2020-07-06 10:59:06 +00:00
|
|
|
# Pleroma: A lightweight social networking server
|
|
|
|
# Copyright © 2017-2020 Pleroma Authors <https://pleroma.social/>
|
|
|
|
# SPDX-License-Identifier: AGPL-3.0-only
|
|
|
|
|
2019-10-17 16:36:52 +00:00
|
|
|
defmodule Pleroma.Web.ActivityPub.ObjectValidatorTest do
|
|
|
|
use Pleroma.DataCase
|
|
|
|
|
2020-04-28 14:45:28 +00:00
|
|
|
alias Pleroma.Object
|
2020-04-20 10:29:19 +00:00
|
|
|
alias Pleroma.Web.ActivityPub.Builder
|
2019-10-17 16:36:52 +00:00
|
|
|
alias Pleroma.Web.ActivityPub.ObjectValidator
|
2020-05-06 14:31:21 +00:00
|
|
|
alias Pleroma.Web.ActivityPub.ObjectValidators.LikeValidator
|
2019-10-17 16:36:52 +00:00
|
|
|
alias Pleroma.Web.ActivityPub.Utils
|
2019-10-23 10:18:05 +00:00
|
|
|
alias Pleroma.Web.CommonAPI
|
|
|
|
|
2019-10-17 16:36:52 +00:00
|
|
|
import Pleroma.Factory
|
|
|
|
|
2020-05-05 12:17:47 +00:00
|
|
|
describe "Undos" do
|
|
|
|
setup do
|
|
|
|
user = insert(:user)
|
2020-05-12 19:59:26 +00:00
|
|
|
{:ok, post_activity} = CommonAPI.post(user, %{status: "uguu"})
|
2020-05-05 12:17:47 +00:00
|
|
|
{:ok, like} = CommonAPI.favorite(user, post_activity.id)
|
|
|
|
{:ok, valid_like_undo, []} = Builder.undo(user, like)
|
|
|
|
|
|
|
|
%{user: user, like: like, valid_like_undo: valid_like_undo}
|
|
|
|
end
|
|
|
|
|
|
|
|
test "it validates a basic like undo", %{valid_like_undo: valid_like_undo} do
|
|
|
|
assert {:ok, _, _} = ObjectValidator.validate(valid_like_undo, [])
|
|
|
|
end
|
|
|
|
|
|
|
|
test "it does not validate if the actor of the undo is not the actor of the object", %{
|
|
|
|
valid_like_undo: valid_like_undo
|
|
|
|
} do
|
|
|
|
other_user = insert(:user, ap_id: "https://gensokyo.2hu/users/raymoo")
|
|
|
|
|
|
|
|
bad_actor =
|
|
|
|
valid_like_undo
|
|
|
|
|> Map.put("actor", other_user.ap_id)
|
|
|
|
|
|
|
|
{:error, cng} = ObjectValidator.validate(bad_actor, [])
|
|
|
|
|
|
|
|
assert {:actor, {"not the same as object actor", []}} in cng.errors
|
|
|
|
end
|
|
|
|
|
|
|
|
test "it does not validate if the object is missing", %{valid_like_undo: valid_like_undo} do
|
|
|
|
missing_object =
|
|
|
|
valid_like_undo
|
|
|
|
|> Map.put("object", "https://gensokyo.2hu/objects/1")
|
|
|
|
|
|
|
|
{:error, cng} = ObjectValidator.validate(missing_object, [])
|
|
|
|
|
|
|
|
assert {:object, {"can't find object", []}} in cng.errors
|
|
|
|
assert length(cng.errors) == 1
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2020-04-29 17:09:51 +00:00
|
|
|
describe "deletes" do
|
|
|
|
setup do
|
|
|
|
user = insert(:user)
|
2020-05-12 19:59:26 +00:00
|
|
|
{:ok, post_activity} = CommonAPI.post(user, %{status: "cancel me daddy"})
|
2020-04-29 17:09:51 +00:00
|
|
|
|
|
|
|
{:ok, valid_post_delete, _} = Builder.delete(user, post_activity.data["object"])
|
2020-04-30 13:42:30 +00:00
|
|
|
{:ok, valid_user_delete, _} = Builder.delete(user, user.ap_id)
|
2020-04-29 17:09:51 +00:00
|
|
|
|
2020-04-30 13:42:30 +00:00
|
|
|
%{user: user, valid_post_delete: valid_post_delete, valid_user_delete: valid_user_delete}
|
