[#114] Account confirmation email, registration as unconfirmed (config-based), auth...
[akkoma] / lib / pleroma / web / twitter_api / twitter_api.ex
1 defmodule Pleroma.Web.TwitterAPI.TwitterAPI do
2 alias Pleroma.{UserInviteToken, User, Activity, Repo, Object}
3 alias Pleroma.{UserEmail, Mailer}
4 alias Pleroma.Web.ActivityPub.ActivityPub
5 alias Pleroma.Web.TwitterAPI.UserView
6 alias Pleroma.Web.CommonAPI
7
8 import Ecto.Query
9
10 def create_status(%User{} = user, %{"status" => _} = data) do
11 CommonAPI.post(user, data)
12 end
13
14 def delete(%User{} = user, id) do
15 with %Activity{data: %{"type" => _type}} <- Repo.get(Activity, id),
16 {:ok, activity} <- CommonAPI.delete(id, user) do
17 {:ok, activity}
18 end
19 end
20
21 def follow(%User{} = follower, params) do
22 with {:ok, %User{} = followed} <- get_user(params),
23 {:ok, follower} <- User.maybe_direct_follow(follower, followed),
24 {:ok, activity} <- ActivityPub.follow(follower, followed),
25 {:ok, follower, followed} <-
26 User.wait_and_refresh(
27 Pleroma.Config.get([:activitypub, :follow_handshake_timeout]),
28 follower,
29 followed
30 ) do
31 {:ok, follower, followed, activity}
32 else
33 err -> err
34 end
35 end
36
37 def unfollow(%User{} = follower, params) do
38 with {:ok, %User{} = unfollowed} <- get_user(params),
39 {:ok, follower, _follow_activity} <- User.unfollow(follower, unfollowed),
40 {:ok, _activity} <- ActivityPub.unfollow(follower, unfollowed) do
41 {:ok, follower, unfollowed}
42 else
43 err -> err
44 end
45 end
46
47 def block(%User{} = blocker, params) do
48 with {:ok, %User{} = blocked} <- get_user(params),
49 {:ok, blocker} <- User.block(blocker, blocked),
50 {:ok, _activity} <- ActivityPub.block(blocker, blocked) do
51 {:ok, blocker, blocked}
52 else
53 err -> err
54 end
55 end
56
57 def unblock(%User{} = blocker, params) do
58 with {:ok, %User{} = blocked} <- get_user(params),
59 {:ok, blocker} <- User.unblock(blocker, blocked),
60 {:ok, _activity} <- ActivityPub.unblock(blocker, blocked) do
61 {:ok, blocker, blocked}
62 else
63 err -> err
64 end
65 end
66
67 def repeat(%User{} = user, ap_id_or_id) do
68 with {:ok, _announce, %{data: %{"id" => id}}} <- CommonAPI.repeat(ap_id_or_id, user),
69 %Activity{} = activity <- Activity.get_create_activity_by_object_ap_id(id) do
70 {:ok, activity}
71 end
72 end
73
74 def unrepeat(%User{} = user, ap_id_or_id) do
75 with {:ok, _unannounce, %{data: %{"id" => id}}} <- CommonAPI.unrepeat(ap_id_or_id, user),
76 %Activity{} = activity <- Activity.get_create_activity_by_object_ap_id(id) do
77 {:ok, activity}
78 end
79 end
80
81 def fav(%User{} = user, ap_id_or_id) do
82 with {:ok, _fav, %{data: %{"id" => id}}} <- CommonAPI.favorite(ap_id_or_id, user),
83 %Activity{} = activity <- Activity.get_create_activity_by_object_ap_id(id) do
84 {:ok, activity}
85 end
86 end
87
88 def unfav(%User{} = user, ap_id_or_id) do
89 with {:ok, _unfav, _fav, %{data: %{"id" => id}}} <- CommonAPI.unfavorite(ap_id_or_id, user),
90 %Activity{} = activity <- Activity.get_create_activity_by_object_ap_id(id) do
91 {:ok, activity}
92 end
93 end
94
95 def upload(%Plug.Upload{} = file, %User{} = user, format \\ "xml") do
96 {:ok, object} = ActivityPub.upload(file, actor: User.ap_id(user))
97
98 url = List.first(object.data["url"])
99 href = url["href"]
100 type = url["mediaType"]
101
102 case format do
103 "xml" ->
104 # Fake this as good as possible...
