1 defmodule Pleroma.Web.ActivityPub.TransmogrifierTest do
3 alias Pleroma.Web.ActivityPub.Transmogrifier
4 alias Pleroma.Web.ActivityPub.Utils
5 alias Pleroma.Web.ActivityPub.ActivityPub
6 alias Pleroma.Web.OStatus
10 alias Pleroma.Web.Websub.WebsubClientSubscription
12 import Pleroma.Factory
13 alias Pleroma.Web.CommonAPI
16 Tesla.Mock.mock_global(fn env -> apply(HttpRequestMock, :request, [env]) end)
20 describe "handle_incoming" do
21 test "it ignores an incoming notice if we already have it" do
22 activity = insert(:note_activity)
25 File.read!("test/fixtures/mastodon-post-activity.json")
27 |> Map.put("object", activity.data["object"])
29 {:ok, returned_activity} = Transmogrifier.handle_incoming(data)
31 assert activity == returned_activity
34 test "it fetches replied-to activities if we don't have them" do
36 File.read!("test/fixtures/mastodon-post-activity.json")
41 |> Map.put("inReplyTo", "https://shitposter.club/notice/2827873")
45 |> Map.put("object", object)
47 {:ok, returned_activity} = Transmogrifier.handle_incoming(data)
50 Activity.get_create_activity_by_object_ap_id(
51 "tag:shitposter.club,2017-05-05:noticeId=2827873:objectType=comment"
54 assert returned_activity.data["object"]["inReplyToAtomUri"] ==
55 "https://shitposter.club/notice/2827873"
57 assert returned_activity.data["object"]["inReplyToStatusId"] == activity.id
60 test "it works for incoming notices" do
61 data = File.read!("test/fixtures/mastodon-post-activity.json") |> Poison.decode!()
63 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
66 "http://mastodon.example.org/users/admin/statuses/99512778738411822/activity"
68 assert data["context"] ==
69 "tag:mastodon.example.org,2018-02-12:objectId=20:objectType=Conversation"
71 assert data["to"] == ["https://www.w3.org/ns/activitystreams#Public"]
73 assert data["cc"] == [
74 "http://mastodon.example.org/users/admin/followers",
75 "http://localtesting.pleroma.lol/users/lain"
78 assert data["actor"] == "http://mastodon.example.org/users/admin"
80 object = data["object"]
81 assert object["id"] == "http://mastodon.example.org/users/admin/statuses/99512778738411822"
83 assert object["to"] == ["https://www.w3.org/ns/activitystreams#Public"]
85 assert object["cc"] == [
86 "http://mastodon.example.org/users/admin/followers",
87 "http://localtesting.pleroma.lol/users/lain"
90 assert object["actor"] == "http://mastodon.example.org/users/admin"
91 assert object["attributedTo"] == "http://mastodon.example.org/users/admin"
93 assert object["context"] ==
94 "tag:mastodon.example.org,2018-02-12:objectId=20:objectType=Conversation"
96 assert object["sensitive"] == true
98 user = User.get_by_ap_id(object["actor"])
100 assert user.info.note_count == 1
103 test "it works for incoming notices with hashtags" do
104 data = File.read!("test/fixtures/mastodon-post-activity-hashtag.json") |> Poison.decode!()
106 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
107 assert Enum.at(data["object"]["tag"], 2) == "moo"
110 test "it works for incoming notices with contentMap" do
112 File.read!("test/fixtures/mastodon-post-activity-contentmap.json") |> Poison.decode!()
114 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
116 assert data["object"]["content"] ==
117 "<p><span class=\"h-card\"><a href=\"http://localtesting.pleroma.lol/users/lain\" class=\"u-url mention\">@<span>lain</span></a></span></p>"
120 test "it works for incoming notices with to/cc not being an array (kroeg)" do
121 data = File.read!("test/fixtures/kroeg-post-activity.json") |> Poison.decode!()
123 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
125 assert data["object"]["content"] ==
126 "<p>henlo from my Psion netBook</p><p>message sent from my Psion netBook</p>"
129 test "it works for incoming announces with actor being inlined (kroeg)" do
130 data = File.read!("test/fixtures/kroeg-announce-with-inline-actor.json") |> Poison.decode!()
132 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
