Merge branch 'openapi/admin/status' into 'develop'
[akkoma] / lib / pleroma / web / activity_pub / object_validators / announce_validator.ex
index 158ae199d4d6ff6bd884901103680e9e1e2ea7b9..40f861f477b83d64dc72d7893bc6bccc72e89daf 100644 (file)
@@ -5,12 +5,17 @@
 defmodule Pleroma.Web.ActivityPub.ObjectValidators.AnnounceValidator do
   use Ecto.Schema
 
+  alias Pleroma.Object
+  alias Pleroma.User
   alias Pleroma.Web.ActivityPub.ObjectValidators.Types
   alias Pleroma.Web.ActivityPub.Utils
+  alias Pleroma.Web.ActivityPub.Visibility
 
   import Ecto.Changeset
   import Pleroma.Web.ActivityPub.ObjectValidators.CommonValidations
 
+  require Pleroma.Constants
+
   @primary_key false
 
   embedded_schema do
@@ -18,9 +23,10 @@ defmodule Pleroma.Web.ActivityPub.ObjectValidators.AnnounceValidator do
     field(:type, :string)
     field(:object, Types.ObjectID)
     field(:actor, Types.ObjectID)
-    field(:context, :string)
+    field(:context, :string, autogenerate: {Utils, :generate_context_id, []})
     field(:to, Types.Recipients, default: [])
     field(:cc, Types.Recipients, default: [])
+    field(:published, Types.DateTime)
   end
 
   def cast_and_validate(data) do
@@ -47,10 +53,37 @@ defmodule Pleroma.Web.ActivityPub.ObjectValidators.AnnounceValidator do
   def validate_data(data_cng) do
     data_cng
     |> validate_inclusion(:type, ["Announce"])
-    |> validate_required([:id, :type, :object, :actor, :context, :to, :cc])
+    |> validate_required([:id, :type, :object, :actor, :to, :cc])
     |> validate_actor_presence()
     |> validate_object_presence()
     |> validate_existing_announce()
+    |> validate_announcable()
+  end
+
+  def validate_announcable(cng) do
+    with actor when is_binary(actor) <- get_field(cng, :actor),
+         object when is_binary(object) <- get_field(cng, :object),
+         %User{} = actor <- User.get_cached_by_ap_id(actor),
+         %Object{} = object <- Object.get_cached_by_ap_id(object),
+         false <- Visibility.is_public?(object) do
+      same_actor = object.data["actor"] == actor.ap_id
+      is_public = Pleroma.Constants.as_public() in (get_field(cng, :to) ++ get_field(cng, :cc))
+
+      cond do
+        same_actor && is_public ->
+          cng
+          |> add_error(:actor, "can not announce this object publicly")
+
+        !same_actor ->
+          cng
+          |> add_error(:actor, "can not announce this object")
+
+        true ->
+          cng
+      end
+    else
+      _ -> cng
+    end
   end
 
   def validate_existing_announce(cng) do