1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2021 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
5 defmodule Pleroma.Web.MastodonAPI.AccountViewTest do
6 use Pleroma.DataCase, async: false
9 alias Pleroma.UserRelationship
10 alias Pleroma.Web.CommonAPI
11 alias Pleroma.Web.MastodonAPI.AccountView
13 import Pleroma.Factory
18 mock(fn env -> apply(HttpRequestMock, :request, [env]) end)
22 test "Represent a user account" do
24 "url" => [%{"href" => "https://example.com/images/asuka_hospital.png"}]
29 ap_id: "https://example.com/users/chikichikibanban",
32 background: background_image,
33 nickname: "shp@shitposter.club",
34 name: ":karjalanpiirakka: shp",
36 "<script src=\"invalid-html\"></script><span>valid html</span>. a<br>b<br/>c<br >d<br />f '&<>\"",
37 inserted_at: ~N[2017-08-15 15:47:06.597036],
38 emoji: %{"karjalanpiirakka" => "/file.png"},
39 raw_bio: "valid html. a\nb\nc\nd\nf '&<>\"",
40 also_known_as: ["https://shitposter.zone/users/shp"],
44 insert(:instance, %{host: "example.com", nodeinfo: %{version: "2.1"}})
47 id: to_string(user.id),
50 display_name: user.name,
52 created_at: "2017-08-15T15:47:06.000Z",
56 note: "<span>valid html</span>. a<br/>b<br/>c<br/>d<br/>f '&<>"",
68 avatar: "http://localhost:4001/images/avi.png",
69 avatar_static: "http://localhost:4001/images/avi.png",
70 header: "http://localhost:4001/images/banner.png",
71 header_static: "http://localhost:4001/images/banner.png",
74 static_url: "/file.png",
76 shortcode: "karjalanpiirakka",
77 visible_in_picker: false
83 note: "valid html. a\nb\nc\nd\nf '&<>\"",
91 fqn: "shp@shitposter.club",
95 also_known_as: ["https://shitposter.zone/users/shp"],
96 background_image: "https://example.com/images/asuka_hospital.png",
103 hide_favorites: true,
104 hide_followers: false,
106 hide_followers_count: false,
107 hide_follows_count: false,
109 skip_thread_containment: false
113 assert expected == AccountView.render("show.json", %{user: user, skip_visibility_check: true})
116 describe "nodeinfo" do
119 user: insert(:user, ap_id: "https://somewhere.example.com/users/chikichikibanban"),
122 host: "somewhere.example.com",
123 favicon: "https://example.com/favicon.ico"
128 test "is embedded in the account view", %{user: user} do
132 name: "somewhere.example.com",
136 favicon: "https://example.com/favicon.ico"
139 } = AccountView.render("show.json", %{user: user, skip_visibility_check: true})
142 test "uses local nodeinfo for local users" do
156 } = AccountView.render("show.json", %{user: user, skip_visibility_check: true})
160 describe "favicon" do
163 user: insert(:user, ap_id: "https://example.com/users/chikichikibanban"),
165 insert(:instance, %{host: "example.com", favicon: "https://example.com/favicon.ico"})
169 test "is parsed when :instance_favicons is enabled", %{user: user} do
170 clear_config([:instances_favicons, :enabled], true)
174 favicon: "https://example.com/favicon.ico"
176 } = AccountView.render("show.json", %{user: user, skip_visibility_check: true})
179 test "is nil when we have no instance", %{user: user} do
180 user = %{user | ap_id: "https://wowee.example.com/users/2"}
182 assert %{pleroma: %{favicon: nil}} =
183 AccountView.render("show.json", %{user: user, skip_visibility_check: true})
187 test "Represent the user account for the account owner" do
190 notification_settings = %{
191 block_from_strangers: false,
192 hide_notification_contents: false
195 privacy = user.default_scope
198 pleroma: %{notification_settings: ^notification_settings, allow_following_move: true},
199 source: %{privacy: ^privacy}
200 } = AccountView.render("show.json", %{user: user, for: user})
203 test "Represent a Service(bot) account" do
208 actor_type: "Service",
209 nickname: "shp@shitposter.club",
210 inserted_at: ~N[2017-08-15 15:47:06.597036]
214 id: to_string(user.id),
217 display_name: user.name,
219 created_at: "2017-08-15T15:47:06.000Z",
225 avatar: "http://localhost:4001/images/avi.png",
226 avatar_static: "http://localhost:4001/images/avi.png",
227 header: "http://localhost:4001/images/banner.png",
228 header_static: "http://localhost:4001/images/banner.png",
236 actor_type: "Service",
241 fqn: "shp@shitposter.club",
246 favicon: "http://localhost:4001/favicon.png",
