1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2020 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
5 defmodule Pleroma.Web.MastodonAPI.TimelineControllerTest do
6 use Pleroma.Web.ConnCase
13 alias Pleroma.Web.CommonAPI
16 mock(fn env -> apply(HttpRequestMock, :request, [env]) end)
21 setup do: oauth_access(["read:statuses"])
23 test "the home timeline", %{user: user, conn: conn} do
24 following = insert(:user)
26 {:ok, _activity} = CommonAPI.post(following, %{"status" => "test"})
28 ret_conn = get(conn, "/api/v1/timelines/home")
30 assert Enum.empty?(json_response(ret_conn, :ok))
32 {:ok, _user} = User.follow(user, following)
34 conn = get(conn, "/api/v1/timelines/home")
36 assert [%{"content" => "test"}] = json_response(conn, :ok)
39 test "the home timeline when the direct messages are excluded", %{user: user, conn: conn} do
40 {:ok, public_activity} = CommonAPI.post(user, %{"status" => ".", "visibility" => "public"})
41 {:ok, direct_activity} = CommonAPI.post(user, %{"status" => ".", "visibility" => "direct"})
43 {:ok, unlisted_activity} =
44 CommonAPI.post(user, %{"status" => ".", "visibility" => "unlisted"})
46 {:ok, private_activity} =
47 CommonAPI.post(user, %{"status" => ".", "visibility" => "private"})
49 conn = get(conn, "/api/v1/timelines/home", %{"exclude_visibilities" => ["direct"]})
51 assert status_ids = json_response(conn, :ok) |> Enum.map(& &1["id"])
52 assert public_activity.id in status_ids
53 assert unlisted_activity.id in status_ids
54 assert private_activity.id in status_ids
55 refute direct_activity.id in status_ids
60 @tag capture_log: true
61 test "the public timeline", %{conn: conn} do
62 following = insert(:user)
64 {:ok, _activity} = CommonAPI.post(following, %{"status" => "test"})
66 _activity = insert(:note_activity, local: false)
68 conn = get(conn, "/api/v1/timelines/public", %{"local" => "False"})
70 assert length(json_response(conn, :ok)) == 2
72 conn = get(build_conn(), "/api/v1/timelines/public", %{"local" => "True"})
74 assert [%{"content" => "test"}] = json_response(conn, :ok)
76 conn = get(build_conn(), "/api/v1/timelines/public", %{"local" => "1"})
78 assert [%{"content" => "test"}] = json_response(conn, :ok)
81 test "the public timeline includes only public statuses for an authenticated user" do
82 %{user: user, conn: conn} = oauth_access(["read:statuses"])
84 {:ok, _activity} = CommonAPI.post(user, %{"status" => "test"})
85 {:ok, _activity} = CommonAPI.post(user, %{"status" => "test", "visibility" => "private"})
86 {:ok, _activity} = CommonAPI.post(user, %{"status" => "test", "visibility" => "unlisted"})
87 {:ok, _activity} = CommonAPI.post(user, %{"status" => "test", "visibility" => "direct"})
89 res_conn = get(conn, "/api/v1/timelines/public")
90 assert length(json_response(res_conn, 200)) == 1
94 defp local_and_remote_activities do
95 insert(:note_activity)
96 insert(:note_activity, local: false)
100 describe "public with restrict unauthenticated timeline for local and federated timelines" do
101 setup do: local_and_remote_activities()
103 setup do: clear_config([:restrict_unauthenticated, :timelines, :local], true)
105 setup do: clear_config([:restrict_unauthenticated, :timelines, :federated], true)
107 test "if user is unauthenticated", %{conn: conn} do
108 res_conn = get(conn, "/api/v1/timelines/public", %{"local" => "true"})
110 assert json_response(res_conn, :unauthorized) == %{
111 "error" => "authorization required for timeline view"
114 res_conn = get(conn, "/api/v1/timelines/public", %{"local" => "false"})
116 assert json_response(res_conn, :unauthorized) == %{
