1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2021 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
5 defmodule Pleroma.Web.ActivityPub.ObjectValidators.AcceptRejectValidator do
12 import Pleroma.Web.ActivityPub.ObjectValidators.CommonValidations
19 import Elixir.Pleroma.Web.ActivityPub.ObjectValidators.CommonFields
26 def cast_data(data) do
28 |> cast(data, __schema__(:fields))
31 defp validate_data(cng) do
33 |> validate_required([:type, :actor, :to, :cc, :object])
34 |> validate_inclusion(:type, ["Accept", "Reject"])
35 |> validate_actor_presence()
36 |> validate_object_presence(allowed_types: ["Follow"])
37 |> validate_accept_reject_rights()
40 def cast_and_validate(data) do
42 |> maybe_fetch_object()
47 def validate_accept_reject_rights(cng) do
48 with object_id when is_binary(object_id) <- get_field(cng, :object),
49 %Activity{data: %{"object" => followed_actor}} <- Activity.get_by_ap_id(object_id),
50 true <- followed_actor == get_field(cng, :actor) do
55 |> add_error(:actor, "can't accept or reject the given activity")
59 defp maybe_fetch_object(%{"object" => %{} = object} = activity) do
60 # If we don't have an ID, we may have to fetch the object
61 if Map.has_key?(object, "id") do
65 Map.put(activity, "object", fetch_transient_object(object))
69 defp maybe_fetch_object(activity), do: activity
71 defp fetch_transient_object(
72 %{"actor" => actor, "object" => target, "type" => "Follow"} = object
74 with %User{} = actor <- User.get_cached_by_ap_id(actor),
75 %User{local: true} = target <- User.get_cached_by_ap_id(target),
76 %Activity{} = activity <- Activity.follow_activity(actor, target) do
84 defp fetch_transient_object(_), do: {:error, "not a supported transient object"}