1 # Pleroma: A lightweight social networking server
2 # Copyright © 2017-2021 Pleroma Authors <https://pleroma.social/>
3 # SPDX-License-Identifier: AGPL-3.0-only
5 defmodule Pleroma.Web.ActivityPub.TransmogrifierTest do
6 use Oban.Testing, repo: Pleroma.Repo
11 alias Pleroma.Tests.ObanHelpers
13 alias Pleroma.Web.ActivityPub.Transmogrifier
14 alias Pleroma.Web.AdminAPI.AccountView
15 alias Pleroma.Web.CommonAPI
18 import Pleroma.Factory
19 import ExUnit.CaptureLog
22 Tesla.Mock.mock_global(fn env -> apply(HttpRequestMock, :request, [env]) end)
26 setup do: clear_config([:instance, :max_remote_account_fields])
28 describe "handle_incoming" do
29 test "it works for incoming unfollows with an existing follow" do
33 File.read!("test/fixtures/mastodon-follow-activity.json")
35 |> Map.put("object", user.ap_id)
37 {:ok, %Activity{data: _, local: false}} = Transmogrifier.handle_incoming(follow_data)
40 File.read!("test/fixtures/mastodon-unfollow-activity.json")
42 |> Map.put("object", follow_data)
44 {:ok, %Activity{data: data, local: false}} = Transmogrifier.handle_incoming(data)
46 assert data["type"] == "Undo"
47 assert data["object"]["type"] == "Follow"
48 assert data["object"]["object"] == user.ap_id
49 assert data["actor"] == "http://mastodon.example.org/users/admin"
51 refute User.following?(User.get_cached_by_ap_id(data["actor"]), user)
54 test "it accepts Flag activities" do
56 other_user = insert(:user)
58 {:ok, activity} = CommonAPI.post(user, %{status: "test post"})
59 object = Object.normalize(activity, fetch: false)
63 "id" => activity.data["id"],
64 "content" => "test post",
65 "published" => object.data["published"],
66 "actor" => AccountView.render("show.json", %{user: user, skip_visibility_check: true})
70 "@context" => "https://www.w3.org/ns/activitystreams",
72 "object" => [user.ap_id, activity.data["id"]],
74 "content" => "blocked AND reported!!!",
75 "actor" => other_user.ap_id
78 assert {:ok, activity} = Transmogrifier.handle_incoming(message)
80 assert activity.data["object"] == [user.ap_id, note_obj]
81 assert activity.data["content"] == "blocked AND reported!!!"
82 assert activity.data["actor"] == other_user.ap_id
83 assert activity.data["cc"] == [user.ap_id]
86 test "it accepts Move activities" do
87 old_user = insert(:user)
88 new_user = insert(:user)
91 "@context" => "https://www.w3.org/ns/activitystreams",
93 "actor" => old_user.ap_id,
94 "object" => old_user.ap_id,
95 "target" => new_user.ap_id
98 assert :error = Transmogrifier.handle_incoming(message)
100 {:ok, _new_user} = User.update_and_set_cache(new_user, %{also_known_as: [old_user.ap_id]})
102 assert {:ok, %Activity{} = activity} = Transmogrifier.handle_incoming(message)
103 assert activity.actor == old_user.ap_id
104 assert activity.data["actor"] == old_user.ap_id
105 assert activity.data["object"] == old_user.ap_id
106 assert activity.data["target"] == new_user.ap_id
107 assert activity.data["type"] == "Move"
111 describe "prepare outgoing" do
112 test "it inlines private announced objects" do
115 {:ok, activity} = CommonAPI.post(user, %{status: "hey", visibility: "private"})
117 {:ok, announce_activity} = CommonAPI.repeat(activity.id, user)
119 {:ok, modified} = Transmogrifier.prepare_outgoing(announce_activity.data)
121 assert modified["object"]["content"] == "hey"
122 assert modified["object"]["actor"] == modified["object"]["attributedTo"]
125 test "it turns mentions into tags" do
127 other_user = insert(:user)
130 CommonAPI.post(user, %{status: "hey, @#{other_user.nickname}, how are ya? #2hu"})
132 with_mock Pleroma.Notification,
133 get_notified_from_activity: fn _, _ -> [] end do