105 """
106 <?xml version="1.0" encoding="UTF-8"?>
107 <rsp stat="ok" xmlns:atom="http://www.w3.org/2005/Atom">
108 <mediaid>#{object.id}</mediaid>
109 <media_id>#{object.id}</media_id>
110 <media_id_string>#{object.id}</media_id_string>
111 <media_url>#{href}</media_url>
112 <mediaurl>#{href}</mediaurl>
113 <atom:link rel="enclosure" href="#{href}" type="#{type}"></atom:link>
114 </rsp>
115 """
116
117 "json" ->
118 %{
119 media_id: object.id,
120 media_id_string: "#{object.id}}",
121 media_url: href,
122 size: 0
123 }
124 |> Jason.encode!()
125 end
126 end
127
128 def register_user(params) do
129 tokenString = params["token"]
130
131 params = %{
132 nickname: params["nickname"],
133 name: params["fullname"],
134 bio: User.parse_bio(params["bio"]),
135 email: params["email"],
136 password: params["password"],
137 password_confirmation: params["confirm"],
138 captcha_solution: params["captcha_solution"],
139 captcha_token: params["captcha_token"]
140 }
141
142 captcha_enabled = Pleroma.Config.get([Pleroma.Captcha, :enabled])
143 # true if captcha is disabled or enabled and valid, false otherwise
144 captcha_ok =
145 if !captcha_enabled do
146 true
147 else
148 Pleroma.Captcha.validate(params[:captcha_token], params[:captcha_solution])
149 end
150
151 # Captcha invalid
152 if not captcha_ok do
153 # I have no idea how this error handling works
154 {:error, %{error: Jason.encode!(%{captcha: ["Invalid CAPTCHA"]})}}
155 else
156 registrations_open = Pleroma.Config.get([:instance, :registrations_open])
157
158 # no need to query DB if registration is open
159 token =
160 unless registrations_open || is_nil(tokenString) do
161 Repo.get_by(UserInviteToken, %{token: tokenString})
162 end
163
164 cond do
165 registrations_open || (!is_nil(token) && !token.used) ->
166 changeset = User.register_changeset(%User{info: %{}}, params)
167
168 with {:ok, user} <- Repo.insert(changeset) do
169 !registrations_open && UserInviteToken.mark_as_used(token.token)
170
171 if Pleroma.Config.get([:instance, :account_activation_required]) do
172 info_change = User.Info.confirmation_update(user.info, :unconfirmed)
173
174 {:ok, unconfirmed_user} =
175 user
176 |> Ecto.Changeset.change()
177 |> Ecto.Changeset.put_embed(:info, info_change)
178 |> Repo.update()
179
180 {:ok, _} =
181 unconfirmed_user
182 |> UserEmail.account_confirmation_email()
183 |> Mailer.deliver()
184 end
185
186 {:ok, user}
187 else
188 {:error, changeset} ->
189 errors =
190 Ecto.Changeset.traverse_errors(changeset, fn {msg, _opts} -> msg end)
191 |> Jason.encode!()
192
193 {:error, %{error: errors}}
194 end
195
196 !registrations_open && is_nil(token) ->
197 {:error, "Invalid token"}
198
199 !registrations_open && token.used ->
200 {:error, "Expired token"}
201 end
202 end
203 end
204
205 def password_reset(nickname_or_email) do
206 with true <- is_binary(nickname_or_email),
207 %User{local: true} = user <- User.get_by_nickname_or_email(nickname_or_email),
208 {:ok, token_record} <- Pleroma.PasswordResetToken.create_token(user) do
209 user
210 |> UserEmail.password_reset_email(token_record.token)
211 |> Mailer.deliver()
212 else
213 false ->
214 {:error, "bad user identifier"}
215
216 %User{local: false} ->
217 {:error, "remote user"}
218
219 nil ->
220 {:error, "unknown user"}
221 end
222 end
223
224 def get_by_id_or_nickname(id_or_nickname) do
225 if !is_integer(id_or_nickname) && :error == Integer.parse(id_or_nickname) do
226 Repo.get_by(User, nickname: id_or_nickname)
227 else
228 Repo.get(User, id_or_nickname)
229 end
230 end
231
232 def get_user(user \\ nil, params) do
233 case params do
234 %{"user_id" => user_id} ->
235 case target = get_by_id_or_nickname(user_id) do
236 nil ->
237 {:error, "No user with such user_id"}
238
239 _ ->
240 {:ok, target}
241 end
242
243 %{"screen_name" => nickname} ->
244 case target = Repo.get_by(User, nickname: nickname) do
245 nil ->
246 {:error, "No user with such screen_name"}
247
248 _ ->
249 {:ok, target}
250 end
251
252 _ ->
253 if user do
254 {:ok, user}
255 else
256 {:error, "You need to specify screen_name or user_id"}
257 end
258 end
259 end
260
261 defp parse_int(string, default)
262
263 defp parse_int(string, default) when is_binary(string) do
264 with {n, _} <- Integer.parse(string) do
265 n
266 else
267 _e -> default
268 end
269 end
270
271 defp parse_int(_, default), do: default
272
273 def search(_user, %{"q" => query} = params) do
274 limit = parse_int(params["rpp"], 20)
275 page = parse_int(params["page"], 1)
276 offset = (page - 1) * limit
277
278 q =
279 from(
280 a in Activity,
281 where: fragment("?->>'type' = 'Create'", a.data),
282 where: "https://www.w3.org/ns/activitystreams#Public" in a.recipients,
283 where:
284 fragment(
285 "to_tsvector('english', ?->'object'->>'content') @@ plainto_tsquery('english', ?)",
286 a.data,
287 ^query
288 ),
289 limit: ^limit,
290 offset: ^offset,
291 # this one isn't indexed so psql won't take the wrong index.
292 order_by: [desc: :inserted_at]
293 )
294
295 _activities = Repo.all(q)
296 end
297
298 # DEPRECATED mostly, context objects are now created at insertion time.
299 def context_to_conversation_id(context) do
300 with %Object{id: id} <- Object.get_cached_by_ap_id(context) do
301 id
302 else
303 _e ->
304 changeset = Object.context_mapping(context)
305
306 case Repo.insert(changeset) do
307 {:ok, %{id: id}} ->
308 id
309
310 # This should be solved by an upsert, but it seems ecto
311 # has problems accessing the constraint inside the jsonb.
312 {:error, _} ->
313 Object.get_cached_by_ap_id(context).id
314 end
315 end
316 end
317
318 def conversation_id_to_context(id) do
319 with %Object{data: %{"id" => context}} <- Repo.get(Object, id) do
320 context
321 else
322 _e ->
323 {:error, "No such conversation"}
324 end
325 end
326
327 def get_external_profile(for_user, uri) do
328 with %User{} = user <- User.get_or_fetch(uri) do
329 {:ok, UserView.render("show.json", %{user: user, for: for_user})}
330 else
331 _e ->
332 {:error, "Couldn't find user"}
333 end
334 end
335 end