Merge branch 'features/staticfe-sanitization' into 'develop'
[akkoma] / lib / pleroma / web / static_fe / static_fe_controller.ex
1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2020 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
4
5 defmodule Pleroma.Web.StaticFE.StaticFEController do
6 use Pleroma.Web, :controller
7
8 alias Pleroma.Activity
9 alias Pleroma.Object
10 alias Pleroma.User
11 alias Pleroma.Web.ActivityPub.ActivityPub
12 alias Pleroma.Web.ActivityPub.Visibility
13 alias Pleroma.Web.Metadata
14 alias Pleroma.Web.Router.Helpers
15
16 plug(:put_layout, :static_fe)
17 plug(:put_view, Pleroma.Web.StaticFE.StaticFEView)
18 plug(:assign_id)
19
20 @page_keys ["max_id", "min_id", "limit", "since_id", "order"]
21
22 defp get_title(%Object{data: %{"name" => name}}) when is_binary(name),
23 do: name
24
25 defp get_title(%Object{data: %{"summary" => summary}}) when is_binary(summary),
26 do: summary
27
28 defp get_title(_), do: nil
29
30 defp not_found(conn, message) do
31 conn
32 |> put_status(404)
33 |> render("error.html", %{message: message, meta: ""})
34 end
35
36 def get_counts(%Activity{} = activity) do
37 %Object{data: data} = Object.normalize(activity)
38
39 %{
40 likes: data["like_count"] || 0,
41 replies: data["repliesCount"] || 0,
42 announces: data["announcement_count"] || 0
43 }
44 end
45
46 def represent(%Activity{} = activity), do: represent(activity, false)
47
48 def represent(%Activity{object: %Object{data: data}} = activity, selected) do
49 {:ok, user} = User.get_or_fetch(activity.object.data["actor"])
50
51 link =
52 case user.local do
53 true -> Helpers.o_status_url(Pleroma.Web.Endpoint, :notice, activity)
54 _ -> data["url"] || data["external_url"] || data["id"]
55 end
56
57 content =
58 if data["content"] do
59 Pleroma.HTML.filter_tags(data["content"])
60 else
61 nil
62 end
63
64 %{
65 user: User.sanitize_html(user),
66 title: get_title(activity.object),
67 content: content,
68 attachment: data["attachment"],
69 link: link,
70 published: data["published"],
71 sensitive: data["sensitive"],
72 selected: selected,
73 counts: get_counts(activity),
74 id: activity.id
75 }
76 end
77
78 def show(%{assigns: %{notice_id: notice_id}} = conn, _params) do
79 with %Activity{local: true} = activity <-
80 Activity.get_by_id_with_object(notice_id),
81 true <- Visibility.is_public?(activity.object),
82 %User{} = user <- User.get_by_ap_id(activity.object.data["actor"]) do
83 meta = Metadata.build_tags(%{activity_id: notice_id, object: activity.object, user: user})
84
85 timeline =
86 activity.object.data["context"]
87 |> ActivityPub.fetch_activities_for_context(%{})
88 |> Enum.reverse()
89 |> Enum.map(&represent(&1, &1.object.id == activity.object.id))
90
91 render(conn, "conversation.html", %{activities: timeline, meta: meta})
92 else
93 %Activity{object: %Object{data: data}} ->
94 conn
95 |> put_status(:found)
96 |> redirect(external: data["url"] || data["external_url"] || data["id"])
97
98 _ ->
99 not_found(conn, "Post not found.")
100 end
101 end
102
103 def show(%{assigns: %{username_or_id: username_or_id}} = conn, params) do
104 case User.get_cached_by_nickname_or_id(username_or_id) do
105 %User{} = user ->
106 meta = Metadata.build_tags(%{user: user})
107
108 timeline =
109 ActivityPub.fetch_user_activities(user, nil, Map.take(params, @page_keys))
110 |> Enum.map(&represent/1)
111
112 prev_page_id =
113 (params["min_id"] || params["max_id"]) &&
114 List.first(timeline) && List.first(timeline).id
115
116 next_page_id = List.last(timeline) && List.last(timeline).id
117
118 render(conn, "profile.html", %{
119 user: User.sanitize_html(user),
120 timeline: timeline,
121 prev_page_id: prev_page_id,
122 next_page_id: next_page_id,
123 meta: meta
124 })
125
126 _ ->
127 not_found(conn, "User not found.")
128 end
129 end
130
131 def show(%{assigns: %{object_id: _}} = conn, _params) do
132 url = Helpers.url(conn) <> conn.request_path
133
134 case Activity.get_create_by_object_ap_id_with_object(url) do
135 %Activity{} = activity ->
136 to = Helpers.o_status_path(Pleroma.Web.Endpoint, :notice, activity)
137 redirect(conn, to: to)
138
139 _ ->
140 not_found(conn, "Post not found.")
141 end
142 end
143
144 def show(%{assigns: %{activity_id: _}} = conn, _params) do
145 url = Helpers.url(conn) <> conn.request_path
146
147 case Activity.get_by_ap_id(url) do
148 %Activity{} = activity ->
149 to = Helpers.o_status_path(Pleroma.Web.Endpoint, :notice, activity)
150 redirect(conn, to: to)
151
152 _ ->
153 not_found(conn, "Post not found.")
154 end
155 end
156
157 def assign_id(%{path_info: ["notice", notice_id]} = conn, _opts),
158 do: assign(conn, :notice_id, notice_id)
159
160 def assign_id(%{path_info: ["users", user_id]} = conn, _opts),
161 do: assign(conn, :username_or_id, user_id)
162
163 def assign_id(%{path_info: ["objects", object_id]} = conn, _opts),
164 do: assign(conn, :object_id, object_id)
165
166 def assign_id(%{path_info: ["activities", activity_id]} = conn, _opts),
167 do: assign(conn, :activity_id, activity_id)
168
169 def assign_id(conn, _opts), do: conn
170 end