951cc1414a329758c29d8daa65bf38a38eae0010
[akkoma] / lib / pleroma / web / activity_pub / object_validators / delete_validator.ex
1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2020 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
4
5 defmodule Pleroma.Web.ActivityPub.ObjectValidators.DeleteValidator do
6 use Ecto.Schema
7
8 alias Pleroma.Activity
9 alias Pleroma.Web.ActivityPub.ObjectValidators.Types
10
11 import Ecto.Changeset
12 import Pleroma.Web.ActivityPub.ObjectValidators.CommonValidations
13
14 @primary_key false
15
16 embedded_schema do
17 field(:id, Types.ObjectID, primary_key: true)
18 field(:type, :string)
19 field(:actor, Types.ObjectID)
20 field(:to, Types.Recipients, default: [])
21 field(:cc, Types.Recipients, default: [])
22 field(:deleted_activity_id)
23 field(:object, Types.ObjectID)
24 end
25
26 def cast_data(data) do
27 %__MODULE__{}
28 |> cast(data, __schema__(:fields))
29 end
30
31 def add_deleted_activity_id(cng) do
32 object =
33 cng
34 |> get_field(:object)
35
36 with %Activity{id: id} <- Activity.get_create_by_object_ap_id(object) do
37 cng
38 |> put_change(:deleted_activity_id, id)
39 else
40 _ -> cng
41 end
42 end
43
44 def validate_data(cng) do
45 cng
46 |> validate_required([:id, :type, :actor, :to, :cc, :object])
47 |> validate_inclusion(:type, ["Delete"])
48 |> validate_same_domain()
49 |> validate_object_or_user_presence()
50 |> add_deleted_activity_id()
51 end
52
53 def validate_same_domain(cng) do
54 actor_domain =
55 cng
56 |> get_field(:actor)
57 |> URI.parse()
58 |> (& &1.host).()
59
60 object_domain =
61 cng
62 |> get_field(:object)
63 |> URI.parse()
64 |> (& &1.host).()
65
66 if object_domain != actor_domain do
67 cng
68 |> add_error(:actor, "is not allowed to delete object")
69 else
70 cng
71 end
72 end
73
74 def cast_and_validate(data) do
75 data
76 |> cast_data
77 |> validate_data
78 end
79 end