[#210] [TwitterAPI] Made actor be stored for uploads. Added ownership check
[akkoma] / lib / pleroma / web / twitter_api / twitter_api.ex
1 defmodule Pleroma.Web.TwitterAPI.TwitterAPI do
2 alias Pleroma.{UserInviteToken, User, Activity, Repo, Object}
3 alias Pleroma.Web.ActivityPub.ActivityPub
4 alias Pleroma.Web.TwitterAPI.UserView
5 alias Pleroma.Web.{OStatus, CommonAPI}
6 alias Pleroma.Web.MediaProxy
7 import Ecto.Query
8
9 @httpoison Application.get_env(:pleroma, :httpoison)
10
11 def create_status(%User{} = user, %{"status" => _} = data) do
12 CommonAPI.post(user, data)
13 end
14
15 def delete(%User{} = user, id) do
16 with %Activity{data: %{"type" => type}} <- Repo.get(Activity, id),
17 {:ok, activity} <- CommonAPI.delete(id, user) do
18 {:ok, activity}
19 end
20 end
21
22 def follow(%User{} = follower, params) do
23 with {:ok, %User{} = followed} <- get_user(params),
24 {:ok, follower} <- User.maybe_direct_follow(follower, followed),
25 {:ok, activity} <- ActivityPub.follow(follower, followed),
26 {:ok, follower, followed} <-
27 User.wait_and_refresh(
28 Pleroma.Config.get([:activitypub, :follow_handshake_timeout]),
29 follower,
30 followed
31 ) do
32 {:ok, follower, followed, activity}
33 else
34 err -> err
35 end
36 end
37
38 def unfollow(%User{} = follower, params) do
39 with {:ok, %User{} = unfollowed} <- get_user(params),
40 {:ok, follower, follow_activity} <- User.unfollow(follower, unfollowed),
41 {:ok, _activity} <- ActivityPub.unfollow(follower, unfollowed) do
42 {:ok, follower, unfollowed}
43 else
44 err -> err
45 end
46 end
47
48 def block(%User{} = blocker, params) do
49 with {:ok, %User{} = blocked} <- get_user(params),
50 {:ok, blocker} <- User.block(blocker, blocked),
51 {:ok, _activity} <- ActivityPub.block(blocker, blocked) do
52 {:ok, blocker, blocked}
53 else
54 err -> err
55 end
56 end
57
58 def unblock(%User{} = blocker, params) do
59 with {:ok, %User{} = blocked} <- get_user(params),
60 {:ok, blocker} <- User.unblock(blocker, blocked),
61 {:ok, _activity} <- ActivityPub.unblock(blocker, blocked) do
62 {:ok, blocker, blocked}
63 else
64 err -> err
65 end
66 end
67
68 def repeat(%User{} = user, ap_id_or_id) do
69 with {:ok, _announce, %{data: %{"id" => id}}} <- CommonAPI.repeat(ap_id_or_id, user),
70 %Activity{} = activity <- Activity.get_create_activity_by_object_ap_id(id) do
71 {:ok, activity}
72 end
73 end
74
75 def unrepeat(%User{} = user, ap_id_or_id) do
76 with {:ok, _unannounce, %{data: %{"id" => id}}} <- CommonAPI.unrepeat(ap_id_or_id, user),
77 %Activity{} = activity <- Activity.get_create_activity_by_object_ap_id(id) do
78 {:ok, activity}
79 end
80 end
81
82 def fav(%User{} = user, ap_id_or_id) do
83 with {:ok, _fav, %{data: %{"id" => id}}} <- CommonAPI.favorite(ap_id_or_id, user),
84 %Activity{} = activity <- Activity.get_create_activity_by_object_ap_id(id) do
85 {:ok, activity}
86 end
87 end
88
89 def unfav(%User{} = user, ap_id_or_id) do
90 with {:ok, _unfav, _fav, %{data: %{"id" => id}}} <- CommonAPI.unfavorite(ap_id_or_id, user),
91 %Activity{} = activity <- Activity.get_create_activity_by_object_ap_id(id) do
92 {:ok, activity}
93 end
94 end
95
96 def ap_upload(%Plug.Upload{} = file, %User{} = user) do
97 ActivityPub.upload(file, actor: User.ap_id(user))
98 end
99
100 def upload(%Plug.Upload{} = file, %User{} = user, format \\ "xml") do
101 {:ok, object} = ap_upload(file, user)
102
103 url = List.first(object.data["url"])
104 href = url["href"]
105 type = url["mediaType"]
106
107 case format do
108 "xml" ->
109 # Fake this as good as possible...
