2a1b5af94dad752970e084e1d63940bbfae22ec1
[akkoma] / lib / pleroma / user.ex
1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2021 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
4
5 defmodule Pleroma.User do
6 use Ecto.Schema
7
8 import Ecto.Changeset
9 import Ecto.Query
10 import Ecto, only: [assoc: 2]
11
12 alias Ecto.Multi
13 alias Pleroma.Activity
14 alias Pleroma.Config
15 alias Pleroma.Conversation.Participation
16 alias Pleroma.Delivery
17 alias Pleroma.EctoType.ActivityPub.ObjectValidators
18 alias Pleroma.Emoji
19 alias Pleroma.FollowingRelationship
20 alias Pleroma.Formatter
21 alias Pleroma.HTML
22 alias Pleroma.Keys
23 alias Pleroma.MFA
24 alias Pleroma.Notification
25 alias Pleroma.Object
26 alias Pleroma.Registration
27 alias Pleroma.Repo
28 alias Pleroma.User
29 alias Pleroma.UserRelationship
30 alias Pleroma.Web.ActivityPub.ActivityPub
31 alias Pleroma.Web.ActivityPub.Builder
32 alias Pleroma.Web.ActivityPub.Pipeline
33 alias Pleroma.Web.ActivityPub.Utils
34 alias Pleroma.Web.CommonAPI
35 alias Pleroma.Web.CommonAPI.Utils, as: CommonUtils
36 alias Pleroma.Web.Endpoint
37 alias Pleroma.Web.OAuth
38 alias Pleroma.Web.RelMe
39 alias Pleroma.Workers.BackgroundWorker
40
41 require Logger
42
43 @type t :: %__MODULE__{}
44 @type account_status ::
45 :active
46 | :deactivated
47 | :password_reset_pending
48 | :confirmation_pending
49 | :approval_pending
50 @primary_key {:id, FlakeId.Ecto.CompatType, autogenerate: true}
51
52 # credo:disable-for-next-line Credo.Check.Readability.MaxLineLength
53 @email_regex ~r/^[a-zA-Z0-9.!#$%&'*+\/=?^_`{|}~-]+@[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?(?:\.[a-zA-Z0-9](?:[a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?)*$/
54
55 @strict_local_nickname_regex ~r/^[a-zA-Z\d]+$/
56 @extended_local_nickname_regex ~r/^[a-zA-Z\d_-]+$/
57
58 # AP ID user relationships (blocks, mutes etc.)
59 # Format: [rel_type: [outgoing_rel: :outgoing_rel_target, incoming_rel: :incoming_rel_source]]
60 @user_relationships_config [
61 block: [
62 blocker_blocks: :blocked_users,
63 blockee_blocks: :blocker_users
64 ],
65 mute: [
66 muter_mutes: :muted_users,
67 mutee_mutes: :muter_users
68 ],
69 reblog_mute: [
70 reblog_muter_mutes: :reblog_muted_users,
71 reblog_mutee_mutes: :reblog_muter_users
72 ],
73 notification_mute: [
74 notification_muter_mutes: :notification_muted_users,
75 notification_mutee_mutes: :notification_muter_users
76 ],
77 # Note: `inverse_subscription` relationship is inverse: subscriber acts as relationship target
78 inverse_subscription: [
79 subscribee_subscriptions: :subscriber_users,
80 subscriber_subscriptions: :subscribee_users
81 ]
82 ]
83
84 @cachex Pleroma.Config.get([:cachex, :provider], Cachex)
85
86 schema "users" do
87 field(:bio, :string, default: "")
88 field(:raw_bio, :string)
89 field(:email, :string)
90 field(:name, :string)
91 field(:nickname, :string)
92 field(:password_hash, :string)
93 field(:password, :string, virtual: true)
94 field(:password_confirmation, :string, virtual: true)
95 field(:keys, :string)
96 field(:public_key, :string)
97 field(:ap_id, :string)
98 field(:avatar, :map, default: %{})
99 field(:local, :boolean, default: true)
100 field(:follower_address, :string)
101 field(:following_address, :string)
102 field(:featured_address, :string)
103 field(:search_rank, :float, virtual: true)
104 field(:search_type, :integer, virtual: true)
105 field(:tags, {:array, :string}, default: [])
106 field(:last_refreshed_at, :naive_datetime_usec)
107 field(:last_digest_emailed_at, :naive_datetime)
108 field(:banner, :map, default: %{})
109 field(:background, :map, default: %{})
110 field(:note_count, :integer, default: 0)
111 field(:follower_count, :integer, default: 0)
112 field(:following_count, :integer, default: 0)
113 field(:is_locked, :boolean, default: false)
114 field(:is_confirmed, :boolean, default: true)
115 field(:password_reset_pending, :boolean, default: false)
116 field(:is_approved, :boolean, default: true)
117 field(:registration_reason, :string, default: nil)
118 field(:confirmation_token, :string, default: nil)
119 field(:default_scope, :string, default: "public")
120 field(:domain_blocks, {:array, :string}, default: [])
121 field(:is_active, :boolean, default: true)
122 field(:no_rich_text, :boolean, default: false)
123 field(:ap_enabled, :boolean, default: false)
124 field(:is_moderator, :boolean, default: false)
125 field(:is_admin, :boolean, default: false)
126 field(:show_role, :boolean, default: true)
127 field(:mastofe_settings, :map, default: nil)
128 field(:uri, ObjectValidators.Uri, default: nil)
129 field(:hide_followers_count, :boolean, default: false)
130 field(:hide_follows_count, :boolean, default: false)
131 field(:hide_followers, :boolean, default: false)
132 field(:hide_follows, :boolean, default: false)
133 field(:hide_favorites, :boolean, default: true)
134 field(:email_notifications, :map, default: %{"digest" => false})
135 field(:mascot, :map, default: nil)
136 field(:emoji, :map, default: %{})
137 field(:pleroma_settings_store, :map, default: %{})
138 field(:fields, {:array, :map}, default: [])
139 field(:raw_fields, {:array, :map}, default: [])
140 field(:is_discoverable, :boolean, default: false)
141 field(:invisible, :boolean, default: false)
142 field(:allow_following_move, :boolean, default: true)
143 field(:skip_thread_containment, :boolean, default: false)
144 field(:actor_type, :string, default: "Person")
145 field(:also_known_as, {:array, ObjectValidators.ObjectID}, default: [])
146 field(:inbox, :string)
147 field(:shared_inbox, :string)
148 field(:last_active_at, :naive_datetime)
149 field(:disclose_client, :boolean, default: true)
150 field(:pinned_objects, :map, default: %{})
151 field(:is_suggested, :boolean, default: false)
152 field(:last_status_at, :naive_datetime)
153 field(:language, :string)
154
155 embeds_one(
156 :notification_settings,
157 Pleroma.User.NotificationSetting,
158 on_replace: :update
159 )
160
161 has_many(:notifications, Notification)
162 has_many(:registrations, Registration)
163 has_many(:deliveries, Delivery)
164
165 has_many(:outgoing_relationships, UserRelationship, foreign_key: :source_id)
166 has_many(:incoming_relationships, UserRelationship, foreign_key: :target_id)
167
168 for {relationship_type,
169 [
170 {outgoing_relation, outgoing_relation_target},
171 {incoming_relation, incoming_relation_source}
172 ]} <- @user_relationships_config do
173 # Definitions of `has_many` relations: :blocker_blocks, :muter_mutes, :reblog_muter_mutes,
174 # :notification_muter_mutes, :subscribee_subscriptions
175 has_many(outgoing_relation, UserRelationship,
176 foreign_key: :source_id,
177 where: [relationship_type: relationship_type]
178 )
179
180 # Definitions of `has_many` relations: :blockee_blocks, :mutee_mutes, :reblog_mutee_mutes,
181 # :notification_mutee_mutes, :subscriber_subscriptions
182 has_many(incoming_relation, UserRelationship,
183 foreign_key: :target_id,
184 where: [relationship_type: relationship_type]
185 )
186
187 # Definitions of `has_many` relations: :blocked_users, :muted_users, :reblog_muted_users,
188 # :notification_muted_users, :subscriber_users
189 has_many(outgoing_relation_target, through: [outgoing_relation, :target])
190
191 # Definitions of `has_many` relations: :blocker_users, :muter_users, :reblog_muter_users,
192 # :notification_muter_users, :subscribee_users
193 has_many(incoming_relation_source, through: [incoming_relation, :source])
194 end
195
196 embeds_one(
197 :multi_factor_authentication_settings,
198 MFA.Settings,
199 on_replace: :delete
200 )
201
202 timestamps()
203 end
204
205 for {_relationship_type, [{_outgoing_relation, outgoing_relation_target}, _]} <-
206 @user_relationships_config do
207 # `def blocked_users_relation/2`, `def muted_users_relation/2`,
208 # `def reblog_muted_users_relation/2`, `def notification_muted_users/2`,
209 # `def subscriber_users/2`
210 def unquote(:"#{outgoing_relation_target}_relation")(user, restrict_deactivated? \\ false) do
211 target_users_query = assoc(user, unquote(outgoing_relation_target))
212
213 if restrict_deactivated? do
214 target_users_query
215 |> User.Query.build(%{deactivated: false})
216 else
217 target_users_query
218 end
219 end
220
221 # `def blocked_users/2`, `def muted_users/2`, `def reblog_muted_users/2`,
222 # `def notification_muted_users/2`, `def subscriber_users/2`
223 def unquote(outgoing_relation_target)(user, restrict_deactivated? \\ false) do
224 __MODULE__
225 |> apply(unquote(:"#{outgoing_relation_target}_relation"), [
226 user,
227 restrict_deactivated?
228 ])
229 |> Repo.all()
230 end
231
232 # `def blocked_users_ap_ids/2`, `def muted_users_ap_ids/2`, `def reblog_muted_users_ap_ids/2`,
233 # `def notification_muted_users_ap_ids/2`, `def subscriber_users_ap_ids/2`
234 def unquote(:"#{outgoing_relation_target}_ap_ids")(user, restrict_deactivated? \\ false) do
235 __MODULE__
236 |> apply(unquote(:"#{outgoing_relation_target}_relation"), [
237 user,
238 restrict_deactivated?