134 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
136 object = modified["object"]
138 expected_mention = %{
139 "href" => other_user.ap_id,
140 "name" => "@#{other_user.nickname}",
145 "href" => Pleroma.Web.Endpoint.url() <> "/tags/2hu",
150 refute called(Pleroma.Notification.get_notified_from_activity(:_, :_))
151 assert Enum.member?(object["tag"], expected_tag)
152 assert Enum.member?(object["tag"], expected_mention)
156 test "it adds the sensitive property" do
159 {:ok, activity} = CommonAPI.post(user, %{status: "#nsfw hey"})
160 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
162 assert modified["object"]["sensitive"]
165 test "it adds the json-ld context and the conversation property" do
168 {:ok, activity} = CommonAPI.post(user, %{status: "hey"})
169 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
171 assert modified["@context"] ==
172 Pleroma.Web.ActivityPub.Utils.make_json_ld_header()["@context"]
174 assert modified["object"]["conversation"] == modified["context"]
177 test "it sets the 'attributedTo' property to the actor of the object if it doesn't have one" do
180 {:ok, activity} = CommonAPI.post(user, %{status: "hey"})
181 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
183 assert modified["object"]["actor"] == modified["object"]["attributedTo"]
186 test "it strips internal hashtag data" do
189 {:ok, activity} = CommonAPI.post(user, %{status: "#2hu"})
192 "href" => Pleroma.Web.Endpoint.url() <> "/tags/2hu",
197 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
199 assert modified["object"]["tag"] == [expected_tag]
202 test "it strips internal fields" do
206 CommonAPI.post(user, %{
207 status: "#2hu :firefox:",
208 generator: %{type: "Application", name: "TestClient", url: "https://pleroma.social"}
211 # Ensure injected application data made it into the activity
212 # as we don't have a Token to derive it from, otherwise it will
213 # be nil and the test will pass
217 url: "https://pleroma.social"
218 } == activity.object.data["generator"]
220 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
222 assert length(modified["object"]["tag"]) == 2
224 assert is_nil(modified["object"]["emoji"])
225 assert is_nil(modified["object"]["like_count"])
226 assert is_nil(modified["object"]["announcements"])
227 assert is_nil(modified["object"]["announcement_count"])
228 assert is_nil(modified["object"]["context_id"])
229 assert is_nil(modified["object"]["generator"])
232 test "it strips internal fields of article" do
233 activity = insert(:article_activity)
235 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
237 assert length(modified["object"]["tag"]) == 2
239 assert is_nil(modified["object"]["emoji"])
240 assert is_nil(modified["object"]["like_count"])
241 assert is_nil(modified["object"]["announcements"])
242 assert is_nil(modified["object"]["announcement_count"])
243 assert is_nil(modified["object"]["context_id"])
244 assert is_nil(modified["object"]["likes"])
247 test "the directMessage flag is present" do
249 other_user = insert(:user)
251 {:ok, activity} = CommonAPI.post(user, %{status: "2hu :moominmamma:"})
253 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
255 assert modified["directMessage"] == false
257 {:ok, activity} = CommonAPI.post(user, %{status: "@#{other_user.nickname} :moominmamma:"})
259 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
261 assert modified["directMessage"] == false
264 CommonAPI.post(user, %{
265 status: "@#{other_user.nickname} :moominmamma:",
269 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
271 assert modified["directMessage"] == true
274 test "it strips BCC field" do
