Merge branch 'security/ap-unsigned-create' into 'develop'
[akkoma] / lib / pleroma / web / activity_pub / activity_pub_controller.ex
1 defmodule Pleroma.Web.ActivityPub.ActivityPubController do
2 use Pleroma.Web, :controller
3 alias Pleroma.{User, Object}
4 alias Pleroma.Web.ActivityPub.{ObjectView, UserView}
5 alias Pleroma.Web.ActivityPub.ActivityPub
6 alias Pleroma.Web.ActivityPub.Relay
7 alias Pleroma.Web.Federator
8
9 require Logger
10
11 action_fallback(:errors)
12
13 def user(conn, %{"nickname" => nickname}) do
14 with %User{} = user <- User.get_cached_by_nickname(nickname),
15 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
16 conn
17 |> put_resp_header("content-type", "application/activity+json")
18 |> json(UserView.render("user.json", %{user: user}))
19 else
20 nil -> {:error, :not_found}
21 end
22 end
23
24 def object(conn, %{"uuid" => uuid}) do
25 with ap_id <- o_status_url(conn, :object, uuid),
26 %Object{} = object <- Object.get_cached_by_ap_id(ap_id),
27 {_, true} <- {:public?, ActivityPub.is_public?(object)} do
28 conn
29 |> put_resp_header("content-type", "application/activity+json")
30 |> json(ObjectView.render("object.json", %{object: object}))
31 else
32 {:public?, false} ->
33 {:error, :not_found}
34 end
35 end
36
37 def following(conn, %{"nickname" => nickname, "page" => page}) do
38 with %User{} = user <- User.get_cached_by_nickname(nickname),
39 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
40 {page, _} = Integer.parse(page)
41
42 conn
43 |> put_resp_header("content-type", "application/activity+json")
44 |> json(UserView.render("following.json", %{user: user, page: page}))
45 end
46 end
47
48 def following(conn, %{"nickname" => nickname}) do
49 with %User{} = user <- User.get_cached_by_nickname(nickname),
50 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
51 conn
52 |> put_resp_header("content-type", "application/activity+json")
53 |> json(UserView.render("following.json", %{user: user}))
54 end
55 end
56
57 def followers(conn, %{"nickname" => nickname, "page" => page}) do
58 with %User{} = user <- User.get_cached_by_nickname(nickname),
59 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
60 {page, _} = Integer.parse(page)
61
62 conn
63 |> put_resp_header("content-type", "application/activity+json")
64 |> json(UserView.render("followers.json", %{user: user, page: page}))
65 end
66 end
67
68 def followers(conn, %{"nickname" => nickname}) do
69 with %User{} = user <- User.get_cached_by_nickname(nickname),
70 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
71 conn
72 |> put_resp_header("content-type", "application/activity+json")
73 |> json(UserView.render("followers.json", %{user: user}))
74 end
75 end
76
77 def outbox(conn, %{"nickname" => nickname, "max_id" => max_id}) do
78 with %User{} = user <- User.get_cached_by_nickname(nickname),
79 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
80 conn
81 |> put_resp_header("content-type", "application/activity+json")
82 |> json(UserView.render("outbox.json", %{user: user, max_id: max_id}))
83 end
84 end
85
86 def outbox(conn, %{"nickname" => nickname}) do
87 outbox(conn, %{"nickname" => nickname, "max_id" => nil})
88 end
89
90 # TODO: Ensure that this inbox is a recipient of the message
91 def inbox(%{assigns: %{valid_signature: true}} = conn, params) do
92 Federator.enqueue(:incoming_ap_doc, params)
93 json(conn, "ok")
94 end
95
96 # only accept relayed Creates
97 def inbox(conn, %{"type" => "Create"} = params) do
98 Logger.info(
99 "Signature missing or not from author, relayed Create message, fetching object from source"
100 )
101
102 ActivityPub.fetch_object_from_id(params["object"]["id"])
103
104 json(conn, "ok")
105 end
106
107 def inbox(conn, params) do
108 headers = Enum.into(conn.req_headers, %{})
109
110 if String.contains?(headers["signature"], params["actor"]) do
111 Logger.info(
112 "Signature validation error for: #{params["actor"]}, make sure you are forwarding the HTTP Host header!"
113 )
114
115 Logger.info(inspect(conn.req_headers))
116 end
117
118 json(conn, "error")
119 end
120
121 def relay(conn, params) do
122 with %User{} = user <- Relay.get_actor(),
123 {:ok, user} <- Pleroma.Web.WebFinger.ensure_keys_present(user) do
124 conn
125 |> put_resp_header("content-type", "application/activity+json")
126 |> json(UserView.render("user.json", %{user: user}))
127 else
128 nil -> {:error, :not_found}
129 end
130 end
131
132 def errors(conn, {:error, :not_found}) do
133 conn
134 |> put_status(404)
135 |> json("Not found")
136 end
137
138 def errors(conn, _e) do
139 conn
140 |> put_status(500)
141 |> json("error")
142 end
143 end