134 assert data["actor"] == "https://puckipedia.com/"
137 test "it works for incoming notices with tag not being an array (kroeg)" do
138 data = File.read!("test/fixtures/kroeg-array-less-emoji.json") |> Poison.decode!()
140 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
142 assert data["object"]["emoji"] == %{
143 "icon_e_smile" => "https://puckipedia.com/forum/images/smilies/icon_e_smile.png"
146 data = File.read!("test/fixtures/kroeg-array-less-hashtag.json") |> Poison.decode!()
148 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
150 assert "test" in data["object"]["tag"]
153 test "it works for incoming notices with url not being a string (prismo)" do
154 data = File.read!("test/fixtures/prismo-url-map.json") |> Poison.decode!()
156 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
158 assert data["object"]["url"] == "https://prismo.news/posts/83"
161 test "it works for incoming follow requests" do
165 File.read!("test/fixtures/mastodon-follow-activity.json")
167 |> Map.put("object", user.ap_id)
169 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
171 assert data["actor"] == "http://mastodon.example.org/users/admin"
172 assert data["type"] == "Follow"
173 assert data["id"] == "http://mastodon.example.org/users/admin#follows/2"
174 assert User.following?(User.get_by_ap_id(data["actor"]), user)
177 test "it works for incoming follow requests from hubzilla" do
181 File.read!("test/fixtures/hubzilla-follow-activity.json")
183 |> Map.put("object", user.ap_id)
184 |> Utils.normalize_params()
186 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
188 assert data["actor"] == "https://hubzilla.example.org/channel/kaniini"
189 assert data["type"] == "Follow"
190 assert data["id"] == "https://hubzilla.example.org/channel/kaniini#follows/2"
191 assert User.following?(User.get_by_ap_id(data["actor"]), user)
194 test "it works for incoming likes" do
196 {:ok, activity} = CommonAPI.post(user, %{"status" => "hello"})
199 File.read!("test/fixtures/mastodon-like.json")
201 |> Map.put("object", activity.data["object"]["id"])
203 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
205 assert data["actor"] == "http://mastodon.example.org/users/admin"
206 assert data["type"] == "Like"
207 assert data["id"] == "http://mastodon.example.org/users/admin#likes/2"
208 assert data["object"] == activity.data["object"]["id"]
211 test "it returns an error for incoming unlikes wihout a like activity" do
213 {:ok, activity} = CommonAPI.post(user, %{"status" => "leave a like pls"})
216 File.read!("test/fixtures/mastodon-undo-like.json")
218 |> Map.put("object", activity.data["object"]["id"])
220 assert Transmogrifier.handle_incoming(data) == :error
223 test "it works for incoming unlikes with an existing like activity" do
225 {:ok, activity} = CommonAPI.post(user, %{"status" => "leave a like pls"})
228 File.read!("test/fixtures/mastodon-like.json")
230 |> Map.put("object", activity.data["object"]["id"])
232 {:ok, %Activity{data: like_data, local: false}} = Transmogrifier.handle_incoming(like_data)
235 File.read!("test/fixtures/mastodon-undo-like.json")
237 |> Map.put("object", like_data)
238 |> Map.put("actor", like_data["actor"])
240 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
242 assert data["actor"] == "http://mastodon.example.org/users/admin"
243 assert data["type"] == "Undo"
244 assert data["id"] == "http://mastodon.example.org/users/admin#likes/2/undo"
245 assert data["object"]["id"] == "http://mastodon.example.org/users/admin#likes/2"
248 test "it works for incoming announces" do
249 data = File.read!("test/fixtures/mastodon-announce.json") |> Poison.decode!()
251 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
253 assert data["actor"] == "http://mastodon.example.org/users/admin"
254 assert data["type"] == "Announce"
257 "http://mastodon.example.org/users/admin/statuses/99542391527669785/activity"
259 assert data["object"] ==
260 "http://mastodon.example.org/users/admin/statuses/99541947525187367"
