ObjectValidator: Add validation for `Delete`s.
[akkoma] / test / web / activity_pub / object_validator_test.exs
1 defmodule Pleroma.Web.ActivityPub.ObjectValidatorTest do
2 use Pleroma.DataCase
3
4 alias Pleroma.Web.ActivityPub.Builder
5 alias Pleroma.Web.ActivityPub.ObjectValidator
6 alias Pleroma.Web.ActivityPub.ObjectValidators.LikeValidator
7 alias Pleroma.Web.ActivityPub.Utils
8 alias Pleroma.Web.CommonAPI
9
10 import Pleroma.Factory
11
12 describe "deletes" do
13 setup do
14 user = insert(:user)
15 {:ok, post_activity} = CommonAPI.post(user, %{"status" => "cancel me daddy"})
16
17 {:ok, valid_post_delete, _} = Builder.delete(user, post_activity.data["object"])
18
19 %{user: user, valid_post_delete: valid_post_delete}
20 end
21
22 test "it is valid for a post deletion", %{valid_post_delete: valid_post_delete} do
23 assert match?({:ok, _, _}, ObjectValidator.validate(valid_post_delete, []))
24 end
25
26 test "it's invalid if the id is missing", %{valid_post_delete: valid_post_delete} do
27 no_id =
28 valid_post_delete
29 |> Map.delete("id")
30
31 {:error, cng} = ObjectValidator.validate(no_id, [])
32
33 assert {:id, {"can't be blank", [validation: :required]}} in cng.errors
34 end
35
36 test "it's invalid if the object doesn't exist", %{valid_post_delete: valid_post_delete} do
37 missing_object =
38 valid_post_delete
39 |> Map.put("object", "http://does.not/exist")
40
41 {:error, cng} = ObjectValidator.validate(missing_object, [])
42
43 assert {:object, {"can't find object", []}} in cng.errors
44 end
45
46 test "it's invalid if the actor of the object and the actor of delete are from different domains",
47 %{valid_post_delete: valid_post_delete} do
48 valid_other_actor =
49 valid_post_delete
50 |> Map.put("actor", valid_post_delete["actor"] <> "1")
51
52 assert match?({:ok, _, _}, ObjectValidator.validate(valid_other_actor, []))
53
54 invalid_other_actor =
55 valid_post_delete
56 |> Map.put("actor", "https://gensokyo.2hu/users/raymoo")
57
58 {:error, cng} = ObjectValidator.validate(invalid_other_actor, [])
59
60 assert {:actor, {"is not allowed to delete object", []}} in cng.errors
61 end
62
63 test "it's invalid if all the recipient fields are empty", %{
64 valid_post_delete: valid_post_delete
65 } do
66 empty_recipients =
67 valid_post_delete
68 |> Map.put("to", [])
69 |> Map.put("cc", [])
70
71 {:error, cng} = ObjectValidator.validate(empty_recipients, [])
72
73 assert {:to, {"no recipients in any field", []}} in cng.errors
74 assert {:cc, {"no recipients in any field", []}} in cng.errors
75 end
76 end
77
78 describe "likes" do
79 setup do
80 user = insert(:user)
81 {:ok, post_activity} = CommonAPI.post(user, %{"status" => "uguu"})
82
83 valid_like = %{
84 "to" => [user.ap_id],
85 "cc" => [],
86 "type" => "Like",
87 "id" => Utils.generate_activity_id(),
88 "object" => post_activity.data["object"],
89 "actor" => user.ap_id,
90 "context" => "a context"
91 }
92
93 %{valid_like: valid_like, user: user, post_activity: post_activity}
94 end
95
96 test "returns ok when called in the ObjectValidator", %{valid_like: valid_like} do
97 {:ok, object, _meta} = ObjectValidator.validate(valid_like, [])
98
99 assert "id" in Map.keys(object)
100 end
101
102 test "is valid for a valid object", %{valid_like: valid_like} do
103 assert LikeValidator.cast_and_validate(valid_like).valid?
104 end
105
106 test "it errors when the actor is missing or not known", %{valid_like: valid_like} do
107 without_actor = Map.delete(valid_like, "actor")
108
109 refute LikeValidator.cast_and_validate(without_actor).valid?
110
111 with_invalid_actor = Map.put(valid_like, "actor", "invalidactor")
112
113 refute LikeValidator.cast_and_validate(with_invalid_actor).valid?
114 end
115
116 test "it errors when the object is missing or not known", %{valid_like: valid_like} do
117 without_object = Map.delete(valid_like, "object")
118
119 refute LikeValidator.cast_and_validate(without_object).valid?
120
121 with_invalid_object = Map.put(valid_like, "object", "invalidobject")
122
123 refute LikeValidator.cast_and_validate(with_invalid_object).valid?
124 end
125
126 test "it errors when the actor has already like the object", %{
127 valid_like: valid_like,
128 user: user,
129 post_activity: post_activity
130 } do
131 _like = CommonAPI.favorite(user, post_activity.id)
132
133 refute LikeValidator.cast_and_validate(valid_like).valid?
134 end
135
136 test "it works when actor or object are wrapped in maps", %{valid_like: valid_like} do
137 wrapped_like =
138 valid_like
139 |> Map.put("actor", %{"id" => valid_like["actor"]})
140 |> Map.put("object", %{"id" => valid_like["object"]})
141
142 validated = LikeValidator.cast_and_validate(wrapped_like)
143
144 assert validated.valid?
145
146 assert {:actor, valid_like["actor"]} in validated.changes
147 assert {:object, valid_like["object"]} in validated.changes
148 end
149 end
150 end