Merge branch 'hotfix/delete-activities' into 'develop'
[akkoma] / lib / pleroma / web / twitter_api / twitter_api.ex
1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2019 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
4
5 defmodule Pleroma.Web.TwitterAPI.TwitterAPI do
6 alias Pleroma.Activity
7 alias Pleroma.Mailer
8 alias Pleroma.Object
9 alias Pleroma.Repo
10 alias Pleroma.User
11 alias Pleroma.UserEmail
12 alias Pleroma.UserInviteToken
13 alias Pleroma.Web.ActivityPub.ActivityPub
14 alias Pleroma.Web.CommonAPI
15 alias Pleroma.Web.TwitterAPI.UserView
16
17 import Ecto.Query
18
19 def create_status(%User{} = user, %{"status" => _} = data) do
20 CommonAPI.post(user, data)
21 end
22
23 def delete(%User{} = user, id) do
24 with %Activity{data: %{"type" => _type}} <- Repo.get(Activity, id),
25 {:ok, activity} <- CommonAPI.delete(id, user) do
26 {:ok, activity}
27 end
28 end
29
30 def follow(%User{} = follower, params) do
31 with {:ok, %User{} = followed} <- get_user(params) do
32 CommonAPI.follow(follower, followed)
33 end
34 end
35
36 def unfollow(%User{} = follower, params) do
37 with {:ok, %User{} = unfollowed} <- get_user(params),
38 {:ok, follower} <- CommonAPI.unfollow(follower, unfollowed) do
39 {:ok, follower, unfollowed}
40 end
41 end
42
43 def block(%User{} = blocker, params) do
44 with {:ok, %User{} = blocked} <- get_user(params),
45 {:ok, blocker} <- User.block(blocker, blocked),
46 {:ok, _activity} <- ActivityPub.block(blocker, blocked) do
47 {:ok, blocker, blocked}
48 else
49 err -> err
50 end
51 end
52
53 def unblock(%User{} = blocker, params) do
54 with {:ok, %User{} = blocked} <- get_user(params),
55 {:ok, blocker} <- User.unblock(blocker, blocked),
56 {:ok, _activity} <- ActivityPub.unblock(blocker, blocked) do
57 {:ok, blocker, blocked}
58 else
59 err -> err
60 end
61 end
62
63 def repeat(%User{} = user, ap_id_or_id) do
64 with {:ok, _announce, %{data: %{"id" => id}}} <- CommonAPI.repeat(ap_id_or_id, user),
65 %Activity{} = activity <- Activity.get_create_by_object_ap_id(id) do
66 {:ok, activity}
67 end
68 end
69
70 def unrepeat(%User{} = user, ap_id_or_id) do
71 with {:ok, _unannounce, %{data: %{"id" => id}}} <- CommonAPI.unrepeat(ap_id_or_id, user),
72 %Activity{} = activity <- Activity.get_create_by_object_ap_id(id) do
73 {:ok, activity}
74 end
75 end
76
77 def pin(%User{} = user, ap_id_or_id) do
78 CommonAPI.pin(ap_id_or_id, user)
79 end
80
81 def unpin(%User{} = user, ap_id_or_id) do
82 CommonAPI.unpin(ap_id_or_id, user)
83 end
84
85 def fav(%User{} = user, ap_id_or_id) do
86 with {:ok, _fav, %{data: %{"id" => id}}} <- CommonAPI.favorite(ap_id_or_id, user),
87 %Activity{} = activity <- Activity.get_create_by_object_ap_id(id) do
88 {:ok, activity}
89 end
90 end
91
92 def unfav(%User{} = user, ap_id_or_id) do
93 with {:ok, _unfav, _fav, %{data: %{"id" => id}}} <- CommonAPI.unfavorite(ap_id_or_id, user),
94 %Activity{} = activity <- Activity.get_create_by_object_ap_id(id) do
95 {:ok, activity}
96 end
97 end
98
99 def upload(%Plug.Upload{} = file, %User{} = user, format \\ "xml") do
100 {:ok, object} = ActivityPub.upload(file, actor: User.ap_id(user))
101
102 url = List.first(object.data["url"])
103 href = url["href"]
104 type = url["mediaType"]
105
106 case format do
107 "xml" ->
108 # Fake this as good as possible...
