Merge branch 'load-all-dms' into 'develop'
[akkoma] / lib / pleroma / web / activity_pub / activity_pub_controller.ex
1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2019 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
4
5 defmodule Pleroma.Web.ActivityPub.ActivityPubController do
6 use Pleroma.Web, :controller
7 alias Pleroma.{Activity, User, Object}
8 alias Pleroma.Web.ActivityPub.{ObjectView, UserView}
9 alias Pleroma.Web.ActivityPub.ActivityPub
10 alias Pleroma.Web.ActivityPub.Relay
11 alias Pleroma.Web.ActivityPub.Utils
12 alias Pleroma.Web.ActivityPub.Transmogrifier
13 alias Pleroma.Web.Federator
14
15 require Logger
16
17 action_fallback(:errors)
18
19 plug(Pleroma.Web.FederatingPlug when action in [:inbox, :relay])
20 plug(:relay_active? when action in [:relay])
21
22 def relay_active?(conn, _) do
23 if Keyword.get(Application.get_env(:pleroma, :instance), :allow_relay) do
24 conn
25 else
26 conn
27 |> put_status(404)
28 |> json(%{error: "not found"})
29 |> halt
30 end
31 end
32
33 def user(conn, %{"nickname" => nickname}) do
34 with %User{} = user <- User.get_cached_by_nickname(nickname),
35 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
36 conn
37 |> put_resp_header("content-type", "application/activity+json")
38 |> json(UserView.render("user.json", %{user: user}))
39 else
40 nil -> {:error, :not_found}
41 end
42 end
43
44 def object(conn, %{"uuid" => uuid}) do
45 with ap_id <- o_status_url(conn, :object, uuid),
46 %Object{} = object <- Object.get_cached_by_ap_id(ap_id),
47 {_, true} <- {:public?, ActivityPub.is_public?(object)} do
48 conn
49 |> put_resp_header("content-type", "application/activity+json")
50 |> json(ObjectView.render("object.json", %{object: object}))
51 else
52 {:public?, false} ->
53 {:error, :not_found}
54 end
55 end
56
57 def object_likes(conn, %{"uuid" => uuid, "page" => page}) do
58 with ap_id <- o_status_url(conn, :object, uuid),
59 %Object{} = object <- Object.get_cached_by_ap_id(ap_id),
60 {_, true} <- {:public?, ActivityPub.is_public?(object)},
61 likes <- Utils.get_object_likes(object) do
62 {page, _} = Integer.parse(page)
63
64 conn
65 |> put_resp_header("content-type", "application/activity+json")
66 |> json(ObjectView.render("likes.json", ap_id, likes, page))
67 else
68 {:public?, false} ->
69 {:error, :not_found}
70 end
71 end
72
73 def object_likes(conn, %{"uuid" => uuid}) do
74 with ap_id <- o_status_url(conn, :object, uuid),
75 %Object{} = object <- Object.get_cached_by_ap_id(ap_id),
76 {_, true} <- {:public?, ActivityPub.is_public?(object)},
77 likes <- Utils.get_object_likes(object) do
78 conn
79 |> put_resp_header("content-type", "application/activity+json")
80 |> json(ObjectView.render("likes.json", ap_id, likes))
81 else
82 {:public?, false} ->
83 {:error, :not_found}
84 end
85 end
86
87 def activity(conn, %{"uuid" => uuid}) do
88 with ap_id <- o_status_url(conn, :activity, uuid),
89 %Activity{} = activity <- Activity.normalize(ap_id),
90 {_, true} <- {:public?, ActivityPub.is_public?(activity)} do
91 conn
92 |> put_resp_header("content-type", "application/activity+json")
93 |> json(ObjectView.render("object.json", %{object: activity}))
94 else
95 {:public?, false} ->
96 {:error, :not_found}
97 end
98 end
99
100 def following(conn, %{"nickname" => nickname, "page" => page}) do
101 with %User{} = user <- User.get_cached_by_nickname(nickname),
102 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
103 {page, _} = Integer.parse(page)
104
105 conn
106 |> put_resp_header("content-type", "application/activity+json")
107 |> json(UserView.render("following.json", %{user: user, page: page}))
108 end
109 end
110
111 def following(conn, %{"nickname" => nickname}) do
112 with %User{} = user <- User.get_cached_by_nickname(nickname),
113 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
114 conn
115 |> put_resp_header("content-type", "application/activity+json")
116 |> json(UserView.render("following.json", %{user: user}))
117 end
118 end
119
120 def followers(conn, %{"nickname" => nickname, "page" => page}) do
121 with %User{} = user <- User.get_cached_by_nickname(nickname),
122 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
123 {page, _} = Integer.parse(page)
124
125 conn
126 |> put_resp_header("content-type", "application/activity+json")
127 |> json(UserView.render("followers.json", %{user: user, page: page}))
128 end
129 end
130
131 def followers(conn, %{"nickname" => nickname}) do
132 with %User{} = user <- User.get_cached_by_nickname(nickname),
133 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
134 conn
