1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2019 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
5 defmodule Pleroma.Web.OStatus.OStatusControllerTest do
6 use Pleroma.Web.ConnCase
8 import ExUnit.CaptureLog
13 alias Pleroma.Web.CommonAPI
14 alias Pleroma.Web.OStatus.ActivityRepresenter
17 Tesla.Mock.mock_global(fn env -> apply(HttpRequestMock, :request, [env]) end)
21 clear_config_all([:instance, :federating]) do
22 Pleroma.Config.put([:instance, :federating], true)
25 describe "salmon_incoming" do
26 test "decodes a salmon", %{conn: conn} do
28 salmon = File.read!("test/fixtures/salmon.xml")
30 assert capture_log(fn ->
33 |> put_req_header("content-type", "application/atom+xml")
34 |> post("/users/#{user.nickname}/salmon", salmon)
36 assert response(conn, 200)
40 test "decodes a salmon with a changed magic key", %{conn: conn} do
42 salmon = File.read!("test/fixtures/salmon.xml")
44 assert capture_log(fn ->
47 |> put_req_header("content-type", "application/atom+xml")
48 |> post("/users/#{user.nickname}/salmon", salmon)
50 assert response(conn, 200)
53 # Set a wrong magic-key for a user so it has to refetch
54 salmon_user = User.get_cached_by_ap_id("http://gs.example.org:4040/index.php/user/1")
58 User.Info.remote_user_creation(salmon_user.info, %{
60 "RSA.pu0s-halox4tu7wmES1FVSx6u-4wc0YrUFXcqWXZG4-27UmbCOpMQftRCldNRfyA-qLbz-eqiwrong1EwUvjsD4cYbAHNGHwTvDOyx5AKthQUP44ykPv7kjKGh3DWKySJvcs9tlUG87hlo7AvnMo9pwRS_Zz2CacQ-MKaXyDepk=.AQAB"
64 |> Ecto.Changeset.change()
65 |> Ecto.Changeset.put_embed(:info, info_cng)
66 |> User.update_and_set_cache()
68 assert capture_log(fn ->
71 |> put_req_header("content-type", "application/atom+xml")
72 |> post("/users/#{user.nickname}/salmon", salmon)
74 assert response(conn, 200)
79 test "gets a feed", %{conn: conn} do
80 note_activity = insert(:note_activity)
81 object = Object.normalize(note_activity)
82 user = User.get_cached_by_ap_id(note_activity.data["actor"])
86 |> put_req_header("content-type", "application/atom+xml")
87 |> get("/users/#{user.nickname}/feed.atom")
89 assert response(conn, 200) =~ object.data["content"]
92 test "returns 404 for a missing feed", %{conn: conn} do
95 |> put_req_header("content-type", "application/atom+xml")
96 |> get("/users/nonexisting/feed.atom")
98 assert response(conn, 404)
101 describe "GET object/2" do
102 test "gets an object", %{conn: conn} do
103 note_activity = insert(:note_activity)
104 object = Object.normalize(note_activity)
105 user = User.get_cached_by_ap_id(note_activity.data["actor"])
106 [_, uuid] = hd(Regex.scan(~r/.+\/([\w-]+)$/, object.data["id"]))
107 url = "/objects/#{uuid}"
111 |> put_req_header("accept", "application/xml")
115 ActivityRepresenter.to_simple_form(note_activity, user, true)
116 |> ActivityRepresenter.wrap_with_entry()
117 |> :xmerl.export_simple(:xmerl_xml)
120 assert response(conn, 200) == expected
123 test "redirects to /notice/id for html format", %{conn: conn} do
124 note_activity = insert(:note_activity)
125 object = Object.normalize(note_activity)
126 [_, uuid] = hd(Regex.scan(~r/.+\/([\w-]+)$/, object.data["id"]))
127 url = "/objects/#{uuid}"
131 |> put_req_header("accept", "text/html")
134 assert redirected_to(conn) == "/notice/#{note_activity.id}"
137 test "500s when user not found", %{conn: conn} do
138 note_activity = insert(:note_activity)
139 object = Object.normalize(note_activity)
140 user = User.get_cached_by_ap_id(note_activity.data["actor"])
141 User.invalidate_cache(user)
142 Pleroma.Repo.delete(user)
143 [_, uuid] = hd(Regex.scan(~r/.+\/([\w-]+)$/, object.data["id"]))
144 url = "/objects/#{uuid}"
148 |> put_req_header("accept", "application/xml")
151 assert response(conn, 500) == ~S({"error":"Something went wrong"})
