1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2020 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
5 defmodule Pleroma.Web.MastodonAPI.AccountViewTest do
10 alias Pleroma.UserRelationship
11 alias Pleroma.Web.CommonAPI
12 alias Pleroma.Web.MastodonAPI.AccountView
14 import Pleroma.Factory
18 mock(fn env -> apply(HttpRequestMock, :request, [env]) end)
22 setup do: clear_config([:instances_favicons, :enabled])
24 test "Represent a user account" do
26 "url" => [%{"href" => "https://example.com/images/asuka_hospital.png"}]
33 background: background_image,
34 nickname: "shp@shitposter.club",
35 name: ":karjalanpiirakka: shp",
37 "<script src=\"invalid-html\"></script><span>valid html</span>. a<br>b<br/>c<br >d<br />f '&<>\"",
38 inserted_at: ~N[2017-08-15 15:47:06.597036],
39 emoji: %{"karjalanpiirakka" => "/file.png"},
40 raw_bio: "valid html. a\nb\nc\nd\nf '&<>\""
44 id: to_string(user.id),
47 display_name: user.name,
49 created_at: "2017-08-15T15:47:06.000Z",
53 note: "<span>valid html</span>. a<br/>b<br/>c<br/>d<br/>f '&<>"",
55 avatar: "http://localhost:4001/images/avi.png",
56 avatar_static: "http://localhost:4001/images/avi.png",
57 header: "http://localhost:4001/images/banner.png",
58 header_static: "http://localhost:4001/images/banner.png",
61 static_url: "/file.png",
63 shortcode: "karjalanpiirakka",
64 visible_in_picker: false
70 note: "valid html. a\nb\nc\nd\nf '&<>\"",
80 background_image: "https://example.com/images/asuka_hospital.png",
82 "https://shitposter.club/plugins/Qvitter/img/gnusocial-favicons/favicon-16x16.png",
83 confirmation_pending: false,
88 hide_followers: false,
90 hide_followers_count: false,
91 hide_follows_count: false,
93 skip_thread_containment: false
97 assert expected == AccountView.render("show.json", %{user: user})
100 test "Favicon is nil when :instances_favicons is disabled" do
103 Config.put([:instances_favicons, :enabled], true)
108 "https://shitposter.club/plugins/Qvitter/img/gnusocial-favicons/favicon-16x16.png"
110 } = AccountView.render("show.json", %{user: user})
112 Config.put([:instances_favicons, :enabled], false)
114 assert %{pleroma: %{favicon: nil}} = AccountView.render("show.json", %{user: user})
117 test "Represent the user account for the account owner" do
120 notification_settings = %{
125 privacy_option: false
128 privacy = user.default_scope
131 pleroma: %{notification_settings: ^notification_settings, allow_following_move: true},
132 source: %{privacy: ^privacy}
133 } = AccountView.render("show.json", %{user: user, for: user})
136 test "Represent a Service(bot) account" do
141 actor_type: "Service",
142 nickname: "shp@shitposter.club",
143 inserted_at: ~N[2017-08-15 15:47:06.597036]
147 id: to_string(user.id),
150 display_name: user.name,
152 created_at: "2017-08-15T15:47:06.000Z",
158 avatar: "http://localhost:4001/images/avi.png",
159 avatar_static: "http://localhost:4001/images/avi.png",
160 header: "http://localhost:4001/images/banner.png",
161 header_static: "http://localhost:4001/images/banner.png",
169 actor_type: "Service",
176 background_image: nil,
178 "https://shitposter.club/plugins/Qvitter/img/gnusocial-favicons/favicon-16x16.png",
179 confirmation_pending: false,
183 hide_favorites: true,
184 hide_followers: false,
186 hide_followers_count: false,
187 hide_follows_count: false,
189 skip_thread_containment: false
193 assert expected == AccountView.render("show.json", %{user: user})
196 test "Represent a Funkwhale channel" do
198 User.get_or_fetch_by_ap_id(
199 "https://channels.tests.funkwhale.audio/federation/actors/compositions"
202 assert represented = AccountView.render("show.json", %{user: user})
203 assert represented.acct == "compositions@channels.tests.funkwhale.audio"
204 assert represented.url == "https://channels.tests.funkwhale.audio/channels/compositions"
207 test "Represent a deactivated user for an admin" do
208 admin = insert(:user, is_admin: true)
209 deactivated_user = insert(:user, deactivated: true)
210 represented = AccountView.render("show.json", %{user: deactivated_user, for: admin})
211 assert represented[:pleroma][:deactivated] == true
214 test "Represent a smaller mention" do
218 id: to_string(user.id),
220 username: user.nickname,
224 assert expected == AccountView.render("mention.json", %{user: user})
227 describe "relationship" do
228 defp test_relationship_rendering(user, other_user, expected_result) do