239 ])
240 |> select([u], u.ap_id)
241 |> Repo.all()
242 end
243 end
244
245 def cached_blocked_users_ap_ids(user) do
246 @cachex.fetch!(:user_cache, "blocked_users_ap_ids:#{user.ap_id}", fn _ ->
247 blocked_users_ap_ids(user)
248 end)
249 end
250
251 def cached_muted_users_ap_ids(user) do
252 @cachex.fetch!(:user_cache, "muted_users_ap_ids:#{user.ap_id}", fn _ ->
253 muted_users_ap_ids(user)
254 end)
255 end
256
257 defdelegate following_count(user), to: FollowingRelationship
258 defdelegate following(user), to: FollowingRelationship
259 defdelegate following?(follower, followed), to: FollowingRelationship
260 defdelegate following_ap_ids(user), to: FollowingRelationship
261 defdelegate get_follow_requests(user), to: FollowingRelationship
262 defdelegate search(query, opts \\ []), to: User.Search
263
264 @doc """
265 Dumps Flake Id to SQL-compatible format (16-byte UUID).
266 E.g. "9pQtDGXuq4p3VlcJEm" -> <<0, 0, 1, 110, 179, 218, 42, 92, 213, 41, 44, 227, 95, 213, 0, 0>>
267 """
268 def binary_id(source_id) when is_binary(source_id) do
269 with {:ok, dumped_id} <- FlakeId.Ecto.CompatType.dump(source_id) do
270 dumped_id
271 else
272 _ -> source_id
273 end
274 end
275
276 def binary_id(source_ids) when is_list(source_ids) do
277 Enum.map(source_ids, &binary_id/1)
278 end
279
280 def binary_id(%User{} = user), do: binary_id(user.id)
281
282 @doc "Returns status account"
283 @spec account_status(User.t()) :: account_status()
284 def account_status(%User{is_active: false}), do: :deactivated
285 def account_status(%User{password_reset_pending: true}), do: :password_reset_pending
286 def account_status(%User{local: true, is_approved: false}), do: :approval_pending
287 def account_status(%User{local: true, is_confirmed: false}), do: :confirmation_pending
288 def account_status(%User{}), do: :active
289
290 @spec visible_for(User.t(), User.t() | nil) ::
291 :visible
292 | :invisible
293 | :restricted_unauthenticated
294 | :deactivated
295 | :confirmation_pending
296 def visible_for(user, for_user \\ nil)
297
298 def visible_for(%User{invisible: true}, _), do: :invisible
299
300 def visible_for(%User{id: user_id}, %User{id: user_id}), do: :visible
301
302 def visible_for(%User{} = user, nil) do
303 if restrict_unauthenticated?(user) do
304 :restrict_unauthenticated
305 else
306 visible_account_status(user)
307 end
308 end
309
310 def visible_for(%User{} = user, for_user) do
311 if superuser?(for_user) do
312 :visible
313 else
314 visible_account_status(user)
315 end
316 end
317
318 def visible_for(_, _), do: :invisible
319
320 defp restrict_unauthenticated?(%User{local: true}) do
321 Config.restrict_unauthenticated_access?(:profiles, :local)
322 end
323
324 defp restrict_unauthenticated?(%User{local: _}) do
325 Config.restrict_unauthenticated_access?(:profiles, :remote)
326 end
327
328 defp visible_account_status(user) do
329 status = account_status(user)
330
331 if status in [:active, :password_reset_pending] do
332 :visible
333 else
334 status
335 end
336 end
337
338 @spec superuser?(User.t()) :: boolean()
339 def superuser?(%User{local: true, is_admin: true}), do: true
340 def superuser?(%User{local: true, is_moderator: true}), do: true
341 def superuser?(_), do: false
342
343 @spec invisible?(User.t()) :: boolean()
344 def invisible?(%User{invisible: true}), do: true
345 def invisible?(_), do: false
346
347 def avatar_url(user, options \\ []) do
348 case user.avatar do
349 %{"url" => [%{"href" => href} | _]} ->
350 href
351
352 _ ->
353 unless options[:no_default] do
354 Config.get([:assets, :default_user_avatar], "#{Endpoint.url()}/images/avi.png")
355 end
356 end
357 end
358
359 def banner_url(user, options \\ []) do
360 case user.banner do
361 %{"url" => [%{"href" => href} | _]} -> href
362 _ -> !options[:no_default] && "#{Endpoint.url()}/images/banner.png"
363 end
364 end
365
366 # Should probably be renamed or removed
367 @spec ap_id(User.t()) :: String.t()
368 def ap_id(%User{nickname: nickname}), do: "#{Endpoint.url()}/users/#{nickname}"
369
370 @spec ap_followers(User.t()) :: String.t()
371 def ap_followers(%User{follower_address: fa}) when is_binary(fa), do: fa
372 def ap_followers(%User{} = user), do: "#{ap_id(user)}/followers"
373
374 @spec ap_following(User.t()) :: String.t()
375 def ap_following(%User{following_address: fa}) when is_binary(fa), do: fa
376 def ap_following(%User{} = user), do: "#{ap_id(user)}/following"
377
378 @spec ap_featured_collection(User.t()) :: String.t()
379 def ap_featured_collection(%User{featured_address: fa}) when is_binary(fa), do: fa
380
381 def ap_featured_collection(%User{} = user), do: "#{ap_id(user)}/collections/featured"
382
383 defp truncate_fields_param(params) do
384 if Map.has_key?(params, :fields) do
385 Map.put(params, :fields, Enum.map(params[:fields], &truncate_field/1))
386 else
387 params
388 end
389 end
390
391 defp truncate_if_exists(params, key, max_length) do
392 if Map.has_key?(params, key) and is_binary(params[key]) do
393 {value, _chopped} = String.split_at(params[key], max_length)
394 Map.put(params, key, value)
395 else
396 params
397 end
398 end
399
400 defp fix_follower_address(%{follower_address: _, following_address: _} = params), do: params
401
402 defp fix_follower_address(%{nickname: nickname} = params),
403 do: Map.put(params, :follower_address, ap_followers(%User{nickname: nickname}))
404
405 defp fix_follower_address(params), do: params
406
407 def remote_user_changeset(struct \\ %User{local: false}, params) do
408 bio_limit = Config.get([:instance, :user_bio_length], 5000)
409 name_limit = Config.get([:instance, :user_name_length], 100)
410
411 name =
412 case params[:name] do
413 name when is_binary(name) and byte_size(name) > 0 -> name
414 _ -> params[:nickname]
415 end
416
417 params =
418 params
419 |> Map.put(:name, name)
420 |> Map.put_new(:last_refreshed_at, NaiveDateTime.utc_now())
421 |> truncate_if_exists(:name, name_limit)
422 |> truncate_if_exists(:bio, bio_limit)
423 |> truncate_fields_param()
424 |> fix_follower_address()
425
426 struct
427 |> cast(
428 params,
429 [
430 :bio,
431 :emoji,
432 :ap_id,
433 :inbox,
434 :shared_inbox,
435 :nickname,
436 :public_key,
437 :avatar,
438 :ap_enabled,
439 :banner,
440 :is_locked,
441 :last_refreshed_at,
442 :uri,
443 :follower_address,
444 :following_address,
445 :featured_address,
446 :hide_followers,
447 :hide_follows,
448 :hide_followers_count,
449 :hide_follows_count,
450 :follower_count,
451 :fields,
452 :following_count,
453 :is_discoverable,
454 :invisible,
455 :actor_type,
456 :also_known_as,
457 :pinned_objects
458 ]
459 )
460 |> cast(params, [:name], empty_values: [])
461 |> validate_required([:ap_id])
462 |> validate_required([:name], trim: false)
463 |> unique_constraint(:nickname)
464 |> validate_format(:nickname, @email_regex)
465 |> validate_length(:bio, max: bio_limit)
466 |> validate_length(:name, max: name_limit)
467 |> validate_fields(true)
468 |> validate_non_local()
469 end
470
471 defp validate_non_local(cng) do
472 local? = get_field(cng, :local)
473
474 if local? do
475 cng
476 |> add_error(:local, "User is local, can't update with this changeset.")
477 else
478 cng
479 end
480 end
481
482 def update_changeset(struct, params \\ %{}) do
483 bio_limit = Config.get([:instance, :user_bio_length], 5000)
484 name_limit = Config.get([:instance, :user_name_length], 100)
485
486 struct
487 |> cast(
488 params,
489 [
490 :bio,
491 :raw_bio,
492 :name,
493 :emoji,
494 :avatar,
495 :public_key,
496 :inbox,
497 :shared_inbox,
498 :is_locked,
499 :no_rich_text,
500 :default_scope,
501 :banner,
502 :hide_follows,
503 :hide_followers,
504 :hide_followers_count,
505 :hide_follows_count,
506 :hide_favorites,
507 :allow_following_move,
508 :also_known_as,
509 :background,
510 :show_role,
511 :skip_thread_containment,
512 :fields,
513 :raw_fields,
514 :pleroma_settings_store,
515 :is_discoverable,
516 :actor_type,
517 :disclose_client
518 ]
519 )
520 |> unique_constraint(:nickname)
521 |> validate_format(:nickname, local_nickname_regex())
522 |> validate_length(:bio, max: bio_limit)
523 |> validate_length(:name, min: 1, max: name_limit)
524 |> validate_inclusion(:actor_type, ["Person", "Service"])
525 |> put_fields()
526 |> put_emoji()
527 |> put_change_if_present(:bio, &{:ok, parse_bio(&1, struct)})
528 |> put_change_if_present(:avatar, &put_upload(&1, :avatar))
529 |> put_change_if_present(:banner, &put_upload(&1, :banner))
530 |> put_change_if_present(:background, &put_upload(&1, :background))
531 |> put_change_if_present(
532 :pleroma_settings_store,
533 &{:ok, Map.merge(struct.pleroma_settings_store, &1)}
534 )
535 |> validate_fields(false)
536 end
537
538 defp put_fields(changeset) do
539 if raw_fields = get_change(changeset, :raw_fields) do
540 raw_fields =
541 raw_fields
542 |> Enum.filter(fn %{"name" => n} -> n != "" end)
543
544 fields =
545 raw_fields
546 |> Enum.map(fn f -> Map.update!(f, "value", &parse_fields(&1)) end)
547
548 changeset
549 |> put_change(:raw_fields, raw_fields)
550 |> put_change(:fields, fields)
551 else
552 changeset
553 end
554 end
555
556 defp parse_fields(value) do
557 value
558 |> Formatter.linkify(mentions_format: :full)
559 |> elem(0)
560 end
561
562 defp put_emoji(changeset) do
563 emojified_fields = [:bio, :name, :raw_fields]
564
565 if Enum.any?(changeset.changes, fn {k, _} -> k in emojified_fields end) do
566 bio = Emoji.Formatter.get_emoji_map(get_field(changeset, :bio))
567 name = Emoji.Formatter.get_emoji_map(get_field(changeset, :name))
568
569 emoji = Map.merge(bio, name)
570
571 emoji =
572 changeset
573 |> get_field(:raw_fields)
574 |> Enum.reduce(emoji, fn x, acc ->
575 Map.merge(acc, Emoji.Formatter.get_emoji_map(x["name"] <> x["value"]))
576 end)
577
578 put_change(changeset, :emoji, emoji)
579 else
580 changeset
581 end
582 end
583
584 defp put_change_if_present(changeset, map_field, value_function) do
585 with {:ok, value} <- fetch_change(changeset, map_field),
586 {:ok, new_value} <- value_function.(value) do
587 put_change(changeset, map_field, new_value)
588 else
589 _ -> changeset
590 end
591 end
592
593 defp put_upload(value, type) do
594 with %Plug.Upload{} <- value,
595 {:ok, object} <- ActivityPub.upload(value, type: type) do
596 {:ok, object.data}
597 end
598 end
599
600 def update_as_admin_changeset(struct, params) do
601 struct
602 |> update_changeset(params)
603 |> cast(params, [:email])
604 |> delete_change(:also_known_as)
605 |> unique_constraint(:email)
606 |> validate_format(:email, @email_regex)
607 |> validate_inclusion(:actor_type, ["Person", "Service"])
608 end
609
610 @spec update_as_admin(User.t(), map()) :: {:ok, User.t()} | {:error, Changeset.t()}
611 def update_as_admin(user, params) do
612 params = Map.put(params, "password_confirmation", params["password"])
613 changeset = update_as_admin_changeset(user, params)
614
615 if params["password"] do
616 reset_password(user, changeset, params)
617 else
618 User.update_and_set_cache(changeset)
619 end
620 end
621
622 def password_update_changeset(struct, params) do
623 struct
624 |> cast(params, [:password, :password_confirmation])
625 |> validate_required([:password, :password_confirmation])
626 |> validate_confirmation(:password)
627 |> put_password_hash()
628 |> put_change(:password_reset_pending, false)
629 end
630
631 @spec reset_password(User.t(), map()) :: {:ok, User.t()} | {:error, Changeset.t()}
632 def reset_password(%User{} = user, params) do
633 reset_password(user, user, params)
634 end
635
636 def reset_password(%User{id: user_id} = user, struct, params) do
637 multi =
638 Multi.new()
639 |> Multi.update(:user, password_update_changeset(struct, params))
640 |> Multi.delete_all(:tokens, OAuth.Token.Query.get_by_user(user_id))
641 |> Multi.delete_all(:auth, OAuth.Authorization.delete_by_user_query(user))
642
643 case Repo.transaction(multi) do
644 {:ok, %{user: user} = _} -> set_cache(user)
645 {:error, _, changeset, _} -> {:error, changeset}
646 end
647 end
648
649 def update_password_reset_pending(user, value) do
650 user
651 |> change()
652 |> put_change(:password_reset_pending, value)
653 |> update_and_set_cache()
654 end
655
656 def force_password_reset_async(user) do
657 BackgroundWorker.enqueue("force_password_reset", %{"user_id" => user.id})
658 end
659
660 @spec force_password_reset(User.t()) :: {:ok, User.t()} | {:error, Ecto.Changeset.t()}
661 def force_password_reset(user), do: update_password_reset_pending(user, true)
662
663 # Used to auto-register LDAP accounts which won't have a password hash stored locally
664 def register_changeset_ldap(struct, params = %{password: password})
665 when is_nil(password) do
666 params =
667 if Map.has_key?(params, :email) do
668 Map.put_new(params, :email, params[:email])
669 else
670 params
671 end
672
673 struct
674 |> cast(params, [
675 :name,
676 :nickname,
677 :email
678 ])
679 |> validate_required([:name, :nickname])
680 |> unique_constraint(:nickname)
681 |> validate_exclusion(:nickname, Config.get([User, :restricted_nicknames]))
682 |> validate_format(:nickname, local_nickname_regex())
683 |> put_ap_id()
684 |> unique_constraint(:ap_id)
685 |> put_following_and_follower_and_featured_address()
686 end
687
688 def register_changeset(struct, params \\ %{}, opts \\ []) do
689 bio_limit = Config.get([:instance, :user_bio_length], 5000)
690 name_limit = Config.get([:instance, :user_name_length], 100)
691 reason_limit = Config.get([:instance, :registration_reason_length], 500)
692
693 confirmed? =
694 if is_nil(opts[:confirmed]) do
695 !Config.get([:instance, :account_activation_required])
696 else
697 opts[:confirmed]
698 end
699
700 approved? =
701 if is_nil(opts[:approved]) do
702 !Config.get([:instance, :account_approval_required])
703 else
704 opts[:approved]
705 end
706
707 struct
708 |> confirmation_changeset(set_confirmation: confirmed?)