262 assert Activity.get_create_activity_by_object_ap_id(data["object"])
265 test "it works for incoming announces with an existing activity" do
267 {:ok, activity} = CommonAPI.post(user, %{"status" => "hey"})
270 File.read!("test/fixtures/mastodon-announce.json")
272 |> Map.put("object", activity.data["object"]["id"])
274 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
276 assert data["actor"] == "http://mastodon.example.org/users/admin"
277 assert data["type"] == "Announce"
280 "http://mastodon.example.org/users/admin/statuses/99542391527669785/activity"
282 assert data["object"] == activity.data["object"]["id"]
284 assert Activity.get_create_activity_by_object_ap_id(data["object"]).id == activity.id
287 test "it works for incoming update activities" do
288 data = File.read!("test/fixtures/mastodon-post-activity.json") |> Poison.decode!()
290 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
291 update_data = File.read!("test/fixtures/mastodon-update.json") |> Poison.decode!()
294 update_data["object"]
295 |> Map.put("actor", data["actor"])
296 |> Map.put("id", data["actor"])
300 |> Map.put("actor", data["actor"])
301 |> Map.put("object", object)
303 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(update_data)
305 user = User.get_cached_by_ap_id(data["actor"])
306 assert user.name == "gargle"
308 assert user.avatar["url"] == [
311 "https://cd.niu.moe/accounts/avatars/000/033/323/original/fd7f8ae0b3ffedc9.jpeg"
315 assert user.info.banner["url"] == [
318 "https://cd.niu.moe/accounts/headers/000/033/323/original/850b3448fa5fd477.png"
322 assert user.bio == "<p>Some bio</p>"
325 test "it works for incoming update activities which lock the account" do
326 data = File.read!("test/fixtures/mastodon-post-activity.json") |> Poison.decode!()
328 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
329 update_data = File.read!("test/fixtures/mastodon-update.json") |> Poison.decode!()
332 update_data["object"]
333 |> Map.put("actor", data["actor"])
334 |> Map.put("id", data["actor"])
335 |> Map.put("manuallyApprovesFollowers", true)
339 |> Map.put("actor", data["actor"])
340 |> Map.put("object", object)
342 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(update_data)
344 user = User.get_cached_by_ap_id(data["actor"])
345 assert user.info.locked == true
348 test "it works for incoming deletes" do
349 activity = insert(:note_activity)
352 File.read!("test/fixtures/mastodon-delete.json")
357 |> Map.put("id", activity.data["object"]["id"])
361 |> Map.put("object", object)
362 |> Map.put("actor", activity.data["actor"])
364 {:ok, %Activity{local: false}} = Transmogrifier.handle_incoming(data)
366 refute Repo.get(Activity, activity.id)
369 test "it fails for incoming deletes with spoofed origin" do
370 activity = insert(:note_activity)
373 File.read!("test/fixtures/mastodon-delete.json")
378 |> Map.put("id", activity.data["object"]["id"])
382 |> Map.put("object", object)
384 :error = Transmogrifier.handle_incoming(data)
386 assert Repo.get(Activity, activity.id)
389 test "it works for incoming unannounces with an existing notice" do
391 {:ok, activity} = CommonAPI.post(user, %{"status" => "hey"})
394 File.read!("test/fixtures/mastodon-announce.json")
396 |> Map.put("object", activity.data["object"]["id"])
398 {:ok, %Activity{data: announce_data, local: false}} =
399 Transmogrifier.handle_incoming(announce_data)
402 File.read!("test/fixtures/mastodon-undo-announce.json")
404 |> Map.put("object", announce_data)
405 |> Map.put("actor", announce_data["actor"])
407 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
409 assert data["type"] == "Undo"
410 assert data["object"]["type"] == "Announce"
411 assert data["object"]["object"] == activity.data["object"]["id"]
413 assert data["object"]["id"] ==
414 "http://mastodon.example.org/users/admin/statuses/99542391527669785/activity"
417 test "it works for incomming unfollows with an existing follow" do
421 File.read!("test/fixtures/mastodon-follow-activity.json")