247 nodeinfo: %{version: "2.0"}
254 background_image: nil,
255 favicon: "http://localhost:4001/favicon.png",
261 hide_favorites: true,
262 hide_followers: false,
264 hide_followers_count: false,
265 hide_follows_count: false,
267 skip_thread_containment: false
272 Pleroma.Web.Nodeinfo.NodeinfoController,
273 raw_nodeinfo: fn -> %{version: "2.0"} end
276 AccountView.render("show.json", %{user: user, skip_visibility_check: true})
280 test "Represent a Funkwhale channel" do
282 User.get_or_fetch_by_ap_id(
283 "https://channels.tests.funkwhale.audio/federation/actors/compositions"
287 AccountView.render("show.json", %{user: user, skip_visibility_check: true})
289 assert represented.acct == "compositions@channels.tests.funkwhale.audio"
290 assert represented.url == "https://channels.tests.funkwhale.audio/channels/compositions"
293 test "Represent a deactivated user for an admin" do
294 admin = insert(:user, is_admin: true)
295 deactivated_user = insert(:user, is_active: false)
296 represented = AccountView.render("show.json", %{user: deactivated_user, for: admin})
297 assert represented[:pleroma][:deactivated] == true
300 test "Represent a smaller mention" do
304 id: to_string(user.id),
306 username: user.nickname,
310 assert expected == AccountView.render("mention.json", %{user: user})
313 test "demands :for or :skip_visibility_check option for account rendering" do
314 clear_config([:restrict_unauthenticated, :profiles, :local], false)
319 assert %{id: ^user_id} = AccountView.render("show.json", %{user: user, for: nil})
320 assert %{id: ^user_id} = AccountView.render("show.json", %{user: user, for: user})
322 assert %{id: ^user_id} =
323 AccountView.render("show.json", %{user: user, skip_visibility_check: true})
325 assert_raise RuntimeError, ~r/:skip_visibility_check or :for option is required/, fn ->
326 AccountView.render("show.json", %{user: user})
330 describe "relationship" do
331 defp test_relationship_rendering(user, other_user, expected_result) do
332 opts = %{user: user, target: other_user, relationships: nil}
333 assert expected_result == AccountView.render("relationship.json", opts)
335 relationships_opt = UserRelationship.view_relationships_option(user, [other_user])
336 opts = Map.put(opts, :relationships, relationships_opt)
337 assert expected_result == AccountView.render("relationship.json", opts)
339 assert [expected_result] ==
340 AccountView.render("relationships.json", %{user: user, targets: [other_user]})
349 muting_notifications: false,
354 domain_blocking: false,
355 showing_reblogs: true,
360 test "represent a relationship for the following and followed user" do
362 other_user = insert(:user)
364 {:ok, user, other_user} = User.follow(user, other_user)
365 {:ok, other_user, user} = User.follow(other_user, user)
366 {:ok, _subscription} = User.subscribe(user, other_user)
367 {:ok, _user_relationships} = User.mute(user, other_user, %{notifications: true})
368 {:ok, _reblog_mute} = CommonAPI.hide_reblogs(user, other_user)
377 muting_notifications: true,
380 showing_reblogs: false,
381 id: to_string(other_user.id)
385 test_relationship_rendering(user, other_user, expected)
388 test "represent a relationship for the blocking and blocked user" do
390 other_user = insert(:user)
392 {:ok, user, other_user} = User.follow(user, other_user)
393 {:ok, _subscription} = User.subscribe(user, other_user)
394 {:ok, _user_relationship} = User.block(user, other_user)
395 {:ok, _user_relationship} = User.block(other_user, user)
400 %{following: false, blocking: true, blocked_by: true, id: to_string(other_user.id)}
403 test_relationship_rendering(user, other_user, expected)
406 test "represent a relationship for the user blocking a domain" do
408 other_user = insert(:user, ap_id: "https://bad.site/users/other_user")
410 {:ok, user} = User.block_domain(user, "bad.site")
415 %{domain_blocking: true, blocking: false, id: to_string(other_user.id)}
418 test_relationship_rendering(user, other_user, expected)
421 test "represent a relationship for the user with a pending follow request" do
423 other_user = insert(:user, is_locked: true)
425 {:ok, user, other_user, _} = CommonAPI.follow(user, other_user)
426 user = User.get_cached_by_id(user.id)
427 other_user = User.get_cached_by_id(other_user.id)
