1 defmodule Pleroma.Web.ActivityPub.TransmogrifierTest do
3 alias Pleroma.Web.ActivityPub.Transmogrifier
4 alias Pleroma.Web.ActivityPub.Utils
5 alias Pleroma.Web.ActivityPub.ActivityPub
6 alias Pleroma.Web.OStatus
10 alias Pleroma.Web.Websub.WebsubClientSubscription
12 import Pleroma.Factory
13 alias Pleroma.Web.CommonAPI
15 Tesla.Mock.mock_global(fn env -> apply(HttpRequestMock, :request, [env]) end)
19 describe "handle_incoming" do
20 test "it ignores an incoming notice if we already have it" do
21 activity = insert(:note_activity)
24 File.read!("test/fixtures/mastodon-post-activity.json")
26 |> Map.put("object", activity.data["object"])
28 {:ok, returned_activity} = Transmogrifier.handle_incoming(data)
30 assert activity == returned_activity
33 test "it fetches replied-to activities if we don't have them" do
35 File.read!("test/fixtures/mastodon-post-activity.json")
40 |> Map.put("inReplyTo", "https://shitposter.club/notice/2827873")
44 |> Map.put("object", object)
46 {:ok, returned_activity} = Transmogrifier.handle_incoming(data)
49 Activity.get_create_activity_by_object_ap_id(
50 "tag:shitposter.club,2017-05-05:noticeId=2827873:objectType=comment"
53 assert returned_activity.data["object"]["inReplyToAtomUri"] ==
54 "https://shitposter.club/notice/2827873"
56 assert returned_activity.data["object"]["inReplyToStatusId"] == activity.id
59 test "it works for incoming notices" do
60 data = File.read!("test/fixtures/mastodon-post-activity.json") |> Poison.decode!()
62 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
65 "http://mastodon.example.org/users/admin/statuses/99512778738411822/activity"
67 assert data["context"] ==
68 "tag:mastodon.example.org,2018-02-12:objectId=20:objectType=Conversation"
70 assert data["to"] == ["https://www.w3.org/ns/activitystreams#Public"]
72 assert data["cc"] == [
73 "http://mastodon.example.org/users/admin/followers",
74 "http://localtesting.pleroma.lol/users/lain"
77 assert data["actor"] == "http://mastodon.example.org/users/admin"
79 object = data["object"]
80 assert object["id"] == "http://mastodon.example.org/users/admin/statuses/99512778738411822"
82 assert object["to"] == ["https://www.w3.org/ns/activitystreams#Public"]
84 assert object["cc"] == [
85 "http://mastodon.example.org/users/admin/followers",
86 "http://localtesting.pleroma.lol/users/lain"
89 assert object["actor"] == "http://mastodon.example.org/users/admin"
90 assert object["attributedTo"] == "http://mastodon.example.org/users/admin"
92 assert object["context"] ==
93 "tag:mastodon.example.org,2018-02-12:objectId=20:objectType=Conversation"
95 assert object["sensitive"] == true
97 user = User.get_by_ap_id(object["actor"])
99 assert user.info.note_count == 1
102 test "it works for incoming notices with hashtags" do
103 data = File.read!("test/fixtures/mastodon-post-activity-hashtag.json") |> Poison.decode!()
105 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
106 assert Enum.at(data["object"]["tag"], 2) == "moo"
109 test "it works for incoming notices with contentMap" do
111 File.read!("test/fixtures/mastodon-post-activity-contentmap.json") |> Poison.decode!()
113 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
115 assert data["object"]["content"] ==
116 "<p><span class=\"h-card\"><a href=\"http://localtesting.pleroma.lol/users/lain\" class=\"u-url mention\">@<span>lain</span></a></span></p>"
119 test "it works for incoming notices with to/cc not being an array (kroeg)" do
120 data = File.read!("test/fixtures/kroeg-post-activity.json") |> Poison.decode!()
122 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
124 assert data["object"]["content"] ==
125 "<p>henlo from my Psion netBook</p><p>message sent from my Psion netBook</p>"
128 test "it works for incoming announces with actor being inlined (kroeg)" do
129 data = File.read!("test/fixtures/kroeg-announce-with-inline-actor.json") |> Poison.decode!()
131 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