423 |> Map.put("object", user.ap_id)
425 {:ok, %Activity{data: _, local: false}} = Transmogrifier.handle_incoming(follow_data)
428 File.read!("test/fixtures/mastodon-unfollow-activity.json")
430 |> Map.put("object", follow_data)
432 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
434 assert data["type"] == "Undo"
435 assert data["object"]["type"] == "Follow"
436 assert data["object"]["object"] == user.ap_id
437 assert data["actor"] == "http://mastodon.example.org/users/admin"
439 refute User.following?(User.get_by_ap_id(data["actor"]), user)
442 test "it works for incoming blocks" do
446 File.read!("test/fixtures/mastodon-block-activity.json")
448 |> Map.put("object", user.ap_id)
450 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
452 assert data["type"] == "Block"
453 assert data["object"] == user.ap_id
454 assert data["actor"] == "http://mastodon.example.org/users/admin"
456 blocker = User.get_by_ap_id(data["actor"])
458 assert User.blocks?(blocker, user)
461 test "incoming blocks successfully tear down any follow relationship" do
462 blocker = insert(:user)
463 blocked = insert(:user)
466 File.read!("test/fixtures/mastodon-block-activity.json")
468 |> Map.put("object", blocked.ap_id)
469 |> Map.put("actor", blocker.ap_id)
471 {:ok, blocker} = User.follow(blocker, blocked)
472 {:ok, blocked} = User.follow(blocked, blocker)
474 assert User.following?(blocker, blocked)
475 assert User.following?(blocked, blocker)
477 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
479 assert data["type"] == "Block"
480 assert data["object"] == blocked.ap_id
481 assert data["actor"] == blocker.ap_id
483 blocker = User.get_by_ap_id(data["actor"])
484 blocked = User.get_by_ap_id(data["object"])
486 assert User.blocks?(blocker, blocked)
488 refute User.following?(blocker, blocked)
489 refute User.following?(blocked, blocker)
492 test "it works for incoming unblocks with an existing block" do
496 File.read!("test/fixtures/mastodon-block-activity.json")
498 |> Map.put("object", user.ap_id)
500 {:ok, %Activity{data: _, local: false}} = Transmogrifier.handle_incoming(block_data)
503 File.read!("test/fixtures/mastodon-unblock-activity.json")
505 |> Map.put("object", block_data)
507 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
508 assert data["type"] == "Undo"
509 assert data["object"]["type"] == "Block"
510 assert data["object"]["object"] == user.ap_id
511 assert data["actor"] == "http://mastodon.example.org/users/admin"
513 blocker = User.get_by_ap_id(data["actor"])
515 refute User.blocks?(blocker, user)
518 test "it works for incoming accepts which were pre-accepted" do
519 follower = insert(:user)
520 followed = insert(:user)
522 {:ok, follower} = User.follow(follower, followed)
523 assert User.following?(follower, followed) == true
525 {:ok, follow_activity} = ActivityPub.follow(follower, followed)
528 File.read!("test/fixtures/mastodon-accept-activity.json")
530 |> Map.put("actor", followed.ap_id)
533 accept_data["object"]
534 |> Map.put("actor", follower.ap_id)
535 |> Map.put("id", follow_activity.data["id"])
537 accept_data = Map.put(accept_data, "object", object)
539 {:ok, activity} = Transmogrifier.handle_incoming(accept_data)
540 refute activity.local
542 assert activity.data["object"] == follow_activity.data["id"]
544 follower = Repo.get(User, follower.id)
546 assert User.following?(follower, followed) == true
549 test "it works for incoming accepts which were orphaned" do
550 follower = insert(:user)
551 followed = insert(:user, %{info: %User.Info{locked: true}})
553 {:ok, follow_activity} = ActivityPub.follow(follower, followed)
556 File.read!("test/fixtures/mastodon-accept-activity.json")
558 |> Map.put("actor", followed.ap_id)
561 Map.put(accept_data, "object", Map.put(accept_data["object"], "actor", follower.ap_id))
563 {:ok, activity} = Transmogrifier.handle_incoming(accept_data)
564 assert activity.data["object"] == follow_activity.data["id"]