135 |> put_resp_header("content-type", "application/activity+json")
136 |> json(UserView.render("followers.json", %{user: user}))
137 end
138 end
139
140 def outbox(conn, %{"nickname" => nickname} = params) do
141 with %User{} = user <- User.get_cached_by_nickname(nickname),
142 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
143 conn
144 |> put_resp_header("content-type", "application/activity+json")
145 |> json(UserView.render("outbox.json", %{user: user, max_id: params["max_id"]}))
146 end
147 end
148
149 def inbox(%{assigns: %{valid_signature: true}} = conn, %{"nickname" => nickname} = params) do
150 with %User{} = user <- User.get_cached_by_nickname(nickname),
151 true <- Utils.recipient_in_message(user.ap_id, params),
152 params <- Utils.maybe_splice_recipient(user.ap_id, params) do
153 Federator.enqueue(:incoming_ap_doc, params)
154 json(conn, "ok")
155 end
156 end
157
158 def inbox(%{assigns: %{valid_signature: true}} = conn, params) do
159 Federator.enqueue(:incoming_ap_doc, params)
160 json(conn, "ok")
161 end
162
163 # only accept relayed Creates
164 def inbox(conn, %{"type" => "Create"} = params) do
165 Logger.info(
166 "Signature missing or not from author, relayed Create message, fetching object from source"
167 )
168
169 ActivityPub.fetch_object_from_id(params["object"]["id"])
170
171 json(conn, "ok")
172 end
173
174 def inbox(conn, params) do
175 headers = Enum.into(conn.req_headers, %{})
176
177 if String.contains?(headers["signature"], params["actor"]) do
178 Logger.info(
179 "Signature validation error for: #{params["actor"]}, make sure you are forwarding the HTTP Host header!"
180 )
181
182 Logger.info(inspect(conn.req_headers))
183 end
184
185 json(conn, "error")
186 end
187
188 def relay(conn, _params) do
189 with %User{} = user <- Relay.get_actor(),
190 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
191 conn
192 |> put_resp_header("content-type", "application/activity+json")
193 |> json(UserView.render("user.json", %{user: user}))
194 else
195 nil -> {:error, :not_found}
196 end
197 end
198
199 def read_inbox(%{assigns: %{user: user}} = conn, %{"nickname" => nickname} = params) do
200 if nickname == user.nickname do
201 conn
202 |> put_resp_header("content-type", "application/activity+json")
203 |> json(UserView.render("inbox.json", %{user: user, max_id: params["max_id"]}))
204 else
205 conn
206 |> put_status(:forbidden)
207 |> json("can't read inbox of #{nickname} as #{user.nickname}")
208 end
209 end
210
211 def handle_user_activity(user, %{"type" => "Create"} = params) do
212 object =
213 params["object"]
214 |> Map.merge(Map.take(params, ["to", "cc"]))
215 |> Map.put("attributedTo", user.ap_id())
216 |> Transmogrifier.fix_object()
217
218 ActivityPub.create(%{
219 to: params["to"],
220 actor: user,
221 context: object["context"],
222 object: object,
223 additional: Map.take(params, ["cc"])
224 })
225 end
226
227 def handle_user_activity(user, %{"type" => "Delete"} = params) do
228 with %Object{} = object <- Object.normalize(params["object"]),
229 true <- user.info.is_moderator || user.ap_id == object.data["actor"],
230 {:ok, delete} <- ActivityPub.delete(object) do
231 {:ok, delete}
232 else
233 _ -> {:error, "Can't delete object"}
234 end
235 end
236
237 def handle_user_activity(user, %{"type" => "Like"} = params) do
238 with %Object{} = object <- Object.normalize(params["object"]),
239 {:ok, activity, _object} <- ActivityPub.like(user, object) do
240 {:ok, activity}
241 else
242 _ -> {:error, "Can't like object"}
243 end
244 end
245
246 def handle_user_activity(_, _) do
247 {:error, "Unhandled activity type"}
248 end
249
250 def update_outbox(
251 %{assigns: %{user: user}} = conn,
252 %{"nickname" => nickname} = params
253 ) do
254 if nickname == user.nickname do
255 actor = user.ap_id()
256
257 params =
258 params
259 |> Map.drop(["id"])
260 |> Map.put("actor", actor)
261 |> Transmogrifier.fix_addressing()
262
263 with {:ok, %Activity{} = activity} <- handle_user_activity(user, params) do
264 conn
265 |> put_status(:created)
266 |> put_resp_header("location", activity.data["id"])
267 |> json(activity.data)
268 else
269 {:error, message} ->
270 conn
271 |> put_status(:bad_request)
272 |> json(message)
273 end
274 else
275 conn
276 |> put_status(:forbidden)
277 |> json("can't update outbox of #{nickname} as #{user.nickname}")
278 end
279 end
280
281 def errors(conn, {:error, :not_found}) do
282 conn
283 |> put_status(404)
284 |> json("Not found")
285 end
286
287 def errors(conn, _e) do
288 conn
289 |> put_status(500)
290 |> json("error")
291 end
292 end