154 test "404s on private objects", %{conn: conn} do
155 note_activity = insert(:direct_note_activity)
156 object = Object.normalize(note_activity)
157 [_, uuid] = hd(Regex.scan(~r/.+\/([\w-]+)$/, object.data["id"]))
160 |> get("/objects/#{uuid}")
164 test "404s on nonexisting objects", %{conn: conn} do
166 |> get("/objects/123")
171 describe "GET activity/2" do
172 test "gets an activity in xml format", %{conn: conn} do
173 note_activity = insert(:note_activity)
174 [_, uuid] = hd(Regex.scan(~r/.+\/([\w-]+)$/, note_activity.data["id"]))
177 |> put_req_header("accept", "application/xml")
178 |> get("/activities/#{uuid}")
182 test "redirects to /notice/id for html format", %{conn: conn} do
183 note_activity = insert(:note_activity)
184 [_, uuid] = hd(Regex.scan(~r/.+\/([\w-]+)$/, note_activity.data["id"]))
188 |> put_req_header("accept", "text/html")
189 |> get("/activities/#{uuid}")
191 assert redirected_to(conn) == "/notice/#{note_activity.id}"
194 test "505s when user not found", %{conn: conn} do
195 note_activity = insert(:note_activity)
196 [_, uuid] = hd(Regex.scan(~r/.+\/([\w-]+)$/, note_activity.data["id"]))
197 user = User.get_cached_by_ap_id(note_activity.data["actor"])
198 User.invalidate_cache(user)
199 Pleroma.Repo.delete(user)
203 |> put_req_header("accept", "text/html")
204 |> get("/activities/#{uuid}")
206 assert response(conn, 500) == ~S({"error":"Something went wrong"})
209 test "404s on deleted objects", %{conn: conn} do
210 note_activity = insert(:note_activity)
211 object = Object.normalize(note_activity)
212 [_, uuid] = hd(Regex.scan(~r/.+\/([\w-]+)$/, object.data["id"]))
215 |> put_req_header("accept", "application/xml")
216 |> get("/objects/#{uuid}")
219 Object.delete(object)
222 |> put_req_header("accept", "application/xml")
223 |> get("/objects/#{uuid}")
227 test "404s on private activities", %{conn: conn} do
228 note_activity = insert(:direct_note_activity)
229 [_, uuid] = hd(Regex.scan(~r/.+\/([\w-]+)$/, note_activity.data["id"]))
232 |> get("/activities/#{uuid}")
236 test "404s on nonexistent activities", %{conn: conn} do
238 |> get("/activities/123")
242 test "gets an activity in AS2 format", %{conn: conn} do
243 note_activity = insert(:note_activity)
244 [_, uuid] = hd(Regex.scan(~r/.+\/([\w-]+)$/, note_activity.data["id"]))
245 url = "/activities/#{uuid}"
249 |> put_req_header("accept", "application/activity+json")
252 assert json_response(conn, 200)
256 describe "GET notice/2" do
257 test "gets a notice in xml format", %{conn: conn} do
258 note_activity = insert(:note_activity)
261 |> get("/notice/#{note_activity.id}")
265 test "gets a notice in AS2 format", %{conn: conn} do
266 note_activity = insert(:note_activity)
269 |> put_req_header("accept", "application/activity+json")
270 |> get("/notice/#{note_activity.id}")
271 |> json_response(200)
274 test "500s when actor not found", %{conn: conn} do
275 note_activity = insert(:note_activity)
276 user = User.get_cached_by_ap_id(note_activity.data["actor"])
277 User.invalidate_cache(user)
278 Pleroma.Repo.delete(user)
282 |> get("/notice/#{note_activity.id}")
284 assert response(conn, 500) == ~S({"error":"Something went wrong"})
287 test "only gets a notice in AS2 format for Create messages", %{conn: conn} do
288 note_activity = insert(:note_activity)
289 url = "/notice/#{note_activity.id}"
293 |> put_req_header("accept", "application/activity+json")
296 assert json_response(conn, 200)
300 {:ok, like_activity, _} = CommonAPI.favorite(note_activity.id, user)
301 url = "/notice/#{like_activity.id}"
303 assert like_activity.data["type"] == "Like"
307 |> put_req_header("accept", "application/activity+json")
310 assert response(conn, 404)
