Respect visibility in API.

This commit is contained in:
lain 2018-02-18 15:50:34 +01:00
parent 5729233c36
commit 5d89997a70
3 changed files with 17 additions and 4 deletions

View file

@ -131,7 +131,9 @@ defmodule Pleroma.Web.ActivityPub.ActivityPub do
query = from activity in Activity,
where: fragment("?->>'type' = ? and ?->>'context' = ?", activity.data, "Create", activity.data, ^context),
order_by: [desc: :id]
query = restrict_blocked(query, opts)
query = query
|> restrict_blocked(opts)
|> restrict_recipients(["https://www.w3.org/ns/activitystreams#Public"], opts["user"])
Repo.all(query)
end
@ -313,4 +315,13 @@ defmodule Pleroma.Web.ActivityPub.ActivityPub do
end
end
end
def visible_for_user?(activity, nil) do
"https://www.w3.org/ns/activitystreams#Public" in (activity.data["to"] ++ (activity.data["cc"] || []))
end
def visible_for_user?(activity, user) do
x = [user.ap_id | user.following]
y = (activity.data["to"] ++ (activity.data["cc"] || []))
visible_for_user?(activity, nil) || Enum.any?(x, &(&1 in y))
end
end

View file

@ -190,14 +190,15 @@ defmodule Pleroma.Web.MastodonAPI.MastodonAPIController do
end
def get_status(%{assigns: %{user: user}} = conn, %{"id" => id}) do
with %Activity{} = activity <- Repo.get(Activity, id) do
with %Activity{} = activity <- Repo.get(Activity, id),
true <- ActivityPub.visible_for_user?(activity, user) do
render conn, StatusView, "status.json", %{activity: activity, for: user}
end
end
def get_context(%{assigns: %{user: user}} = conn, %{"id" => id}) do
with %Activity{} = activity <- Repo.get(Activity, id),
activities <- ActivityPub.fetch_activities_for_context(activity.data["object"]["context"], %{"blocking_user" => user}),
activities <- ActivityPub.fetch_activities_for_context(activity.data["object"]["context"], %{"blocking_user" => user, "user" => user}),
activities <- activities |> Enum.filter(fn (%{id: aid}) -> to_string(aid) != to_string(id) end),
activities <- activities |> Enum.filter(fn (%{data: %{"type" => type}}) -> type == "Create" end),
grouped_activities <- Enum.group_by(activities, fn (%{id: id}) -> id < activity.id end) do

View file

@ -56,7 +56,8 @@ defmodule Pleroma.Web.TwitterAPI.TwitterAPI do
end
def fetch_status(user, id) do
with %Activity{} = activity <- Repo.get(Activity, id) do
with %Activity{} = activity <- Repo.get(Activity, id),
true <- ActivityPub.visible_for_user?(activity, user) do
activity_to_status(activity, %{for: user})
end
end