2020-04-29 17:09:51 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
test "it is valid for a post deletion", %{valid_post_delete: valid_post_delete} do
|
2020-04-30 15:58:31 +00:00
|
|
|
{:ok, valid_post_delete, _} = ObjectValidator.validate(valid_post_delete, [])
|
2020-04-30 15:53:02 +00:00
|
|
|
|
2020-04-30 15:58:31 +00:00
|
|
|
assert valid_post_delete["deleted_activity_id"]
|
2020-04-29 17:09:51 +00:00
|
|
|
end
|
|
|
|
|
2020-05-01 11:34:47 +00:00
|
|
|
test "it is invalid if the object isn't in a list of certain types", %{
|
|
|
|
valid_post_delete: valid_post_delete
|
|
|
|
} do
|
|
|
|
object = Object.get_by_ap_id(valid_post_delete["object"])
|
|
|
|
|
|
|
|
data =
|
|
|
|
object.data
|
|
|
|
|> Map.put("type", "Like")
|
|
|
|
|
|
|
|
{:ok, _object} =
|
|
|
|
object
|
|
|
|
|> Ecto.Changeset.change(%{data: data})
|
|
|
|
|> Object.update_and_set_cache()
|
|
|
|
|
|
|
|
{:error, cng} = ObjectValidator.validate(valid_post_delete, [])
|
|
|
|
assert {:object, {"object not in allowed types", []}} in cng.errors
|
|
|
|
end
|
|
|
|
|
2020-04-30 13:42:30 +00:00
|
|
|
test "it is valid for a user deletion", %{valid_user_delete: valid_user_delete} do
|
|
|
|
assert match?({:ok, _, _}, ObjectValidator.validate(valid_user_delete, []))
|
|
|
|
end
|
|
|
|
|
2020-04-29 17:09:51 +00:00
|
|
|
test "it's invalid if the id is missing", %{valid_post_delete: valid_post_delete} do
|
|
|
|
no_id =
|
|
|
|
valid_post_delete
|
|
|
|
|> Map.delete("id")
|
|
|
|
|
|
|
|
{:error, cng} = ObjectValidator.validate(no_id, [])
|
|
|
|
|
|
|
|
assert {:id, {"can't be blank", [validation: :required]}} in cng.errors
|
|
|
|
end
|
|
|
|
|
|
|
|
test "it's invalid if the object doesn't exist", %{valid_post_delete: valid_post_delete} do
|
|
|
|
missing_object =
|
|
|
|
valid_post_delete
|
|
|
|
|> Map.put("object", "http://does.not/exist")
|
|
|
|
|
|
|
|
{:error, cng} = ObjectValidator.validate(missing_object, [])
|
|
|
|
|
|
|
|
assert {:object, {"can't find object", []}} in cng.errors
|
|
|
|
end
|
|
|
|
|
|
|
|
test "it's invalid if the actor of the object and the actor of delete are from different domains",
|
|
|
|
%{valid_post_delete: valid_post_delete} do
|
2020-04-30 19:23:18 +00:00
|
|
|
valid_user = insert(:user)
|
|
|
|
|
2020-04-29 17:09:51 +00:00
|
|
|
valid_other_actor =
|
|
|
|
valid_post_delete
|
2020-04-30 19:23:18 +00:00
|
|
|
|> Map.put("actor", valid_user.ap_id)
|
2020-04-29 17:09:51 +00:00
|
|
|
|
|
|
|
assert match?({:ok, _, _}, ObjectValidator.validate(valid_other_actor, []))
|
|
|
|
|
|
|
|
invalid_other_actor =
|
|
|
|
valid_post_delete
|
|
|
|
|> Map.put("actor", "https://gensokyo.2hu/users/raymoo")
|
|
|
|
|
|
|
|
{:error, cng} = ObjectValidator.validate(invalid_other_actor, [])
|
|
|
|
|
|
|
|
assert {:actor, {"is not allowed to delete object", []}} in cng.errors
|
|
|
|
end
|
2020-04-30 19:23:18 +00:00
|
|
|
|
|
|
|
test "it's valid if the actor of the object is a local superuser",
|
|
|
|
%{valid_post_delete: valid_post_delete} do
|
|
|
|
user =
|
|
|
|
insert(:user, local: true, is_moderator: true, ap_id: "https://gensokyo.2hu/users/raymoo")