117 "error" => "authorization required for timeline view"
121 test "if user is authenticated" do
122 %{conn: conn} = oauth_access(["read:statuses"])
124 res_conn = get(conn, "/api/v1/timelines/public", %{"local" => "true"})
125 assert length(json_response(res_conn, 200)) == 1
127 res_conn = get(conn, "/api/v1/timelines/public", %{"local" => "false"})
128 assert length(json_response(res_conn, 200)) == 2
132 describe "public with restrict unauthenticated timeline for local" do
133 setup do: local_and_remote_activities()
135 setup do: clear_config([:restrict_unauthenticated, :timelines, :local], true)
137 test "if user is unauthenticated", %{conn: conn} do
138 res_conn = get(conn, "/api/v1/timelines/public", %{"local" => "true"})
140 assert json_response(res_conn, :unauthorized) == %{
141 "error" => "authorization required for timeline view"
144 res_conn = get(conn, "/api/v1/timelines/public", %{"local" => "false"})
145 assert length(json_response(res_conn, 200)) == 2
148 test "if user is authenticated", %{conn: _conn} do
149 %{conn: conn} = oauth_access(["read:statuses"])
151 res_conn = get(conn, "/api/v1/timelines/public", %{"local" => "true"})
152 assert length(json_response(res_conn, 200)) == 1
154 res_conn = get(conn, "/api/v1/timelines/public", %{"local" => "false"})
155 assert length(json_response(res_conn, 200)) == 2
159 describe "public with restrict unauthenticated timeline for remote" do
160 setup do: local_and_remote_activities()
162 setup do: clear_config([:restrict_unauthenticated, :timelines, :federated], true)
164 test "if user is unauthenticated", %{conn: conn} do
165 res_conn = get(conn, "/api/v1/timelines/public", %{"local" => "true"})
166 assert length(json_response(res_conn, 200)) == 1
168 res_conn = get(conn, "/api/v1/timelines/public", %{"local" => "false"})
170 assert json_response(res_conn, :unauthorized) == %{
171 "error" => "authorization required for timeline view"
175 test "if user is authenticated", %{conn: _conn} do
176 %{conn: conn} = oauth_access(["read:statuses"])
178 res_conn = get(conn, "/api/v1/timelines/public", %{"local" => "true"})
179 assert length(json_response(res_conn, 200)) == 1
181 res_conn = get(conn, "/api/v1/timelines/public", %{"local" => "false"})
182 assert length(json_response(res_conn, 200)) == 2
187 test "direct timeline", %{conn: conn} do
188 user_one = insert(:user)
189 user_two = insert(:user)
191 {:ok, user_two} = User.follow(user_two, user_one)
194 CommonAPI.post(user_one, %{
195 "status" => "Hi @#{user_two.nickname}!",
196 "visibility" => "direct"
199 {:ok, _follower_only} =
200 CommonAPI.post(user_one, %{
201 "status" => "Hi @#{user_two.nickname}!",
202 "visibility" => "private"
207 |> assign(:user, user_two)
208 |> assign(:token, insert(:oauth_token, user: user_two, scopes: ["read:statuses"]))
210 # Only direct should be visible here
211 res_conn = get(conn_user_two, "api/v1/timelines/direct")
213 [status] = json_response(res_conn, :ok)
215 assert %{"visibility" => "direct"} = status
216 assert status["url"] != direct.data["id"]
218 # User should be able to see their own direct message
221 |> assign(:user, user_one)
222 |> assign(:token, insert(:oauth_token, user: user_one, scopes: ["read:statuses"]))
223 |> get("api/v1/timelines/direct")
225 [status] = json_response(res_conn, :ok)
227 assert %{"visibility" => "direct"} = status
229 # Both should be visible here
230 res_conn = get(conn_user_two, "api/v1/timelines/home")
232 [_s1, _s2] = json_response(res_conn, :ok)
235 Enum.each(1..20, fn _ ->
237 CommonAPI.post(user_one, %{
238 "status" => "Hi @#{user_two.nickname}!",
