1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2019 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
5 defmodule Pleroma.Web.OStatus.OStatusControllerTest do
6 use Pleroma.Web.ConnCase
8 import ExUnit.CaptureLog
13 alias Pleroma.Web.CommonAPI
14 alias Pleroma.Web.OStatus.ActivityRepresenter
17 Tesla.Mock.mock_global(fn env -> apply(HttpRequestMock, :request, [env]) end)
21 clear_config_all([:instance, :federating]) do
22 Pleroma.Config.put([:instance, :federating], true)
25 describe "salmon_incoming" do
26 test "decodes a salmon", %{conn: conn} do
28 salmon = File.read!("test/fixtures/salmon.xml")
30 assert capture_log(fn ->
33 |> put_req_header("content-type", "application/atom+xml")
34 |> post("/users/#{user.nickname}/salmon", salmon)
36 assert response(conn, 200)
40 test "decodes a salmon with a changed magic key", %{conn: conn} do
42 salmon = File.read!("test/fixtures/salmon.xml")
44 assert capture_log(fn ->
47 |> put_req_header("content-type", "application/atom+xml")
48 |> post("/users/#{user.nickname}/salmon", salmon)
50 assert response(conn, 200)
56 "RSA.pu0s-halox4tu7wmES1FVSx6u-4wc0YrUFXcqWXZG4-27UmbCOpMQftRCldNRfyA-qLbz-eqiwrong1EwUvjsD4cYbAHNGHwTvDOyx5AKthQUP44ykPv7kjKGh3DWKySJvcs9tlUG87hlo7AvnMo9pwRS_Zz2CacQ-MKaXyDepk=.AQAB"
59 # Set a wrong magic-key for a user so it has to refetch
60 "http://gs.example.org:4040/index.php/user/1"
61 |> User.get_cached_by_ap_id()
62 |> User.update_info(&User.Info.remote_user_creation(&1, info))
64 assert capture_log(fn ->
67 |> put_req_header("content-type", "application/atom+xml")
68 |> post("/users/#{user.nickname}/salmon", salmon)
70 assert response(conn, 200)
75 test "gets a feed", %{conn: conn} do
76 note_activity = insert(:note_activity)
77 object = Object.normalize(note_activity)
78 user = User.get_cached_by_ap_id(note_activity.data["actor"])
82 |> put_req_header("content-type", "application/atom+xml")
83 |> get("/users/#{user.nickname}/feed.atom")
85 assert response(conn, 200) =~ object.data["content"]
88 test "returns 404 for a missing feed", %{conn: conn} do
91 |> put_req_header("content-type", "application/atom+xml")
92 |> get("/users/nonexisting/feed.atom")
94 assert response(conn, 404)
97 describe "GET object/2" do
98 test "gets an object", %{conn: conn} do
99 note_activity = insert(:note_activity)
100 object = Object.normalize(note_activity)
101 user = User.get_cached_by_ap_id(note_activity.data["actor"])
102 [_, uuid] = hd(Regex.scan(~r/.+\/([\w-]+)$/, object.data["id"]))
103 url = "/objects/#{uuid}"
107 |> put_req_header("accept", "application/xml")
111 ActivityRepresenter.to_simple_form(note_activity, user, true)
112 |> ActivityRepresenter.wrap_with_entry()
113 |> :xmerl.export_simple(:xmerl_xml)
116 assert response(conn, 200) == expected
119 test "redirects to /notice/id for html format", %{conn: conn} do
120 note_activity = insert(:note_activity)
121 object = Object.normalize(note_activity)
122 [_, uuid] = hd(Regex.scan(~r/.+\/([\w-]+)$/, object.data["id"]))
123 url = "/objects/#{uuid}"
127 |> put_req_header("accept", "text/html")
130 assert redirected_to(conn) == "/notice/#{note_activity.id}"
133 test "500s when user not found", %{conn: conn} do
134 note_activity = insert(:note_activity)
135 object = Object.normalize(note_activity)
136 user = User.get_cached_by_ap_id(note_activity.data["actor"])
137 User.invalidate_cache(user)
138 Pleroma.Repo.delete(user)
139 [_, uuid] = hd(Regex.scan(~r/.+\/([\w-]+)$/, object.data["id"]))
140 url = "/objects/#{uuid}"
144 |> put_req_header("accept", "application/xml")
147 assert response(conn, 500) == ~S({"error":"Something went wrong"})
150 test "404s on private objects", %{conn: conn} do