276 {:ok, list} = Pleroma.List.create("foo", user)
278 {:ok, activity} = CommonAPI.post(user, %{status: "foobar", visibility: "list:#{list.id}"})
280 {:ok, modified} = Transmogrifier.prepare_outgoing(activity.data)
282 assert is_nil(modified["bcc"])
285 test "it can handle Listen activities" do
286 listen_activity = insert(:listen)
288 {:ok, modified} = Transmogrifier.prepare_outgoing(listen_activity.data)
290 assert modified["type"] == "Listen"
294 {:ok, activity} = CommonAPI.listen(user, %{"title" => "lain radio episode 1"})
296 {:ok, _modified} = Transmogrifier.prepare_outgoing(activity.data)
299 test "custom emoji urls are URI encoded" do
300 # :dinosaur: filename has a space -> dino walking.gif
303 {:ok, activity} = CommonAPI.post(user, %{status: "everybody do the dinosaur :dinosaur:"})
305 {:ok, prepared} = Transmogrifier.prepare_outgoing(activity.data)
307 assert length(prepared["object"]["tag"]) == 1
309 url = prepared["object"]["tag"] |> List.first() |> Map.get("icon") |> Map.get("url")
311 assert url == "http://localhost:4001/emoji/dino%20walking.gif"
315 describe "user upgrade" do
316 test "it upgrades a user to activitypub" do
319 nickname: "rye@niu.moe",
321 ap_id: "https://niu.moe/users/rye",
322 follower_address: User.ap_followers(%User{nickname: "rye@niu.moe"})
325 user_two = insert(:user)
326 Pleroma.FollowingRelationship.follow(user_two, user, :follow_accept)
328 {:ok, activity} = CommonAPI.post(user, %{status: "test"})
329 {:ok, unrelated_activity} = CommonAPI.post(user_two, %{status: "test"})
330 assert "http://localhost:4001/users/rye@niu.moe/followers" in activity.recipients
332 user = User.get_cached_by_id(user.id)
333 assert user.note_count == 1
335 {:ok, user} = Transmogrifier.upgrade_user_from_ap_id("https://niu.moe/users/rye")
336 ObanHelpers.perform_all()
338 assert user.ap_enabled
339 assert user.note_count == 1
340 assert user.follower_address == "https://niu.moe/users/rye/followers"
341 assert user.following_address == "https://niu.moe/users/rye/following"
343 user = User.get_cached_by_id(user.id)
344 assert user.note_count == 1
346 activity = Activity.get_by_id(activity.id)
347 assert user.follower_address in activity.recipients
353 "https://cdn.niu.moe/accounts/avatars/000/033/323/original/fd7f8ae0b3ffedc9.jpeg"
362 "https://cdn.niu.moe/accounts/headers/000/033/323/original/850b3448fa5fd477.png"
367 refute "..." in activity.recipients
369 unrelated_activity = Activity.get_by_id(unrelated_activity.id)
370 refute user.follower_address in unrelated_activity.recipients
372 user_two = User.get_cached_by_id(user_two.id)
373 assert User.following?(user_two, user)
374 refute "..." in User.following(user_two)
378 describe "actor rewriting" do
379 test "it fixes the actor URL property to be a proper URI" do
381 "url" => %{"href" => "http://example.com"}
384 rewritten = Transmogrifier.maybe_fix_user_object(data)
385 assert rewritten["url"] == "http://example.com"
389 describe "actor origin containment" do
390 test "it rejects activities which reference objects with bogus origins" do
392 "@context" => "https://www.w3.org/ns/activitystreams",
393 "id" => "http://mastodon.example.org/users/admin/activities/1234",
394 "actor" => "http://mastodon.example.org/users/admin",
395 "to" => ["https://www.w3.org/ns/activitystreams#Public"],
396 "object" => "https://info.pleroma.site/activity.json",
400 assert capture_log(fn ->
401 {:error, _} = Transmogrifier.handle_incoming(data)
402 end) =~ "Object containment failed"
405 test "it rejects activities which reference objects that have an incorrect attribution (variant 1)" do
407 "@context" => "https://www.w3.org/ns/activitystreams",