133 assert data["actor"] == "https://puckipedia.com/"
136 test "it works for incoming notices with tag not being an array (kroeg)" do
137 data = File.read!("test/fixtures/kroeg-array-less-emoji.json") |> Poison.decode!()
139 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
141 assert data["object"]["emoji"] == %{
142 "icon_e_smile" => "https://puckipedia.com/forum/images/smilies/icon_e_smile.png"
145 data = File.read!("test/fixtures/kroeg-array-less-hashtag.json") |> Poison.decode!()
147 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
149 assert "test" in data["object"]["tag"]
152 test "it works for incoming notices with url not being a string (prismo)" do
153 data = File.read!("test/fixtures/prismo-url-map.json") |> Poison.decode!()
155 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
157 assert data["object"]["url"] == "https://prismo.news/posts/83"
160 test "it works for incoming follow requests" do
164 File.read!("test/fixtures/mastodon-follow-activity.json")
166 |> Map.put("object", user.ap_id)
168 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
170 assert data["actor"] == "http://mastodon.example.org/users/admin"
171 assert data["type"] == "Follow"
172 assert data["id"] == "http://mastodon.example.org/users/admin#follows/2"
173 assert User.following?(User.get_by_ap_id(data["actor"]), user)
176 test "it works for incoming follow requests from hubzilla" do
180 File.read!("test/fixtures/hubzilla-follow-activity.json")
182 |> Map.put("object", user.ap_id)
183 |> Utils.normalize_params()
185 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
187 assert data["actor"] == "https://hubzilla.example.org/channel/kaniini"
188 assert data["type"] == "Follow"
189 assert data["id"] == "https://hubzilla.example.org/channel/kaniini#follows/2"
190 assert User.following?(User.get_by_ap_id(data["actor"]), user)
193 test "it works for incoming likes" do
195 {:ok, activity} = CommonAPI.post(user, %{"status" => "hello"})
198 File.read!("test/fixtures/mastodon-like.json")
200 |> Map.put("object", activity.data["object"]["id"])
202 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
204 assert data["actor"] == "http://mastodon.example.org/users/admin"
205 assert data["type"] == "Like"
206 assert data["id"] == "http://mastodon.example.org/users/admin#likes/2"
207 assert data["object"] == activity.data["object"]["id"]
210 test "it returns an error for incoming unlikes wihout a like activity" do
212 {:ok, activity} = CommonAPI.post(user, %{"status" => "leave a like pls"})
215 File.read!("test/fixtures/mastodon-undo-like.json")
217 |> Map.put("object", activity.data["object"]["id"])
219 assert Transmogrifier.handle_incoming(data) == :error
222 test "it works for incoming unlikes with an existing like activity" do
224 {:ok, activity} = CommonAPI.post(user, %{"status" => "leave a like pls"})
227 File.read!("test/fixtures/mastodon-like.json")
229 |> Map.put("object", activity.data["object"]["id"])
231 {:ok, %Activity{data: like_data, local: false}} = Transmogrifier.handle_incoming(like_data)
234 File.read!("test/fixtures/mastodon-undo-like.json")
236 |> Map.put("object", like_data)
237 |> Map.put("actor", like_data["actor"])
239 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
241 assert data["actor"] == "http://mastodon.example.org/users/admin"
242 assert data["type"] == "Undo"
243 assert data["id"] == "http://mastodon.example.org/users/admin#likes/2/undo"
244 assert data["object"]["id"] == "http://mastodon.example.org/users/admin#likes/2"
247 test "it works for incoming announces" do
248 data = File.read!("test/fixtures/mastodon-announce.json") |> Poison.decode!()
250 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
252 assert data["actor"] == "http://mastodon.example.org/users/admin"
253 assert data["type"] == "Announce"
256 "http://mastodon.example.org/users/admin/statuses/99542391527669785/activity"
258 assert data["object"] ==
259 "http://mastodon.example.org/users/admin/statuses/99541947525187367"