151 note_activity = insert(:direct_note_activity)
152 object = Object.normalize(note_activity)
153 [_, uuid] = hd(Regex.scan(~r/.+\/([\w-]+)$/, object.data["id"]))
156 |> get("/objects/#{uuid}")
160 test "404s on nonexisting objects", %{conn: conn} do
162 |> get("/objects/123")
167 describe "GET activity/2" do
168 test "gets an activity in xml format", %{conn: conn} do
169 note_activity = insert(:note_activity)
170 [_, uuid] = hd(Regex.scan(~r/.+\/([\w-]+)$/, note_activity.data["id"]))
173 |> put_req_header("accept", "application/xml")
174 |> get("/activities/#{uuid}")
178 test "redirects to /notice/id for html format", %{conn: conn} do
179 note_activity = insert(:note_activity)
180 [_, uuid] = hd(Regex.scan(~r/.+\/([\w-]+)$/, note_activity.data["id"]))
184 |> put_req_header("accept", "text/html")
185 |> get("/activities/#{uuid}")
187 assert redirected_to(conn) == "/notice/#{note_activity.id}"
190 test "505s when user not found", %{conn: conn} do
191 note_activity = insert(:note_activity)
192 [_, uuid] = hd(Regex.scan(~r/.+\/([\w-]+)$/, note_activity.data["id"]))
193 user = User.get_cached_by_ap_id(note_activity.data["actor"])
194 User.invalidate_cache(user)
195 Pleroma.Repo.delete(user)
199 |> put_req_header("accept", "text/html")
200 |> get("/activities/#{uuid}")
202 assert response(conn, 500) == ~S({"error":"Something went wrong"})
205 test "404s on deleted objects", %{conn: conn} do
206 note_activity = insert(:note_activity)
207 object = Object.normalize(note_activity)
208 [_, uuid] = hd(Regex.scan(~r/.+\/([\w-]+)$/, object.data["id"]))
211 |> put_req_header("accept", "application/xml")
212 |> get("/objects/#{uuid}")
215 Object.delete(object)
218 |> put_req_header("accept", "application/xml")
219 |> get("/objects/#{uuid}")
223 test "404s on private activities", %{conn: conn} do
224 note_activity = insert(:direct_note_activity)
225 [_, uuid] = hd(Regex.scan(~r/.+\/([\w-]+)$/, note_activity.data["id"]))
228 |> get("/activities/#{uuid}")
232 test "404s on nonexistent activities", %{conn: conn} do
234 |> get("/activities/123")
238 test "gets an activity in AS2 format", %{conn: conn} do
239 note_activity = insert(:note_activity)
240 [_, uuid] = hd(Regex.scan(~r/.+\/([\w-]+)$/, note_activity.data["id"]))
241 url = "/activities/#{uuid}"
245 |> put_req_header("accept", "application/activity+json")
248 assert json_response(conn, 200)
252 describe "GET notice/2" do
253 test "gets a notice in xml format", %{conn: conn} do
254 note_activity = insert(:note_activity)
257 |> get("/notice/#{note_activity.id}")
261 test "gets a notice in AS2 format", %{conn: conn} do
262 note_activity = insert(:note_activity)
265 |> put_req_header("accept", "application/activity+json")
266 |> get("/notice/#{note_activity.id}")
267 |> json_response(200)
270 test "500s when actor not found", %{conn: conn} do
271 note_activity = insert(:note_activity)
272 user = User.get_cached_by_ap_id(note_activity.data["actor"])
273 User.invalidate_cache(user)
274 Pleroma.Repo.delete(user)
278 |> get("/notice/#{note_activity.id}")
280 assert response(conn, 500) == ~S({"error":"Something went wrong"})
283 test "only gets a notice in AS2 format for Create messages", %{conn: conn} do
284 note_activity = insert(:note_activity)
285 url = "/notice/#{note_activity.id}"
289 |> put_req_header("accept", "application/activity+json")
292 assert json_response(conn, 200)
296 {:ok, like_activity, _} = CommonAPI.favorite(note_activity.id, user)
297 url = "/notice/#{like_activity.id}"
299 assert like_activity.data["type"] == "Like"
303 |> put_req_header("accept", "application/activity+json")
306 assert response(conn, 404)
309 test "render html for redirect for html format", %{conn: conn} do