709 |> approval_changeset(set_approval: approved?)
710 |> cast(params, [
711 :bio,
712 :raw_bio,
713 :email,
714 :name,
715 :nickname,
716 :password,
717 :password_confirmation,
718 :emoji,
719 :registration_reason,
720 :language
721 ])
722 |> validate_required([:name, :nickname, :password, :password_confirmation])
723 |> validate_confirmation(:password)
724 |> unique_constraint(:email)
725 |> validate_format(:email, @email_regex)
726 |> validate_change(:email, fn :email, email ->
727 valid? =
728 Config.get([User, :email_blacklist])
729 |> Enum.all?(fn blacklisted_domain ->
730 !String.ends_with?(email, ["@" <> blacklisted_domain, "." <> blacklisted_domain])
731 end)
732
733 if valid?, do: [], else: [email: "Invalid email"]
734 end)
735 |> unique_constraint(:nickname)
736 |> validate_exclusion(:nickname, Config.get([User, :restricted_nicknames]))
737 |> validate_format(:nickname, local_nickname_regex())
738 |> validate_length(:bio, max: bio_limit)
739 |> validate_length(:name, min: 1, max: name_limit)
740 |> validate_length(:registration_reason, max: reason_limit)
741 |> maybe_validate_required_email(opts[:external])
742 |> put_password_hash
743 |> put_ap_id()
744 |> unique_constraint(:ap_id)
745 |> put_following_and_follower_and_featured_address()
746 end
747
748 def maybe_validate_required_email(changeset, true), do: changeset
749
750 def maybe_validate_required_email(changeset, _) do
751 if Config.get([:instance, :account_activation_required]) do
752 validate_required(changeset, [:email])
753 else
754 changeset
755 end
756 end
757
758 def put_ap_id(changeset) do
759 ap_id = ap_id(%User{nickname: get_field(changeset, :nickname)})
760 put_change(changeset, :ap_id, ap_id)
761 end
762
763 def put_following_and_follower_and_featured_address(changeset) do
764 user = %User{nickname: get_field(changeset, :nickname)}
765 followers = ap_followers(user)
766 following = ap_following(user)
767 featured = ap_featured_collection(user)
768
769 changeset
770 |> put_change(:follower_address, followers)
771 |> put_change(:following_address, following)
772 |> put_change(:featured_address, featured)
773 end
774
775 defp autofollow_users(user) do
776 candidates = Config.get([:instance, :autofollowed_nicknames])
777
778 autofollowed_users =
779 User.Query.build(%{nickname: candidates, local: true, is_active: true})
780 |> Repo.all()
781
782 follow_all(user, autofollowed_users)
783 end
784
785 defp autofollowing_users(user) do
786 candidates = Config.get([:instance, :autofollowing_nicknames])
787
788 User.Query.build(%{nickname: candidates, local: true, deactivated: false})
789 |> Repo.all()
790 |> Enum.each(&follow(&1, user, :follow_accept))
791
792 {:ok, :success}
793 end
794
795 @doc "Inserts provided changeset, performs post-registration actions (confirmation email sending etc.)"
796 def register(%Ecto.Changeset{} = changeset) do
797 with {:ok, user} <- Repo.insert(changeset) do
798 post_register_action(user)
799 end
800 end
801
802 def post_register_action(%User{is_confirmed: false} = user) do
803 with {:ok, _} <- maybe_send_confirmation_email(user) do
804 {:ok, user}
805 end
806 end
807
808 def post_register_action(%User{is_approved: false} = user) do
809 with {:ok, _} <- send_user_approval_email(user),
810 {:ok, _} <- send_admin_approval_emails(user) do
811 {:ok, user}
812 end
813 end
814
815 def post_register_action(%User{is_approved: true, is_confirmed: true} = user) do
816 with {:ok, user} <- autofollow_users(user),
817 {:ok, _} <- autofollowing_users(user),
818 {:ok, user} <- set_cache(user),
819 {:ok, _} <- maybe_send_registration_email(user),
820 {:ok, _} <- maybe_send_welcome_email(user),
821 {:ok, _} <- maybe_send_welcome_message(user) do
822 {:ok, user}
823 end
824 end
825
826 defp send_user_approval_email(user) do
827 user
828 |> Pleroma.Emails.UserEmail.approval_pending_email()
829 |> Pleroma.Emails.Mailer.deliver_async()
830
831 {:ok, :enqueued}
832 end
833
834 defp send_admin_approval_emails(user) do
835 all_superusers()
836 |> Enum.filter(fn user -> not is_nil(user.email) end)
837 |> Enum.each(fn superuser ->
838 superuser
839 |> Pleroma.Emails.AdminEmail.new_unapproved_registration(user)
840 |> Pleroma.Emails.Mailer.deliver_async()
841 end)
842
843 {:ok, :enqueued}
844 end
845
846 defp maybe_send_welcome_message(user) do
847 if User.WelcomeMessage.enabled?() do
848 User.WelcomeMessage.post_message(user)
849 {:ok, :enqueued}
850 else
851 {:ok, :noop}
852 end
853 end
854
855 defp maybe_send_welcome_email(%User{email: email} = user) when is_binary(email) do
856 if User.WelcomeEmail.enabled?() do
857 User.WelcomeEmail.send_email(user)
858 {:ok, :enqueued}
859 else
860 {:ok, :noop}
861 end
862 end
863
864 defp maybe_send_welcome_email(_), do: {:ok, :noop}
865
866 @spec maybe_send_confirmation_email(User.t()) :: {:ok, :enqueued | :noop}
867 def maybe_send_confirmation_email(%User{is_confirmed: false, email: email} = user)
868 when is_binary(email) do
869 if Config.get([:instance, :account_activation_required]) do
870 send_confirmation_email(user)
871 {:ok, :enqueued}
872 else
873 {:ok, :noop}
874 end
875 end
876
877 def maybe_send_confirmation_email(_), do: {:ok, :noop}
878
879 @spec send_confirmation_email(Uset.t()) :: User.t()
880 def send_confirmation_email(%User{} = user) do
881 user
882 |> Pleroma.Emails.UserEmail.account_confirmation_email()
883 |> Pleroma.Emails.Mailer.deliver_async()
884
885 user
886 end
887
888 @spec maybe_send_registration_email(User.t()) :: {:ok, :enqueued | :noop}
889 defp maybe_send_registration_email(%User{email: email} = user) when is_binary(email) do
890 with false <- User.WelcomeEmail.enabled?(),
891 false <- Config.get([:instance, :account_activation_required], false),
892 false <- Config.get([:instance, :account_approval_required], false) do
893 user
894 |> Pleroma.Emails.UserEmail.successful_registration_email()
895 |> Pleroma.Emails.Mailer.deliver_async()
896
897 {:ok, :enqueued}
898 else
899 _ ->
900 {:ok, :noop}
901 end
902 end
903
904 defp maybe_send_registration_email(_), do: {:ok, :noop}
905
906 def needs_update?(%User{local: true}), do: false
907
908 def needs_update?(%User{local: false, last_refreshed_at: nil}), do: true
909
910 def needs_update?(%User{local: false} = user) do
911 NaiveDateTime.diff(NaiveDateTime.utc_now(), user.last_refreshed_at) >= 86_400
912 end
913
914 def needs_update?(_), do: true
915
916 @spec maybe_direct_follow(User.t(), User.t()) :: {:ok, User.t()} | {:error, String.t()}
917
918 # "Locked" (self-locked) users demand explicit authorization of follow requests
919 def maybe_direct_follow(%User{} = follower, %User{local: true, is_locked: true} = followed) do
920 follow(follower, followed, :follow_pending)
921 end
922
923 def maybe_direct_follow(%User{} = follower, %User{local: true} = followed) do
924 follow(follower, followed)
925 end
926
927 def maybe_direct_follow(%User{} = follower, %User{} = followed) do
928 if not ap_enabled?(followed) do
929 follow(follower, followed)
930 else
931 {:ok, follower, followed}
932 end
933 end
934
935 @doc "A mass follow for local users. Respects blocks in both directions but does not create activities."