261 assert Activity.get_create_activity_by_object_ap_id(data["object"])
264 test "it works for incoming announces with an existing activity" do
266 {:ok, activity} = CommonAPI.post(user, %{"status" => "hey"})
269 File.read!("test/fixtures/mastodon-announce.json")
271 |> Map.put("object", activity.data["object"]["id"])
273 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
275 assert data["actor"] == "http://mastodon.example.org/users/admin"
276 assert data["type"] == "Announce"
279 "http://mastodon.example.org/users/admin/statuses/99542391527669785/activity"
281 assert data["object"] == activity.data["object"]["id"]
283 assert Activity.get_create_activity_by_object_ap_id(data["object"]).id == activity.id
286 test "it works for incoming update activities" do
287 data = File.read!("test/fixtures/mastodon-post-activity.json") |> Poison.decode!()
289 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
290 update_data = File.read!("test/fixtures/mastodon-update.json") |> Poison.decode!()
293 update_data["object"]
294 |> Map.put("actor", data["actor"])
295 |> Map.put("id", data["actor"])
299 |> Map.put("actor", data["actor"])
300 |> Map.put("object", object)
302 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(update_data)
304 user = User.get_cached_by_ap_id(data["actor"])
305 assert user.name == "gargle"
307 assert user.avatar["url"] == [
310 "https://cd.niu.moe/accounts/avatars/000/033/323/original/fd7f8ae0b3ffedc9.jpeg"
314 assert user.info.banner["url"] == [
317 "https://cd.niu.moe/accounts/headers/000/033/323/original/850b3448fa5fd477.png"
321 assert user.bio == "<p>Some bio</p>"
324 test "it works for incoming update activities which lock the account" do
325 data = File.read!("test/fixtures/mastodon-post-activity.json") |> Poison.decode!()
327 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
328 update_data = File.read!("test/fixtures/mastodon-update.json") |> Poison.decode!()
331 update_data["object"]
332 |> Map.put("actor", data["actor"])
333 |> Map.put("id", data["actor"])
334 |> Map.put("manuallyApprovesFollowers", true)
338 |> Map.put("actor", data["actor"])
339 |> Map.put("object", object)
341 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(update_data)
343 user = User.get_cached_by_ap_id(data["actor"])
344 assert user.info.locked == true
347 test "it works for incoming deletes" do
348 activity = insert(:note_activity)
351 File.read!("test/fixtures/mastodon-delete.json")
356 |> Map.put("id", activity.data["object"]["id"])
360 |> Map.put("object", object)
361 |> Map.put("actor", activity.data["actor"])
363 {:ok, %Activity{local: false}} = Transmogrifier.handle_incoming(data)
365 refute Repo.get(Activity, activity.id)
368 test "it fails for incoming deletes with spoofed origin" do
369 activity = insert(:note_activity)
372 File.read!("test/fixtures/mastodon-delete.json")
377 |> Map.put("id", activity.data["object"]["id"])
381 |> Map.put("object", object)
383 :error = Transmogrifier.handle_incoming(data)
385 assert Repo.get(Activity, activity.id)
388 test "it works for incoming unannounces with an existing notice" do
390 {:ok, activity} = CommonAPI.post(user, %{"status" => "hey"})
393 File.read!("test/fixtures/mastodon-announce.json")
395 |> Map.put("object", activity.data["object"]["id"])
397 {:ok, %Activity{data: announce_data, local: false}} =
398 Transmogrifier.handle_incoming(announce_data)
401 File.read!("test/fixtures/mastodon-undo-announce.json")
403 |> Map.put("object", announce_data)
404 |> Map.put("actor", announce_data["actor"])
406 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
408 assert data["type"] == "Undo"
409 assert data["object"]["type"] == "Announce"
410 assert data["object"]["object"] == activity.data["object"]["id"]
412 assert data["object"]["id"] ==
413 "http://mastodon.example.org/users/admin/statuses/99542391527669785/activity"
416 test "it works for incomming unfollows with an existing follow" do
420 File.read!("test/fixtures/mastodon-follow-activity.json")