109 """
110 <?xml version="1.0" encoding="UTF-8"?>
111 <rsp stat="ok" xmlns:atom="http://www.w3.org/2005/Atom">
112 <mediaid>#{object.id}</mediaid>
113 <media_id>#{object.id}</media_id>
114 <media_id_string>#{object.id}</media_id_string>
115 <media_url>#{href}</media_url>
116 <mediaurl>#{href}</mediaurl>
117 <atom:link rel="enclosure" href="#{href}" type="#{type}"></atom:link>
118 </rsp>
119 """
120
121 "json" ->
122 %{
123 media_id: object.id,
124 media_id_string: "#{object.id}}",
125 media_url: href,
126 size: 0
127 }
128 |> Jason.encode!()
129 end
130 end
131
132 def register_user(params) do
133 token_string = params["token"]
134
135 params = %{
136 nickname: params["nickname"],
137 name: params["fullname"],
138 bio: User.parse_bio(params["bio"]),
139 email: params["email"],
140 password: params["password"],
141 password_confirmation: params["confirm"],
142 captcha_solution: params["captcha_solution"],
143 captcha_token: params["captcha_token"],
144 captcha_answer_data: params["captcha_answer_data"]
145 }
146
147 captcha_enabled = Pleroma.Config.get([Pleroma.Captcha, :enabled])
148 # true if captcha is disabled or enabled and valid, false otherwise
149 captcha_ok =
150 if !captcha_enabled do
151 :ok
152 else
153 Pleroma.Captcha.validate(
154 params[:captcha_token],
155 params[:captcha_solution],
156 params[:captcha_answer_data]
157 )
158 end
159
160 # Captcha invalid
161 if captcha_ok != :ok do
162 {:error, error} = captcha_ok
163 # I have no idea how this error handling works
164 {:error, %{error: Jason.encode!(%{captcha: [error]})}}
165 else
166 registrations_open = Pleroma.Config.get([:instance, :registrations_open])
167
168 # no need to query DB if registration is open
169 token =
170 unless registrations_open || is_nil(token_string) do
171 Repo.get_by(UserInviteToken, %{token: token_string})
172 end
173
174 cond do
175 registrations_open || (!is_nil(token) && !token.used) ->
176 changeset = User.register_changeset(%User{}, params)
177
178 with {:ok, user} <- User.register(changeset) do
179 !registrations_open && UserInviteToken.mark_as_used(token.token)
180
181 {:ok, user}
182 else
183 {:error, changeset} ->
184 errors =
185 Ecto.Changeset.traverse_errors(changeset, fn {msg, _opts} -> msg end)
186 |> Jason.encode!()
187
188 {:error, %{error: errors}}
189 end
190
191 !registrations_open && is_nil(token) ->
192 {:error, "Invalid token"}
193
194 !registrations_open && token.used ->
195 {:error, "Expired token"}
196 end
197 end
198 end
199
200 def password_reset(nickname_or_email) do
201 with true <- is_binary(nickname_or_email),
202 %User{local: true} = user <- User.get_by_nickname_or_email(nickname_or_email),
203 {:ok, token_record} <- Pleroma.PasswordResetToken.create_token(user) do
204 user
205 |> UserEmail.password_reset_email(token_record.token)
206 |> Mailer.deliver_async()
207 else
208 false ->
209 {:error, "bad user identifier"}
210
211 %User{local: false} ->
212 {:error, "remote user"}
213
214 nil ->
215 {:error, "unknown user"}
216 end
217 end
218
219 def get_user(user \\ nil, params) do
220 case params do
221 %{"user_id" => user_id} ->
222 case target = User.get_cached_by_nickname_or_id(user_id) do
223 nil ->
224 {:error, "No user with such user_id"}
225
226 _ ->
227 {:ok, target}
228 end
229
230 %{"screen_name" => nickname} ->
231 case target = Repo.get_by(User, nickname: nickname) do
232 nil ->
233 {:error, "No user with such screen_name"}
234
235 _ ->
236 {:ok, target}
237 end
238
239 _ ->
240 if user do
241 {:ok, user}
242 else
243 {:error, "You need to specify screen_name or user_id"}
244 end
245 end
246 end
247
248 defp parse_int(string, default)
249
250 defp parse_int(string, default) when is_binary(string) do
251 with {n, _} <- Integer.parse(string) do
252 n
253 else
254 _e -> default
255 end
256 end
257
258 defp parse_int(_, default), do: default
259
260 def search(_user, %{"q" => query} = params) do
261 limit = parse_int(params["rpp"], 20)
262 page = parse_int(params["page"], 1)
263 offset = (page - 1) * limit
264
265 q =
266 from(
267 a in Activity,
268 where: fragment("?->>'type' = 'Create'", a.data),
269 where: "https://www.w3.org/ns/activitystreams#Public" in a.recipients,
270 where:
271 fragment(
272 "to_tsvector('english', ?->'object'->>'content') @@ plainto_tsquery('english', ?)",
273 a.data,
274 ^query
275 ),
276 limit: ^limit,
277 offset: ^offset,
278 # this one isn't indexed so psql won't take the wrong index.
279 order_by: [desc: :inserted_at]
280 )
281
282 _activities = Repo.all(q)
283 end
284
285 # DEPRECATED mostly, context objects are now created at insertion time.
286 def context_to_conversation_id(context) do
287 with %Object{id: id} <- Object.get_cached_by_ap_id(context) do
288 id
289 else
290 _e ->
291 changeset = Object.context_mapping(context)
292
293 case Repo.insert(changeset) do
294 {:ok, %{id: id}} ->
295 id
296
297 # This should be solved by an upsert, but it seems ecto
298 # has problems accessing the constraint inside the jsonb.
299 {:error, _} ->
300 Object.get_cached_by_ap_id(context).id
301 end
302 end
303 end
304
305 def conversation_id_to_context(id) do
306 with %Object{data: %{"id" => context}} <- Repo.get(Object, id) do
307 context
308 else
309 _e ->
310 {:error, "No such conversation"}
311 end
312 end
313
314 def get_external_profile(for_user, uri) do
315 with %User{} = user <- User.get_or_fetch(uri) do
316 {:ok, UserView.render("show.json", %{user: user, for: for_user})}
317 else
318 _e ->
319 {:error, "Couldn't find user"}
320 end
321 end
322 end