Credo fixes: alias grouping/ordering
[akkoma] / lib / pleroma / web / activity_pub / activity_pub_controller.ex
1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2019 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
4
5 defmodule Pleroma.Web.ActivityPub.ActivityPubController do
6 use Pleroma.Web, :controller
7
8 alias Pleroma.{Activity, User, Object}
9 alias Pleroma.Web.ActivityPub.{ObjectView, UserView}
10 alias Pleroma.Web.ActivityPub.{ActivityPub, Relay, Transmogrifier, Utils}
11 alias Pleroma.Web.Federator
12
13 require Logger
14
15 action_fallback(:errors)
16
17 plug(Pleroma.Web.FederatingPlug when action in [:inbox, :relay])
18 plug(:set_requester_reachable when action in [:inbox])
19 plug(:relay_active? when action in [:relay])
20
21 def relay_active?(conn, _) do
22 if Keyword.get(Application.get_env(:pleroma, :instance), :allow_relay) do
23 conn
24 else
25 conn
26 |> put_status(404)
27 |> json(%{error: "not found"})
28 |> halt
29 end
30 end
31
32 def user(conn, %{"nickname" => nickname}) do
33 with %User{} = user <- User.get_cached_by_nickname(nickname),
34 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
35 conn
36 |> put_resp_header("content-type", "application/activity+json")
37 |> json(UserView.render("user.json", %{user: user}))
38 else
39 nil -> {:error, :not_found}
40 end
41 end
42
43 def object(conn, %{"uuid" => uuid}) do
44 with ap_id <- o_status_url(conn, :object, uuid),
45 %Object{} = object <- Object.get_cached_by_ap_id(ap_id),
46 {_, true} <- {:public?, ActivityPub.is_public?(object)} do
47 conn
48 |> put_resp_header("content-type", "application/activity+json")
49 |> json(ObjectView.render("object.json", %{object: object}))
50 else
51 {:public?, false} ->
52 {:error, :not_found}
53 end
54 end
55
56 def object_likes(conn, %{"uuid" => uuid, "page" => page}) do
57 with ap_id <- o_status_url(conn, :object, uuid),
58 %Object{} = object <- Object.get_cached_by_ap_id(ap_id),
59 {_, true} <- {:public?, ActivityPub.is_public?(object)},
60 likes <- Utils.get_object_likes(object) do
61 {page, _} = Integer.parse(page)
62
63 conn
64 |> put_resp_header("content-type", "application/activity+json")
65 |> json(ObjectView.render("likes.json", ap_id, likes, page))
66 else
67 {:public?, false} ->
68 {:error, :not_found}
69 end
70 end
71
72 def object_likes(conn, %{"uuid" => uuid}) do
73 with ap_id <- o_status_url(conn, :object, uuid),
74 %Object{} = object <- Object.get_cached_by_ap_id(ap_id),
75 {_, true} <- {:public?, ActivityPub.is_public?(object)},
76 likes <- Utils.get_object_likes(object) do
77 conn
78 |> put_resp_header("content-type", "application/activity+json")
79 |> json(ObjectView.render("likes.json", ap_id, likes))
80 else
81 {:public?, false} ->
82 {:error, :not_found}
83 end
84 end
85
86 def activity(conn, %{"uuid" => uuid}) do
87 with ap_id <- o_status_url(conn, :activity, uuid),
88 %Activity{} = activity <- Activity.normalize(ap_id),
89 {_, true} <- {:public?, ActivityPub.is_public?(activity)} do
90 conn
91 |> put_resp_header("content-type", "application/activity+json")
92 |> json(ObjectView.render("object.json", %{object: activity}))
93 else
94 {:public?, false} ->
95 {:error, :not_found}
96 end
97 end
98
99 def following(conn, %{"nickname" => nickname, "page" => page}) do
100 with %User{} = user <- User.get_cached_by_nickname(nickname),
101 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
102 {page, _} = Integer.parse(page)
103
104 conn
105 |> put_resp_header("content-type", "application/activity+json")
106 |> json(UserView.render("following.json", %{user: user, page: page}))
107 end
108 end
109
110 def following(conn, %{"nickname" => nickname}) do
111 with %User{} = user <- User.get_cached_by_nickname(nickname),
112 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
113 conn
114 |> put_resp_header("content-type", "application/activity+json")
115 |> json(UserView.render("following.json", %{user: user}))
116 end
117 end
118
119 def followers(conn, %{"nickname" => nickname, "page" => page}) do
120 with %User{} = user <- User.get_cached_by_nickname(nickname),
121 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
122 {page, _} = Integer.parse(page)
123
124 conn
125 |> put_resp_header("content-type", "application/activity+json")
126 |> json(UserView.render("followers.json", %{user: user, page: page}))
127 end
128 end
129
130 def followers(conn, %{"nickname" => nickname}) do
131 with %User{} = user <- User.get_cached_by_nickname(nickname),
132 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
133 conn
134 |> put_resp_header("content-type", "application/activity+json")
135 |> json(UserView.render("followers.json", %{user: user}))
136 end
137 end
138
139 def outbox(conn, %{"nickname" => nickname} = params) do
140 with %User{} = user <- User.get_cached_by_nickname(nickname),
141 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
142 conn
143 |> put_resp_header("content-type", "application/activity+json")
144 |> json(UserView.render("outbox.json", %{user: user, max_id: params["max_id"]}))
145 end
146 end
147
148 def inbox(%{assigns: %{valid_signature: true}} = conn, %{"nickname" => nickname} = params) do
149 with %User{} = user <- User.get_cached_by_nickname(nickname),
150 true <- Utils.recipient_in_message(user.ap_id, params),
151 params <- Utils.maybe_splice_recipient(user.ap_id, params) do
152 Federator.enqueue(:incoming_ap_doc, params)
153 json(conn, "ok")
154 end
155 end
156
157 def inbox(%{assigns: %{valid_signature: true}} = conn, params) do
158 Federator.enqueue(:incoming_ap_doc, params)
159 json(conn, "ok")
160 end
161
162 # only accept relayed Creates
163 def inbox(conn, %{"type" => "Create"} = params) do
164 Logger.info(
165 "Signature missing or not from author, relayed Create message, fetching object from source"
166 )
167
168 ActivityPub.fetch_object_from_id(params["object"]["id"])
169
170 json(conn, "ok")
171 end
172
173 def inbox(conn, params) do
174 headers = Enum.into(conn.req_headers, %{})
175
176 if String.contains?(headers["signature"], params["actor"]) do
177 Logger.info(
178 "Signature validation error for: #{params["actor"]}, make sure you are forwarding the HTTP Host header!"
