Safety measures.
[akkoma] / test / web / twitter_api / twitter_api_controller_test.exs
1 defmodule Pleroma.Web.TwitterAPI.ControllerTest do
2 use Pleroma.Web.ConnCase
3 alias Pleroma.Web.TwitterAPI.Representers.{UserRepresenter, ActivityRepresenter}
4 alias Pleroma.Builders.{ActivityBuilder, UserBuilder}
5 alias Pleroma.{Repo, Activity, User, Object}
6 alias Pleroma.Web.ActivityPub.ActivityPub
7
8 import Pleroma.Factory
9
10 describe "POST /api/account/verify_credentials" do
11 setup [:valid_user]
12 test "without valid credentials", %{conn: conn} do
13 conn = post conn, "/api/account/verify_credentials.json"
14 assert json_response(conn, 403) == %{"error" => "Invalid credentials."}
15 end
16
17 test "with credentials", %{conn: conn, user: user} do
18 conn = conn
19 |> with_credentials(user.nickname, "test")
20 |> post("/api/account/verify_credentials.json")
21
22 assert json_response(conn, 200) == UserRepresenter.to_map(user)
23 end
24 end
25
26 describe "POST /statuses/update.json" do
27 setup [:valid_user]
28 test "without valid credentials", %{conn: conn} do
29 conn = post conn, "/api/statuses/update.json"
30 assert json_response(conn, 403) == %{"error" => "Invalid credentials."}
31 end
32
33 test "with credentials", %{conn: conn, user: user} do
34 conn_with_creds = conn |> with_credentials(user.nickname, "test")
35 request_path = "/api/statuses/update.json"
36
37 error_response = %{"request" => request_path,
38 "error" => "Client must provide a 'status' parameter with a value."}
39 conn = conn_with_creds |> post(request_path)
40 assert json_response(conn, 400) == error_response
41
42 conn = conn_with_creds |> post(request_path, %{ status: "" })
43 assert json_response(conn, 400) == error_response
44
45 conn = conn_with_creds |> post(request_path, %{ status: " " })
46 assert json_response(conn, 400) == error_response
47
48 conn = conn_with_creds |> post(request_path, %{ status: "Nice meme." })
49 assert json_response(conn, 200) == ActivityRepresenter.to_map(Repo.one(Activity), %{user: user})
50 end
51 end
52
53 describe "GET /statuses/public_timeline.json" do
54 test "returns statuses", %{conn: conn} do
55 {:ok, user} = UserBuilder.insert
56 activities = ActivityBuilder.insert_list(30, %{}, %{user: user})
57 ActivityBuilder.insert_list(10, %{}, %{user: user})
58 since_id = List.last(activities).id
59
60 conn = conn
61 |> get("/api/statuses/public_timeline.json", %{since_id: since_id})
62
63 response = json_response(conn, 200)
64
65 assert length(response) == 10
66 end
67 end
68
69 describe "GET /statuses/show/:id.json" do
70 test "returns one status", %{conn: conn} do
71 {:ok, user} = UserBuilder.insert
72 {:ok, activity} = ActivityBuilder.insert(%{}, %{user: user})
73 actor = Repo.get_by!(User, ap_id: activity.data["actor"])
74
75 conn = conn
76 |> get("/api/statuses/show/#{activity.id}.json")
77
78 response = json_response(conn, 200)
79
80 assert response == ActivityRepresenter.to_map(activity, %{user: actor})
81 end
82 end
83
84 describe "GET /statusnet/conversation/:id.json" do
85 test "returns the statuses in the conversation", %{conn: conn} do
86 {:ok, _user} = UserBuilder.insert
87 {:ok, _activity} = ActivityBuilder.insert(%{"context" => "2hu"})
88 {:ok, _activity_two} = ActivityBuilder.insert(%{"context" => "2hu"})
89 {:ok, _activity_three} = ActivityBuilder.insert(%{"context" => "3hu"})
90
91 {:ok, object} = Object.context_mapping("2hu") |> Repo.insert
92 conn = conn
93 |> get("/api/statusnet/conversation/#{object.id}.json")
94
95 response = json_response(conn, 200)
96
97 assert length(response) == 2
98 end
99 end
100
101 describe "GET /statuses/friends_timeline.json" do
102 setup [:valid_user]
103 test "without valid credentials", %{conn: conn} do
104 conn = get conn, "/api/statuses/friends_timeline.json"
105 assert json_response(conn, 403) == %{"error" => "Invalid credentials."}
106 end
107
108 test "with credentials", %{conn: conn, user: current_user} do
109 user = insert(:user)
110 activities = ActivityBuilder.insert_list(30, %{"to" => [User.ap_followers(user)]}, %{user: user})
111 returned_activities = ActivityBuilder.insert_list(10, %{"to" => [User.ap_followers(user)]}, %{user: user})
112 other_user = insert(:user)
113 ActivityBuilder.insert_list(10, %{}, %{user: other_user})
114 since_id = List.last(activities).id
115
116 current_user = Ecto.Changeset.change(current_user, following: [User.ap_followers(user)]) |> Repo.update!
