User deletion mix task: Use common pipeline.
[akkoma] / test / web / activity_pub / object_validator_test.exs
1 defmodule Pleroma.Web.ActivityPub.ObjectValidatorTest do
2 use Pleroma.DataCase
3
4 alias Pleroma.Object
5 alias Pleroma.Web.ActivityPub.Builder
6 alias Pleroma.Web.ActivityPub.ObjectValidator
7 alias Pleroma.Web.ActivityPub.ObjectValidators.LikeValidator
8 alias Pleroma.Web.ActivityPub.Utils
9 alias Pleroma.Web.CommonAPI
10
11 import Pleroma.Factory
12
13 describe "deletes" do
14 setup do
15 user = insert(:user)
16 {:ok, post_activity} = CommonAPI.post(user, %{"status" => "cancel me daddy"})
17
18 {:ok, valid_post_delete, _} = Builder.delete(user, post_activity.data["object"])
19 {:ok, valid_user_delete, _} = Builder.delete(user, user.ap_id)
20
21 %{user: user, valid_post_delete: valid_post_delete, valid_user_delete: valid_user_delete}
22 end
23
24 test "it is valid for a post deletion", %{valid_post_delete: valid_post_delete} do
25 {:ok, valid_post_delete, _} = ObjectValidator.validate(valid_post_delete, [])
26
27 assert valid_post_delete["deleted_activity_id"]
28 end
29
30 test "it is invalid if the object isn't in a list of certain types", %{
31 valid_post_delete: valid_post_delete
32 } do
33 object = Object.get_by_ap_id(valid_post_delete["object"])
34
35 data =
36 object.data
37 |> Map.put("type", "Like")
38
39 {:ok, _object} =
40 object
41 |> Ecto.Changeset.change(%{data: data})
42 |> Object.update_and_set_cache()
43
44 {:error, cng} = ObjectValidator.validate(valid_post_delete, [])
45 assert {:object, {"object not in allowed types", []}} in cng.errors
46 end
47
48 test "it is valid for a user deletion", %{valid_user_delete: valid_user_delete} do
49 assert match?({:ok, _, _}, ObjectValidator.validate(valid_user_delete, []))
50 end
51
52 test "it's invalid if the id is missing", %{valid_post_delete: valid_post_delete} do
53 no_id =
54 valid_post_delete
55 |> Map.delete("id")
56
57 {:error, cng} = ObjectValidator.validate(no_id, [])
58
59 assert {:id, {"can't be blank", [validation: :required]}} in cng.errors
60 end
61
62 test "it's invalid if the object doesn't exist", %{valid_post_delete: valid_post_delete} do
63 missing_object =
64 valid_post_delete
65 |> Map.put("object", "http://does.not/exist")
66
67 {:error, cng} = ObjectValidator.validate(missing_object, [])
68
69 assert {:object, {"can't find object", []}} in cng.errors
70 end
71
72 test "it's invalid if the actor of the object and the actor of delete are from different domains",
73 %{valid_post_delete: valid_post_delete} do
74 valid_user = insert(:user)
75
76 valid_other_actor =
77 valid_post_delete
78 |> Map.put("actor", valid_user.ap_id)
79
80 assert match?({:ok, _, _}, ObjectValidator.validate(valid_other_actor, []))
81
82 invalid_other_actor =
83 valid_post_delete
84 |> Map.put("actor", "https://gensokyo.2hu/users/raymoo")
85
86 {:error, cng} = ObjectValidator.validate(invalid_other_actor, [])
87
88 assert {:actor, {"is not allowed to delete object", []}} in cng.errors
89 end
90
91 test "it's valid if the actor of the object is a local superuser",
92 %{valid_post_delete: valid_post_delete} do
93 user =
94 insert(:user, local: true, is_moderator: true, ap_id: "https://gensokyo.2hu/users/raymoo")
95
96 valid_other_actor =
97 valid_post_delete
98 |> Map.put("actor", user.ap_id)
99
100 {:ok, _, meta} = ObjectValidator.validate(valid_other_actor, [])
101 assert meta[:do_not_federate]
102 end
103 end
104
105 describe "likes" do
106 setup do
107 user = insert(:user)
108 {:ok, post_activity} = CommonAPI.post(user, %{"status" => "uguu"})
109
110 valid_like = %{
111 "to" => [user.ap_id],
112 "cc" => [],
113 "type" => "Like",
114 "id" => Utils.generate_activity_id(),
115 "object" => post_activity.data["object"],
116 "actor" => user.ap_id,
117 "context" => "a context"
118 }
119
120 %{valid_like: valid_like, user: user, post_activity: post_activity}
121 end
122
123 test "returns ok when called in the ObjectValidator", %{valid_like: valid_like} do
124 {:ok, object, _meta} = ObjectValidator.validate(valid_like, [])
125
126 assert "id" in Map.keys(object)
127 end
128
129 test "is valid for a valid object", %{valid_like: valid_like} do
130 assert LikeValidator.cast_and_validate(valid_like).valid?
131 end
132
133 test "it errors when the actor is missing or not known", %{valid_like: valid_like} do
134 without_actor = Map.delete(valid_like, "actor")
135
136 refute LikeValidator.cast_and_validate(without_actor).valid?
137
138 with_invalid_actor = Map.put(valid_like, "actor", "invalidactor")
139
140 refute LikeValidator.cast_and_validate(with_invalid_actor).valid?
141 end
142
143 test "it errors when the object is missing or not known", %{valid_like: valid_like} do
144 without_object = Map.delete(valid_like, "object")
145
146 refute LikeValidator.cast_and_validate(without_object).valid?
147
148 with_invalid_object = Map.put(valid_like, "object", "invalidobject")
149
150 refute LikeValidator.cast_and_validate(with_invalid_object).valid?
151 end
152
153 test "it errors when the actor has already like the object", %{
154 valid_like: valid_like,
155 user: user,
156 post_activity: post_activity
157 } do
158 _like = CommonAPI.favorite(user, post_activity.id)
159
160 refute LikeValidator.cast_and_validate(valid_like).valid?
161 end
162
163 test "it works when actor or object are wrapped in maps", %{valid_like: valid_like} do
164 wrapped_like =
165 valid_like
166 |> Map.put("actor", %{"id" => valid_like["actor"]})
167 |> Map.put("object", %{"id" => valid_like["object"]})
168
169 validated = LikeValidator.cast_and_validate(wrapped_like)
170
171 assert validated.valid?
172
173 assert {:actor, valid_like["actor"]} in validated.changes
174 assert {:object, valid_like["object"]} in validated.changes
175 end
176 end
177 end