936 @spec follow_all(User.t(), list(User.t())) :: {atom(), User.t()}
937 def follow_all(follower, followeds) do
938 followeds
939 |> Enum.reject(fn followed -> blocks?(follower, followed) || blocks?(followed, follower) end)
940 |> Enum.each(&follow(follower, &1, :follow_accept))
941
942 set_cache(follower)
943 end
944
945 def follow(%User{} = follower, %User{} = followed, state \\ :follow_accept) do
946 deny_follow_blocked = Config.get([:user, :deny_follow_blocked])
947
948 cond do
949 not followed.is_active ->
950 {:error, "Could not follow user: #{followed.nickname} is deactivated."}
951
952 deny_follow_blocked and blocks?(followed, follower) ->
953 {:error, "Could not follow user: #{followed.nickname} blocked you."}
954
955 true ->
956 FollowingRelationship.follow(follower, followed, state)
957 end
958 end
959
960 def unfollow(%User{ap_id: ap_id}, %User{ap_id: ap_id}) do
961 {:error, "Not subscribed!"}
962 end
963
964 @spec unfollow(User.t(), User.t()) :: {:ok, User.t(), Activity.t()} | {:error, String.t()}
965 def unfollow(%User{} = follower, %User{} = followed) do
966 case do_unfollow(follower, followed) do
967 {:ok, follower, followed} ->
968 {:ok, follower, Utils.fetch_latest_follow(follower, followed)}
969
970 error ->
971 error
972 end
973 end
974
975 @spec do_unfollow(User.t(), User.t()) :: {:ok, User.t(), User.t()} | {:error, String.t()}
976 defp do_unfollow(%User{} = follower, %User{} = followed) do
977 case get_follow_state(follower, followed) do
978 state when state in [:follow_pending, :follow_accept] ->
979 FollowingRelationship.unfollow(follower, followed)
980
981 nil ->
982 {:error, "Not subscribed!"}
983 end
984 end
985
986 @doc "Returns follow state as Pleroma.FollowingRelationship.State value"
987 def get_follow_state(%User{} = follower, %User{} = following) do
988 following_relationship = FollowingRelationship.get(follower, following)
989 get_follow_state(follower, following, following_relationship)
990 end
991
992 def get_follow_state(
993 %User{} = follower,
994 %User{} = following,
995 following_relationship
996 ) do
997 case {following_relationship, following.local} do
998 {nil, false} ->
999 case Utils.fetch_latest_follow(follower, following) do
1000 %Activity{data: %{"state" => state}} when state in ["pending", "accept"] ->
1001 FollowingRelationship.state_to_enum(state)
1002
1003 _ ->
1004 nil
1005 end
1006
1007 {%{state: state}, _} ->
1008 state
1009
1010 {nil, _} ->
1011 nil
1012 end
1013 end
1014
1015 def locked?(%User{} = user) do
1016 user.is_locked || false
1017 end
1018
1019 def get_by_id(id) do
1020 Repo.get_by(User, id: id)
1021 end
1022
1023 def get_by_ap_id(ap_id) do
1024 Repo.get_by(User, ap_id: ap_id)
1025 end
1026
1027 def get_all_by_ap_id(ap_ids) do
1028 from(u in __MODULE__,
1029 where: u.ap_id in ^ap_ids
1030 )
1031 |> Repo.all()
1032 end
1033
1034 def get_all_by_ids(ids) do
1035 from(u in __MODULE__, where: u.id in ^ids)
1036 |> Repo.all()
1037 end
1038
1039 # This is mostly an SPC migration fix. This guesses the user nickname by taking the last part
1040 # of the ap_id and the domain and tries to get that user
1041 def get_by_guessed_nickname(ap_id) do
1042 domain = URI.parse(ap_id).host
1043 name = List.last(String.split(ap_id, "/"))
1044 nickname = "#{name}@#{domain}"
1045
1046 get_cached_by_nickname(nickname)
1047 end
1048
1049 def set_cache({:ok, user}), do: set_cache(user)
1050 def set_cache({:error, err}), do: {:error, err}
1051
1052 def set_cache(%User{} = user) do
1053 @cachex.put(:user_cache, "ap_id:#{user.ap_id}", user)
1054 @cachex.put(:user_cache, "nickname:#{user.nickname}", user)
1055 @cachex.put(:user_cache, "friends_ap_ids:#{user.nickname}", get_user_friends_ap_ids(user))
1056 {:ok, user}
1057 end
1058
1059 def update_and_set_cache(struct, params) do
1060 struct
1061 |> update_changeset(params)
1062 |> update_and_set_cache()
1063 end
1064
1065 def update_and_set_cache(%{data: %Pleroma.User{} = user} = changeset) do
1066 was_superuser_before_update = User.superuser?(user)
1067
1068 with {:ok, user} <- Repo.update(changeset, stale_error_field: :id) do
1069 set_cache(user)
1070 end
1071 |> maybe_remove_report_notifications(was_superuser_before_update)
1072 end
1073
1074 defp maybe_remove_report_notifications({:ok, %Pleroma.User{} = user} = result, true) do
1075 if not User.superuser?(user),
1076 do: user |> Notification.destroy_multiple_from_types(["pleroma:report"])
1077
1078 result
1079 end
1080
1081 defp maybe_remove_report_notifications(result, _) do
1082 result
1083 end
1084
1085 def get_user_friends_ap_ids(user) do
1086 from(u in User.get_friends_query(user), select: u.ap_id)
1087 |> Repo.all()
1088 end
1089
1090 @spec get_cached_user_friends_ap_ids(User.t()) :: [String.t()]
1091 def get_cached_user_friends_ap_ids(user) do
1092 @cachex.fetch!(:user_cache, "friends_ap_ids:#{user.ap_id}", fn _ ->
1093 get_user_friends_ap_ids(user)
1094 end)
1095 end
1096
1097 def invalidate_cache(user) do
1098 @cachex.del(:user_cache, "ap_id:#{user.ap_id}")
1099 @cachex.del(:user_cache, "nickname:#{user.nickname}")
1100 @cachex.del(:user_cache, "friends_ap_ids:#{user.ap_id}")
1101 @cachex.del(:user_cache, "blocked_users_ap_ids:#{user.ap_id}")
1102 @cachex.del(:user_cache, "muted_users_ap_ids:#{user.ap_id}")
1103 end
1104
1105 @spec get_cached_by_ap_id(String.t()) :: User.t() | nil
1106 def get_cached_by_ap_id(ap_id) do
1107 key = "ap_id:#{ap_id}"
1108
1109 with {:ok, nil} <- @cachex.get(:user_cache, key),
1110 user when not is_nil(user) <- get_by_ap_id(ap_id),
1111 {:ok, true} <- @cachex.put(:user_cache, key, user) do
1112 user
1113 else
1114 {:ok, user} -> user
1115 nil -> nil
1116 end
1117 end
1118
1119 def get_cached_by_id(id) do
1120 key = "id:#{id}"
1121
1122 ap_id =
1123 @cachex.fetch!(:user_cache, key, fn _ ->
1124 user = get_by_id(id)
1125
1126 if user do
1127 @cachex.put(:user_cache, "ap_id:#{user.ap_id}", user)
1128 {:commit, user.ap_id}
1129 else
1130 {:ignore, ""}
1131 end
1132 end)
1133
1134 get_cached_by_ap_id(ap_id)
1135 end
1136
1137 def get_cached_by_nickname(nickname) do
1138 key = "nickname:#{nickname}"
1139
1140 @cachex.fetch!(:user_cache, key, fn _ ->
1141 case get_or_fetch_by_nickname(nickname) do
1142 {:ok, user} -> {:commit, user}
1143 {:error, _error} -> {:ignore, nil}
1144 end
1145 end)
1146 end
1147
1148 def get_cached_by_nickname_or_id(nickname_or_id, opts \\ []) do
1149 restrict_to_local = Config.get([:instance, :limit_to_local_content])
1150
1151 cond do
1152 is_integer(nickname_or_id) or FlakeId.flake_id?(nickname_or_id) ->
1153 get_cached_by_id(nickname_or_id) || get_cached_by_nickname(nickname_or_id)
1154
1155 restrict_to_local == false or not String.contains?(nickname_or_id, "@") ->
1156 get_cached_by_nickname(nickname_or_id)
1157
1158 restrict_to_local == :unauthenticated and match?(%User{}, opts[:for]) ->
1159 get_cached_by_nickname(nickname_or_id)
1160
1161 true ->
1162 nil
1163 end
1164 end
1165
1166 @spec get_by_nickname(String.t()) :: User.t() | nil
1167 def get_by_nickname(nickname) do
1168 Repo.get_by(User, nickname: nickname) ||
1169 if Regex.match?(~r(@#{Pleroma.Web.Endpoint.host()})i, nickname) do
1170 Repo.get_by(User, nickname: local_nickname(nickname))
1171 end
1172 end
1173
1174 def get_by_email(email), do: Repo.get_by(User, email: email)
1175
1176 def get_by_nickname_or_email(nickname_or_email) do
1177 get_by_nickname(nickname_or_email) || get_by_email(nickname_or_email)
1178 end
1179
1180 def fetch_by_nickname(nickname), do: ActivityPub.make_user_from_nickname(nickname)
1181
1182 def get_or_fetch_by_nickname(nickname) do
1183 with %User{} = user <- get_by_nickname(nickname) do
1184 {:ok, user}
1185 else
1186 _e ->
1187 with [_nick, _domain] <- String.split(nickname, "@"),
1188 {:ok, user} <- fetch_by_nickname(nickname) do
1189 {:ok, user}
1190 else
1191 _e -> {:error, "not found " <> nickname}
1192 end
1193 end
1194 end
1195
1196 @spec get_followers_query(User.t(), pos_integer() | nil) :: Ecto.Query.t()
1197 def get_followers_query(%User{} = user, nil) do
1198 User.Query.build(%{followers: user, is_active: true})
1199 end
1200
1201 def get_followers_query(%User{} = user, page) do
1202 user
1203 |> get_followers_query(nil)
1204 |> User.Query.paginate(page, 20)
1205 end
1206
1207 @spec get_followers_query(User.t()) :: Ecto.Query.t()
1208 def get_followers_query(%User{} = user), do: get_followers_query(user, nil)
1209
1210 @spec get_followers(User.t(), pos_integer() | nil) :: {:ok, list(User.t())}
1211 def get_followers(%User{} = user, page \\ nil) do
1212 user
1213 |> get_followers_query(page)
1214 |> Repo.all()
1215 end
1216
1217 @spec get_external_followers(User.t(), pos_integer() | nil) :: {:ok, list(User.t())}
1218 def get_external_followers(%User{} = user, page \\ nil) do
1219 user
1220 |> get_followers_query(page)
1221 |> User.Query.build(%{external: true})
1222 |> Repo.all()
1223 end
1224
1225 def get_followers_ids(%User{} = user, page \\ nil) do
1226 user
1227 |> get_followers_query(page)
1228 |> select([u], u.id)
1229 |> Repo.all()
1230 end
1231
1232 @spec get_friends_query(User.t(), pos_integer() | nil) :: Ecto.Query.t()
1233 def get_friends_query(%User{} = user, nil) do
1234 User.Query.build(%{friends: user, deactivated: false})
1235 end
1236
1237 def get_friends_query(%User{} = user, page) do
1238 user
1239 |> get_friends_query(nil)
1240 |> User.Query.paginate(page, 20)
1241 end
1242
1243 @spec get_friends_query(User.t()) :: Ecto.Query.t()
1244 def get_friends_query(%User{} = user), do: get_friends_query(user, nil)
1245
1246 def get_friends(%User{} = user, page \\ nil) do
1247 user
1248 |> get_friends_query(page)
1249 |> Repo.all()
1250 end
1251
1252 def get_friends_ap_ids(%User{} = user) do
1253 user