110 """
111 <?xml version="1.0" encoding="UTF-8"?>
112 <rsp stat="ok" xmlns:atom="http://www.w3.org/2005/Atom">
113 <mediaid>#{object.id}</mediaid>
114 <media_id>#{object.id}</media_id>
115 <media_id_string>#{object.id}</media_id_string>
116 <media_url>#{href}</media_url>
117 <mediaurl>#{href}</mediaurl>
118 <atom:link rel="enclosure" href="#{href}" type="#{type}"></atom:link>
119 </rsp>
120 """
121
122 "json" ->
123 %{
124 media_id: object.id,
125 media_id_string: "#{object.id}}",
126 media_url: href,
127 size: 0
128 }
129 |> Jason.encode!()
130 end
131 end
132
133 def register_user(params) do
134 tokenString = params["token"]
135
136 params = %{
137 nickname: params["nickname"],
138 name: params["fullname"],
139 bio: User.parse_bio(params["bio"]),
140 email: params["email"],
141 password: params["password"],
142 password_confirmation: params["confirm"]
143 }
144
145 registrations_open = Pleroma.Config.get([:instance, :registrations_open])
146
147 # no need to query DB if registration is open
148 token =
149 unless registrations_open || is_nil(tokenString) do
150 Repo.get_by(UserInviteToken, %{token: tokenString})
151 end
152
153 cond do
154 registrations_open || (!is_nil(token) && !token.used) ->
155 changeset = User.register_changeset(%User{info: %{}}, params)
156
157 with {:ok, user} <- Repo.insert(changeset) do
158 !registrations_open && UserInviteToken.mark_as_used(token.token)
159 {:ok, user}
160 else
161 {:error, changeset} ->
162 errors =
163 Ecto.Changeset.traverse_errors(changeset, fn {msg, _opts} -> msg end)
164 |> Jason.encode!()
165
166 {:error, %{error: errors}}
167 end
168
169 !registrations_open && is_nil(token) ->
170 {:error, "Invalid token"}
171
172 !registrations_open && token.used ->
173 {:error, "Expired token"}
174 end
175 end
176
177 def get_by_id_or_nickname(id_or_nickname) do
178 if !is_integer(id_or_nickname) && :error == Integer.parse(id_or_nickname) do
179 Repo.get_by(User, nickname: id_or_nickname)
180 else
181 Repo.get(User, id_or_nickname)
182 end
183 end
184
185 def get_user(user \\ nil, params) do
186 case params do
187 %{"user_id" => user_id} ->
188 case target = get_by_id_or_nickname(user_id) do
189 nil ->
190 {:error, "No user with such user_id"}
191
192 _ ->
193 {:ok, target}
194 end
195
196 %{"screen_name" => nickname} ->
197 case target = Repo.get_by(User, nickname: nickname) do
198 nil ->
199 {:error, "No user with such screen_name"}
200
201 _ ->
202 {:ok, target}
203 end
204
205 _ ->
206 if user do
207 {:ok, user}
208 else
209 {:error, "You need to specify screen_name or user_id"}
210 end
211 end
212 end
213
214 defp parse_int(string, default)
215
216 defp parse_int(string, default) when is_binary(string) do
217 with {n, _} <- Integer.parse(string) do
218 n
219 else
220 _e -> default
221 end
222 end
223
224 defp parse_int(_, default), do: default
225
226 def search(_user, %{"q" => query} = params) do
227 limit = parse_int(params["rpp"], 20)
228 page = parse_int(params["page"], 1)
229 offset = (page - 1) * limit
230
231 q =
232 from(
233 a in Activity,
234 where: fragment("?->>'type' = 'Create'", a.data),
235 where: "https://www.w3.org/ns/activitystreams#Public" in a.recipients,
236 where:
237 fragment(
238 "to_tsvector('english', ?->'object'->>'content') @@ plainto_tsquery('english', ?)",
239 a.data,
240 ^query
241 ),
242 limit: ^limit,
243 offset: ^offset,
244 # this one isn't indexed so psql won't take the wrong index.
245 order_by: [desc: :inserted_at]
246 )
247
248 _activities = Repo.all(q)
249 end
250
251 defp make_date do
252 DateTime.utc_now() |> DateTime.to_iso8601()
253 end
254
255 # DEPRECATED mostly, context objects are now created at insertion time.
256 def context_to_conversation_id(context) do
257 with %Object{id: id} <- Object.get_cached_by_ap_id(context) do
258 id
259 else
260 _e ->
261 changeset = Object.context_mapping(context)
262
263 case Repo.insert(changeset) do
264 {:ok, %{id: id}} ->
265 id
266
267 # This should be solved by an upsert, but it seems ecto
268 # has problems accessing the constraint inside the jsonb.
269 {:error, _} ->
270 Object.get_cached_by_ap_id(context).id
271 end
272 end
273 end
274
275 def conversation_id_to_context(id) do
276 with %Object{data: %{"id" => context}} <- Repo.get(Object, id) do
277 context
278 else
279 _e ->
280 {:error, "No such conversation"}
281 end
282 end
283
284 def get_external_profile(for_user, uri) do
285 with %User{} = user <- User.get_or_fetch(uri) do
286 {:ok, UserView.render("show.json", %{user: user, for: for_user})}
287 else
288 _e ->
289 {:error, "Couldn't find user"}
290 end
291 end
292 end