566 follower = Repo.get(User, follower.id)
568 assert User.following?(follower, followed) == true
571 test "it works for incoming accepts which are referenced by IRI only" do
572 follower = insert(:user)
573 followed = insert(:user, %{info: %User.Info{locked: true}})
575 {:ok, follow_activity} = ActivityPub.follow(follower, followed)
578 File.read!("test/fixtures/mastodon-accept-activity.json")
580 |> Map.put("actor", followed.ap_id)
581 |> Map.put("object", follow_activity.data["id"])
583 {:ok, activity} = Transmogrifier.handle_incoming(accept_data)
584 assert activity.data["object"] == follow_activity.data["id"]
586 follower = Repo.get(User, follower.id)
588 assert User.following?(follower, followed) == true
591 test "it fails for incoming accepts which cannot be correlated" do
592 follower = insert(:user)
593 followed = insert(:user, %{info: %User.Info{locked: true}})
596 File.read!("test/fixtures/mastodon-accept-activity.json")
598 |> Map.put("actor", followed.ap_id)
601 Map.put(accept_data, "object", Map.put(accept_data["object"], "actor", follower.ap_id))
603 :error = Transmogrifier.handle_incoming(accept_data)
605 follower = Repo.get(User, follower.id)
607 refute User.following?(follower, followed) == true
610 test "it fails for incoming rejects which cannot be correlated" do
611 follower = insert(:user)
612 followed = insert(:user, %{info: %User.Info{locked: true}})
615 File.read!("test/fixtures/mastodon-reject-activity.json")
617 |> Map.put("actor", followed.ap_id)
620 Map.put(accept_data, "object", Map.put(accept_data["object"], "actor", follower.ap_id))
622 :error = Transmogrifier.handle_incoming(accept_data)
624 follower = Repo.get(User, follower.id)
626 refute User.following?(follower, followed) == true
629 test "it works for incoming rejects which are orphaned" do
630 follower = insert(:user)
631 followed = insert(:user, %{info: %User.Info{locked: true}})
633 {:ok, follower} = User.follow(follower, followed)
634 {:ok, _follow_activity} = ActivityPub.follow(follower, followed)
636 assert User.following?(follower, followed) == true
639 File.read!("test/fixtures/mastodon-reject-activity.json")
641 |> Map.put("actor", followed.ap_id)
644 Map.put(reject_data, "object", Map.put(reject_data["object"], "actor", follower.ap_id))
646 {:ok, activity} = Transmogrifier.handle_incoming(reject_data)
647 refute activity.local
649 follower = Repo.get(User, follower.id)
651 assert User.following?(follower, followed) == false
654 test "it works for incoming rejects which are referenced by IRI only" do
655 follower = insert(:user)
656 followed = insert(:user, %{info: %User.Info{locked: true}})
658 {:ok, follower} = User.follow(follower, followed)
659 {:ok, follow_activity} = ActivityPub.follow(follower, followed)
661 assert User.following?(follower, followed) == true
664 File.read!("test/fixtures/mastodon-reject-activity.json")
666 |> Map.put("actor", followed.ap_id)
667 |> Map.put("object", follow_activity.data["id"])
669 {:ok, %Activity{data: _}} = Transmogrifier.handle_incoming(reject_data)
671 follower = Repo.get(User, follower.id)
673 assert User.following?(follower, followed) == false
676 test "it rejects activities without a valid ID" do
680 File.read!("test/fixtures/mastodon-follow-activity.json")
682 |> Map.put("object", user.ap_id)
685 :error = Transmogrifier.handle_incoming(data)
689 describe "prepare outgoing" do
690 test "it turns mentions into tags" do
692 other_user = insert(:user)
695 CommonAPI.post(user, %{"status" => "hey, @#{other_user.nickname}, how are ya? #2hu"})
697 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
698 object = modified["object"]
700 expected_mention = %{
701 "href" => other_user.ap_id,
702 "name" => "@#{other_user.nickname}",
707 "href" => Pleroma.Web.Endpoint.url() <> "/tags/2hu",
712 assert Enum.member?(object["tag"], expected_tag)
713 assert Enum.member?(object["tag"], expected_mention)
716 test "it adds the sensitive property" do