|
|
|
|
|
|
|
|
valid_other_actor =
|
|
|
|
valid_post_delete
|
|
|
|
|> Map.put("actor", user.ap_id)
|
|
|
|
|
|
|
|
{:ok, _, meta} = ObjectValidator.validate(valid_other_actor, [])
|
|
|
|
assert meta[:do_not_federate]
|
|
|
|
end
|
2020-04-29 17:09:51 +00:00
|
|
|
end
|
|
|
|
|
2019-10-17 16:36:52 +00:00
|
|
|
describe "likes" do
|
|
|
|
setup do
|
|
|
|
user = insert(:user)
|
2020-05-12 19:59:26 +00:00
|
|
|
{:ok, post_activity} = CommonAPI.post(user, %{status: "uguu"})
|
2019-10-17 16:36:52 +00:00
|
|
|
|
|
|
|
valid_like = %{
|
2019-10-17 17:35:31 +00:00
|
|
|
"to" => [user.ap_id],
|
|
|
|
"cc" => [],
|
2019-10-17 16:36:52 +00:00
|
|
|
"type" => "Like",
|
|
|
|
"id" => Utils.generate_activity_id(),
|
|
|
|
"object" => post_activity.data["object"],
|
|
|
|
"actor" => user.ap_id,
|
|
|
|
"context" => "a context"
|
|
|
|
}
|
|
|
|
|
|
|
|
%{valid_like: valid_like, user: user, post_activity: post_activity}
|
|
|
|
end
|
|
|
|
|
|
|
|
test "returns ok when called in the ObjectValidator", %{valid_like: valid_like} do
|
|
|
|
{:ok, object, _meta} = ObjectValidator.validate(valid_like, [])
|
|
|
|
|
|
|
|
assert "id" in Map.keys(object)
|
|
|
|
end
|
|
|
|
|
|
|
|
test "is valid for a valid object", %{valid_like: valid_like} do
|
|
|
|
assert LikeValidator.cast_and_validate(valid_like).valid?
|
|
|
|
end
|
|
|
|
|
2020-05-04 15:08:31 +00:00
|
|
|
test "sets the 'to' field to the object actor if no recipients are given", %{
|
|
|
|
valid_like: valid_like,
|
|
|
|
user: user
|
|
|
|
} do
|
|
|
|
without_recipients =
|
|
|
|
valid_like
|
|
|
|
|> Map.delete("to")
|
|
|
|
|
|
|
|
{:ok, object, _meta} = ObjectValidator.validate(without_recipients, [])
|
|
|
|
|
|
|
|
assert object["to"] == [user.ap_id]
|
|
|
|
end
|
|
|
|
|
2020-05-04 15:18:17 +00:00
|
|
|
test "sets the context field to the context of the object if no context is given", %{
|
|
|
|
valid_like: valid_like,
|
|
|
|
post_activity: post_activity
|
|
|
|
} do
|
|
|
|
without_context =
|
|
|
|
valid_like
|
|
|
|
|> Map.delete("context")
|
|
|
|
|
|
|
|
{:ok, object, _meta} = ObjectValidator.validate(without_context, [])
|
|
|
|
|
|
|
|
assert object["context"] == post_activity.data["context"]
|
|
|
|
end
|
|
|
|
|
2019-10-17 16:36:52 +00:00
|
|
|
test "it errors when the actor is missing or not known", %{valid_like: valid_like} do
|
|
|
|
without_actor = Map.delete(valid_like, "actor")
|
|
|
|
|
|
|
|
refute LikeValidator.cast_and_validate(without_actor).valid?
|
|
|
|
|
|
|
|
with_invalid_actor = Map.put(valid_like, "actor", "invalidactor")
|
|
|
|
|
|
|
|
refute LikeValidator.cast_and_validate(with_invalid_actor).valid?
|
|
|
|
end
|
|
|
|
|
|
|
|
test "it errors when the object is missing or not known", %{valid_like: valid_like} do
|
|
|
|
without_object = Map.delete(valid_like, "object")
|
|
|
|
|
|
|
|
refute LikeValidator.cast_and_validate(without_object).valid?
|
|
|
|
|
|
|
|
with_invalid_object = Map.put(valid_like, "object", "invalidobject")
|
|
|
|
|
|
|
|
refute LikeValidator.cast_and_validate(with_invalid_object).valid?
