Add an ability to disabled captcha
[akkoma] / lib / pleroma / web / twitter_api / twitter_api.ex
1 defmodule Pleroma.Web.TwitterAPI.TwitterAPI do
2 alias Pleroma.{UserInviteToken, User, Activity, Repo, Object}
3 alias Pleroma.Web.ActivityPub.ActivityPub
4 alias Pleroma.Web.TwitterAPI.UserView
5 alias Pleroma.Web.CommonAPI
6 import Ecto.Query
7
8 def create_status(%User{} = user, %{"status" => _} = data) do
9 CommonAPI.post(user, data)
10 end
11
12 def delete(%User{} = user, id) do
13 with %Activity{data: %{"type" => _type}} <- Repo.get(Activity, id),
14 {:ok, activity} <- CommonAPI.delete(id, user) do
15 {:ok, activity}
16 end
17 end
18
19 def follow(%User{} = follower, params) do
20 with {:ok, %User{} = followed} <- get_user(params),
21 {:ok, follower} <- User.maybe_direct_follow(follower, followed),
22 {:ok, activity} <- ActivityPub.follow(follower, followed),
23 {:ok, follower, followed} <-
24 User.wait_and_refresh(
25 Pleroma.Config.get([:activitypub, :follow_handshake_timeout]),
26 follower,
27 followed
28 ) do
29 {:ok, follower, followed, activity}
30 else
31 err -> err
32 end
33 end
34
35 def unfollow(%User{} = follower, params) do
36 with {:ok, %User{} = unfollowed} <- get_user(params),
37 {:ok, follower, _follow_activity} <- User.unfollow(follower, unfollowed),
38 {:ok, _activity} <- ActivityPub.unfollow(follower, unfollowed) do
39 {:ok, follower, unfollowed}
40 else
41 err -> err
42 end
43 end
44
45 def block(%User{} = blocker, params) do
46 with {:ok, %User{} = blocked} <- get_user(params),
47 {:ok, blocker} <- User.block(blocker, blocked),
48 {:ok, _activity} <- ActivityPub.block(blocker, blocked) do
49 {:ok, blocker, blocked}
50 else
51 err -> err
52 end
53 end
54
55 def unblock(%User{} = blocker, params) do
56 with {:ok, %User{} = blocked} <- get_user(params),
57 {:ok, blocker} <- User.unblock(blocker, blocked),
58 {:ok, _activity} <- ActivityPub.unblock(blocker, blocked) do
59 {:ok, blocker, blocked}
60 else
61 err -> err
62 end
63 end
64
65 def repeat(%User{} = user, ap_id_or_id) do
66 with {:ok, _announce, %{data: %{"id" => id}}} <- CommonAPI.repeat(ap_id_or_id, user),
67 %Activity{} = activity <- Activity.get_create_activity_by_object_ap_id(id) do
68 {:ok, activity}
69 end
70 end
71
72 def unrepeat(%User{} = user, ap_id_or_id) do
73 with {:ok, _unannounce, %{data: %{"id" => id}}} <- CommonAPI.unrepeat(ap_id_or_id, user),
74 %Activity{} = activity <- Activity.get_create_activity_by_object_ap_id(id) do
75 {:ok, activity}
76 end
77 end
78
79 def fav(%User{} = user, ap_id_or_id) do
80 with {:ok, _fav, %{data: %{"id" => id}}} <- CommonAPI.favorite(ap_id_or_id, user),
81 %Activity{} = activity <- Activity.get_create_activity_by_object_ap_id(id) do
82 {:ok, activity}
83 end
84 end
85
86 def unfav(%User{} = user, ap_id_or_id) do
87 with {:ok, _unfav, _fav, %{data: %{"id" => id}}} <- CommonAPI.unfavorite(ap_id_or_id, user),
88 %Activity{} = activity <- Activity.get_create_activity_by_object_ap_id(id) do
89 {:ok, activity}
90 end
91 end
92
93 def upload(%Plug.Upload{} = file, %User{} = user, format \\ "xml") do
94 {:ok, object} = ActivityPub.upload(file, actor: User.ap_id(user))
95
96 url = List.first(object.data["url"])
97 href = url["href"]
98 type = url["mediaType"]
99
100 case format do
101 "xml" ->
102 # Fake this as good as possible...
