _} = Integer.parse(page)
67 |> put_resp_header("content-type", "application/activity+json")
68 |> json(ObjectView.render("likes.json", ap_id, likes, page))
75 def object_likes(conn, %{"uuid" => uuid}) do
76 with ap_id <- o_status_url(conn, :object, uuid),
77 %Object{} = object <- Object.get_cached_by_ap_id(ap_id),
78 {_, true} <- {:public?, ActivityPub.is_public?(object)},
79 likes <- Utils.get_object_likes(object) do
81 |> put_resp_header("content-type", "application/activity+json")
82 |> json(ObjectView.render("likes.json", ap_id, likes))
89 def activity(conn, %{"uuid" => uuid}) do
90 with ap_id <- o_status_url(conn, :activity, uuid),
91 %Activity{} = activity <- Activity.normalize(ap_id),
92 {_, true} <- {:public?, ActivityPub.is_public?(activity)} do
94 |> put_resp_header("content-type", "application/activity+json")
95 |> json(ObjectView.render("object.json", %{object: activity}))
102 def following(conn, %{"nickname" => nickname, "page" => page}) do
103 with %User{} = user <- User.get_cached_by_nickname(nickname),
104 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
105 {page, _} = Integer.parse(page)
108 |> put_resp_header("content-type", "application/activity+json")
109 |> json(UserView.render("following.json", %{user: user, page: page}))
113 def following(conn, %{"nickname" => nickname}) do
114 with %User{} = user <- User.get_cached_by_nickname(nickname),
115 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
117 |> put_resp_header("content-type", "application/activity+json")
118 |> json(UserView.render("following.json", %{user: user}))
122 def followers(conn, %{"nickname" => nickname, "page" => page}) do
123 with %User{} = user <- User.get_cached_by_nickname(nickname),
124 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
125 {page, _} = Integer.parse(page)
128 |> put_resp_header("content-type", "application/activity+json")
129 |> json(UserView.render("followers.json", %{user: user, page: page}))
133 def followers(conn, %{"nickname" => nickname}) do
134 with %User{} = user <- User.get_cached_by_nickname(nickname),
135 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
137 |> put_resp_header("content-type", "application/activity+json")
138 |> json(UserView.render("followers.json", %{user: user}))
142 def outbox(conn, %{"nickname" => nickname} = params) do
143 with %User{} = user <- User.get_cached_by_nickname(nickname),
144 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
146 |> put_resp_header("content-type", "application/activity+json")
147 |> json(UserView.render("outbox.json", %{user: user, max_id: params["max_id"]}))
151 def inbox(%{assigns: %{valid_signature: true}} = conn, %{"nickname" => nickname} = params) do
152 with %User{} = user <- User.get_cached_by_nickname(nickname),
153 true <- Utils.recipient_in_message(user.ap_id, params),
154 params <- Utils.maybe_splice_recipient(user.ap_id, params) do
155 Federator.enqueue(:incoming_ap_doc, params)
160 def inbox(%{assigns: %{valid_signature: true}} = conn, params) do
161 Federator.enqueue(:incoming_ap_doc, params)
165 # only accept relayed Creates
166 def inbox(conn, %{"type" => "Create"} = params) do
168 "Signature missing or not from author, relayed Create message, fetching object from source"
171 ActivityPub.fetch_object_from_id(params["object"]["id"])
176 def inbox(conn, params) do
177 headers = Enum.into(conn.req_headers, %{})
179 if String.contains?(headers["signature"], params["actor"]) do
181 "Signature validation error for: #{params["actor"]}, make sure you are forwarding the HTTP Host header!"
184 Logger.info(inspect(conn.req_headers))
190 def relay(conn, _params) do
191 with %User{} = user <- Relay.get_actor(),
192 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
194 |> put_resp_header("content-type", "application/activity+json")
195 |> json(UserView.render("user.json", %{user: user}))
197 nil -> {:error, :not_found}
201 def whoami(%{assigns: %{user: %User{} = user}} = conn, _params) do
203 |> put_resp_header("content-type", "application/activity+json")
204 |> json(UserView.render("user.json", %{user: user}))
207 def whoami(_conn, _params), do: {:error, :not_found}
209 def read_inbox(%{assigns: %{user: user}} = conn, %{"nickname" => nickname} = params) do
210 if nickname == user.nickname do
212 |> put_resp_header("content-type", "application/activity+json")
213 |> json(UserView.render("inbox.json", %{user: user, max_id: params["max_id"]}))
216 |> put_status(:forbidden)
217 |> json("can't read inbox of #{nickname} as #{user.nickname}")
221 def handle_user_activity(user, %{"type" => "Create"} = params) do
224 |> Map.merge(Map.take(params, ["to", "cc"]))
225 |> Map.put("attributedTo", user.ap_id())
226 |> Transmogrifier.fix_object()
228 ActivityPub.create(%{
231 context: object["context"],
233 additional: Map.take(params, ["cc"])
237 def handle_user_activity(user, %{"type" => "Delete"} = params) do
238 with %Object{} = object <- Object.normalize(params["object"]),
239 true <- user.info.is_moderator || user.ap_id == object.data["actor"],
240 {:ok, delete} <- ActivityPub.delete(object) do
243 _ -> {:error, "Can't delete object"}
247 def handle_user_activity(user, %{"type" => "Like"} = params) do
248 with %Object{} = object <- Object.normalize(params["object"]),
249 {:ok, activity, _object} <- ActivityPub.like(user, object) do
252 _ -> {:error, "Can't like object"}
256 def handle_user_activity(_, _) do
257 {:error, "Unhandled activity type"}
261 %{assigns: %{user: user}} = conn,
262 %{"nickname" => nickname} = params
264 if nickname == user.nickname do
270 |> Map.put("actor", actor)
271 |> Transmogrifier.fix_addressing()
273 with {:ok, %Activity{} = activity} <- handle_user_activity(user, params) do
275 |> put_status(:created)
276 |> put_resp_header("location", activity.data["id"])
277 |> json(activity.data)
281 |> put_status(:bad_request)
286 |> put_status(:forbidden)
287 |> json("can't update outbox of #{nickname} as #{user.nickname}")
291 def errors(conn, {:error, :not_found}) do
297 def errors(conn, _e) do
303 defp set_requester_reachable(%Plug.Conn{} = conn, _) do
304 with actor <- conn.params["actor"],
305 true <- is_binary(actor) do
306 Pleroma.Instances.set_reachable(actor)