310 note_activity = insert(:note_activity)
314 |> put_req_header("accept", "text/html")
315 |> get("/notice/#{note_activity.id}")
319 "<meta content=\"#{Pleroma.Web.base_url()}/notice/#{note_activity.id}\" property=\"og:url\">"
323 {:ok, like_activity, _} = CommonAPI.favorite(note_activity.id, user)
325 assert like_activity.data["type"] == "Like"
329 |> put_req_header("accept", "text/html")
330 |> get("/notice/#{like_activity.id}")
333 assert resp =~ "<!--server-generated-meta-->"
336 test "404s a private notice", %{conn: conn} do
337 note_activity = insert(:direct_note_activity)
338 url = "/notice/#{note_activity.id}"
344 assert response(conn, 404)
347 test "404s a nonexisting notice", %{conn: conn} do
354 assert response(conn, 404)
358 describe "feed_redirect" do
359 test "undefined format. it redirects to feed", %{conn: conn} do
360 note_activity = insert(:note_activity)
361 user = User.get_cached_by_ap_id(note_activity.data["actor"])
365 |> put_req_header("accept", "application/xml")
366 |> get("/users/#{user.nickname}")
370 "<html><body>You are being <a href=\"#{Pleroma.Web.base_url()}/users/#{
372 }/feed.atom\">redirected</a>.</body></html>"
375 test "undefined format. it returns error when user not found", %{conn: conn} do
378 |> put_req_header("accept", "application/xml")
379 |> get("/users/jimm")
382 assert response == ~S({"error":"Not found"})
385 test "activity+json format. it redirects on actual feed of user", %{conn: conn} do
386 note_activity = insert(:note_activity)
387 user = User.get_cached_by_ap_id(note_activity.data["actor"])
391 |> put_req_header("accept", "application/activity+json")
392 |> get("/users/#{user.nickname}")
393 |> json_response(200)
395 assert response["endpoints"] == %{
396 "oauthAuthorizationEndpoint" => "#{Pleroma.Web.base_url()}/oauth/authorize",
397 "oauthRegistrationEndpoint" => "#{Pleroma.Web.base_url()}/api/v1/apps",
398 "oauthTokenEndpoint" => "#{Pleroma.Web.base_url()}/oauth/token",
399 "sharedInbox" => "#{Pleroma.Web.base_url()}/inbox",
400 "uploadMedia" => "#{Pleroma.Web.base_url()}/api/ap/upload_media"
403 assert response["@context"] == [
404 "https://www.w3.org/ns/activitystreams",
405 "http://localhost:4001/schemas/litepub-0.1.jsonld",
406 %{"@language" => "und"}
409 assert Map.take(response, [
414 "manuallyApprovesFollowers",
423 "followers" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}/followers",
424 "following" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}/following",
425 "id" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}",
426 "inbox" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}/inbox",
427 "manuallyApprovesFollowers" => false,
429 "outbox" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}/outbox",
430 "preferredUsername" => user.nickname,
431 "summary" => user.bio,
434 "url" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}"
438 test "activity+json format. it returns error whe use not found", %{conn: conn} do
441 |> put_req_header("accept", "application/activity+json")
442 |> get("/users/jimm")
443 |> json_response(404)
445 assert response == "Not found"
448 test "json format. it redirects on actual feed of user", %{conn: conn} do
449 note_activity = insert(:note_activity)
450 user = User.get_cached_by_ap_id(note_activity.data["actor"])
454 |> put_req_header("accept", "application/json")
455 |> get("/users/#{user.nickname}")
456 |> json_response(200)
458 assert response["endpoints"] == %{
459 "oauthAuthorizationEndpoint" => "#{Pleroma.Web.base_url()}/oauth/authorize",
460 "oauthRegistrationEndpoint" => "#{Pleroma.Web.base_url()}/api/v1/apps",
461 "oauthTokenEndpoint" => "#{Pleroma.Web.base_url()}/oauth/token",
462 "sharedInbox" => "#{Pleroma.Web.base_url()}/inbox",