|
|
|
|
end
|
|
|
|
|
|
|
|
test "it errors when the actor has already like the object", %{
|
|
|
|
valid_like: valid_like,
|
|
|
|
user: user,
|
|
|
|
post_activity: post_activity
|
|
|
|
} do
|
|
|
|
_like = CommonAPI.favorite(user, post_activity.id)
|
|
|
|
|
|
|
|
refute LikeValidator.cast_and_validate(valid_like).valid?
|
|
|
|
end
|
|
|
|
|
|
|
|
test "it works when actor or object are wrapped in maps", %{valid_like: valid_like} do
|
|
|
|
wrapped_like =
|
|
|
|
valid_like
|
|
|
|
|> Map.put("actor", %{"id" => valid_like["actor"]})
|
|
|
|
|> Map.put("object", %{"id" => valid_like["object"]})
|
|
|
|
|
|
|
|
validated = LikeValidator.cast_and_validate(wrapped_like)
|
|
|
|
|
|
|
|
assert validated.valid?
|
|
|
|
|
|
|
|
assert {:actor, valid_like["actor"]} in validated.changes
|
|
|
|
assert {:object, valid_like["object"]} in validated.changes
|
|
|
|
end
|
|
|
|
end
|
2020-05-18 14:45:11 +00:00
|
|
|
|
|
|
|
describe "announces" do
|
|
|
|
setup do
|
|
|
|
user = insert(:user)
|
|
|
|
announcer = insert(:user)
|
|
|
|
{:ok, post_activity} = CommonAPI.post(user, %{status: "uguu"})
|
|
|
|
|
|
|
|
object = Object.normalize(post_activity, false)
|
|
|
|
{:ok, valid_announce, []} = Builder.announce(announcer, object)
|
|
|
|
|
|
|
|
%{
|
|
|
|
valid_announce: valid_announce,
|
|
|
|
user: user,
|
|
|
|
post_activity: post_activity,
|
|
|
|
announcer: announcer
|
|
|
|
}
|
|
|
|
end
|
|
|
|
|
|
|
|
test "returns ok for a valid announce", %{valid_announce: valid_announce} do
|
|
|
|
assert {:ok, _object, _meta} = ObjectValidator.validate(valid_announce, [])
|
|
|
|
end
|
|
|
|
|
|
|
|
test "returns an error if the object can't be found", %{valid_announce: valid_announce} do
|
|
|
|
without_object =
|
|
|
|
valid_announce
|
|
|
|
|> Map.delete("object")
|
|
|
|
|
|
|
|
{:error, cng} = ObjectValidator.validate(without_object, [])
|
|
|
|
|
|
|
|
assert {:object, {"can't be blank", [validation: :required]}} in cng.errors
|
|
|
|
|
|
|
|
nonexisting_object =
|
|
|
|
valid_announce
|
|
|
|
|> Map.put("object", "https://gensokyo.2hu/objects/99999999")
|
|
|
|
|
|
|
|
{:error, cng} = ObjectValidator.validate(nonexisting_object, [])
|
|
|
|
|
|
|
|
assert {:object, {"can't find object", []}} in cng.errors
|
|
|
|
end
|
|
|
|
|
|
|
|
test "returns an error if we don't have the actor", %{valid_announce: valid_announce} do
|
|
|
|
nonexisting_actor =
|
|
|
|
valid_announce
|
|
|
|
|> Map.put("actor", "https://gensokyo.2hu/users/raymoo")
|
|
|
|
|
|
|
|
{:error, cng} = ObjectValidator.validate(nonexisting_actor, [])
|
|
|
|
|
|
|
|
assert {:actor, {"can't find user", []}} in cng.errors
|
|
|
|
end
|
2020-05-18 14:54:10 +00:00
|
|
|
|
|
|
|
test "returns an error if the actor already announced the object", %{
|
|
|
|
valid_announce: valid_announce,
|
|
|
|
announcer: announcer,
|
|
|
|
post_activity: post_activity
|
|
|
|
} do
|
|
|
|
_announce = CommonAPI.repeat(post_activity.id, announcer)
|
|
|
|
|
|
|
|
{:error, cng} = ObjectValidator.validate(valid_announce, [])
|
|
|
|
|
|
|
|
assert {:actor, {"already announced this object", []}} in cng.errors
|
|
|
|
assert {:object, {"already announced by this actor", []}} in cng.errors