432 %{requested: true, following: false, id: to_string(other_user.id)}
435 test_relationship_rendering(user, other_user, expected)
439 test "represent a relationship for a user with an inbound pending follow request" do
440 follower = insert(:user)
441 followed = insert(:user, is_locked: true)
443 {:ok, follower, followed, _} = CommonAPI.follow(follower, followed)
445 follower = User.get_cached_by_id(follower.id)
446 followed = User.get_cached_by_id(followed.id)
451 %{requested_by: true, followed_by: false, id: to_string(follower.id)}
454 test_relationship_rendering(followed, follower, expected)
457 test "returns the settings store if the requesting user is the represented user and it's requested specifically" do
458 user = insert(:user, pleroma_settings_store: %{fe: "test"})
461 AccountView.render("show.json", %{user: user, for: user, with_pleroma_settings: true})
463 assert result.pleroma.settings_store == %{:fe => "test"}
465 result = AccountView.render("show.json", %{user: user, for: nil, with_pleroma_settings: true})
466 assert result.pleroma[:settings_store] == nil
468 result = AccountView.render("show.json", %{user: user, for: user})
469 assert result.pleroma[:settings_store] == nil
472 test "doesn't sanitize display names" do
473 user = insert(:user, name: "<marquee> username </marquee>")
474 result = AccountView.render("show.json", %{user: user, skip_visibility_check: true})
475 assert result.display_name == "<marquee> username </marquee>"
478 test "never display nil user follow counts" do
479 user = insert(:user, following_count: 0, follower_count: 0)
480 result = AccountView.render("show.json", %{user: user, skip_visibility_check: true})
482 assert result.following_count == 0
483 assert result.followers_count == 0
486 describe "hiding follows/following" do
487 test "shows when follows/followers stats are hidden and sets follow/follower count to 0" do
490 hide_followers: true,
491 hide_followers_count: true,
493 hide_follows_count: true
496 other_user = insert(:user)
497 {:ok, user, other_user, _activity} = CommonAPI.follow(user, other_user)
498 {:ok, _other_user, user, _activity} = CommonAPI.follow(other_user, user)
503 pleroma: %{hide_follows_count: true, hide_followers_count: true}
504 } = AccountView.render("show.json", %{user: user, skip_visibility_check: true})
507 test "shows when follows/followers are hidden" do
508 user = insert(:user, hide_followers: true, hide_follows: true)
509 other_user = insert(:user)
510 {:ok, user, other_user, _activity} = CommonAPI.follow(user, other_user)
511 {:ok, _other_user, user, _activity} = CommonAPI.follow(other_user, user)
516 pleroma: %{hide_follows: true, hide_followers: true}
517 } = AccountView.render("show.json", %{user: user, skip_visibility_check: true})
520 test "shows actual follower/following count to the account owner" do
521 user = insert(:user, hide_followers: true, hide_follows: true)
522 other_user = insert(:user)
523 {:ok, user, other_user, _activity} = CommonAPI.follow(user, other_user)
525 assert User.following?(user, other_user)
526 assert Pleroma.FollowingRelationship.follower_count(other_user) == 1
527 {:ok, _other_user, user, _activity} = CommonAPI.follow(other_user, user)
532 } = AccountView.render("show.json", %{user: user, for: user})
535 test "shows unread_conversation_count only to the account owner" do
537 other_user = insert(:user)
540 CommonAPI.post(other_user, %{
541 status: "Hey @#{user.nickname}.",
545 user = User.get_cached_by_ap_id(user.ap_id)
547 assert AccountView.render("show.json", %{user: user, for: other_user})[:pleroma][
548 :unread_conversation_count
551 assert AccountView.render("show.json", %{user: user, for: user})[:pleroma][
552 :unread_conversation_count
556 test "shows unread_count only to the account owner" do
558 insert_list(7, :notification, user: user, activity: insert(:note_activity))
559 other_user = insert(:user)
561 user = User.get_cached_by_ap_id(user.ap_id)
563 assert AccountView.render(
565 %{user: user, for: other_user}
566 )[:pleroma][:unread_notifications_count] == nil
568 assert AccountView.render(
570 %{user: user, for: user}
571 )[:pleroma][:unread_notifications_count] == 7
574 test "shows email only to the account owner" do