422 |> Map.put("object", user.ap_id)
424 {:ok, %Activity{data: _, local: false}} = Transmogrifier.handle_incoming(follow_data)
427 File.read!("test/fixtures/mastodon-unfollow-activity.json")
429 |> Map.put("object", follow_data)
431 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
433 assert data["type"] == "Undo"
434 assert data["object"]["type"] == "Follow"
435 assert data["object"]["object"] == user.ap_id
436 assert data["actor"] == "http://mastodon.example.org/users/admin"
438 refute User.following?(User.get_by_ap_id(data["actor"]), user)
441 test "it works for incoming blocks" do
445 File.read!("test/fixtures/mastodon-block-activity.json")
447 |> Map.put("object", user.ap_id)
449 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
451 assert data["type"] == "Block"
452 assert data["object"] == user.ap_id
453 assert data["actor"] == "http://mastodon.example.org/users/admin"
455 blocker = User.get_by_ap_id(data["actor"])
457 assert User.blocks?(blocker, user)
460 test "incoming blocks successfully tear down any follow relationship" do
461 blocker = insert(:user)
462 blocked = insert(:user)
465 File.read!("test/fixtures/mastodon-block-activity.json")
467 |> Map.put("object", blocked.ap_id)
468 |> Map.put("actor", blocker.ap_id)
470 {:ok, blocker} = User.follow(blocker, blocked)
471 {:ok, blocked} = User.follow(blocked, blocker)
473 assert User.following?(blocker, blocked)
474 assert User.following?(blocked, blocker)
476 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
478 assert data["type"] == "Block"
479 assert data["object"] == blocked.ap_id
480 assert data["actor"] == blocker.ap_id
482 blocker = User.get_by_ap_id(data["actor"])
483 blocked = User.get_by_ap_id(data["object"])
485 assert User.blocks?(blocker, blocked)
487 refute User.following?(blocker, blocked)
488 refute User.following?(blocked, blocker)
491 test "it works for incoming unblocks with an existing block" do
495 File.read!("test/fixtures/mastodon-block-activity.json")
497 |> Map.put("object", user.ap_id)
499 {:ok, %Activity{data: _, local: false}} = Transmogrifier.handle_incoming(block_data)
502 File.read!("test/fixtures/mastodon-unblock-activity.json")
504 |> Map.put("object", block_data)
506 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
507 assert data["type"] == "Undo"
508 assert data["object"]["type"] == "Block"
509 assert data["object"]["object"] == user.ap_id
510 assert data["actor"] == "http://mastodon.example.org/users/admin"
512 blocker = User.get_by_ap_id(data["actor"])
514 refute User.blocks?(blocker, user)
517 test "it works for incoming accepts which were pre-accepted" do
518 follower = insert(:user)
519 followed = insert(:user)
521 {:ok, follower} = User.follow(follower, followed)
522 assert User.following?(follower, followed) == true
524 {:ok, follow_activity} = ActivityPub.follow(follower, followed)
527 File.read!("test/fixtures/mastodon-accept-activity.json")
529 |> Map.put("actor", followed.ap_id)
532 accept_data["object"]
533 |> Map.put("actor", follower.ap_id)
534 |> Map.put("id", follow_activity.data["id"])
536 accept_data = Map.put(accept_data, "object", object)
538 {:ok, activity} = Transmogrifier.handle_incoming(accept_data)
539 refute activity.local
541 assert activity.data["object"] == follow_activity.data["id"]
543 follower = Repo.get(User, follower.id)
545 assert User.following?(follower, followed) == true
548 test "it works for incoming accepts which were orphaned" do
549 follower = insert(:user)
550 followed = insert(:user, %{info: %User.Info{locked: true}})
552 {:ok, follow_activity} = ActivityPub.follow(follower, followed)
555 File.read!("test/fixtures/mastodon-accept-activity.json")
557 |> Map.put("actor", followed.ap_id)
560 Map.put(accept_data, "object", Map.put(accept_data["object"], "actor", follower.ap_id))
562 {:ok, activity} = Transmogrifier.handle_incoming(accept_data)
563 assert activity.data["object"] == follow_activity.data["id"]