117
118 conn = conn
119 |> with_credentials(current_user.nickname, "test")
120 |> get("/api/statuses/friends_timeline.json", %{since_id: since_id})
121
122 response = json_response(conn, 200)
123
124 assert length(response) == 10
125 assert response == Enum.map(returned_activities, fn (activity) -> ActivityRepresenter.to_map(activity, %{user: User.get_cached_by_ap_id(activity.data["actor"]), for: current_user}) end)
126 end
127 end
128
129 describe "GET /statuses/mentions.json" do
130 setup [:valid_user]
131 test "without valid credentials", %{conn: conn} do
132 conn = get conn, "/api/statuses/mentions.json"
133 assert json_response(conn, 403) == %{"error" => "Invalid credentials."}
134 end
135
136 test "with credentials", %{conn: conn, user: current_user} do
137 {:ok, activity} = ActivityBuilder.insert(%{"to" => [current_user.ap_id]}, %{user: current_user})
138
139 conn = conn
140 |> with_credentials(current_user.nickname, "test")
141 |> get("/api/statuses/mentions.json")
142
143 response = json_response(conn, 200)
144
145 assert length(response) == 1
146 assert Enum.at(response, 0) == ActivityRepresenter.to_map(activity, %{user: current_user, mentioned: [current_user]})
147 end
148 end
149
150 describe "GET /statuses/user_timeline.json" do
151 setup [:valid_user]
152 test "without any params", %{conn: conn} do
153 conn = get(conn, "/api/statuses/user_timeline.json")
154 assert json_response(conn, 400) == %{"error" => "You need to specify screen_name or user_id", "request" => "/api/statuses/user_timeline.json"}
155 end
156
157 test "with user_id", %{conn: conn} do
158 user = insert(:user)
159 {:ok, activity} = ActivityBuilder.insert(%{"id" => 1}, %{user: user})
160
161 conn = get(conn, "/api/statuses/user_timeline.json", %{"user_id" => user.id})
162 response = json_response(conn, 200)
163 assert length(response) == 1
164 assert Enum.at(response, 0) == ActivityRepresenter.to_map(activity, %{user: user})
165 end
166
167 test "with screen_name", %{conn: conn} do
168 user = insert(:user)
169 {:ok, activity} = ActivityBuilder.insert(%{"id" => 1}, %{user: user})
170
171 conn = get(conn, "/api/statuses/user_timeline.json", %{"screen_name" => user.nickname})
172 response = json_response(conn, 200)
173 assert length(response) == 1
174 assert Enum.at(response, 0) == ActivityRepresenter.to_map(activity, %{user: user})
175 end
176
177 test "with credentials", %{conn: conn, user: current_user} do
178 {:ok, activity} = ActivityBuilder.insert(%{"id" => 1}, %{user: current_user})
179 conn = conn
180 |> with_credentials(current_user.nickname, "test")
181 |> get("/api/statuses/user_timeline.json")
182
183 response = json_response(conn, 200)
184
185 assert length(response) == 1
186 assert Enum.at(response, 0) == ActivityRepresenter.to_map(activity, %{user: current_user})
187 end
188
189 test "with credentials with user_id", %{conn: conn, user: current_user} do
190 user = insert(:user)
191 {:ok, activity} = ActivityBuilder.insert(%{"id" => 1}, %{user: user})
192 conn = conn
193 |> with_credentials(current_user.nickname, "test")
194 |> get("/api/statuses/user_timeline.json", %{"user_id" => user.id})
195
196 response = json_response(conn, 200)
197
198 assert length(response) == 1
199 assert Enum.at(response, 0) == ActivityRepresenter.to_map(activity, %{user: user})
200 end
201
202 test "with credentials screen_name", %{conn: conn, user: current_user} do
203 user = insert(:user)