|
|
|
|
end
|
2020-05-21 11:58:18 +00:00
|
|
|
|
|
|
|
test "returns an error if the actor can't announce the object", %{
|
|
|
|
announcer: announcer,
|
|
|
|
user: user
|
|
|
|
} do
|
|
|
|
{:ok, post_activity} =
|
|
|
|
CommonAPI.post(user, %{status: "a secret post", visibility: "private"})
|
|
|
|
|
|
|
|
object = Object.normalize(post_activity, false)
|
|
|
|
|
|
|
|
# Another user can't announce it
|
|
|
|
{:ok, announce, []} = Builder.announce(announcer, object, public: false)
|
|
|
|
|
|
|
|
{:error, cng} = ObjectValidator.validate(announce, [])
|
|
|
|
|
|
|
|
assert {:actor, {"can not announce this object", []}} in cng.errors
|
|
|
|
|
|
|
|
# The actor of the object can announce it
|
|
|
|
{:ok, announce, []} = Builder.announce(user, object, public: false)
|
|
|
|
|
|
|
|
assert {:ok, _, _} = ObjectValidator.validate(announce, [])
|
|
|
|
|
2020-05-21 12:12:32 +00:00
|
|
|
# The actor of the object can not announce it publicly
|
2020-05-21 11:58:18 +00:00
|
|
|
{:ok, announce, []} = Builder.announce(user, object, public: true)
|
|
|
|
|
|
|
|
{:error, cng} = ObjectValidator.validate(announce, [])
|
|
|
|
|
|
|
|
assert {:actor, {"can not announce this object publicly", []}} in cng.errors
|
|
|
|
end
|
2020-05-18 14:45:11 +00:00
|
|
|
end
|
2020-06-19 13:30:30 +00:00
|
|
|
|
|
|
|
describe "updates" do
|
|
|
|
setup do
|
|
|
|
user = insert(:user)
|
|
|
|
|
|
|
|
object = %{
|
|
|
|
"id" => user.ap_id,
|
|
|
|
"name" => "A new name",
|
|
|
|
"summary" => "A new bio"
|
|
|
|
}
|
|
|
|
|
|
|
|
{:ok, valid_update, []} = Builder.update(user, object)
|
|
|
|
|
|
|
|
%{user: user, valid_update: valid_update}
|
|
|
|
end
|
|
|
|
|
|
|
|
test "validates a basic object", %{valid_update: valid_update} do
|
|
|
|
assert {:ok, _update, []} = ObjectValidator.validate(valid_update, [])
|
|
|
|
end
|
2020-06-19 14:38:57 +00:00
|
|
|
|
|
|
|
test "returns an error if the object can't be updated by the actor", %{
|
|
|
|
valid_update: valid_update
|
|
|
|
} do
|
|
|
|
other_user = insert(:user)
|
|
|
|
|
|
|
|
update =
|
|
|
|
valid_update
|
|
|
|
|> Map.put("actor", other_user.ap_id)
|
|
|
|
|
|
|
|
assert {:error, _cng} = ObjectValidator.validate(update, [])
|
|
|
|
end
|
2020-06-19 13:30:30 +00:00
|
|
|
end
|
2020-06-25 09:13:35 +00:00
|
|
|
|
|
|
|
describe "blocks" do
|
|
|
|
setup do
|
2020-06-26 09:58:40 +00:00
|
|
|
user = insert(:user, local: false)
|
2020-06-25 09:13:35 +00:00
|
|
|
blocked = insert(:user)
|
|
|
|
|
|
|
|
{:ok, valid_block, []} = Builder.block(user, blocked)
|
|
|
|
|
|
|
|
%{user: user, valid_block: valid_block}
|
|
|
|
end
|
|
|
|
|
|
|
|
test "validates a basic object", %{
|
|
|
|
valid_block: valid_block
|
|
|
|
} do
|
|
|
|
assert {:ok, _block, []} = ObjectValidator.validate(valid_block, [])
|
|
|
|
end
|
|
|
|
|
|
|
|
test "returns an error if we don't know the blocked user", %{
|
|
|
|
valid_block: valid_block
|
|
|
|
} do
|
|
|
|
block =
|
|
|
|
valid_block
|
|
|
|
|> Map.put("object", "https://gensokyo.2hu/users/raymoo")
|
|
|
|
|
|
|
|
assert {:error, _cng} = ObjectValidator.validate(block, [])
|
|
|
|
end
|
|
|
|
end
|
2019-10-17 16:36:52 +00:00
|
|
|
end
|