1254 |> get_friends_query(nil)
1255 |> select([u], u.ap_id)
1256 |> Repo.all()
1257 end
1258
1259 def get_friends_ids(%User{} = user, page \\ nil) do
1260 user
1261 |> get_friends_query(page)
1262 |> select([u], u.id)
1263 |> Repo.all()
1264 end
1265
1266 def increase_note_count(%User{} = user) do
1267 User
1268 |> where(id: ^user.id)
1269 |> update([u], inc: [note_count: 1])
1270 |> select([u], u)
1271 |> Repo.update_all([])
1272 |> case do
1273 {1, [user]} -> set_cache(user)
1274 _ -> {:error, user}
1275 end
1276 end
1277
1278 def decrease_note_count(%User{} = user) do
1279 User
1280 |> where(id: ^user.id)
1281 |> update([u],
1282 set: [
1283 note_count: fragment("greatest(0, note_count - 1)")
1284 ]
1285 )
1286 |> select([u], u)
1287 |> Repo.update_all([])
1288 |> case do
1289 {1, [user]} -> set_cache(user)
1290 _ -> {:error, user}
1291 end
1292 end
1293
1294 def update_note_count(%User{} = user, note_count \\ nil) do
1295 note_count =
1296 note_count ||
1297 from(
1298 a in Object,
1299 where: fragment("?->>'actor' = ? and ?->>'type' = 'Note'", a.data, ^user.ap_id, a.data),
1300 select: count(a.id)
1301 )
1302 |> Repo.one()
1303
1304 user
1305 |> cast(%{note_count: note_count}, [:note_count])
1306 |> update_and_set_cache()
1307 end
1308
1309 @spec maybe_fetch_follow_information(User.t()) :: User.t()
1310 def maybe_fetch_follow_information(user) do
1311 with {:ok, user} <- fetch_follow_information(user) do
1312 user
1313 else
1314 e ->
1315 Logger.error("Follower/Following counter update for #{user.ap_id} failed.\n#{inspect(e)}")
1316
1317 user
1318 end
1319 end
1320
1321 def fetch_follow_information(user) do
1322 with {:ok, info} <- ActivityPub.fetch_follow_information_for_user(user) do
1323 user
1324 |> follow_information_changeset(info)
1325 |> update_and_set_cache()
1326 end
1327 end
1328
1329 defp follow_information_changeset(user, params) do
1330 user
1331 |> cast(params, [
1332 :hide_followers,
1333 :hide_follows,
1334 :follower_count,
1335 :following_count,
1336 :hide_followers_count,
1337 :hide_follows_count
1338 ])
1339 end
1340
1341 @spec update_follower_count(User.t()) :: {:ok, User.t()}
1342 def update_follower_count(%User{} = user) do
1343 if user.local or !Config.get([:instance, :external_user_synchronization]) do
1344 follower_count = FollowingRelationship.follower_count(user)
1345
1346 user
1347 |> follow_information_changeset(%{follower_count: follower_count})
1348 |> update_and_set_cache
1349 else
1350 {:ok, maybe_fetch_follow_information(user)}
1351 end
1352 end
1353
1354 @spec update_following_count(User.t()) :: {:ok, User.t()}
1355 def update_following_count(%User{local: false} = user) do
1356 if Config.get([:instance, :external_user_synchronization]) do
1357 {:ok, maybe_fetch_follow_information(user)}
1358 else
1359 {:ok, user}
1360 end
1361 end
1362
1363 def update_following_count(%User{local: true} = user) do
1364 following_count = FollowingRelationship.following_count(user)
1365
1366 user
1367 |> follow_information_changeset(%{following_count: following_count})
1368 |> update_and_set_cache()
1369 end
1370
1371 @spec get_users_from_set([String.t()], keyword()) :: [User.t()]
1372 def get_users_from_set(ap_ids, opts \\ []) do
1373 local_only = Keyword.get(opts, :local_only, true)
1374 criteria = %{ap_id: ap_ids, is_active: true}
1375 criteria = if local_only, do: Map.put(criteria, :local, true), else: criteria
1376
1377 User.Query.build(criteria)
1378 |> Repo.all()
1379 end
1380
1381 @spec get_recipients_from_activity(Activity.t()) :: [User.t()]
1382 def get_recipients_from_activity(%Activity{recipients: to, actor: actor}) do
1383 to = [actor | to]
1384
1385 query = User.Query.build(%{recipients_from_activity: to, local: true, is_active: true})
1386
1387 query
1388 |> Repo.all()
1389 end
1390
1391 @spec mute(User.t(), User.t(), map()) ::
1392 {:ok, list(UserRelationship.t())} | {:error, String.t()}
1393 def mute(%User{} = muter, %User{} = mutee, params \\ %{}) do
1394 notifications? = Map.get(params, :notifications, true)
1395 expires_in = Map.get(params, :expires_in, 0)
1396
1397 with {:ok, user_mute} <- UserRelationship.create_mute(muter, mutee),
1398 {:ok, user_notification_mute} <-
1399 (notifications? && UserRelationship.create_notification_mute(muter, mutee)) ||
1400 {:ok, nil} do
1401 if expires_in > 0 do
1402 Pleroma.Workers.MuteExpireWorker.enqueue(
1403 "unmute_user",
1404 %{"muter_id" => muter.id, "mutee_id" => mutee.id},
1405 schedule_in: expires_in
1406 )
1407 end
1408
1409 @cachex.del(:user_cache, "muted_users_ap_ids:#{muter.ap_id}")
1410
1411 {:ok, Enum.filter([user_mute, user_notification_mute], & &1)}
1412 end
1413 end
1414
1415 def unmute(%User{} = muter, %User{} = mutee) do
1416 with {:ok, user_mute} <- UserRelationship.delete_mute(muter, mutee),
1417 {:ok, user_notification_mute} <-
1418 UserRelationship.delete_notification_mute(muter, mutee) do
1419 @cachex.del(:user_cache, "muted_users_ap_ids:#{muter.ap_id}")
1420 {:ok, [user_mute, user_notification_mute]}
1421 end
1422 end
1423
1424 def unmute(muter_id, mutee_id) do
1425 with {:muter, %User{} = muter} <- {:muter, User.get_by_id(muter_id)},
1426 {:mutee, %User{} = mutee} <- {:mutee, User.get_by_id(mutee_id)} do
1427 unmute(muter, mutee)
1428 else
1429 {who, result} = error ->
1430 Logger.warn(
1431 "User.unmute/2 failed. #{who}: #{result}, muter_id: #{muter_id}, mutee_id: #{mutee_id}"
1432 )
1433
1434 {:error, error}
1435 end
1436 end
1437
1438 def subscribe(%User{} = subscriber, %User{} = target) do
1439 deny_follow_blocked = Config.get([:user, :deny_follow_blocked])
1440
1441 if blocks?(target, subscriber) and deny_follow_blocked do
1442 {:error, "Could not subscribe: #{target.nickname} is blocking you"}
1443 else
1444 # Note: the relationship is inverse: subscriber acts as relationship target
1445 UserRelationship.create_inverse_subscription(target, subscriber)
1446 end
1447 end
1448
1449 def subscribe(%User{} = subscriber, %{ap_id: ap_id}) do
1450 with %User{} = subscribee <- get_cached_by_ap_id(ap_id) do
1451 subscribe(subscriber, subscribee)
1452 end
1453 end
1454
1455 def unsubscribe(%User{} = unsubscriber, %User{} = target) do
1456 # Note: the relationship is inverse: subscriber acts as relationship target
1457 UserRelationship.delete_inverse_subscription(target, unsubscriber)
1458 end
1459
1460 def unsubscribe(%User{} = unsubscriber, %{ap_id: ap_id}) do
1461 with %User{} = user <- get_cached_by_ap_id(ap_id) do
1462 unsubscribe(unsubscriber, user)
1463 end
1464 end
1465
1466 def block(%User{} = blocker, %User{} = blocked) do
1467 # sever any follow relationships to prevent leaks per activitypub (Pleroma issue #213)
1468 blocker =
1469 if following?(blocker, blocked) do
1470 {:ok, blocker, _} = unfollow(blocker, blocked)
1471 blocker
1472 else
1473 blocker
1474 end
1475
1476 # clear any requested follows from both sides as well
1477 blocked =
1478 case CommonAPI.reject_follow_request(blocked, blocker) do
1479 {:ok, %User{} = updated_blocked} -> updated_blocked
1480 nil -> blocked
1481 end
1482
1483 blocker =
1484 case CommonAPI.reject_follow_request(blocker, blocked) do
1485 {:ok, %User{} = updated_blocker} -> updated_blocker
1486 nil -> blocker
1487 end
1488
1489 unsubscribe(blocked, blocker)
1490
1491 unfollowing_blocked = Config.get([:activitypub, :unfollow_blocked], true)
1492 if unfollowing_blocked && following?(blocked, blocker), do: unfollow(blocked, blocker)
1493
1494 {:ok, blocker} = update_follower_count(blocker)
1495 {:ok, blocker, _} = Participation.mark_all_as_read(blocker, blocked)
1496 add_to_block(blocker, blocked)
1497 end
1498
1499 # helper to handle the block given only an actor's AP id
1500 def block(%User{} = blocker, %{ap_id: ap_id}) do
1501 block(blocker, get_cached_by_ap_id(ap_id))
1502 end
1503
1504 def unblock(%User{} = blocker, %User{} = blocked) do
1505 remove_from_block(blocker, blocked)
1506 end
1507
1508 # helper to handle the block given only an actor's AP id
1509 def unblock(%User{} = blocker, %{ap_id: ap_id}) do
1510 unblock(blocker, get_cached_by_ap_id(ap_id))
1511 end
1512
1513 def mutes?(nil, _), do: false
1514 def mutes?(%User{} = user, %User{} = target), do: mutes_user?(user, target)
1515
1516 def mutes_user?(%User{} = user, %User{} = target) do
1517 UserRelationship.mute_exists?(user, target)
1518 end
1519
1520 @spec muted_notifications?(User.t() | nil, User.t() | map()) :: boolean()
1521 def muted_notifications?(nil, _), do: false
1522
1523 def muted_notifications?(%User{} = user, %User{} = target),
1524 do: UserRelationship.notification_mute_exists?(user, target)
1525
1526 def blocks?(nil, _), do: false
1527
1528 def blocks?(%User{} = user, %User{} = target) do
1529 blocks_user?(user, target) ||
1530 (blocks_domain?(user, target) and not User.following?(user, target))
1531 end
1532
1533 def blocks_user?(%User{} = user, %User{} = target) do
1534 UserRelationship.block_exists?(user, target)
1535 end
1536
1537 def blocks_user?(_, _), do: false
1538
1539 def blocks_domain?(%User{} = user, %User{} = target) do
1540 domain_blocks = Pleroma.Web.ActivityPub.MRF.subdomains_regex(user.domain_blocks)
1541 %{host: host} = URI.parse(target.ap_id)
1542 Pleroma.Web.ActivityPub.MRF.subdomain_match?(domain_blocks, host)
1543 end
1544
1545 def blocks_domain?(_, _), do: false
1546
1547 def subscribed_to?(%User{} = user, %User{} = target) do
1548 # Note: the relationship is inverse: subscriber acts as relationship target
1549 UserRelationship.inverse_subscription_exists?(target, user)
1550 end
1551
1552 def subscribed_to?(%User{} = user, %{ap_id: ap_id}) do
1553 with %User{} = target <- get_cached_by_ap_id(ap_id) do
1554 subscribed_to?(user, target)
1555 end
1556 end
1557
1558 @doc """