204 {:ok, activity} = ActivityBuilder.insert(%{"id" => 1}, %{user: user})
205 conn = conn
206 |> with_credentials(current_user.nickname, "test")
207 |> get("/api/statuses/user_timeline.json", %{"screen_name" => user.nickname})
208
209 response = json_response(conn, 200)
210
211 assert length(response) == 1
212 assert Enum.at(response, 0) == ActivityRepresenter.to_map(activity, %{user: user})
213 end
214 end
215
216 describe "POST /friendships/create.json" do
217 setup [:valid_user]
218 test "without valid credentials", %{conn: conn} do
219 conn = post conn, "/api/friendships/create.json"
220 assert json_response(conn, 403) == %{"error" => "Invalid credentials."}
221 end
222
223 test "with credentials", %{conn: conn, user: current_user} do
224 followed = insert(:user)
225
226 conn = conn
227 |> with_credentials(current_user.nickname, "test")
228 |> post("/api/friendships/create.json", %{user_id: followed.id})
229
230 current_user = Repo.get(User, current_user.id)
231 assert current_user.following == [User.ap_followers(followed)]
232 assert json_response(conn, 200) == UserRepresenter.to_map(followed, %{for: current_user})
233 end
234 end
235
236 describe "POST /friendships/destroy.json" do
237 setup [:valid_user]
238 test "without valid credentials", %{conn: conn} do
239 conn = post conn, "/api/friendships/destroy.json"
240 assert json_response(conn, 403) == %{"error" => "Invalid credentials."}
241 end
242
243 test "with credentials", %{conn: conn, user: current_user} do
244 followed = insert(:user)
245
246 {:ok, current_user} = User.follow(current_user, followed)
247 assert current_user.following == [User.ap_followers(followed)]
248
249 conn = conn
250 |> with_credentials(current_user.nickname, "test")
251 |> post("/api/friendships/destroy.json", %{user_id: followed.id})
252
253 current_user = Repo.get(User, current_user.id)
254 assert current_user.following == []
255 assert json_response(conn, 200) == UserRepresenter.to_map(followed, %{for: current_user})
256 end
257 end
258
259 describe "GET /help/test.json" do
260 test "returns \"ok\"", %{conn: conn} do
261 conn = get conn, "/api/help/test.json"
262 assert json_response(conn, 200) == "ok"
263 end
264 end
265
266 describe "POST /api/qvitter/update_avatar.json" do
267 setup [:valid_user]
268 test "without valid credentials", %{conn: conn} do
269 conn = post conn, "/api/qvitter/update_avatar.json"
270 assert json_response(conn, 403) == %{"error" => "Invalid credentials."}
271 end
272
273 test "with credentials", %{conn: conn, user: current_user} do
274 conn = conn
275 |> with_credentials(current_user.nickname, "test")
276 |> post("/api/qvitter/update_avatar.json", %{img: Pleroma.Web.ActivityPub.ActivityPubTest.data_uri})
277
278 current_user = Repo.get(User, current_user.id)
279 assert is_map(current_user.avatar)
280 assert json_response(conn, 200) == UserRepresenter.to_map(current_user, %{for: current_user})
281 end
282 end
283
284 describe "POST /api/favorites/create/:id" do
285 setup [:valid_user]
286 test "without valid credentials", %{conn: conn} do
287 note_activity = insert(:note_activity)
288 conn = post conn, "/api/favorites/create/#{note_activity.id}.json"
289 assert json_response(conn, 403) == %{"error" => "Invalid credentials."}
290 end
291
292 test "with credentials", %{conn: conn, user: current_user} do
293 note_activity = insert(:note_activity)
294
295 conn = conn
296 |> with_credentials(current_user.nickname, "test")