313 test "render html for redirect for html format", %{conn: conn} do
314 note_activity = insert(:note_activity)
318 |> put_req_header("accept", "text/html")
319 |> get("/notice/#{note_activity.id}")
323 "<meta content=\"#{Pleroma.Web.base_url()}/notice/#{note_activity.id}\" property=\"og:url\">"
327 {:ok, like_activity, _} = CommonAPI.favorite(note_activity.id, user)
329 assert like_activity.data["type"] == "Like"
333 |> put_req_header("accept", "text/html")
334 |> get("/notice/#{like_activity.id}")
337 assert resp =~ "<!--server-generated-meta-->"
340 test "404s a private notice", %{conn: conn} do
341 note_activity = insert(:direct_note_activity)
342 url = "/notice/#{note_activity.id}"
348 assert response(conn, 404)
351 test "404s a nonexisting notice", %{conn: conn} do
358 assert response(conn, 404)
362 describe "feed_redirect" do
363 test "undefined format. it redirects to feed", %{conn: conn} do
364 note_activity = insert(:note_activity)
365 user = User.get_cached_by_ap_id(note_activity.data["actor"])
369 |> put_req_header("accept", "application/xml")
370 |> get("/users/#{user.nickname}")
374 "<html><body>You are being <a href=\"#{Pleroma.Web.base_url()}/users/#{
376 }/feed.atom\">redirected</a>.</body></html>"
379 test "undefined format. it returns error when user not found", %{conn: conn} do
382 |> put_req_header("accept", "application/xml")
383 |> get("/users/jimm")
386 assert response == ~S({"error":"Not found"})
389 test "activity+json format. it redirects on actual feed of user", %{conn: conn} do
390 note_activity = insert(:note_activity)
391 user = User.get_cached_by_ap_id(note_activity.data["actor"])
395 |> put_req_header("accept", "application/activity+json")
396 |> get("/users/#{user.nickname}")
397 |> json_response(200)
399 assert response["endpoints"] == %{
400 "oauthAuthorizationEndpoint" => "#{Pleroma.Web.base_url()}/oauth/authorize",
401 "oauthRegistrationEndpoint" => "#{Pleroma.Web.base_url()}/api/v1/apps",
402 "oauthTokenEndpoint" => "#{Pleroma.Web.base_url()}/oauth/token",
403 "sharedInbox" => "#{Pleroma.Web.base_url()}/inbox",
404 "uploadMedia" => "#{Pleroma.Web.base_url()}/api/ap/upload_media"
407 assert response["@context"] == [
408 "https://www.w3.org/ns/activitystreams",
409 "http://localhost:4001/schemas/litepub-0.1.jsonld",
410 %{"@language" => "und"}
413 assert Map.take(response, [
418 "manuallyApprovesFollowers",
427 "followers" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}/followers",
428 "following" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}/following",
429 "id" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}",
430 "inbox" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}/inbox",
431 "manuallyApprovesFollowers" => false,
433 "outbox" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}/outbox",
434 "preferredUsername" => user.nickname,
435 "summary" => user.bio,
438 "url" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}"
442 test "activity+json format. it returns error whe use not found", %{conn: conn} do
445 |> put_req_header("accept", "application/activity+json")
446 |> get("/users/jimm")
447 |> json_response(404)
449 assert response == "Not found"
452 test "json format. it redirects on actual feed of user", %{conn: conn} do
453 note_activity = insert(:note_activity)
454 user = User.get_cached_by_ap_id(note_activity.data["actor"])
458 |> put_req_header("accept", "application/json")
459 |> get("/users/#{user.nickname}")
460 |> json_response(200)
462 assert response["endpoints"] == %{
463 "oauthAuthorizationEndpoint" => "#{Pleroma.Web.base_url()}/oauth/authorize",
464 "oauthRegistrationEndpoint" => "#{Pleroma.Web.base_url()}/api/v1/apps",
465 "oauthTokenEndpoint" => "#{Pleroma.Web.base_url()}/oauth/token",