1559 Returns map of outgoing (blocked, muted etc.) relationships' user AP IDs by relation type.
1560 E.g. `outgoing_relationships_ap_ids(user, [:block])` -> `%{block: ["https://some.site/users/userapid"]}`
1561 """
1562 @spec outgoing_relationships_ap_ids(User.t(), list(atom())) :: %{atom() => list(String.t())}
1563 def outgoing_relationships_ap_ids(_user, []), do: %{}
1564
1565 def outgoing_relationships_ap_ids(nil, _relationship_types), do: %{}
1566
1567 def outgoing_relationships_ap_ids(%User{} = user, relationship_types)
1568 when is_list(relationship_types) do
1569 db_result =
1570 user
1571 |> assoc(:outgoing_relationships)
1572 |> join(:inner, [user_rel], u in assoc(user_rel, :target))
1573 |> where([user_rel, u], user_rel.relationship_type in ^relationship_types)
1574 |> select([user_rel, u], [user_rel.relationship_type, fragment("array_agg(?)", u.ap_id)])
1575 |> group_by([user_rel, u], user_rel.relationship_type)
1576 |> Repo.all()
1577 |> Enum.into(%{}, fn [k, v] -> {k, v} end)
1578
1579 Enum.into(
1580 relationship_types,
1581 %{},
1582 fn rel_type -> {rel_type, db_result[rel_type] || []} end
1583 )
1584 end
1585
1586 def incoming_relationships_ungrouped_ap_ids(user, relationship_types, ap_ids \\ nil)
1587
1588 def incoming_relationships_ungrouped_ap_ids(_user, [], _ap_ids), do: []
1589
1590 def incoming_relationships_ungrouped_ap_ids(nil, _relationship_types, _ap_ids), do: []
1591
1592 def incoming_relationships_ungrouped_ap_ids(%User{} = user, relationship_types, ap_ids)
1593 when is_list(relationship_types) do
1594 user
1595 |> assoc(:incoming_relationships)
1596 |> join(:inner, [user_rel], u in assoc(user_rel, :source))
1597 |> where([user_rel, u], user_rel.relationship_type in ^relationship_types)
1598 |> maybe_filter_on_ap_id(ap_ids)
1599 |> select([user_rel, u], u.ap_id)
1600 |> distinct(true)
1601 |> Repo.all()
1602 end
1603
1604 defp maybe_filter_on_ap_id(query, ap_ids) when is_list(ap_ids) do
1605 where(query, [user_rel, u], u.ap_id in ^ap_ids)
1606 end
1607
1608 defp maybe_filter_on_ap_id(query, _ap_ids), do: query
1609
1610 def set_activation_async(user, status \\ true) do
1611 BackgroundWorker.enqueue("user_activation", %{"user_id" => user.id, "status" => status})
1612 end
1613
1614 @spec set_activation([User.t()], boolean()) :: {:ok, User.t()} | {:error, Changeset.t()}
1615 def set_activation(users, status) when is_list(users) do
1616 Repo.transaction(fn ->
1617 for user <- users, do: set_activation(user, status)
1618 end)
1619 end
1620
1621 @spec set_activation(User.t(), boolean()) :: {:ok, User.t()} | {:error, Changeset.t()}
1622 def set_activation(%User{} = user, status) do
1623 with {:ok, user} <- set_activation_status(user, status) do
1624 user
1625 |> get_followers()
1626 |> Enum.filter(& &1.local)
1627 |> Enum.each(&set_cache(update_following_count(&1)))
1628
1629 # Only update local user counts, remote will be update during the next pull.
1630 user
1631 |> get_friends()
1632 |> Enum.filter(& &1.local)
1633 |> Enum.each(&do_unfollow(user, &1))
1634
1635 {:ok, user}
1636 end
1637 end
1638
1639 def approve(users) when is_list(users) do
1640 Repo.transaction(fn ->
1641 Enum.map(users, fn user ->
1642 with {:ok, user} <- approve(user), do: user
1643 end)
1644 end)
1645 end
1646
1647 def approve(%User{is_approved: false} = user) do
1648 with chg <- change(user, is_approved: true),
1649 {:ok, user} <- update_and_set_cache(chg) do
1650 post_register_action(user)
1651 {:ok, user}
1652 end
1653 end
1654
1655 def approve(%User{} = user), do: {:ok, user}
1656
1657 def confirm(users) when is_list(users) do
1658 Repo.transaction(fn ->
1659 Enum.map(users, fn user ->
1660 with {:ok, user} <- confirm(user), do: user
1661 end)
1662 end)
1663 end
1664
1665 def confirm(%User{is_confirmed: false} = user) do
1666 with chg <- confirmation_changeset(user, set_confirmation: true),
1667 {:ok, user} <- update_and_set_cache(chg) do
1668 post_register_action(user)
1669 {:ok, user}
1670 end
1671 end
1672
1673 def confirm(%User{} = user), do: {:ok, user}
1674
1675 def set_suggestion(users, is_suggested) when is_list(users) do
1676 Repo.transaction(fn ->
1677 Enum.map(users, fn user ->
1678 with {:ok, user} <- set_suggestion(user, is_suggested), do: user
1679 end)
1680 end)
1681 end
1682
1683 def set_suggestion(%User{is_suggested: is_suggested} = user, is_suggested), do: {:ok, user}
1684
1685 def set_suggestion(%User{} = user, is_suggested) when is_boolean(is_suggested) do
1686 user
1687 |> change(is_suggested: is_suggested)
1688 |> update_and_set_cache()
1689 end
1690
1691 def update_notification_settings(%User{} = user, settings) do
1692 user
1693 |> cast(%{notification_settings: settings}, [])
1694 |> cast_embed(:notification_settings)
1695 |> validate_required([:notification_settings])
1696 |> update_and_set_cache()
1697 end
1698
1699 @spec purge_user_changeset(User.t()) :: Changeset.t()
1700 def purge_user_changeset(user) do
1701 # "Right to be forgotten"
1702 # https://gdpr.eu/right-to-be-forgotten/
1703 change(user, %{
1704 bio: "",
1705 raw_bio: nil,
1706 email: nil,
1707 name: nil,
1708 password_hash: nil,
1709 avatar: %{},
1710 tags: [],
1711 last_refreshed_at: nil,
1712 last_digest_emailed_at: nil,
1713 banner: %{},
1714 background: %{},
1715 note_count: 0,
1716 follower_count: 0,
1717 following_count: 0,
1718 is_locked: false,
1719 password_reset_pending: false,
1720 registration_reason: nil,
1721 confirmation_token: nil,
1722 domain_blocks: [],
1723 is_active: false,
1724 ap_enabled: false,
1725 is_moderator: false,
1726 is_admin: false,
1727 mastofe_settings: nil,
1728 mascot: nil,
1729 emoji: %{},
1730 pleroma_settings_store: %{},
1731 fields: [],
1732 raw_fields: [],
1733 is_discoverable: false,
1734 also_known_as: []
1735 # id: preserved
1736 # ap_id: preserved
1737 # nickname: preserved
1738 })
1739 end
1740
1741 # Purge doesn't delete the user from the database.
1742 # It just nulls all its fields and deactivates it.
1743 # See `User.purge_user_changeset/1` above.
1744 defp purge(%User{} = user) do
1745 user
1746 |> purge_user_changeset()
1747 |> update_and_set_cache()
1748 end
1749
1750 def delete(users) when is_list(users) do
1751 for user <- users, do: delete(user)
1752 end
1753
1754 def delete(%User{} = user) do
1755 # Purge the user immediately
1756 purge(user)
1757 BackgroundWorker.enqueue("delete_user", %{"user_id" => user.id})
1758 end
1759
1760 # *Actually* delete the user from the DB
1761 defp delete_from_db(%User{} = user) do
1762 invalidate_cache(user)
1763 Repo.delete(user)
1764 end
1765
1766 # If the user never finalized their account, it's safe to delete them.
1767 defp maybe_delete_from_db(%User{local: true, is_confirmed: false} = user),
1768 do: delete_from_db(user)
1769
1770 defp maybe_delete_from_db(%User{local: true, is_approved: false} = user),
1771 do: delete_from_db(user)
1772
1773 defp maybe_delete_from_db(user), do: {:ok, user}
1774
1775 def perform(:force_password_reset, user), do: force_password_reset(user)
1776
1777 @spec perform(atom(), User.t()) :: {:ok, User.t()}
1778 def perform(:delete, %User{} = user) do
1779 # Purge the user again, in case perform/2 is called directly
1780 purge(user)
1781
1782 # Remove all relationships
1783 user
1784 |> get_followers()
1785 |> Enum.each(fn follower ->
1786 ActivityPub.unfollow(follower, user)
1787 unfollow(follower, user)
1788 end)
1789
1790 user
1791 |> get_friends()
1792 |> Enum.each(fn followed ->
1793 ActivityPub.unfollow(user, followed)
1794 unfollow(user, followed)
1795 end)
1796
1797 delete_user_activities(user)
1798 delete_notifications_from_user_activities(user)
1799 delete_outgoing_pending_follow_requests(user)
1800
1801 maybe_delete_from_db(user)
1802 end
1803
1804 def perform(:set_activation_async, user, status), do: set_activation(user, status)
1805
1806 @spec external_users_query() :: Ecto.Query.t()
1807 def external_users_query do
1808 User.Query.build(%{
1809 external: true,
1810 active: true,
1811 order_by: :id
1812 })
1813 end
1814
1815 @spec external_users(keyword()) :: [User.t()]
1816 def external_users(opts \\ []) do
1817 query =
1818 external_users_query()
1819 |> select([u], struct(u, [:id, :ap_id]))
1820
1821 query =
1822 if opts[:max_id],
1823 do: where(query, [u], u.id > ^opts[:max_id]),
1824 else: query
1825
1826 query =
1827 if opts[:limit],
1828 do: limit(query, ^opts[:limit]),
1829 else: query
1830
1831 Repo.all(query)
1832 end
1833
1834 def delete_notifications_from_user_activities(%User{ap_id: ap_id}) do
1835 Notification
1836 |> join(:inner, [n], activity in assoc(n, :activity))
1837 |> where([n, a], fragment("? = ?", a.actor, ^ap_id))
1838 |> Repo.delete_all()
1839 end
1840
1841 def delete_user_activities(%User{ap_id: ap_id} = user) do
1842 ap_id
1843 |> Activity.Queries.by_actor()
1844 |> Repo.chunk_stream(50, :batches)
1845 |> Stream.each(fn activities ->
1846 Enum.each(activities, fn activity -> delete_activity(activity, user) end)
1847 end)
1848 |> Stream.run()
1849 end
1850
1851 defp delete_activity(%{data: %{"type" => "Create", "object" => object}} = activity, user) do
1852 with {_, %Object{}} <- {:find_object, Object.get_by_ap_id(object)},
1853 {:ok, delete_data, _} <- Builder.delete(user, object) do
1854 Pipeline.common_pipeline(delete_data, local: user.local)
1855 else
1856 {:find_object, nil} ->
1857 # We have the create activity, but not the object, it was probably pruned.