103 """
104 <?xml version="1.0" encoding="UTF-8"?>
105 <rsp stat="ok" xmlns:atom="http://www.w3.org/2005/Atom">
106 <mediaid>#{object.id}</mediaid>
107 <media_id>#{object.id}</media_id>
108 <media_id_string>#{object.id}</media_id_string>
109 <media_url>#{href}</media_url>
110 <mediaurl>#{href}</mediaurl>
111 <atom:link rel="enclosure" href="#{href}" type="#{type}"></atom:link>
112 </rsp>
113 """
114
115 "json" ->
116 %{
117 media_id: object.id,
118 media_id_string: "#{object.id}}",
119 media_url: href,
120 size: 0
121 }
122 |> Jason.encode!()
123 end
124 end
125
126 def register_user(params) do
127 tokenString = params["token"]
128
129 params = %{
130 nickname: params["nickname"],
131 name: params["fullname"],
132 bio: User.parse_bio(params["bio"]),
133 email: params["email"],
134 password: params["password"],
135 password_confirmation: params["confirm"],
136 captcha_solution: params["captcha_solution"],
137 captcha_token: params["captcha_token"]
138 }
139
140 captcha_enabled = Pleroma.Config.get([Pleroma.Captcha, :enabled])
141 # true if captcha is disabled or enabled and valid, false otherwise
142 captcha_ok = if !captcha_enabled do
143 true
144 else
145 Pleroma.Captcha.validate(params[:captcha_token], params[:captcha_solution])
146 end
147
148 # Captcha invalid
149 if not captcha_ok do
150 # I have no idea how this error handling works
151 {:error, %{error: Jason.encode!(%{captcha: ["Invalid CAPTCHA"]})}}
152 else
153 registrations_open = Pleroma.Config.get([:instance, :registrations_open])
154
155 # no need to query DB if registration is open
156 token =
157 unless registrations_open || is_nil(tokenString) do
158 Repo.get_by(UserInviteToken, %{token: tokenString})
159 end
160
161 cond do
162 registrations_open || (!is_nil(token) && !token.used) ->
163 changeset = User.register_changeset(%User{info: %{}}, params)
164
165 with {:ok, user} <- Repo.insert(changeset) do
166 !registrations_open && UserInviteToken.mark_as_used(token.token)
167 {:ok, user}
168 else
169 {:error, changeset} ->
170 errors =
171 Ecto.Changeset.traverse_errors(changeset, fn {msg, _opts} -> msg end)
172 |> Jason.encode!()
173
174 {:error, %{error: errors}}
175 end
176
177
178 !registrations_open && is_nil(token) ->
179 {:error, "Invalid token"}
180
181 !registrations_open && token.used ->
182 {:error, "Expired token"}
183 end
184 end
185 end
186
187 def password_reset(nickname_or_email) do
188 with true <- is_binary(nickname_or_email),
189 %User{local: true} = user <- User.get_by_nickname_or_email(nickname_or_email),
190 {:ok, token_record} <- Pleroma.PasswordResetToken.create_token(user) do
191 user
192 |> Pleroma.UserEmail.password_reset_email(token_record.token)
193 |> Pleroma.Mailer.deliver()
194 else
195 false ->
196 {:error, "bad user identifier"}
197
198 %User{local: false} ->
199 {:error, "remote user"}
200
201 nil ->
202 {:error, "unknown user"}
203 end
204 end
205
206 def get_by_id_or_nickname(id_or_nickname) do
207 if !is_integer(id_or_nickname) && :error == Integer.parse(id_or_nickname) do
208 Repo.get_by(User, nickname: id_or_nickname)
209 else
210 Repo.get(User, id_or_nickname)
211 end
212 end
213
214 def get_user(user \\ nil, params) do
215 case params do
216 %{"user_id" => user_id} ->
217 case target = get_by_id_or_nickname(user_id) do
218 nil ->
219 {:error, "No user with such user_id"}
220
221 _ ->
222 {:ok, target}
223 end
224
225 %{"screen_name" => nickname} ->
226 case target = Repo.get_by(User, nickname: nickname) do
227 nil ->
228 {:error, "No user with such screen_name"}
229
230 _ ->
231 {:ok, target}
232 end
233
234 _ ->
235 if user do
236 {:ok, user}
237 else
238 {:error, "You need to specify screen_name or user_id"}
239 end
240 end
241 end
242
243 defp parse_int(string, default)
244
245 defp parse_int(string, default) when is_binary(string) do
246 with {n, _} <- Integer.parse(string) do
247 n
248 else
249 _e -> default
250 end
251 end
252
253 defp parse_int(_, default), do: default
254
255 def search(_user, %{"q" => query} = params) do
256 limit = parse_int(params["rpp"], 20)
257 page = parse_int(params["page"], 1)
258 offset = (page - 1) * limit
259
260 q =
261 from(
262 a in Activity,
263 where: fragment("?->>'type' = 'Create'", a.data),
264 where: "https://www.w3.org/ns/activitystreams#Public" in a.recipients,
265 where:
266 fragment(
267 "to_tsvector('english', ?->'object'->>'content') @@ plainto_tsquery('english', ?)",
268 a.data,
269 ^query
270 ),
271 limit: ^limit,
272 offset: ^offset,
273 # this one isn't indexed so psql won't take the wrong index.
274 order_by: [desc: :inserted_at]
275 )
276
277 _activities = Repo.all(q)
278 end
279
280 # DEPRECATED mostly, context objects are now created at insertion time.
281 def context_to_conversation_id(context) do
282 with %Object{id: id} <- Object.get_cached_by_ap_id(context) do
283 id
284 else
285 _e ->
286 changeset = Object.context_mapping(context)
287
288 case Repo.insert(changeset) do
289 {:ok, %{id: id}} ->
290 id
291
292 # This should be solved by an upsert, but it seems ecto
293 # has problems accessing the constraint inside the jsonb.
294 {:error, _} ->
295 Object.get_cached_by_ap_id(context).id
296 end
297 end
298 end
299
300 def conversation_id_to_context(id) do
301 with %Object{data: %{"id" => context}} <- Repo.get(Object, id) do
302 context
303 else
304 _e ->
305 {:error, "No such conversation"}
306 end
307 end
308
309 def get_external_profile(for_user, uri) do
310 with %User{} = user <- User.get_or_fetch(uri) do
311 {:ok, UserView.render("show.json", %{user: user, for: for_user})}
312 else
313 _e ->
314 {:error, "Couldn't find user"}
315 end
316 end
317 end