565 follower = Repo.get(User, follower.id)
567 assert User.following?(follower, followed) == true
570 test "it works for incoming accepts which are referenced by IRI only" do
571 follower = insert(:user)
572 followed = insert(:user, %{info: %User.Info{locked: true}})
574 {:ok, follow_activity} = ActivityPub.follow(follower, followed)
577 File.read!("test/fixtures/mastodon-accept-activity.json")
579 |> Map.put("actor", followed.ap_id)
580 |> Map.put("object", follow_activity.data["id"])
582 {:ok, activity} = Transmogrifier.handle_incoming(accept_data)
583 assert activity.data["object"] == follow_activity.data["id"]
585 follower = Repo.get(User, follower.id)
587 assert User.following?(follower, followed) == true
590 test "it fails for incoming accepts which cannot be correlated" do
591 follower = insert(:user)
592 followed = insert(:user, %{info: %User.Info{locked: true}})
595 File.read!("test/fixtures/mastodon-accept-activity.json")
597 |> Map.put("actor", followed.ap_id)
600 Map.put(accept_data, "object", Map.put(accept_data["object"], "actor", follower.ap_id))
602 :error = Transmogrifier.handle_incoming(accept_data)
604 follower = Repo.get(User, follower.id)
606 refute User.following?(follower, followed) == true
609 test "it fails for incoming rejects which cannot be correlated" do
610 follower = insert(:user)
611 followed = insert(:user, %{info: %User.Info{locked: true}})
614 File.read!("test/fixtures/mastodon-reject-activity.json")
616 |> Map.put("actor", followed.ap_id)
619 Map.put(accept_data, "object", Map.put(accept_data["object"], "actor", follower.ap_id))
621 :error = Transmogrifier.handle_incoming(accept_data)
623 follower = Repo.get(User, follower.id)
625 refute User.following?(follower, followed) == true
628 test "it works for incoming rejects which are orphaned" do
629 follower = insert(:user)
630 followed = insert(:user, %{info: %User.Info{locked: true}})
632 {:ok, follower} = User.follow(follower, followed)
633 {:ok, _follow_activity} = ActivityPub.follow(follower, followed)
635 assert User.following?(follower, followed) == true
638 File.read!("test/fixtures/mastodon-reject-activity.json")
640 |> Map.put("actor", followed.ap_id)
643 Map.put(reject_data, "object", Map.put(reject_data["object"], "actor", follower.ap_id))
645 {:ok, activity} = Transmogrifier.handle_incoming(reject_data)
646 refute activity.local
648 follower = Repo.get(User, follower.id)
650 assert User.following?(follower, followed) == false
653 test "it works for incoming rejects which are referenced by IRI only" do
654 follower = insert(:user)
655 followed = insert(:user, %{info: %User.Info{locked: true}})
657 {:ok, follower} = User.follow(follower, followed)
658 {:ok, follow_activity} = ActivityPub.follow(follower, followed)
660 assert User.following?(follower, followed) == true
663 File.read!("test/fixtures/mastodon-reject-activity.json")
665 |> Map.put("actor", followed.ap_id)
666 |> Map.put("object", follow_activity.data["id"])
668 {:ok, %Activity{data: _}} = Transmogrifier.handle_incoming(reject_data)
670 follower = Repo.get(User, follower.id)
672 assert User.following?(follower, followed) == false
675 test "it rejects activities without a valid ID" do
679 File.read!("test/fixtures/mastodon-follow-activity.json")
681 |> Map.put("object", user.ap_id)
684 :error = Transmogrifier.handle_incoming(data)
688 describe "prepare outgoing" do
689 test "it turns mentions into tags" do
691 other_user = insert(:user)
694 CommonAPI.post(user, %{"status" => "hey, @#{other_user.nickname}, how are ya? #2hu"})
696 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
697 object = modified["object"]
699 expected_mention = %{
700 "href" => other_user.ap_id,
701 "name" => "@#{other_user.nickname}",
706 "href" => Pleroma.Web.Endpoint.url() <> "/tags/2hu",
711 assert Enum.member?(object["tag"], expected_tag)
712 assert Enum.member?(object["tag"], expected_mention)
715 test "it adds the sensitive property" do
