activitypub: object view: sanitize both the activity and the object when an activity...
authorWilliam Pitcock <nenolod@dereferenced.org>
Sat, 10 Nov 2018 12:04:09 +0000 (12:04 +0000)
committerWilliam Pitcock <nenolod@dereferenced.org>
Sat, 10 Nov 2018 12:04:09 +0000 (12:04 +0000)
lib/pleroma/web/activity_pub/views/object_view.ex

index df734a871f76ae32ef64d66751abcd4c4eb58b64..1911ddfb7e18a0958d17efdb3814bf4aee820813 100644 (file)
@@ -1,11 +1,23 @@
 defmodule Pleroma.Web.ActivityPub.ObjectView do
   use Pleroma.Web, :view
+  alias Pleroma.{Object, Activity}
   alias Pleroma.Web.ActivityPub.Transmogrifier
 
-  def render("object.json", %{object: object}) do
+  def render("object.json", %{object: %Object{} = object}) do
     base = Pleroma.Web.ActivityPub.Utils.make_json_ld_header()
 
     additional = Transmogrifier.prepare_object(object.data)
     Map.merge(base, additional)
   end
+
+  def render("object.json", %{object: %Activity{} = activity}) do
+    base = Pleroma.Web.ActivityPub.Utils.make_json_ld_header()
+    object = Object.normalize(activity.data["object"])
+
+    additional =
+      Transmogrifier.prepare_object(activity.data)
+      |> Map.put("object", Transmogrifier.prepare_object(object.data))
+
+    Map.merge(base, additional)
+  end
 end