229 opts = %{user: user, target: other_user, relationships: nil}
230 assert expected_result == AccountView.render("relationship.json", opts)
232 relationships_opt = UserRelationship.view_relationships_option(user, [other_user])
233 opts = Map.put(opts, :relationships, relationships_opt)
234 assert expected_result == AccountView.render("relationship.json", opts)
236 assert [expected_result] ==
237 AccountView.render("relationships.json", %{user: user, targets: [other_user]})
246 muting_notifications: false,
249 domain_blocking: false,
250 showing_reblogs: true,
254 test "represent a relationship for the following and followed user" do
256 other_user = insert(:user)
258 {:ok, user} = User.follow(user, other_user)
259 {:ok, other_user} = User.follow(other_user, user)
260 {:ok, _subscription} = User.subscribe(user, other_user)
261 {:ok, _user_relationships} = User.mute(user, other_user, true)
262 {:ok, _reblog_mute} = CommonAPI.hide_reblogs(user, other_user)
271 muting_notifications: true,
273 showing_reblogs: false,
274 id: to_string(other_user.id)
278 test_relationship_rendering(user, other_user, expected)
281 test "represent a relationship for the blocking and blocked user" do
283 other_user = insert(:user)
285 {:ok, user} = User.follow(user, other_user)
286 {:ok, _subscription} = User.subscribe(user, other_user)
287 {:ok, _user_relationship} = User.block(user, other_user)
288 {:ok, _user_relationship} = User.block(other_user, user)
293 %{following: false, blocking: true, blocked_by: true, id: to_string(other_user.id)}
296 test_relationship_rendering(user, other_user, expected)
299 test "represent a relationship for the user blocking a domain" do
301 other_user = insert(:user, ap_id: "https://bad.site/users/other_user")
303 {:ok, user} = User.block_domain(user, "bad.site")
308 %{domain_blocking: true, blocking: false, id: to_string(other_user.id)}
311 test_relationship_rendering(user, other_user, expected)
314 test "represent a relationship for the user with a pending follow request" do
316 other_user = insert(:user, locked: true)
318 {:ok, user, other_user, _} = CommonAPI.follow(user, other_user)
319 user = User.get_cached_by_id(user.id)
320 other_user = User.get_cached_by_id(other_user.id)
325 %{requested: true, following: false, id: to_string(other_user.id)}
328 test_relationship_rendering(user, other_user, expected)
332 test "returns the settings store if the requesting user is the represented user and it's requested specifically" do
333 user = insert(:user, pleroma_settings_store: %{fe: "test"})
336 AccountView.render("show.json", %{user: user, for: user, with_pleroma_settings: true})
338 assert result.pleroma.settings_store == %{:fe => "test"}
340 result = AccountView.render("show.json", %{user: user, with_pleroma_settings: true})
341 assert result.pleroma[:settings_store] == nil
343 result = AccountView.render("show.json", %{user: user, for: user})
344 assert result.pleroma[:settings_store] == nil
347 test "doesn't sanitize display names" do
348 user = insert(:user, name: "<marquee> username </marquee>")
349 result = AccountView.render("show.json", %{user: user})
350 assert result.display_name == "<marquee> username </marquee>"
353 test "never display nil user follow counts" do
354 user = insert(:user, following_count: 0, follower_count: 0)
355 result = AccountView.render("show.json", %{user: user})
357 assert result.following_count == 0
358 assert result.followers_count == 0
361 describe "hiding follows/following" do
362 test "shows when follows/followers stats are hidden and sets follow/follower count to 0" do
365 hide_followers: true,
366 hide_followers_count: true,
368 hide_follows_count: true
371 other_user = insert(:user)
372 {:ok, user, other_user, _activity} = CommonAPI.follow(user, other_user)
373 {:ok, _other_user, user, _activity} = CommonAPI.follow(other_user, user)
378 pleroma: %{hide_follows_count: true, hide_followers_count: true}
379 } = AccountView.render("show.json", %{user: user})
382 test "shows when follows/followers are hidden" do
383 user = insert(:user, hide_followers: true, hide_follows: true)
384 other_user = insert(:user)
385 {:ok, user, other_user, _activity} = CommonAPI.follow(user, other_user)
386 {:ok, _other_user, user, _activity} = CommonAPI.follow(other_user, user)
391 pleroma: %{hide_follows: true, hide_followers: true}
392 } = AccountView.render("show.json", %{user: user})
395 test "shows actual follower/following count to the account owner" do
