# Pleroma: A lightweight social networking server
-# Copyright © 2017-2020 Pleroma Authors <https://pleroma.social/>
+# Copyright © 2017-2021 Pleroma Authors <https://pleroma.social/>
# SPDX-License-Identifier: AGPL-3.0-only
defmodule Pleroma.Web.ActivityPub.ObjectValidators.CommonValidations do
cng
|> validate_change(field_name, fn field_name, actor ->
case User.get_cached_by_ap_id(actor) do
- %User{deactivated: true} ->
+ %User{is_active: false} ->
[{field_name, "user is deactivated"}]
%User{} ->
end)
end
- def validate_actor_is_active(cng, options \\ []) do
- field_name = Keyword.get(options, :field_name, :actor)
-
- cng
- |> validate_change(field_name, fn field_name, actor ->
- if %User{deactivated: false} = User.get_cached_by_ap_id(actor) do
- []
- else
- [{field_name, "can't find user (or deactivated)"}]
- end
- end)
- end
-
def validate_object_presence(cng, options \\ []) do
field_name = Keyword.get(options, :field_name, :object)
allowed_types = Keyword.get(options, :allowed_types, false)
end
def validate_host_match(cng, fields \\ [:id, :actor]) do
- unique_hosts =
- fields
- |> Enum.map(fn field ->
- %URI{host: host} =
- cng
- |> get_field(field)
- |> URI.parse()
-
- host
- end)
- |> Enum.uniq()
- |> Enum.count()
-
- if unique_hosts == 1 do
+ if same_domain?(cng, fields) do
cng
else
fields
end
def validate_fields_match(cng, fields) do
- unique_fields =
- fields
- |> Enum.map(fn field -> get_field(cng, field) end)
- |> Enum.uniq()
- |> Enum.count()
-
- if unique_fields == 1 do
+ if map_unique?(cng, fields) do
cng
else
fields
end)
end
end
+
+ defp map_unique?(cng, fields, func \\ & &1) do
+ Enum.reduce_while(fields, nil, fn field, acc ->
+ value =
+ cng
+ |> get_field(field)
+ |> func.()
+
+ case {value, acc} do
+ {value, nil} -> {:cont, value}
+ {value, value} -> {:cont, value}
+ _ -> {:halt, false}
+ end
+ end)
+ end
+
+ def same_domain?(cng, fields \\ [:actor, :object]) do
+ map_unique?(cng, fields, fn value -> URI.parse(value).host end)
+ end
+
+ # This figures out if a user is able to create, delete or modify something
+ # based on the domain and superuser status
+ def validate_modification_rights(cng) do
+ actor = User.get_cached_by_ap_id(get_field(cng, :actor))
+
+ if User.superuser?(actor) || same_domain?(cng) do
+ cng
+ else
+ cng
+ |> add_error(:actor, "is not allowed to modify object")
+ end
+ end
end