576 other_user = insert(:user)
578 user = User.get_cached_by_ap_id(user.ap_id)
580 assert AccountView.render(
582 %{user: user, for: other_user}
583 )[:pleroma][:email] == nil
585 assert AccountView.render(
587 %{user: user, for: user}
588 )[:pleroma][:email] == user.email
592 describe "follow requests counter" do
593 test "shows zero when no follow requests are pending" do
596 assert %{follow_requests_count: 0} =
597 AccountView.render("show.json", %{user: user, for: user})
599 other_user = insert(:user)
600 {:ok, _other_user, user, _activity} = CommonAPI.follow(other_user, user)
602 assert %{follow_requests_count: 0} =
603 AccountView.render("show.json", %{user: user, for: user})
606 test "shows non-zero when follow requests are pending" do
607 user = insert(:user, is_locked: true)
609 assert %{locked: true} = AccountView.render("show.json", %{user: user, for: user})
611 other_user = insert(:user)
612 {:ok, _other_user, user, _activity} = CommonAPI.follow(other_user, user)
614 assert %{locked: true, follow_requests_count: 1} =
615 AccountView.render("show.json", %{user: user, for: user})
618 test "decreases when accepting a follow request" do
619 user = insert(:user, is_locked: true)
621 assert %{locked: true} = AccountView.render("show.json", %{user: user, for: user})
623 other_user = insert(:user)
624 {:ok, other_user, user, _activity} = CommonAPI.follow(other_user, user)
626 assert %{locked: true, follow_requests_count: 1} =
627 AccountView.render("show.json", %{user: user, for: user})
629 {:ok, _other_user} = CommonAPI.accept_follow_request(other_user, user)
631 assert %{locked: true, follow_requests_count: 0} =
632 AccountView.render("show.json", %{user: user, for: user})
635 test "decreases when rejecting a follow request" do
636 user = insert(:user, is_locked: true)
638 assert %{locked: true} = AccountView.render("show.json", %{user: user, for: user})
640 other_user = insert(:user)
641 {:ok, other_user, user, _activity} = CommonAPI.follow(other_user, user)
643 assert %{locked: true, follow_requests_count: 1} =
644 AccountView.render("show.json", %{user: user, for: user})
646 {:ok, _other_user} = CommonAPI.reject_follow_request(other_user, user)
648 assert %{locked: true, follow_requests_count: 0} =
649 AccountView.render("show.json", %{user: user, for: user})
652 test "shows non-zero when historical unapproved requests are present" do
653 user = insert(:user, is_locked: true)
655 assert %{locked: true} = AccountView.render("show.json", %{user: user, for: user})
657 other_user = insert(:user)
658 {:ok, _other_user, user, _activity} = CommonAPI.follow(other_user, user)
660 {:ok, user} = User.update_and_set_cache(user, %{is_locked: false})
662 assert %{locked: false, follow_requests_count: 1} =
663 AccountView.render("show.json", %{user: user, for: user})
667 test "uses mediaproxy urls when it's enabled (regardless of media preview proxy state)" do
668 clear_config([:media_proxy, :enabled], true)
669 clear_config([:media_preview_proxy, :enabled])
673 avatar: %{"url" => [%{"href" => "https://evil.website/avatar.png"}]},
674 banner: %{"url" => [%{"href" => "https://evil.website/banner.png"}]},
675 emoji: %{"joker_smile" => "https://evil.website/society.png"}
678 insert(:instance, %{host: "localhost", favicon: "https://evil.website/favicon.png"})
680 with media_preview_enabled <- [false, true] do
681 clear_config([:media_preview_proxy, :enabled], media_preview_enabled)
683 AccountView.render("show.json", %{user: user, skip_visibility_check: true})
685 {key, url} when key in [:avatar, :avatar_static, :header, :header_static] ->
686 String.starts_with?(url, Pleroma.Web.Endpoint.url())
688 {:akkoma, %{instance: %{favicon: favicon_url}}} ->
689 String.starts_with?(favicon_url, Pleroma.Web.Endpoint.url())
692 Enum.all?(emojis, fn %{url: url, static_url: static_url} ->
693 String.starts_with?(url, Pleroma.Web.Endpoint.url()) &&
694 String.starts_with?(static_url, Pleroma.Web.Endpoint.url())
704 test "returns nil in the instance field when no instance is held locally" do
705 user = insert(:user, ap_id: "https://example.com/users/1")
706 view = AccountView.render("show.json", %{user: user, skip_visibility_check: true})
707 assert view[:akkoma][:instance] == nil