408 "id" => "http://mastodon.example.org/users/admin/activities/1234",
409 "actor" => "http://mastodon.example.org/users/admin",
410 "to" => ["https://www.w3.org/ns/activitystreams#Public"],
411 "object" => "https://info.pleroma.site/activity2.json",
415 assert capture_log(fn ->
416 {:error, _} = Transmogrifier.handle_incoming(data)
417 end) =~ "Object containment failed"
420 test "it rejects activities which reference objects that have an incorrect attribution (variant 2)" do
422 "@context" => "https://www.w3.org/ns/activitystreams",
423 "id" => "http://mastodon.example.org/users/admin/activities/1234",
424 "actor" => "http://mastodon.example.org/users/admin",
425 "to" => ["https://www.w3.org/ns/activitystreams#Public"],
426 "object" => "https://info.pleroma.site/activity3.json",
430 assert capture_log(fn ->
431 {:error, _} = Transmogrifier.handle_incoming(data)
432 end) =~ "Object containment failed"
436 describe "fix_explicit_addressing" do
442 test "moves non-explicitly mentioned actors to cc", %{user: user} do
443 explicitly_mentioned_actors = [
444 "https://pleroma.gold/users/user1",
445 "https://pleroma.gold/user2"
449 "actor" => user.ap_id,
450 "to" => explicitly_mentioned_actors ++ ["https://social.beepboop.ga/users/dirb"],
453 Enum.map(explicitly_mentioned_actors, fn href ->
454 %{"type" => "Mention", "href" => href}
458 fixed_object = Transmogrifier.fix_explicit_addressing(object)
459 assert Enum.all?(explicitly_mentioned_actors, &(&1 in fixed_object["to"]))
460 refute "https://social.beepboop.ga/users/dirb" in fixed_object["to"]
461 assert "https://social.beepboop.ga/users/dirb" in fixed_object["cc"]
464 test "does not move actor's follower collection to cc", %{user: user} do
466 "actor" => user.ap_id,
467 "to" => [user.follower_address],
471 fixed_object = Transmogrifier.fix_explicit_addressing(object)
472 assert user.follower_address in fixed_object["to"]
473 refute user.follower_address in fixed_object["cc"]
476 test "removes recipient's follower collection from cc", %{user: user} do
477 recipient = insert(:user)
480 "actor" => user.ap_id,
481 "to" => [recipient.ap_id, "https://www.w3.org/ns/activitystreams#Public"],
482 "cc" => [user.follower_address, recipient.follower_address]
485 fixed_object = Transmogrifier.fix_explicit_addressing(object)
487 assert user.follower_address in fixed_object["cc"]
488 refute recipient.follower_address in fixed_object["cc"]
489 refute recipient.follower_address in fixed_object["to"]
493 describe "fix_summary/1" do
494 test "returns fixed object" do
495 assert Transmogrifier.fix_summary(%{"summary" => nil}) == %{"summary" => ""}
496 assert Transmogrifier.fix_summary(%{"summary" => "ok"}) == %{"summary" => "ok"}
497 assert Transmogrifier.fix_summary(%{}) == %{"summary" => ""}
501 describe "fix_url/1" do
502 test "fixes data for object when url is map" do
506 "mimeType" => "video/mp4",
507 "href" => "https://peede8d-46fb-ad81-2d4c2d1630e3-480.mp4"
511 assert Transmogrifier.fix_url(object) == %{
512 "url" => "https://peede8d-46fb-ad81-2d4c2d1630e3-480.mp4"
516 test "returns non-modified object" do
517 assert Transmogrifier.fix_url(%{"type" => "Text"}) == %{"type" => "Text"}
521 describe "get_obj_helper/2" do
522 test "returns nil when cannot normalize object" do
523 assert capture_log(fn ->
524 refute Transmogrifier.get_obj_helper("test-obj-id")
525 end) =~ "Unsupported URI scheme"
528 @tag capture_log: true
529 test "returns {:ok, %Object{}} for success case" do
530 assert {:ok, %Object{}} =
531 Transmogrifier.get_obj_helper(
532 "https://mstdn.io/users/mayuutann/statuses/99568293732299394"