297 |> post("/api/favorites/create/#{note_activity.id}.json")
298
299 assert json_response(conn, 200)
300 end
301 end
302
303 describe "POST /api/favorites/destroy/:id" do
304 setup [:valid_user]
305 test "without valid credentials", %{conn: conn} do
306 note_activity = insert(:note_activity)
307 conn = post conn, "/api/favorites/destroy/#{note_activity.id}.json"
308 assert json_response(conn, 403) == %{"error" => "Invalid credentials."}
309 end
310
311 test "with credentials", %{conn: conn, user: current_user} do
312 note_activity = insert(:note_activity)
313 object = Object.get_by_ap_id(note_activity.data["object"]["id"])
314 ActivityPub.like(current_user, object)
315
316 conn = conn
317 |> with_credentials(current_user.nickname, "test")
318 |> post("/api/favorites/destroy/#{note_activity.id}.json")
319
320 assert json_response(conn, 200)
321 end
322 end
323
324 describe "POST /api/statuses/retweet/:id" do
325 setup [:valid_user]
326 test "without valid credentials", %{conn: conn} do
327 note_activity = insert(:note_activity)
328 conn = post conn, "/api/statuses/retweet/#{note_activity.id}.json"
329 assert json_response(conn, 403) == %{"error" => "Invalid credentials."}
330 end
331
332 test "with credentials", %{conn: conn, user: current_user} do
333 note_activity = insert(:note_activity)
334
335 request_path = "/api/statuses/retweet/#{note_activity.id}.json"
336
337 user = Repo.get_by(User, ap_id: note_activity.data["actor"])
338 response = conn
339 |> with_credentials(user.nickname, "test")
340 |> post(request_path)
341 assert json_response(response, 400) == %{"error" => "You cannot repeat your own notice.",
342 "request" => request_path}
343
344 response = conn
345 |> with_credentials(current_user.nickname, "test")
346 |> post(request_path)
347 activity = Repo.get(Activity, note_activity.id)
348 activity_user = Repo.get_by(User, ap_id: note_activity.data["actor"])
349 assert json_response(response, 200) == ActivityRepresenter.to_map(activity, %{user: activity_user, for: current_user})
350 end
351 end
352
353 describe "POST /api/account/register" do
354 test "it creates a new user", %{conn: conn} do
355 data = %{
356 "nickname" => "lain",
357 "email" => "lain@wired.jp",
358 "fullname" => "lain iwakura",
359 "bio" => "close the world.",
360 "password" => "bear",
361 "confirm" => "bear"
362 }
363
364 conn = conn
365 |> post("/api/account/register", data)
366
367 user = json_response(conn, 200)
368
369 fetched_user = Repo.get_by(User, nickname: "lain")
370 assert user == UserRepresenter.to_map(fetched_user)
371 end
372
373 test "it returns errors on a problem", %{conn: conn} do
374 data = %{
375 "email" => "lain@wired.jp",
376 "fullname" => "lain iwakura",
377 "bio" => "close the world.",
378 "password" => "bear",
379 "confirm" => "bear"
380 }
381
382 conn = conn
383 |> post("/api/account/register", data)
384
385 errors = json_response(conn, 400)
386
387 assert is_binary(errors["error"])
388 end
389 end
390
391 defp valid_user(_context) do
392 user = insert(:user)
393 [user: user]
394 end
395
396 defp with_credentials(conn, username, password) do
397 header_content = "Basic " <> Base.encode64("#{username}:#{password}")
398 put_req_header(conn, "authorization", header_content)
399 end
400
401 setup do
402 Supervisor.terminate_child(Pleroma.Supervisor, ConCache)
403 Supervisor.restart_child(Pleroma.Supervisor, ConCache)
404 :ok
405 end
406 end