ensure local statuses are not visible remotely
[akkoma] / lib / pleroma / web / activity_pub / visibility.ex
1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2021 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
4
5 defmodule Pleroma.Web.ActivityPub.Visibility do
6 alias Pleroma.Activity
7 alias Pleroma.Object
8 alias Pleroma.Repo
9 alias Pleroma.User
10 alias Pleroma.Web.ActivityPub.Utils
11
12 require Pleroma.Constants
13
14 @spec is_public?(Object.t() | Activity.t() | map()) :: boolean()
15 def is_public?(%Object{data: %{"type" => "Tombstone"}}), do: false
16 def is_public?(%Object{data: data}), do: is_public?(data)
17 def is_public?(%Activity{data: %{"type" => "Move"}}), do: true
18 def is_public?(%Activity{data: data}), do: is_public?(data)
19 def is_public?(%{"directMessage" => true}), do: false
20
21 def is_public?(data) do
22 Utils.label_in_message?(Pleroma.Constants.as_public(), data) or
23 Utils.label_in_message?(Utils.as_local_public(), data)
24 end
25
26 def is_local_public?(%Object{data: data}), do: is_local_public?(data)
27 def is_local_public?(%Activity{data: data}), do: is_local_public?(data)
28
29 def is_local_public?(data) do
30 Utils.label_in_message?(Utils.as_local_public(), data) and
31 not Utils.label_in_message?(Pleroma.Constants.as_public(), data)
32 end
33
34 def is_private?(activity) do
35 with false <- is_public?(activity),
36 %User{follower_address: follower_address} <-
37 User.get_cached_by_ap_id(activity.data["actor"]) do
38 follower_address in activity.data["to"]
39 else
40 _ -> false
41 end
42 end
43
44 def is_announceable?(activity, user, public \\ true) do
45 is_public?(activity) ||
46 (!public && is_private?(activity) && activity.data["actor"] == user.ap_id)
47 end
48
49 def is_direct?(%Activity{data: %{"directMessage" => true}}), do: true
50 def is_direct?(%Object{data: %{"directMessage" => true}}), do: true
51
52 def is_direct?(activity) do
53 !is_public?(activity) && !is_private?(activity)
54 end
55
56 def is_list?(%{data: %{"listMessage" => _}}), do: true
57 def is_list?(_), do: false
58
59 @spec visible_for_user?(Object.t() | Activity.t() | nil, User.t() | nil) :: boolean()
60 def visible_for_user?(%Object{data: %{"type" => "Tombstone"}}, _), do: false
61 def visible_for_user?(%Activity{actor: ap_id}, %User{ap_id: ap_id}), do: true
62 def visible_for_user?(%Object{data: %{"actor" => ap_id}}, %User{ap_id: ap_id}), do: true
63 def visible_for_user?(nil, _), do: false
64 def visible_for_user?(%Activity{data: %{"listMessage" => _}}, nil), do: false
65
66 def visible_for_user?(
67 %Activity{data: %{"listMessage" => list_ap_id}} = activity,
68 %User{} = user
69 ) do
70 user.ap_id in activity.data["to"] ||
71 list_ap_id
72 |> Pleroma.List.get_by_ap_id()
73 |> Pleroma.List.member?(user)
74 end
75
76 def visible_for_user?(%{__struct__: module} = message, nil)
77 when module in [Activity, Object] do
78 if restrict_unauthenticated_access?(message),
79 do: false,
80 else: is_public?(message) and not is_local_public?(message)
81 end
82
83 def visible_for_user?(%{__struct__: module} = message, user)
84 when module in [Activity, Object] do
85 x = [user.ap_id | User.following(user)]
86 y = [message.data["actor"]] ++ message.data["to"] ++ (message.data["cc"] || [])
87
88 if is_local_public?(message) do
89 user.local
90 else
91 is_public?(message) || Enum.any?(x, &(&1 in y))
92 end
93 end
94
95 def entire_thread_visible_for_user?(%Activity{} = activity, %User{} = user) do
96 {:ok, %{rows: [[result]]}} =
97 Ecto.Adapters.SQL.query(Repo, "SELECT thread_visibility($1, $2)", [
98 user.ap_id,
99 activity.data["id"]
100 ])
101
102 result
103 end
104
105 def restrict_unauthenticated_access?(%Activity{local: local}) do
106 restrict_unauthenticated_access_to_activity?(local)
107 end
108
109 def restrict_unauthenticated_access?(%Object{} = object) do
110 object
111 |> Object.local?()
112 |> restrict_unauthenticated_access_to_activity?()
113 end
114
115 def restrict_unauthenticated_access?(%User{} = user) do
116 User.visible_for(user, _reading_user = nil)
117 end
118
119 defp restrict_unauthenticated_access_to_activity?(local?) when is_boolean(local?) do
120 cfg_key = if local?, do: :local, else: :remote
121
122 Pleroma.Config.restrict_unauthenticated_access?(:activities, cfg_key)
123 end
124
125 def get_visibility(object) do
126 to = object.data["to"] || []
127 cc = object.data["cc"] || []
128
129 cond do
130 Pleroma.Constants.as_public() in to ->
131 "public"
132
133 Pleroma.Constants.as_public() in cc ->
134 "unlisted"
135
136 Utils.as_local_public() in to ->
137 "local"
138
139 # this should use the sql for the object's activity
140 Enum.any?(to, &String.contains?(&1, "/followers")) ->
141 "private"
142
143 object.data["directMessage"] == true ->
144 "direct"
145
146 is_binary(object.data["listMessage"]) ->
147 "list"
148
149 length(cc) > 0 ->
150 "private"
151
152 true ->
153 "direct"
154 end
155 end
156 end