239 "visibility" => "direct"
243 res_conn = get(conn_user_two, "api/v1/timelines/direct")
245 statuses = json_response(res_conn, :ok)
246 assert length(statuses) == 20
249 get(conn_user_two, "api/v1/timelines/direct", %{max_id: List.last(statuses)["id"]})
251 [status] = json_response(res_conn, :ok)
253 assert status["url"] != direct.data["id"]
256 test "doesn't include DMs from blocked users" do
257 %{user: blocker, conn: conn} = oauth_access(["read:statuses"])
258 blocked = insert(:user)
259 other_user = insert(:user)
260 {:ok, _user_relationship} = User.block(blocker, blocked)
262 {:ok, _blocked_direct} =
263 CommonAPI.post(blocked, %{
264 "status" => "Hi @#{blocker.nickname}!",
265 "visibility" => "direct"
269 CommonAPI.post(other_user, %{
270 "status" => "Hi @#{blocker.nickname}!",
271 "visibility" => "direct"
274 res_conn = get(conn, "api/v1/timelines/direct")
276 [status] = json_response(res_conn, :ok)
277 assert status["id"] == direct.id
282 setup do: oauth_access(["read:lists"])
284 test "list timeline", %{user: user, conn: conn} do
285 other_user = insert(:user)
286 {:ok, _activity_one} = CommonAPI.post(user, %{"status" => "Marisa is cute."})
287 {:ok, activity_two} = CommonAPI.post(other_user, %{"status" => "Marisa is cute."})
288 {:ok, list} = Pleroma.List.create("name", user)
289 {:ok, list} = Pleroma.List.follow(list, other_user)
291 conn = get(conn, "/api/v1/timelines/list/#{list.id}")
293 assert [%{"id" => id}] = json_response(conn, :ok)
295 assert id == to_string(activity_two.id)
298 test "list timeline does not leak non-public statuses for unfollowed users", %{
302 other_user = insert(:user)
303 {:ok, activity_one} = CommonAPI.post(other_user, %{"status" => "Marisa is cute."})
305 {:ok, _activity_two} =
306 CommonAPI.post(other_user, %{
307 "status" => "Marisa is cute.",
308 "visibility" => "private"
311 {:ok, list} = Pleroma.List.create("name", user)
312 {:ok, list} = Pleroma.List.follow(list, other_user)
314 conn = get(conn, "/api/v1/timelines/list/#{list.id}")
316 assert [%{"id" => id}] = json_response(conn, :ok)
318 assert id == to_string(activity_one.id)
322 describe "hashtag" do
323 setup do: oauth_access(["n/a"])
325 @tag capture_log: true
326 test "hashtag timeline", %{conn: conn} do
327 following = insert(:user)
329 {:ok, activity} = CommonAPI.post(following, %{"status" => "test #2hu"})
331 nconn = get(conn, "/api/v1/timelines/tag/2hu")
333 assert [%{"id" => id}] = json_response(nconn, :ok)
335 assert id == to_string(activity.id)
337 # works for different capitalization too
338 nconn = get(conn, "/api/v1/timelines/tag/2HU")
340 assert [%{"id" => id}] = json_response(nconn, :ok)
342 assert id == to_string(activity.id)
345 test "multi-hashtag timeline", %{conn: conn} do
348 {:ok, activity_test} = CommonAPI.post(user, %{"status" => "#test"})
349 {:ok, activity_test1} = CommonAPI.post(user, %{"status" => "#test #test1"})
350 {:ok, activity_none} = CommonAPI.post(user, %{"status" => "#test #none"})
352 any_test = get(conn, "/api/v1/timelines/tag/test", %{"any" => ["test1"]})
354 [status_none, status_test1, status_test] = json_response(any_test, :ok)
356 assert to_string(activity_test.id) == status_test["id"]
357 assert to_string(activity_test1.id) == status_test1["id"]
358 assert to_string(activity_none.id) == status_none["id"]
361 get(conn, "/api/v1/timelines/tag/test", %{"all" => ["test1"], "none" => ["none"]})
363 assert [status_test1] == json_response(restricted_test, :ok)
365 all_test = get(conn, "/api/v1/timelines/tag/test", %{"all" => ["none"]})
367 assert [status_none] == json_response(all_test, :ok)