1858 # Insert a tombstone and try again
1859 with {:ok, tombstone_data, _} <- Builder.tombstone(user.ap_id, object),
1860 {:ok, _tombstone} <- Object.create(tombstone_data) do
1861 delete_activity(activity, user)
1862 end
1863
1864 e ->
1865 Logger.error("Could not delete #{object} created by #{activity.data["ap_id"]}")
1866 Logger.error("Error: #{inspect(e)}")
1867 end
1868 end
1869
1870 defp delete_activity(%{data: %{"type" => type}} = activity, user)
1871 when type in ["Like", "Announce"] do
1872 {:ok, undo, _} = Builder.undo(user, activity)
1873 Pipeline.common_pipeline(undo, local: user.local)
1874 end
1875
1876 defp delete_activity(_activity, _user), do: "Doing nothing"
1877
1878 defp delete_outgoing_pending_follow_requests(user) do
1879 user
1880 |> FollowingRelationship.outgoing_pending_follow_requests_query()
1881 |> Repo.delete_all()
1882 end
1883
1884 def html_filter_policy(%User{no_rich_text: true}) do
1885 Pleroma.HTML.Scrubber.TwitterText
1886 end
1887
1888 def html_filter_policy(_), do: Config.get([:markup, :scrub_policy])
1889
1890 def fetch_by_ap_id(ap_id), do: ActivityPub.make_user_from_ap_id(ap_id)
1891
1892 def get_or_fetch_by_ap_id(ap_id) do
1893 cached_user = get_cached_by_ap_id(ap_id)
1894
1895 maybe_fetched_user = needs_update?(cached_user) && fetch_by_ap_id(ap_id)
1896
1897 case {cached_user, maybe_fetched_user} do
1898 {_, {:ok, %User{} = user}} ->
1899 {:ok, user}
1900
1901 {%User{} = user, _} ->
1902 {:ok, user}
1903
1904 _ ->
1905 {:error, :not_found}
1906 end
1907 end
1908
1909 @doc """
1910 Creates an internal service actor by URI if missing.
1911 Optionally takes nickname for addressing.
1912 """
1913 @spec get_or_create_service_actor_by_ap_id(String.t(), String.t()) :: User.t() | nil
1914 def get_or_create_service_actor_by_ap_id(uri, nickname) do
1915 {_, user} =
1916 case get_cached_by_ap_id(uri) do
1917 nil ->
1918 with {:error, %{errors: errors}} <- create_service_actor(uri, nickname) do
1919 Logger.error("Cannot create service actor: #{uri}/.\n#{inspect(errors)}")
1920 {:error, nil}
1921 end
1922
1923 %User{invisible: false} = user ->
1924 set_invisible(user)
1925
1926 user ->
1927 {:ok, user}
1928 end
1929
1930 user
1931 end
1932
1933 @spec set_invisible(User.t()) :: {:ok, User.t()}
1934 defp set_invisible(user) do
1935 user
1936 |> change(%{invisible: true})
1937 |> update_and_set_cache()
1938 end
1939
1940 @spec create_service_actor(String.t(), String.t()) ::
1941 {:ok, User.t()} | {:error, Ecto.Changeset.t()}
1942 defp create_service_actor(uri, nickname) do
1943 %User{
1944 invisible: true,
1945 local: true,
1946 ap_id: uri,
1947 nickname: nickname,
1948 follower_address: uri <> "/followers"
1949 }
1950 |> change
1951 |> unique_constraint(:nickname)
1952 |> Repo.insert()
1953 |> set_cache()
1954 end
1955
1956 def public_key(%{public_key: public_key_pem}) when is_binary(public_key_pem) do
1957 key =
1958 public_key_pem
1959 |> :public_key.pem_decode()
1960 |> hd()
1961 |> :public_key.pem_entry_decode()
1962
1963 {:ok, key}
1964 end
1965
1966 def public_key(_), do: {:error, "key not found"}
1967
1968 def get_public_key_for_ap_id(ap_id) do
1969 with {:ok, %User{} = user} <- get_or_fetch_by_ap_id(ap_id),
1970 {:ok, public_key} <- public_key(user) do
1971 {:ok, public_key}
1972 else
1973 _ -> :error
1974 end
1975 end
1976
1977 def ap_enabled?(%User{local: true}), do: true
1978 def ap_enabled?(%User{ap_enabled: ap_enabled}), do: ap_enabled
1979 def ap_enabled?(_), do: false
1980
1981 @doc "Gets or fetch a user by uri or nickname."
1982 @spec get_or_fetch(String.t()) :: {:ok, User.t()} | {:error, String.t()}
1983 def get_or_fetch("http" <> _host = uri), do: get_or_fetch_by_ap_id(uri)
1984 def get_or_fetch(nickname), do: get_or_fetch_by_nickname(nickname)
1985
1986 # wait a period of time and return newest version of the User structs
1987 # this is because we have synchronous follow APIs and need to simulate them
1988 # with an async handshake
1989 def wait_and_refresh(_, %User{local: true} = a, %User{local: true} = b) do
1990 with %User{} = a <- get_cached_by_id(a.id),
1991 %User{} = b <- get_cached_by_id(b.id) do
1992 {:ok, a, b}
1993 else
1994 nil -> :error
1995 end
1996 end
1997
1998 def wait_and_refresh(timeout, %User{} = a, %User{} = b) do
1999 with :ok <- :timer.sleep(timeout),
2000 %User{} = a <- get_cached_by_id(a.id),
2001 %User{} = b <- get_cached_by_id(b.id) do
2002 {:ok, a, b}
2003 else
2004 nil -> :error
2005 end
2006 end
2007
2008 def parse_bio(bio) when is_binary(bio) and bio != "" do
2009 bio
2010 |> CommonUtils.format_input("text/plain", mentions_format: :full)
2011 |> elem(0)
2012 end
2013
2014 def parse_bio(_), do: ""
2015
2016 def parse_bio(bio, user) when is_binary(bio) and bio != "" do
2017 # TODO: get profile URLs other than user.ap_id
2018 profile_urls = [user.ap_id]
2019
2020 bio
2021 |> CommonUtils.format_input("text/plain",
2022 mentions_format: :full,
2023 rel: &RelMe.maybe_put_rel_me(&1, profile_urls)
2024 )
2025 |> elem(0)
2026 end
2027
2028 def parse_bio(_, _), do: ""
2029
2030 def tag(user_identifiers, tags) when is_list(user_identifiers) do
2031 Repo.transaction(fn ->
2032 for user_identifier <- user_identifiers, do: tag(user_identifier, tags)
2033 end)
2034 end
2035
2036 def tag(nickname, tags) when is_binary(nickname),
2037 do: tag(get_by_nickname(nickname), tags)
2038
2039 def tag(%User{} = user, tags),
2040 do: update_tags(user, Enum.uniq((user.tags || []) ++ normalize_tags(tags)))
2041
2042 def untag(user_identifiers, tags) when is_list(user_identifiers) do
2043 Repo.transaction(fn ->
2044 for user_identifier <- user_identifiers, do: untag(user_identifier, tags)
2045 end)
2046 end
2047
2048 def untag(nickname, tags) when is_binary(nickname),
2049 do: untag(get_by_nickname(nickname), tags)
2050
2051 def untag(%User{} = user, tags),
2052 do: update_tags(user, (user.tags || []) -- normalize_tags(tags))
2053
2054 defp update_tags(%User{} = user, new_tags) do
2055 {:ok, updated_user} =
2056 user
2057 |> change(%{tags: new_tags})
2058 |> update_and_set_cache()
2059
2060 updated_user
2061 end
2062
2063 defp normalize_tags(tags) do
2064 [tags]
2065 |> List.flatten()
2066 |> Enum.map(&String.downcase/1)
2067 end
2068
2069 def local_nickname_regex do
2070 if Config.get([:instance, :extended_nickname_format]) do
2071 @extended_local_nickname_regex
2072 else
2073 @strict_local_nickname_regex
2074 end
2075 end
2076
2077 def local_nickname(nickname_or_mention) do
2078 nickname_or_mention
2079 |> full_nickname()
2080 |> String.split("@")
2081 |> hd()
2082 end
2083
2084 def full_nickname(%User{} = user) do
2085 if String.contains?(user.nickname, "@") do
2086 user.nickname
2087 else
2088 %{host: host} = URI.parse(user.ap_id)
2089 user.nickname <> "@" <> host
2090 end
2091 end
2092
2093 def full_nickname(nickname_or_mention),
2094 do: String.trim_leading(nickname_or_mention, "@")
2095
2096 def error_user(ap_id) do
2097 %User{
2098 name: ap_id,
2099 ap_id: ap_id,
2100 nickname: "erroruser@example.com",
2101 inserted_at: NaiveDateTime.utc_now()
2102 }
2103 end
2104
2105 @spec all_superusers() :: [User.t()]
2106 def all_superusers do
2107 User.Query.build(%{super_users: true, local: true, is_active: true})
2108 |> Repo.all()
2109 end
2110
2111 def muting_reblogs?(%User{} = user, %User{} = target) do
2112 UserRelationship.reblog_mute_exists?(user, target)
2113 end
2114
2115 def showing_reblogs?(%User{} = user, %User{} = target) do
2116 not muting_reblogs?(user, target)
2117 end
2118
2119 @doc """
2120 The function returns a query to get users with no activity for given interval of days.
2121 Inactive users are those who didn't read any notification, or had any activity where
2122 the user is the activity's actor, during `inactivity_threshold` days.
2123 Deactivated users will not appear in this list.
2124
2125 ## Examples
2126
2127 iex> Pleroma.User.list_inactive_users()
2128 %Ecto.Query{}
2129 """
2130 @spec list_inactive_users_query(integer()) :: Ecto.Query.t()
2131 def list_inactive_users_query(inactivity_threshold \\ 7) do
2132 negative_inactivity_threshold = -inactivity_threshold
2133 now = NaiveDateTime.truncate(NaiveDateTime.utc_now(), :second)
2134 # Subqueries are not supported in `where` clauses, join gets too complicated.