466 "sharedInbox" => "#{Pleroma.Web.base_url()}/inbox",
467 "uploadMedia" => "#{Pleroma.Web.base_url()}/api/ap/upload_media"
470 assert response["@context"] == [
471 "https://www.w3.org/ns/activitystreams",
472 "http://localhost:4001/schemas/litepub-0.1.jsonld",
473 %{"@language" => "und"}
476 assert Map.take(response, [
481 "manuallyApprovesFollowers",
490 "followers" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}/followers",
491 "following" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}/following",
492 "id" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}",
493 "inbox" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}/inbox",
494 "manuallyApprovesFollowers" => false,
496 "outbox" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}/outbox",
497 "preferredUsername" => user.nickname,
498 "summary" => user.bio,
501 "url" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}"
505 test "json format. it returns error whe use not found", %{conn: conn} do
508 |> put_req_header("accept", "application/json")
509 |> get("/users/jimm")
510 |> json_response(404)
512 assert response == "Not found"
515 test "html format. it redirects on actual feed of user", %{conn: conn} do
516 note_activity = insert(:note_activity)
517 user = User.get_cached_by_ap_id(note_activity.data["actor"])
521 |> get("/users/#{user.nickname}")
525 Fallback.RedirectController.redirector_with_meta(
531 test "html format. it returns error when user not found", %{conn: conn} do
534 |> get("/users/jimm")
535 |> json_response(404)
537 assert response == %{"error" => "Not found"}
541 describe "GET /notice/:id/embed_player" do
542 test "render embed player", %{conn: conn} do
543 note_activity = insert(:note_activity)
544 object = Pleroma.Object.normalize(note_activity)
547 Map.put(object.data, "attachment", [
552 "https://peertube.moe/static/webseed/df5f464b-be8d-46fb-ad81-2d4c2d1630e3-480.mp4",
553 "mediaType" => "video/mp4",
561 |> Ecto.Changeset.change(data: object_data)
562 |> Pleroma.Repo.update()
566 |> get("/notice/#{note_activity.id}/embed_player")
568 assert Plug.Conn.get_resp_header(conn, "x-frame-options") == ["ALLOW"]
570 assert Plug.Conn.get_resp_header(
572 "content-security-policy"
574 "default-src 'none';style-src 'self' 'unsafe-inline';img-src 'self' data: https:; media-src 'self' https:;"
577 assert response(conn, 200) =~
578 "<video controls loop><source src=\"https://peertube.moe/static/webseed/df5f464b-be8d-46fb-ad81-2d4c2d1630e3-480.mp4\" type=\"video/mp4\">Your browser does not support video/mp4 playback.</video>"
581 test "404s when activity isn't create", %{conn: conn} do
582 note_activity = insert(:note_activity, data_attrs: %{"type" => "Like"})
585 |> get("/notice/#{note_activity.id}/embed_player")
589 test "404s when activity is direct message", %{conn: conn} do
590 note_activity = insert(:note_activity, data_attrs: %{"directMessage" => true})
593 |> get("/notice/#{note_activity.id}/embed_player")
597 test "404s when attachment is empty", %{conn: conn} do
598 note_activity = insert(:note_activity)
599 object = Pleroma.Object.normalize(note_activity)
600 object_data = Map.put(object.data, "attachment", [])
603 |> Ecto.Changeset.change(data: object_data)
604 |> Pleroma.Repo.update()
607 |> get("/notice/#{note_activity.id}/embed_player")
611 test "404s when attachment isn't audio or video", %{conn: conn} do
612 note_activity = insert(:note_activity)
613 object = Pleroma.Object.normalize(note_activity)
616 Map.put(object.data, "attachment", [
620 "href" => "https://peertube.moe/static/webseed/480.jpg",
621 "mediaType" => "image/jpg",
629 |> Ecto.Changeset.change(data: object_data)
630 |> Pleroma.Repo.update()
633 |> get("/notice/#{note_activity.id}/embed_player")