718 {:ok, activity} = CommonAPI.post(user, %{"status" => "#nsfw hey"})
719 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
721 assert modified["object"]["sensitive"]
724 test "it adds the json-ld context and the conversation property" do
727 {:ok, activity} = CommonAPI.post(user, %{"status" => "hey"})
728 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
730 assert modified["@context"] ==
731 Pleroma.Web.ActivityPub.Utils.make_json_ld_header()["@context"]
733 assert modified["object"]["conversation"] == modified["context"]
736 test "it sets the 'attributedTo' property to the actor of the object if it doesn't have one" do
739 {:ok, activity} = CommonAPI.post(user, %{"status" => "hey"})
740 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
742 assert modified["object"]["actor"] == modified["object"]["attributedTo"]
745 test "it translates ostatus IDs to external URLs" do
746 incoming = File.read!("test/fixtures/incoming_note_activity.xml")
747 {:ok, [referent_activity]} = OStatus.handle_incoming(incoming)
751 {:ok, activity, _} = CommonAPI.favorite(referent_activity.id, user)
752 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
754 assert modified["object"] == "http://gs.example.org:4040/index.php/notice/29"
757 test "it translates ostatus reply_to IDs to external URLs" do
758 incoming = File.read!("test/fixtures/incoming_note_activity.xml")
759 {:ok, [referred_activity]} = OStatus.handle_incoming(incoming)
764 CommonAPI.post(user, %{"status" => "HI!", "in_reply_to_status_id" => referred_activity.id})
766 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
768 assert modified["object"]["inReplyTo"] == "http://gs.example.org:4040/index.php/notice/29"
771 test "it strips internal hashtag data" do
774 {:ok, activity} = CommonAPI.post(user, %{"status" => "#2hu"})
777 "href" => Pleroma.Web.Endpoint.url() <> "/tags/2hu",
782 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
784 assert modified["object"]["tag"] == [expected_tag]
787 test "it strips internal fields" do
790 {:ok, activity} = CommonAPI.post(user, %{"status" => "#2hu :moominmamma:"})
792 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
794 assert length(modified["object"]["tag"]) == 2
796 assert is_nil(modified["object"]["emoji"])
797 assert is_nil(modified["object"]["likes"])
798 assert is_nil(modified["object"]["like_count"])
799 assert is_nil(modified["object"]["announcements"])
800 assert is_nil(modified["object"]["announcement_count"])
801 assert is_nil(modified["object"]["context_id"])
805 describe "user upgrade" do
806 test "it upgrades a user to activitypub" do
809 nickname: "rye@niu.moe",
811 ap_id: "https://niu.moe/users/rye",
812 follower_address: User.ap_followers(%User{nickname: "rye@niu.moe"})
815 user_two = insert(:user, %{following: [user.follower_address]})
817 {:ok, activity} = CommonAPI.post(user, %{"status" => "test"})
818 {:ok, unrelated_activity} = CommonAPI.post(user_two, %{"status" => "test"})
819 assert "http://localhost:4001/users/rye@niu.moe/followers" in activity.recipients
821 user = Repo.get(User, user.id)
822 assert user.info.note_count == 1
824 {:ok, user} = Transmogrifier.upgrade_user_from_ap_id("https://niu.moe/users/rye")
825 assert user.info.ap_enabled
826 assert user.info.note_count == 1
827 assert user.follower_address == "https://niu.moe/users/rye/followers"
829 # Wait for the background task
832 user = Repo.get(User, user.id)
833 assert user.info.note_count == 1
835 activity = Repo.get(Activity, activity.id)
836 assert user.follower_address in activity.recipients
842 "https://cdn.niu.moe/accounts/avatars/000/033/323/original/fd7f8ae0b3ffedc9.jpeg"
851 "https://cdn.niu.moe/accounts/headers/000/033/323/original/850b3448fa5fd477.png"
856 refute "..." in activity.recipients
858 unrelated_activity = Repo.get(Activity, unrelated_activity.id)
859 refute user.follower_address in unrelated_activity.recipients
861 user_two = Repo.get(User, user_two.id)
862 assert user.follower_address in user_two.following