396 user = insert(:user, hide_followers: true, hide_follows: true)
397 other_user = insert(:user)
398 {:ok, user, other_user, _activity} = CommonAPI.follow(user, other_user)
399 {:ok, _other_user, user, _activity} = CommonAPI.follow(other_user, user)
404 } = AccountView.render("show.json", %{user: user, for: user})
407 test "shows unread_conversation_count only to the account owner" do
409 other_user = insert(:user)
412 CommonAPI.post(other_user, %{
413 status: "Hey @#{user.nickname}.",
417 user = User.get_cached_by_ap_id(user.ap_id)
419 assert AccountView.render("show.json", %{user: user, for: other_user})[:pleroma][
420 :unread_conversation_count
423 assert AccountView.render("show.json", %{user: user, for: user})[:pleroma][
424 :unread_conversation_count
428 test "shows unread_count only to the account owner" do
430 insert_list(7, :notification, user: user)
431 other_user = insert(:user)
433 user = User.get_cached_by_ap_id(user.ap_id)
435 assert AccountView.render(
437 %{user: user, for: other_user}
438 )[:pleroma][:unread_notifications_count] == nil
440 assert AccountView.render(
442 %{user: user, for: user}
443 )[:pleroma][:unread_notifications_count] == 7
447 describe "follow requests counter" do
448 test "shows zero when no follow requests are pending" do
451 assert %{follow_requests_count: 0} =
452 AccountView.render("show.json", %{user: user, for: user})
454 other_user = insert(:user)
455 {:ok, _other_user, user, _activity} = CommonAPI.follow(other_user, user)
457 assert %{follow_requests_count: 0} =
458 AccountView.render("show.json", %{user: user, for: user})
461 test "shows non-zero when follow requests are pending" do
462 user = insert(:user, locked: true)
464 assert %{locked: true} = AccountView.render("show.json", %{user: user, for: user})
466 other_user = insert(:user)
467 {:ok, _other_user, user, _activity} = CommonAPI.follow(other_user, user)
469 assert %{locked: true, follow_requests_count: 1} =
470 AccountView.render("show.json", %{user: user, for: user})
473 test "decreases when accepting a follow request" do
474 user = insert(:user, locked: true)
476 assert %{locked: true} = AccountView.render("show.json", %{user: user, for: user})
478 other_user = insert(:user)
479 {:ok, other_user, user, _activity} = CommonAPI.follow(other_user, user)
481 assert %{locked: true, follow_requests_count: 1} =
482 AccountView.render("show.json", %{user: user, for: user})
484 {:ok, _other_user} = CommonAPI.accept_follow_request(other_user, user)
486 assert %{locked: true, follow_requests_count: 0} =
487 AccountView.render("show.json", %{user: user, for: user})
490 test "decreases when rejecting a follow request" do
491 user = insert(:user, locked: true)
493 assert %{locked: true} = AccountView.render("show.json", %{user: user, for: user})
495 other_user = insert(:user)
496 {:ok, other_user, user, _activity} = CommonAPI.follow(other_user, user)
498 assert %{locked: true, follow_requests_count: 1} =
499 AccountView.render("show.json", %{user: user, for: user})
501 {:ok, _other_user} = CommonAPI.reject_follow_request(other_user, user)
503 assert %{locked: true, follow_requests_count: 0} =
504 AccountView.render("show.json", %{user: user, for: user})
507 test "shows non-zero when historical unapproved requests are present" do
508 user = insert(:user, locked: true)
510 assert %{locked: true} = AccountView.render("show.json", %{user: user, for: user})
512 other_user = insert(:user)
513 {:ok, _other_user, user, _activity} = CommonAPI.follow(other_user, user)
515 {:ok, user} = User.update_and_set_cache(user, %{locked: false})
517 assert %{locked: false, follow_requests_count: 1} =
518 AccountView.render("show.json", %{user: user, for: user})
522 test "uses mediaproxy urls when it's enabled" do
523 clear_config([:media_proxy, :enabled], true)
527 avatar: %{"url" => [%{"href" => "https://evil.website/avatar.png"}]},
528 banner: %{"url" => [%{"href" => "https://evil.website/banner.png"}]},
529 emoji: %{"joker_smile" => "https://evil.website/society.png"}
532 AccountView.render("show.json", %{user: user})
534 {key, url} when key in [:avatar, :avatar_static, :header, :header_static] ->
535 String.starts_with?(url, Pleroma.Web.base_url())
538 Enum.all?(emojis, fn %{url: url, static_url: static_url} ->
539 String.starts_with?(url, Pleroma.Web.base_url()) &&
540 String.starts_with?(static_url, Pleroma.Web.base_url())