463 "uploadMedia" => "#{Pleroma.Web.base_url()}/api/ap/upload_media"
466 assert response["@context"] == [
467 "https://www.w3.org/ns/activitystreams",
468 "http://localhost:4001/schemas/litepub-0.1.jsonld",
469 %{"@language" => "und"}
472 assert Map.take(response, [
477 "manuallyApprovesFollowers",
486 "followers" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}/followers",
487 "following" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}/following",
488 "id" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}",
489 "inbox" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}/inbox",
490 "manuallyApprovesFollowers" => false,
492 "outbox" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}/outbox",
493 "preferredUsername" => user.nickname,
494 "summary" => user.bio,
497 "url" => "#{Pleroma.Web.base_url()}/users/#{user.nickname}"
501 test "json format. it returns error whe use not found", %{conn: conn} do
504 |> put_req_header("accept", "application/json")
505 |> get("/users/jimm")
506 |> json_response(404)
508 assert response == "Not found"
511 test "html format. it redirects on actual feed of user", %{conn: conn} do
512 note_activity = insert(:note_activity)
513 user = User.get_cached_by_ap_id(note_activity.data["actor"])
517 |> get("/users/#{user.nickname}")
521 Fallback.RedirectController.redirector_with_meta(
527 test "html format. it returns error when user not found", %{conn: conn} do
530 |> get("/users/jimm")
531 |> json_response(404)
533 assert response == %{"error" => "Not found"}
537 describe "GET /notice/:id/embed_player" do
538 test "render embed player", %{conn: conn} do
539 note_activity = insert(:note_activity)
540 object = Pleroma.Object.normalize(note_activity)
543 Map.put(object.data, "attachment", [
548 "https://peertube.moe/static/webseed/df5f464b-be8d-46fb-ad81-2d4c2d1630e3-480.mp4",
549 "mediaType" => "video/mp4",
557 |> Ecto.Changeset.change(data: object_data)
558 |> Pleroma.Repo.update()
562 |> get("/notice/#{note_activity.id}/embed_player")
564 assert Plug.Conn.get_resp_header(conn, "x-frame-options") == ["ALLOW"]
566 assert Plug.Conn.get_resp_header(
568 "content-security-policy"
570 "default-src 'none';style-src 'self' 'unsafe-inline';img-src 'self' data: https:; media-src 'self' https:;"
573 assert response(conn, 200) =~
574 "<video controls loop><source src=\"https://peertube.moe/static/webseed/df5f464b-be8d-46fb-ad81-2d4c2d1630e3-480.mp4\" type=\"video/mp4\">Your browser does not support video/mp4 playback.</video>"
577 test "404s when activity isn't create", %{conn: conn} do
578 note_activity = insert(:note_activity, data_attrs: %{"type" => "Like"})
581 |> get("/notice/#{note_activity.id}/embed_player")
585 test "404s when activity is direct message", %{conn: conn} do
586 note_activity = insert(:note_activity, data_attrs: %{"directMessage" => true})
589 |> get("/notice/#{note_activity.id}/embed_player")
593 test "404s when attachment is empty", %{conn: conn} do
594 note_activity = insert(:note_activity)
595 object = Pleroma.Object.normalize(note_activity)
596 object_data = Map.put(object.data, "attachment", [])
599 |> Ecto.Changeset.change(data: object_data)
600 |> Pleroma.Repo.update()
603 |> get("/notice/#{note_activity.id}/embed_player")
607 test "404s when attachment isn't audio or video", %{conn: conn} do
608 note_activity = insert(:note_activity)
609 object = Pleroma.Object.normalize(note_activity)
612 Map.put(object.data, "attachment", [
616 "href" => "https://peertube.moe/static/webseed/480.jpg",
617 "mediaType" => "image/jpg",
625 |> Ecto.Changeset.change(data: object_data)
626 |> Pleroma.Repo.update()
629 |> get("/notice/#{note_activity.id}/embed_player")