1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2019 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
5 defmodule Pleroma.Web.MastodonAPI.AccountController do
6 use Pleroma.Web, :controller
8 import Pleroma.Web.ControllerHelper, only: [add_link_headers: 2, truthy_param?: 1]
11 alias Pleroma.Web.CommonAPI
12 alias Pleroma.Web.ActivityPub.ActivityPub
13 alias Pleroma.Web.MastodonAPI.StatusView
14 alias Pleroma.Web.MastodonAPI.MastodonAPI
15 alias Pleroma.Web.MastodonAPI.ListView
16 alias Pleroma.Plugs.RateLimiter
18 require Pleroma.Constants
20 @relations ~w(follow unfollow)a
22 plug(RateLimiter, {:relations_id_action, params: ["id", "uri"]} when action in @relations)
23 plug(RateLimiter, :relations_actions when action in @relations)
24 plug(:assign_account when action not in [:show, :statuses, :follows])
26 action_fallback(Pleroma.Web.MastodonAPI.FallbackController)
28 @doc "GET /api/v1/accounts/:id"
29 def show(%{assigns: %{user: for_user}} = conn, %{"id" => nickname_or_id}) do
30 with %User{} = user <- User.get_cached_by_nickname_or_id(nickname_or_id, for: for_user),
31 true <- User.auth_active?(user) || user.id == for_user.id || User.superuser?(for_user) do
32 render(conn, "show.json", user: user, for: for_user)
34 _e -> render_error(conn, :not_found, "Can't find user")
38 @doc "GET /api/v1/accounts/:id/statuses"
39 def statuses(%{assigns: %{user: reading_user}} = conn, params) do
40 with %User{} = user <- User.get_cached_by_nickname_or_id(params["id"], for: reading_user) do
41 params = Map.put(params, "tag", params["tagged"])
42 activities = ActivityPub.fetch_user_activities(user, reading_user, params)
45 |> add_link_headers(activities)
46 |> put_view(StatusView)
47 |> render("index.json", activities: activities, for: reading_user, as: :activity)
51 @doc "GET /api/v1/accounts/:id/followers"
52 def followers(%{assigns: %{user: for_user, account: user}} = conn, params) do
55 for_user && user.id == for_user.id -> MastodonAPI.get_followers(user, params)
56 user.info.hide_followers -> []
57 true -> MastodonAPI.get_followers(user, params)
61 |> add_link_headers(followers)
62 |> render("index.json", for: for_user, users: followers, as: :user)
65 @doc "GET /api/v1/accounts/:id/following"
66 def following(%{assigns: %{user: for_user, account: user}} = conn, params) do
69 for_user && user.id == for_user.id -> MastodonAPI.get_friends(user, params)
70 user.info.hide_follows -> []
71 true -> MastodonAPI.get_friends(user, params)
75 |> add_link_headers(followers)
76 |> render("index.json", for: for_user, users: followers, as: :user)
79 @doc "GET /api/v1/accounts/:id/lists"
80 def lists(%{assigns: %{user: user, account: account}} = conn, _params) do
81 lists = Pleroma.List.get_lists_account_belongs(user, account)
85 |> render("index.json", lists: lists)
88 @doc "GET /api/v1/pleroma/accounts/:id/favourites"
89 def favourites(%{assigns: %{account: %{info: %{hide_favorites: true}}}} = conn, _params) do
90 render_error(conn, :forbidden, "Can't get favorites")
93 def favourites(%{assigns: %{user: for_user, account: user}} = conn, params) do
96 |> Map.put("type", "Create")
97 |> Map.put("favorited_by", user.ap_id)
98 |> Map.put("blocking_user", for_user)
102 [Pleroma.Constants.as_public()] ++ [for_user.ap_id | for_user.following]
104 [Pleroma.Constants.as_public()]
109 |> ActivityPub.fetch_activities(params)
113 |> add_link_headers(activities)
114 |> put_view(StatusView)
115 |> render("index.json", activities: activities, for: for_user, as: :activity)
118 @doc "POST /api/v1/pleroma/accounts/:id/subscribe"
119 def subscribe(%{assigns: %{user: user, account: subscription_target}} = conn, _params) do
120 with {:ok, subscription_target} <- User.subscribe(user, subscription_target) do
121 render(conn, "relationship.json", user: user, target: subscription_target)
125 |> put_status(:forbidden)
126 |> json(%{error: message})
130 @doc "POST /api/v1/pleroma/accounts/:id/unsubscribe"
131 def unsubscribe(%{assigns: %{user: user, account: subscription_target}} = conn, _params) do
132 with {:ok, subscription_target} <- User.unsubscribe(user, subscription_target) do
133 render(conn, "relationship.json", user: user, target: subscription_target)
137 |> put_status(:forbidden)
138 |> json(%{error: message})
142 @doc "POST /api/v1/accounts/:id/follow"
143 def follow(%{assigns: %{user: %{id: id}, account: %{id: id}}}, _params) do
147 def follow(%{assigns: %{user: follower, account: followed}} = conn, _params) do
148 with {:ok, follower} <- MastodonAPI.follow(follower, followed, conn.params) do
149 render(conn, "relationship.json", user: follower, target: followed)
153 |> put_status(:forbidden)
154 |> json(%{error: message})
158 @doc "POST /api/v1/pleroma/:id/unfollow"
159 def unfollow(%{assigns: %{user: %{id: id}, account: %{id: id}}}, _params) do
163 def unfollow(%{assigns: %{user: follower, account: followed}} = conn, _params) do
164 with {:ok, follower} <- CommonAPI.unfollow(follower, followed) do
165 render(conn, "relationship.json", user: follower, target: followed)
169 @doc "POST /api/v1/accounts/:id/mute"
170 def mute(%{assigns: %{user: muter, account: muted}} = conn, params) do
171 notifications? = params |> Map.get("notifications", true) |> truthy_param?()
173 with {:ok, muter} <- User.mute(muter, muted, notifications?) do
174 render(conn, "relationship.json", user: muter, target: muted)
178 |> put_status(:forbidden)
179 |> json(%{error: message})
183 @doc "POST /api/v1/accounts/:id/unmute"
184 def unmute(%{assigns: %{user: muter, account: muted}} = conn, _params) do
185 with {:ok, muter} <- User.unmute(muter, muted) do
186 render(conn, "relationship.json", user: muter, target: muted)
190 |> put_status(:forbidden)
191 |> json(%{error: message})
195 @doc "POST /api/v1/accounts/:id/block"
196 def block(%{assigns: %{user: blocker, account: blocked}} = conn, _params) do
197 with {:ok, blocker} <- User.block(blocker, blocked),
198 {:ok, _activity} <- ActivityPub.block(blocker, blocked) do
199 render(conn, "relationship.json", user: blocker, target: blocked)
203 |> put_status(:forbidden)
204 |> json(%{error: message})
208 @doc "POST /api/v1/accounts/:id/unblock"
209 def unblock(%{assigns: %{user: blocker, account: blocked}} = conn, _params) do
210 with {:ok, blocker} <- User.unblock(blocker, blocked),
211 {:ok, _activity} <- ActivityPub.unblock(blocker, blocked) do
212 render(conn, "relationship.json", user: blocker, target: blocked)
216 |> put_status(:forbidden)
217 |> json(%{error: message})
221 defp assign_account(%{params: %{"id" => id}} = conn, _) do
222 case User.get_cached_by_id(id) do
223 %User{} = account -> assign(conn, :account, account)
224 nil -> Pleroma.Web.MastodonAPI.FallbackController.call(conn, {:error, :not_found}) |> halt()