179 )
180
181 Logger.info(inspect(conn.req_headers))
182 end
183
184 json(conn, "error")
185 end
186
187 def relay(conn, _params) do
188 with %User{} = user <- Relay.get_actor(),
189 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
190 conn
191 |> put_resp_header("content-type", "application/activity+json")
192 |> json(UserView.render("user.json", %{user: user}))
193 else
194 nil -> {:error, :not_found}
195 end
196 end
197
198 def whoami(%{assigns: %{user: %User{} = user}} = conn, _params) do
199 conn
200 |> put_resp_header("content-type", "application/activity+json")
201 |> json(UserView.render("user.json", %{user: user}))
202 end
203
204 def whoami(_conn, _params), do: {:error, :not_found}
205
206 def read_inbox(%{assigns: %{user: user}} = conn, %{"nickname" => nickname} = params) do
207 if nickname == user.nickname do
208 conn
209 |> put_resp_header("content-type", "application/activity+json")
210 |> json(UserView.render("inbox.json", %{user: user, max_id: params["max_id"]}))
211 else
212 conn
213 |> put_status(:forbidden)
214 |> json("can't read inbox of #{nickname} as #{user.nickname}")
215 end
216 end
217
218 def handle_user_activity(user, %{"type" => "Create"} = params) do
219 object =
220 params["object"]
221 |> Map.merge(Map.take(params, ["to", "cc"]))
222 |> Map.put("attributedTo", user.ap_id())
223 |> Transmogrifier.fix_object()
224
225 ActivityPub.create(%{
226 to: params["to"],
227 actor: user,
228 context: object["context"],
229 object: object,
230 additional: Map.take(params, ["cc"])
231 })
232 end
233
234 def handle_user_activity(user, %{"type" => "Delete"} = params) do
235 with %Object{} = object <- Object.normalize(params["object"]),
236 true <- user.info.is_moderator || user.ap_id == object.data["actor"],
237 {:ok, delete} <- ActivityPub.delete(object) do
238 {:ok, delete}
239 else
240 _ -> {:error, "Can't delete object"}
241 end
242 end
243
244 def handle_user_activity(user, %{"type" => "Like"} = params) do
245 with %Object{} = object <- Object.normalize(params["object"]),
246 {:ok, activity, _object} <- ActivityPub.like(user, object) do
247 {:ok, activity}
248 else
249 _ -> {:error, "Can't like object"}
250 end
251 end
252
253 def handle_user_activity(_, _) do
254 {:error, "Unhandled activity type"}
255 end
256
257 def update_outbox(
258 %{assigns: %{user: user}} = conn,
259 %{"nickname" => nickname} = params
260 ) do
261 if nickname == user.nickname do
262 actor = user.ap_id()
263
264 params =
265 params
266 |> Map.drop(["id"])
267 |> Map.put("actor", actor)
268 |> Transmogrifier.fix_addressing()
269
270 with {:ok, %Activity{} = activity} <- handle_user_activity(user, params) do
271 conn
272 |> put_status(:created)
273 |> put_resp_header("location", activity.data["id"])
274 |> json(activity.data)
275 else
276 {:error, message} ->
277 conn
278 |> put_status(:bad_request)
279 |> json(message)
280 end
281 else
282 conn
283 |> put_status(:forbidden)
284 |> json("can't update outbox of #{nickname} as #{user.nickname}")
285 end
286 end
287
288 def errors(conn, {:error, :not_found}) do
289 conn
290 |> put_status(404)
291 |> json("Not found")
292 end
293
294 def errors(conn, _e) do
295 conn
296 |> put_status(500)
297 |> json("error")
298 end
299
300 defp set_requester_reachable(%Plug.Conn{} = conn, _) do
301 with actor <- conn.params["actor"],
302 true <- is_binary(actor) do
303 Pleroma.Instances.set_reachable(actor)
304 end
305
306 conn
307 end
308 end