863 refute "..." in user_two.following
867 describe "maybe_retire_websub" do
868 test "it deletes all websub client subscripitions with the user as topic" do
869 subscription = %WebsubClientSubscription{topic: "https://niu.moe/users/rye.atom"}
870 {:ok, ws} = Repo.insert(subscription)
872 subscription = %WebsubClientSubscription{topic: "https://niu.moe/users/pasty.atom"}
873 {:ok, ws2} = Repo.insert(subscription)
875 Transmogrifier.maybe_retire_websub("https://niu.moe/users/rye")
877 refute Repo.get(WebsubClientSubscription, ws.id)
878 assert Repo.get(WebsubClientSubscription, ws2.id)
882 describe "actor rewriting" do
883 test "it fixes the actor URL property to be a proper URI" do
885 "url" => %{"href" => "http://example.com"}
888 rewritten = Transmogrifier.maybe_fix_user_object(data)
889 assert rewritten["url"] == "http://example.com"
893 describe "actor origin containment" do
894 test "it rejects objects with a bogus origin" do
895 {:error, _} = ActivityPub.fetch_object_from_id("https://info.pleroma.site/activity.json")
898 test "it rejects activities which reference objects with bogus origins" do
900 "@context" => "https://www.w3.org/ns/activitystreams",
901 "id" => "http://mastodon.example.org/users/admin/activities/1234",
902 "actor" => "http://mastodon.example.org/users/admin",
903 "to" => ["https://www.w3.org/ns/activitystreams#Public"],
904 "object" => "https://info.pleroma.site/activity.json",
908 :error = Transmogrifier.handle_incoming(data)
911 test "it rejects objects when attributedTo is wrong (variant 1)" do
912 {:error, _} = ActivityPub.fetch_object_from_id("https://info.pleroma.site/activity2.json")
915 test "it rejects activities which reference objects that have an incorrect attribution (variant 1)" do
917 "@context" => "https://www.w3.org/ns/activitystreams",
918 "id" => "http://mastodon.example.org/users/admin/activities/1234",
919 "actor" => "http://mastodon.example.org/users/admin",
920 "to" => ["https://www.w3.org/ns/activitystreams#Public"],
921 "object" => "https://info.pleroma.site/activity2.json",
925 :error = Transmogrifier.handle_incoming(data)
928 test "it rejects objects when attributedTo is wrong (variant 2)" do
929 {:error, _} = ActivityPub.fetch_object_from_id("https://info.pleroma.site/activity3.json")
932 test "it rejects activities which reference objects that have an incorrect attribution (variant 2)" do
934 "@context" => "https://www.w3.org/ns/activitystreams",
935 "id" => "http://mastodon.example.org/users/admin/activities/1234",
936 "actor" => "http://mastodon.example.org/users/admin",
937 "to" => ["https://www.w3.org/ns/activitystreams#Public"],
938 "object" => "https://info.pleroma.site/activity3.json",
942 :error = Transmogrifier.handle_incoming(data)
946 describe "general origin containment" do
947 test "contain_origin_from_id() catches obvious spoofing attempts" do
949 "id" => "http://example.com/~alyssa/activities/1234.json"
953 Transmogrifier.contain_origin_from_id(
954 "http://example.org/~alyssa/activities/1234.json",
959 test "contain_origin_from_id() allows alternate IDs within the same origin domain" do
961 "id" => "http://example.com/~alyssa/activities/1234.json"
965 Transmogrifier.contain_origin_from_id(
966 "http://example.com/~alyssa/activities/1234",
971 test "contain_origin_from_id() allows matching IDs" do
973 "id" => "http://example.com/~alyssa/activities/1234.json"
977 Transmogrifier.contain_origin_from_id(
978 "http://example.com/~alyssa/activities/1234.json",
983 test "users cannot be collided through fake direction spoofing attempts" do
986 nickname: "rye@niu.moe",
988 ap_id: "https://niu.moe/users/rye",
989 follower_address: User.ap_followers(%User{nickname: "rye@niu.moe"})
992 {:error, _} = User.get_or_fetch_by_ap_id("https://n1u.moe/users/rye")
995 test "all objects with fake directions are rejected by the object fetcher" do
997 ActivityPub.fetch_and_contain_remote_object_from_id(
998 "https://info.pleroma.site/activity4.json"