719 {:ok, activity} = CommonAPI.post(user, %{"status" => "#nsfw hey"})
720 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
722 assert modified["object"]["sensitive"]
725 test "it adds the json-ld context and the conversation property" do
728 {:ok, activity} = CommonAPI.post(user, %{"status" => "hey"})
729 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
731 assert modified["@context"] ==
732 Pleroma.Web.ActivityPub.Utils.make_json_ld_header()["@context"]
734 assert modified["object"]["conversation"] == modified["context"]
737 test "it sets the 'attributedTo' property to the actor of the object if it doesn't have one" do
740 {:ok, activity} = CommonAPI.post(user, %{"status" => "hey"})
741 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
743 assert modified["object"]["actor"] == modified["object"]["attributedTo"]
746 test "it translates ostatus IDs to external URLs" do
747 incoming = File.read!("test/fixtures/incoming_note_activity.xml")
748 {:ok, [referent_activity]} = OStatus.handle_incoming(incoming)
752 {:ok, activity, _} = CommonAPI.favorite(referent_activity.id, user)
753 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
755 assert modified["object"] == "http://gs.example.org:4040/index.php/notice/29"
758 test "it translates ostatus reply_to IDs to external URLs" do
759 incoming = File.read!("test/fixtures/incoming_note_activity.xml")
760 {:ok, [referred_activity]} = OStatus.handle_incoming(incoming)
765 CommonAPI.post(user, %{"status" => "HI!", "in_reply_to_status_id" => referred_activity.id})
767 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
769 assert modified["object"]["inReplyTo"] == "http://gs.example.org:4040/index.php/notice/29"
772 test "it strips internal hashtag data" do
775 {:ok, activity} = CommonAPI.post(user, %{"status" => "#2hu"})
778 "href" => Pleroma.Web.Endpoint.url() <> "/tags/2hu",
783 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
785 assert modified["object"]["tag"] == [expected_tag]
788 test "it strips internal fields" do
791 {:ok, activity} = CommonAPI.post(user, %{"status" => "#2hu :moominmamma:"})
793 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
795 assert length(modified["object"]["tag"]) == 2
797 assert is_nil(modified["object"]["emoji"])
798 assert is_nil(modified["object"]["likes"])
799 assert is_nil(modified["object"]["like_count"])
800 assert is_nil(modified["object"]["announcements"])
801 assert is_nil(modified["object"]["announcement_count"])
802 assert is_nil(modified["object"]["context_id"])
806 describe "user upgrade" do
807 test "it upgrades a user to activitypub" do
810 nickname: "rye@niu.moe",
812 ap_id: "https://niu.moe/users/rye",
813 follower_address: User.ap_followers(%User{nickname: "rye@niu.moe"})
816 user_two = insert(:user, %{following: [user.follower_address]})
818 {:ok, activity} = CommonAPI.post(user, %{"status" => "test"})
819 {:ok, unrelated_activity} = CommonAPI.post(user_two, %{"status" => "test"})
820 assert "http://localhost:4001/users/rye@niu.moe/followers" in activity.recipients
822 user = Repo.get(User, user.id)
823 assert user.info.note_count == 1
825 {:ok, user} = Transmogrifier.upgrade_user_from_ap_id("https://niu.moe/users/rye")
826 assert user.info.ap_enabled
827 assert user.info.note_count == 1
828 assert user.follower_address == "https://niu.moe/users/rye/followers"
830 # Wait for the background task
833 user = Repo.get(User, user.id)
834 assert user.info.note_count == 1
836 activity = Repo.get(Activity, activity.id)
837 assert user.follower_address in activity.recipients
843 "https://cdn.niu.moe/accounts/avatars/000/033/323/original/fd7f8ae0b3ffedc9.jpeg"
852 "https://cdn.niu.moe/accounts/headers/000/033/323/original/850b3448fa5fd477.png"
857 refute "..." in activity.recipients
859 unrelated_activity = Repo.get(Activity, unrelated_activity.id)
860 refute user.follower_address in unrelated_activity.recipients
862 user_two = Repo.get(User, user_two.id)
863 assert user.follower_address in user_two.following