2135 has_read_notifications =
2136 from(n in Pleroma.Notification,
2137 where: n.seen == true,
2138 group_by: n.id,
2139 having: max(n.updated_at) > datetime_add(^now, ^negative_inactivity_threshold, "day"),
2140 select: n.user_id
2141 )
2142 |> Pleroma.Repo.all()
2143
2144 from(u in Pleroma.User,
2145 left_join: a in Pleroma.Activity,
2146 on: u.ap_id == a.actor,
2147 where: not is_nil(u.nickname),
2148 where: u.is_active == ^true,
2149 where: u.id not in ^has_read_notifications,
2150 group_by: u.id,
2151 having:
2152 max(a.inserted_at) < datetime_add(^now, ^negative_inactivity_threshold, "day") or
2153 is_nil(max(a.inserted_at))
2154 )
2155 end
2156
2157 @doc """
2158 Enable or disable email notifications for user
2159
2160 ## Examples
2161
2162 iex> Pleroma.User.switch_email_notifications(Pleroma.User{email_notifications: %{"digest" => false}}, "digest", true)
2163 Pleroma.User{email_notifications: %{"digest" => true}}
2164
2165 iex> Pleroma.User.switch_email_notifications(Pleroma.User{email_notifications: %{"digest" => true}}, "digest", false)
2166 Pleroma.User{email_notifications: %{"digest" => false}}
2167 """
2168 @spec switch_email_notifications(t(), String.t(), boolean()) ::
2169 {:ok, t()} | {:error, Ecto.Changeset.t()}
2170 def switch_email_notifications(user, type, status) do
2171 User.update_email_notifications(user, %{type => status})
2172 end
2173
2174 @doc """
2175 Set `last_digest_emailed_at` value for the user to current time
2176 """
2177 @spec touch_last_digest_emailed_at(t()) :: t()
2178 def touch_last_digest_emailed_at(user) do
2179 now = NaiveDateTime.truncate(NaiveDateTime.utc_now(), :second)
2180
2181 {:ok, updated_user} =
2182 user
2183 |> change(%{last_digest_emailed_at: now})
2184 |> update_and_set_cache()
2185
2186 updated_user
2187 end
2188
2189 @spec set_confirmation(User.t(), boolean()) :: {:ok, User.t()} | {:error, Changeset.t()}
2190 def set_confirmation(%User{} = user, bool) do
2191 user
2192 |> confirmation_changeset(set_confirmation: bool)
2193 |> update_and_set_cache()
2194 end
2195
2196 def get_mascot(%{mascot: %{} = mascot}) when not is_nil(mascot) do
2197 mascot
2198 end
2199
2200 def get_mascot(%{mascot: mascot}) when is_nil(mascot) do
2201 # use instance-default
2202 config = Config.get([:assets, :mascots])
2203 default_mascot = Config.get([:assets, :default_mascot])
2204 mascot = Keyword.get(config, default_mascot)
2205
2206 %{
2207 "id" => "default-mascot",
2208 "url" => mascot[:url],
2209 "preview_url" => mascot[:url],
2210 "pleroma" => %{
2211 "mime_type" => mascot[:mime_type]
2212 }
2213 }
2214 end
2215
2216 def ensure_keys_present(%{keys: keys} = user) when not is_nil(keys), do: {:ok, user}
2217
2218 def ensure_keys_present(%User{} = user) do
2219 with {:ok, pem} <- Keys.generate_rsa_pem() do
2220 user
2221 |> cast(%{keys: pem}, [:keys])
2222 |> validate_required([:keys])
2223 |> update_and_set_cache()
2224 end
2225 end
2226
2227 def get_ap_ids_by_nicknames(nicknames) do
2228 from(u in User,
2229 where: u.nickname in ^nicknames,
2230 select: u.ap_id
2231 )
2232 |> Repo.all()
2233 end
2234
2235 defp put_password_hash(
2236 %Ecto.Changeset{valid?: true, changes: %{password: password}} = changeset
2237 ) do
2238 change(changeset, password_hash: Pleroma.Password.Pbkdf2.hash_pwd_salt(password))
2239 end
2240
2241 defp put_password_hash(changeset), do: changeset
2242
2243 def is_internal_user?(%User{nickname: nil}), do: true
2244 def is_internal_user?(%User{local: true, nickname: "internal." <> _}), do: true
2245 def is_internal_user?(_), do: false
2246
2247 # A hack because user delete activities have a fake id for whatever reason
2248 # TODO: Get rid of this
2249 def get_delivered_users_by_object_id("pleroma:fake_object_id"), do: []
2250
2251 def get_delivered_users_by_object_id(object_id) do
2252 from(u in User,
2253 inner_join: delivery in assoc(u, :deliveries),
2254 where: delivery.object_id == ^object_id
2255 )
2256 |> Repo.all()
2257 end
2258
2259 def change_email(user, email) do
2260 user
2261 |> cast(%{email: email}, [:email])
2262 |> maybe_validate_required_email(false)
2263 |> unique_constraint(:email)
2264 |> validate_format(:email, @email_regex)
2265 |> update_and_set_cache()
2266 end
2267
2268 def alias_users(user) do
2269 user.also_known_as
2270 |> Enum.map(&User.get_cached_by_ap_id/1)
2271 |> Enum.filter(fn user -> user != nil end)
2272 end
2273
2274 def add_alias(user, new_alias_user) do
2275 current_aliases = user.also_known_as || []
2276 new_alias_ap_id = new_alias_user.ap_id
2277
2278 if new_alias_ap_id in current_aliases do
2279 {:ok, user}
2280 else
2281 user
2282 |> cast(%{also_known_as: current_aliases ++ [new_alias_ap_id]}, [:also_known_as])
2283 |> update_and_set_cache()
2284 end
2285 end
2286
2287 def delete_alias(user, alias_user) do
2288 current_aliases = user.also_known_as || []
2289 alias_ap_id = alias_user.ap_id
2290
2291 if alias_ap_id in current_aliases do
2292 user
2293 |> cast(%{also_known_as: current_aliases -- [alias_ap_id]}, [:also_known_as])
2294 |> update_and_set_cache()
2295 else
2296 {:error, :no_such_alias}
2297 end
2298 end
2299
2300 # Internal function; public one is `deactivate/2`
2301 defp set_activation_status(user, status) do
2302 user
2303 |> cast(%{is_active: status}, [:is_active])
2304 |> update_and_set_cache()
2305 end
2306
2307 def update_banner(user, banner) do
2308 user
2309 |> cast(%{banner: banner}, [:banner])
2310 |> update_and_set_cache()
2311 end
2312
2313 def update_background(user, background) do
2314 user
2315 |> cast(%{background: background}, [:background])
2316 |> update_and_set_cache()
2317 end
2318
2319 def validate_fields(changeset, remote? \\ false) do
2320 limit_name = if remote?, do: :max_remote_account_fields, else: :max_account_fields
2321 limit = Config.get([:instance, limit_name], 0)
2322
2323 changeset
2324 |> validate_length(:fields, max: limit)
2325 |> validate_change(:fields, fn :fields, fields ->
2326 if Enum.all?(fields, &valid_field?/1) do
2327 []
2328 else
2329 [fields: "invalid"]
2330 end
2331 end)
2332 end
2333
2334 defp valid_field?(%{"name" => name, "value" => value}) do
2335 name_limit = Config.get([:instance, :account_field_name_length], 255)
2336 value_limit = Config.get([:instance, :account_field_value_length], 255)
2337
2338 is_binary(name) && is_binary(value) && String.length(name) <= name_limit &&
2339 String.length(value) <= value_limit
2340 end
2341
2342 defp valid_field?(_), do: false
2343
2344 defp truncate_field(%{"name" => name, "value" => value}) do
2345 {name, _chopped} =
2346 String.split_at(name, Config.get([:instance, :account_field_name_length], 255))
2347
2348 {value, _chopped} =
2349 String.split_at(value, Config.get([:instance, :account_field_value_length], 255))
2350
2351 %{"name" => name, "value" => value}
2352 end
2353
2354 def admin_api_update(user, params) do
2355 user
2356 |> cast(params, [
2357 :is_moderator,
2358 :is_admin,
2359 :show_role
2360 ])
2361 |> update_and_set_cache()
2362 end
2363
2364 @doc "Signs user out of all applications"
2365 def global_sign_out(user) do
2366 OAuth.Authorization.delete_user_authorizations(user)
2367 OAuth.Token.delete_user_tokens(user)
2368 end
2369
2370 def mascot_update(user, url) do
2371 user
2372 |> cast(%{mascot: url}, [:mascot])
2373 |> validate_required([:mascot])
2374 |> update_and_set_cache()
2375 end
2376
2377 def mastodon_settings_update(user, settings) do
2378 user
2379 |> cast(%{mastofe_settings: settings}, [:mastofe_settings])
2380 |> validate_required([:mastofe_settings])
2381 |> update_and_set_cache()
2382 end
2383
2384 @spec confirmation_changeset(User.t(), keyword()) :: Changeset.t()
2385 def confirmation_changeset(user, set_confirmation: confirmed?) do
2386 params =
2387 if confirmed? do
2388 %{
2389 is_confirmed: true,
2390 confirmation_token: nil
2391 }
2392 else
2393 %{
2394 is_confirmed: false,
2395 confirmation_token: :crypto.strong_rand_bytes(32) |> Base.url_encode64()
2396 }
2397 end
2398
2399 cast(user, params, [:is_confirmed, :confirmation_token])
2400 end
2401
2402 @spec approval_changeset(User.t(), keyword()) :: Changeset.t()
2403 def approval_changeset(user, set_approval: approved?) do
2404 cast(user, %{is_approved: approved?}, [:is_approved])
2405 end
2406
2407 @spec add_pinned_object_id(User.t(), String.t()) :: {:ok, User.t()} | {:error, term()}
2408 def add_pinned_object_id(%User{} = user, object_id) do
2409 if !user.pinned_objects[object_id] do
2410 params = %{pinned_objects: Map.put(user.pinned_objects, object_id, NaiveDateTime.utc_now())}
2411
2412 user
2413 |> cast(params, [:pinned_objects])
2414 |> validate_change(:pinned_objects, fn :pinned_objects, pinned_objects ->
2415 max_pinned_statuses = Config.get([:instance, :max_pinned_statuses], 0)
2416
2417 if Enum.count(pinned_objects) <= max_pinned_statuses do
2418 []
2419 else
2420 [pinned_objects: "You have already pinned the maximum number of statuses"]
2421 end
2422 end)
2423 else
2424 change(user)
2425 end
2426 |> update_and_set_cache()
2427 end
2428
2429 @spec remove_pinned_object_id(User.t(), String.t()) :: {:ok, t()} | {:error, term()}
2430 def remove_pinned_object_id(%User{} = user, object_id) do
2431 user
2432 |> cast(
2433 %{pinned_objects: Map.delete(user.pinned_objects, object_id)},
2434 [:pinned_objects]
2435 )
2436 |> update_and_set_cache()
2437 end
2438
2439 def update_email_notifications(user, settings) do
2440 email_notifications =
2441 user.email_notifications
2442 |> Map.merge(settings)
2443 |> Map.take(["digest"])
2444
2445 params = %{email_notifications: email_notifications}
2446 fields = [:email_notifications]
2447
2448 user
2449 |> cast(params, fields)
2450 |> validate_required(fields)
2451 |> update_and_set_cache()
2452 end
2453
2454 defp set_domain_blocks(user, domain_blocks) do
2455 params = %{domain_blocks: domain_blocks}
2456
2457 user
2458 |> cast(params, [:domain_blocks])
2459 |> validate_required([:domain_blocks])
2460 |> update_and_set_cache()
2461 end
2462
2463 def block_domain(user, domain_blocked) do
2464 set_domain_blocks(user, Enum.uniq([domain_blocked | user.domain_blocks]))
2465 end
2466
2467 def unblock_domain(user, domain_blocked) do
2468 set_domain_blocks(user, List.delete(user.domain_blocks, domain_blocked))
2469 end
2470
2471 @spec add_to_block(User.t(), User.t()) ::
2472 {:ok, UserRelationship.t()} | {:error, Ecto.Changeset.t()}
2473 defp add_to_block(%User{} = user, %User{} = blocked) do
2474 with {:ok, relationship} <- UserRelationship.create_block(user, blocked) do
2475 @cachex.del(:user_cache, "blocked_users_ap_ids:#{user.ap_id}")
2476 {:ok, relationship}
2477 end
2478 end
2479
2480 @spec add_to_block(User.t(), User.t()) ::
2481 {:ok, UserRelationship.t()} | {:ok, nil} | {:error, Ecto.Changeset.t()}
2482 defp remove_from_block(%User{} = user, %User{} = blocked) do
2483 with {:ok, relationship} <- UserRelationship.delete_block(user, blocked) do
2484 @cachex.del(:user_cache, "blocked_users_ap_ids:#{user.ap_id}")
2485 {:ok, relationship}
2486 end
2487 end
2488
2489 def set_invisible(user, invisible) do
2490 params = %{invisible: invisible}
2491
2492 user
2493 |> cast(params, [:invisible])
2494 |> validate_required([:invisible])
2495 |> update_and_set_cache()
2496 end
2497
2498 def sanitize_html(%User{} = user) do
2499 sanitize_html(user, nil)
2500 end
2501
2502 # User data that mastodon isn't filtering (treated as plaintext):
2503 # - field name
2504 # - display name
2505 def sanitize_html(%User{} = user, filter) do
2506 fields =
2507 Enum.map(user.fields, fn %{"name" => name, "value" => value} ->
2508 %{
2509 "name" => name,
2510 "value" => HTML.filter_tags(value, Pleroma.HTML.Scrubber.LinksOnly)
2511 }
2512 end)
2513
2514 user
2515 |> Map.put(:bio, HTML.filter_tags(user.bio, filter))
2516 |> Map.put(:fields, fields)
2517 end
2518
2519 def get_host(%User{ap_id: ap_id} = _user) do
2520 URI.parse(ap_id).host
2521 end
2522
2523 def update_last_active_at(%__MODULE__{local: true} = user) do
2524 user
2525 |> cast(%{last_active_at: NaiveDateTime.utc_now()}, [:last_active_at])
2526 |> update_and_set_cache()
2527 end
2528
2529 def active_user_count(days \\ 30) do
2530 active_after = Timex.shift(NaiveDateTime.utc_now(), days: -days)
2531
2532 __MODULE__
2533 |> where([u], u.last_active_at >= ^active_after)
2534 |> where([u], u.local == true)
2535 |> Repo.aggregate(:count)
2536 end
2537
2538 def update_last_status_at(user) do
2539 User
2540 |> where(id: ^user.id)
2541 |> update([u], set: [last_status_at: fragment("NOW()")])
2542 |> select([u], u)
2543 |> Repo.update_all([])
2544 |> case do
2545 {1, [user]} -> set_cache(user)
2546 _ -> {:error, user}
2547 end
2548 end
2549 end