1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2019 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
5 defmodule Pleroma.Web.ActivityPub.MRF.SimplePolicy do
7 alias Pleroma.Web.ActivityPub.MRF
8 @moduledoc "Filter activities depending on their origin instance"
11 defp check_accept(%{host: actor_host} = _actor_info, object) do
13 Pleroma.Config.get([:mrf_simple, :accept])
14 |> MRF.subdomains_regex()
17 accepts == [] -> {:ok, object}
18 actor_host == Pleroma.Config.get([Pleroma.Web.Endpoint, :url, :host]) -> {:ok, object}
19 MRF.subdomain_match?(accepts, actor_host) -> {:ok, object}
20 true -> {:reject, nil}
24 defp check_reject(%{host: actor_host} = _actor_info, object) do
26 Pleroma.Config.get([:mrf_simple, :reject])
27 |> MRF.subdomains_regex()
29 if MRF.subdomain_match?(rejects, actor_host) do
36 defp check_media_removal(
37 %{host: actor_host} = _actor_info,
38 %{"type" => "Create", "object" => %{"attachment" => child_attachment}} = object
40 when length(child_attachment) > 0 do
42 Pleroma.Config.get([:mrf_simple, :media_removal])
43 |> MRF.subdomains_regex()
46 if MRF.subdomain_match?(media_removal, actor_host) do
47 child_object = Map.delete(object["object"], "attachment")
48 Map.put(object, "object", child_object)
56 defp check_media_removal(_actor_info, object), do: {:ok, object}
58 defp check_media_nsfw(
59 %{host: actor_host} = _actor_info,
62 "object" => child_object
66 Pleroma.Config.get([:mrf_simple, :media_nsfw])
67 |> MRF.subdomains_regex()
70 if MRF.subdomain_match?(media_nsfw, actor_host) do
71 tags = (child_object["tag"] || []) ++ ["nsfw"]
72 child_object = Map.put(child_object, "tag", tags)
73 child_object = Map.put(child_object, "sensitive", true)
74 Map.put(object, "object", child_object)
82 defp check_media_nsfw(_actor_info, object), do: {:ok, object}
84 defp check_ftl_removal(%{host: actor_host} = _actor_info, object) do
86 Pleroma.Config.get([:mrf_simple, :federated_timeline_removal])
87 |> MRF.subdomains_regex()
90 with true <- MRF.subdomain_match?(timeline_removal, actor_host),
91 user <- User.get_cached_by_ap_id(object["actor"]),
92 true <- "https://www.w3.org/ns/activitystreams#Public" in object["to"] do
94 List.delete(object["to"], "https://www.w3.org/ns/activitystreams#Public") ++
95 [user.follower_address]
98 List.delete(object["cc"], user.follower_address) ++
99 ["https://www.w3.org/ns/activitystreams#Public"]
111 defp check_report_removal(%{host: actor_host} = _actor_info, %{"type" => "Flag"} = object) do
113 Pleroma.Config.get([:mrf_simple, :report_removal])
114 |> MRF.subdomains_regex()
116 if MRF.subdomain_match?(report_removal, actor_host) do
123 defp check_report_removal(_actor_info, object), do: {:ok, object}
125 defp check_avatar_removal(%{host: actor_host} = _actor_info, %{"icon" => _icon} = object) do
127 Pleroma.Config.get([:mrf_simple, :avatar_removal])
128 |> MRF.subdomains_regex()
130 if MRF.subdomain_match?(avatar_removal, actor_host) do
131 {:ok, Map.delete(object, "icon")}
137 defp check_avatar_removal(_actor_info, object), do: {:ok, object}
139 defp check_banner_removal(%{host: actor_host} = _actor_info, %{"image" => _image} = object) do
141 Pleroma.Config.get([:mrf_simple, :banner_removal])
142 |> MRF.subdomains_regex()
144 if MRF.subdomain_match?(banner_removal, actor_host) do
145 {:ok, Map.delete(object, "image")}
151 defp check_banner_removal(_actor_info, object), do: {:ok, object}
154 def filter(%{"actor" => actor} = object) do
155 actor_info = URI.parse(actor)
157 with {:ok, object} <- check_accept(actor_info, object),
158 {:ok, object} <- check_reject(actor_info, object),
159 {:ok, object} <- check_media_removal(actor_info, object),
160 {:ok, object} <- check_media_nsfw(actor_info, object),
161 {:ok, object} <- check_ftl_removal(actor_info, object),
162 {:ok, object} <- check_report_removal(actor_info, object) do
169 def filter(%{"id" => actor, "type" => obj_type} = object)
170 when obj_type in ["Application", "Group", "Organization", "Person", "Service"] do
171 actor_info = URI.parse(actor)
173 with {:ok, object} <- check_avatar_removal(actor_info, object),
174 {:ok, object} <- check_banner_removal(actor_info, object) do
181 def filter(object), do: {:ok, object}