864 refute "..." in user_two.following
868 describe "maybe_retire_websub" do
869 test "it deletes all websub client subscripitions with the user as topic" do
870 subscription = %WebsubClientSubscription{topic: "https://niu.moe/users/rye.atom"}
871 {:ok, ws} = Repo.insert(subscription)
873 subscription = %WebsubClientSubscription{topic: "https://niu.moe/users/pasty.atom"}
874 {:ok, ws2} = Repo.insert(subscription)
876 Transmogrifier.maybe_retire_websub("https://niu.moe/users/rye")
878 refute Repo.get(WebsubClientSubscription, ws.id)
879 assert Repo.get(WebsubClientSubscription, ws2.id)
883 describe "actor rewriting" do
884 test "it fixes the actor URL property to be a proper URI" do
886 "url" => %{"href" => "http://example.com"}
889 rewritten = Transmogrifier.maybe_fix_user_object(data)
890 assert rewritten["url"] == "http://example.com"
894 describe "actor origin containment" do
895 test "it rejects objects with a bogus origin" do
896 {:error, _} = ActivityPub.fetch_object_from_id("https://info.pleroma.site/activity.json")
899 test "it rejects activities which reference objects with bogus origins" do
901 "@context" => "https://www.w3.org/ns/activitystreams",
902 "id" => "http://mastodon.example.org/users/admin/activities/1234",
903 "actor" => "http://mastodon.example.org/users/admin",
904 "to" => ["https://www.w3.org/ns/activitystreams#Public"],
905 "object" => "https://info.pleroma.site/activity.json",
909 :error = Transmogrifier.handle_incoming(data)
912 test "it rejects objects when attributedTo is wrong (variant 1)" do
913 {:error, _} = ActivityPub.fetch_object_from_id("https://info.pleroma.site/activity2.json")
916 test "it rejects activities which reference objects that have an incorrect attribution (variant 1)" do
918 "@context" => "https://www.w3.org/ns/activitystreams",
919 "id" => "http://mastodon.example.org/users/admin/activities/1234",
920 "actor" => "http://mastodon.example.org/users/admin",
921 "to" => ["https://www.w3.org/ns/activitystreams#Public"],
922 "object" => "https://info.pleroma.site/activity2.json",
926 :error = Transmogrifier.handle_incoming(data)
929 test "it rejects objects when attributedTo is wrong (variant 2)" do
930 {:error, _} = ActivityPub.fetch_object_from_id("https://info.pleroma.site/activity3.json")
933 test "it rejects activities which reference objects that have an incorrect attribution (variant 2)" do
935 "@context" => "https://www.w3.org/ns/activitystreams",
936 "id" => "http://mastodon.example.org/users/admin/activities/1234",
937 "actor" => "http://mastodon.example.org/users/admin",
938 "to" => ["https://www.w3.org/ns/activitystreams#Public"],
939 "object" => "https://info.pleroma.site/activity3.json",
943 :error = Transmogrifier.handle_incoming(data)
947 describe "general origin containment" do
948 test "contain_origin_from_id() catches obvious spoofing attempts" do
950 "id" => "http://example.com/~alyssa/activities/1234.json"
954 Transmogrifier.contain_origin_from_id(
955 "http://example.org/~alyssa/activities/1234.json",
960 test "contain_origin_from_id() allows alternate IDs within the same origin domain" do
962 "id" => "http://example.com/~alyssa/activities/1234.json"
966 Transmogrifier.contain_origin_from_id(
967 "http://example.com/~alyssa/activities/1234",
972 test "contain_origin_from_id() allows matching IDs" do
974 "id" => "http://example.com/~alyssa/activities/1234.json"
978 Transmogrifier.contain_origin_from_id(
979 "http://example.com/~alyssa/activities/1234.json",
984 test "users cannot be collided through fake direction spoofing attempts" do
987 nickname: "rye@niu.moe",
989 ap_id: "https://niu.moe/users/rye",
990 follower_address: User.ap_followers(%User{nickname: "rye@niu.moe"})
993 {:error, _} = User.get_or_fetch_by_ap_id("https://n1u.moe/users/rye")
996 test "all objects with fake directions are rejected by the object fetcher" do
998 ActivityPub.fetch_and_contain_remote_object_from_id(
999 "https://info.pleroma.site/activity4.json"